Cyber Insurance Readiness
Cyber Insurance Readiness Assessment — Melbourne
Get the documented evidence your insurer needs. Fixed price. Fixed timeline. No surprises.
The Problem
Insurers want evidence. Most SMBs don't have it.
The cyber insurance landscape has shifted. Insurers now require documented evidence of security controls before issuing or renewing policies. Renewals are harder. Premiums are higher. And most SMBs don't know exactly what's missing until they're told they're uninsurable.
A structured assessment gives you a clear picture of where you stand, what gaps exist, and what to fix first — documented in a format your broker and underwriter can use.
Assessment Scope
Six control areas. Every one of them matters.
The assessment covers the six domains that Australian cyber insurance underwriters consistently ask about.
Access Control & MFA
Account policies, multi-factor authentication coverage, offboarding processes, and privilege separation. MFA absence is the top reason for policy refusals.
Patch Management
Device inventory, OS and application patching cadence, end-of-life systems, and endpoint protection tooling. Unpatched systems are the leading ransomware entry point.
Backup & Recovery
Backup frequency, offsite and immutable storage, tested recovery capability, and documented RTO/RPO. Tested backups are the most effective ransomware mitigation.
Email & Phishing Controls
DMARC, DKIM, and SPF configuration, email filtering capability, phishing awareness training, and BEC exposure. BEC is the highest-frequency claim type in Australia.
Incident Response Readiness
Documented incident response plan, designated contacts, regulatory notification obligations, and tabletop exercise history. A tested IRP cuts breach costs significantly.
Vendor & Third-Party Risk
Vendor register, contract security obligations, critical supplier identification, and supply chain monitoring. Third-party access is now involved in over 60% of breaches.
What You Receive
The deliverable
An 8-10 page PDF report covering all six control areas. Each area gets a RAG rating (Red, Amber, Green), a summary of current state, identified gaps, and specific recommended actions — not generic advice.
The report includes a 90-day remediation roadmap prioritised by risk and effort. It is written to be shared with your insurance broker, underwriter, or board.
This is an advisory assessment only. It does not include penetration testing, live system access, or any certification. It gives you a structured, documented baseline.
Pricing
$750 AUD — flat fee
One fixed price. No scope creep. Delivered in 10 business days from receipt of your completed questionnaire and payment. Payment required upfront before work commences.
What the $750 includes
Advisory only. No penetration testing. No access to live systems. Total liability capped at engagement fee per the engagement letter. Victorian governing law.