| Cyber insurance can help pay specified costs following a covered incident, such as investigation, recovery, business interruption and liability claims. What it pays depends on the policy, its limits and conditions, and the circumstances of the loss. Before applying or renewing, check that your technical answers describe what is actually in place. |
Consider this example. A renewal form lands on the office manager’s desk in October. Somewhere in the cyber insurance renewal’s forty-odd questions it asks whether the business uses multi-factor authentication. She forwards it to the IT provider, the IT provider writes yes, and the cyber insurance renewal goes back in the post.
Eighteen months later there is a claim, and an assessor is reading that form next to the sign-in logs. Multi-factor authentication was on for most people. The finance team had an exemption from a project two years earlier that nobody switched back.
That gap, between a tick box and what was actually running on the day, is what cyber insurance preparation is for. A gap is a reason to investigate and disclose accurately. It is not by itself enough to predict how a claim would be decided.
Before going further: we do not sell cyber insurance and we are not brokers, so nothing here tells you which policy to buy or what limit to carry. Your broker advises on cover and policy terms. What we see is the other half of the transaction, where an insurer asks a long set of questions about how the IT is run and somebody has to produce the evidence behind every answer. Parts of that answer sit with your IT provider, parts with internal staff, software suppliers or the business owner, so the first job is working out who holds which part.
This covers the kind of questions insurers ask, what can put a cyber insurance claim in dispute, what cover may include, what to keep on file, and where our lane ends and a broker’s begins.
What Do Insurers Ask For Before They Will Cover You?
Insurers may ask how you protect email and remote access, manage security updates, back up data, train staff and respond to incidents. The questions, and the controls a particular insurer requires, vary by insurer and by business, so work from the actual form rather than a generic checklist. QBE publishes a New Zealand cyber insurance proposal form for businesses below NZD 250 million revenue, and it is a useful concrete example: it asks about multi-factor authentication scope, security-product coverage, backup frequency and annual awareness activity, some questions apply only above a revenue threshold, and the security operations centre question offers both business-hours and round-the-clock options. That variation is the point.
| Typical question area | The vague answer | What supports an accurate answer |
|---|---|---|
| Multi-factor authentication | Yes, we have MFA | Coverage report by user and system, with exclusions named |
| Backups | Yes, we back up nightly | Date and result of the last restore test |
| Patching | We keep things updated | Patch compliance percentage and the stated window |
| Endpoint detection | We have antivirus | The product, what it covers, and who watches the alerts |
| Staff training | We run training | Completion rates and phishing simulation click rate |
| Incident response plan | We would call our IT provider | A written plan naming who decides and who notifies |
The cyber insurance questions are specific enough that a vague answer reads as a vague answer. The proposal form, the declaration, the policy wording, the schedule and any endorsements have to be read together, so ask your broker which controls must be maintained during the period of cover and which changes have to be notified.

Remember what that form legally is. The business is signing a set of representations, and an assessor is entitled to hold you to them eighteen months later, when the circumstances are considerably less relaxed. Signing off on those answers is a governance responsibility, not a form-filling exercise.
Yes to multi-factor authentication when one team has an exemption, and yes to backups when nobody has attempted a restore this year, are the two we are asked about most often. Neither is dishonesty. They are the distance between what was configured once and what is running today, and nobody looked in between.
Scope catches people out as well. Cyber insurance questions cover the whole environment, which includes the server nobody uses, the old domain still pointing somewhere, and the site that arrived with an acquisition. Those are precisely the corners missing a control, and the corners nobody has in mind while filling in a form.
So answer it with the people responsible for each system, and answer it accurately and completely. Multi-factor authentication on email and remote access, with three named service accounts excluded, is a better answer than a bare yes. Where something is partial, say so, describe the limitation and any alternative safeguards, and keep a planned rollout separate from the current answer, because a plan is not a control already operating.
Disclosing a gap does not guarantee it will be accepted, or simply priced differently. What it does is let the underwriter assess the risk they are actually taking, and let your broker tell you what it means for the terms on offer.
The questions have also moved past the perimeter. Expect to be asked who holds administrative rights, whether those accounts have separate credentials, how fast a leaver loses access, and which suppliers can reach your data.
That last one surprises people. If a bookkeeper, a software vendor or an offshore support team can reach your systems, a cyber insurance underwriter treats their security as part of yours, and will want to know what your contract with them requires.
Why Do Cyber Insurance Claims Get Declined?
A cyber insurance claim may be disputed, or fall outside cover, because of the type of event or loss, an exclusion, inaccurate information given at application, an unmet policy condition, or notification and consent requirements. Which of those applies depends on the facts, the policy and the applicable law. Technical records help explain what happened, and they do not decide coverage by themselves.
Three situations come up repeatedly in the technical conversations we have. A control described as universal turns out to have exceptions. A backup existed but had never been proved to restore. Or money left because somebody in the finance team authorised the payment, which is treated as social engineering and may be included, optional, limited or excluded depending on the policy. None of those decides an outcome on its own, and each is worth resolving with your broker before it is tested.
That third one catches New Zealand businesses out. The expensive incident here is an invoice redirection, one of the phishing scams aimed at finance teams, and it looks like an ordinary bank transfer approved by an ordinary person having an ordinary Tuesday.
QBE lists social engineering losses among the categories its New Zealand cyber cover includes, which is a useful reminder that this varies by product rather than being absent as a rule. Ask specifically about payments authorised by deceived staff, any sublimit that applies, and the verification conditions attached, and read the schedule alongside the full wording rather than on its own.
Timing is the one nobody plans for. Before an incident, confirm the insurer emergency contact, the notification requirements and any approval needed for response costs, and put them alongside your IT contact in the incident response plan. Wordings set out prompt notice, reporting limits and consent provisions rather than one universal number of hours, so check what yours says. Some policies require approved responders, which means calling your usual forensics firm first can start an argument about who pays for them. Do not wait for a complete investigation before asking whether notification is required.
There is a version of all this that is nobody’s fault. A control was accurate in March, drifted by September, and no one thought to revisit a form that had already been filed. Cyber insurance is priced on a snapshot and claimed against a moving picture.
The guard is to treat the form as a live document, not an annual chore. A new site, a new system, a control paused for a project: tell the broker when it happens, not when you need them.
It costs an email. The alternative is discovering at the worst possible moment that the business you insured in March is not the business you were running in November, and having that conversation for the first time during a claim.
None of this makes cyber insurance a poor purchase. It makes it a product with conditions attached, in the way a commercial building policy has conditions about alarms and locks. The difference is that everybody understands the alarm. Very few owners could say today whether every account in the business has multi-factor authentication on it.
What Evidence Should You Be Keeping?
Follow the information your broker and your insurer actually ask for, and keep it where you can find it. The point of cyber insurance evidence is that it exists before anybody asks for it. In practice that often means the same handful of records: how much of the estate is patched, who holds administrative rights, what alerts came in and what was done about each, and when a restore was last proved to work.

A provider already reporting on those will have them to hand. One that has to assemble them from scratch is telling you the reporting was not built into the service.
Keep the signed form with them, noting who supplied each technical answer and when. If an assessor ever asks how a particular yes came to be written, you want a name and a date, not a shrug.
Training records belong in the same folder. Completion rates and phishing simulation results are the standard proof that the staff-training answer meant something, and they are the first thing to lapse. A programme that ran once in March is not a programme, and an insurer reading a single completion date will draw exactly that conclusion.
Then preserve the incident itself if one happens. The message, the sign-in logs and any mailbox rules the attacker created all matter to an assessor, and an inbox somebody has tidied up is an empty evidence trail.
None of this is heavy work once it is routine. A monthly report somebody already runs, saved where you can put your hand on it, and a record of who answered what. It will not decide a cyber insurance claim on its own, and it is what you will be asked for.
What Does Cyber Insurance Actually Cover?
Cyber insurance is usually built around two sides: your own costs after an incident, and other people making claims against you. Most New Zealand policies follow that split, and what sits on each side is set by the wording rather than by the split itself, so treat everything below as possible cover rather than a guaranteed inclusion.
On your side sit the things that start happening early. Forensic investigation to establish what was reached, the cost of restoring systems and data, income lost while you cannot trade, and the expense of telling customers and regulators. Extortion cover may sit here too, subject to the policy, to the payment being lawful, and to any consent the insurer requires.
On the other side sit the consequences that arrive later. Claims from customers or suppliers whose data was exposed, the cost of defending a regulatory investigation, and in some wordings the penalties that follow one.
Several things change the answer more than the section headings do: the excess, any sublimits, the waiting period before interruption cover starts, which entities are insured, and whether you have to use approved response providers. Ask about those specifically.
QBE publishes its New Zealand cyber cover in detail, listing network security and privacy liability, privacy regulatory proceedings, media liability, event expenses, network extortion, business interruption, dependent business interruption, bricking, consequential reputational loss, reward funds, cryptojacking and social engineering losses. Read that as one insurer example of the possible shape rather than a cyber insurance market standard, and assume every insurer words it differently.
The limits of a policy are more useful to know than the inclusions, because they are where the surprises live, and each one is a question about your wording rather than a rule. Ask how losses authorised by your own deceived staff are treated. Ask how the policy handles an incident that began before inception, because the relevant dates can include the act, the discovery, the claim and the notification, alongside any prior-knowledge exclusion and any retroactive date. Ask how the security conditions and exclusions apply to a known unpatched vulnerability, rather than assuming any such loss automatically falls outside cover.
Contractual penalties are often treated differently from regulatory ones, so ask which your wording covers. The cost of improving security afterwards is not automatically excluded either: QBE includes betterment expenses to provide enhancement to network protections after an event, so whether you have that depends on the product. Insurance also cannot remove a statutory duty or restore trust, though some products cover specified reputational losses, regulatory defence costs, or penalties that can lawfully be insured. Separate the obligations from the costs that might be funded.
None of that is a substitute for reading your own cyber insurance schedule. Wordings differ enough between insurers that two policies with the same name behave differently on the same loss, and which one you hold is a question for the person who sold it to you.
What Does a Cyber Incident Cost a New Zealand Business?
QBE puts the average New Zealand SME breach at NZ$173,000 and says one in two cyber events here target small and medium businesses. QBE does not publish what that average includes or excludes, so take it as a published figure rather than a breakdown of costs.
It does not buy back the clients who go quiet, or the contract that stalls while you explain what happened. Those costs land months later, nobody sends you an invoice for them, and they are the ones owners tell us actually stung.
The national picture sits alongside it. The NCSC recorded 1,129 incident reports between April and June 2026, of which 92 were triaged for specialist technical support because of their potential national significance rather than because they were the most severe. Those are national figures covering individuals as well as organisations, not insurance claims data and not businesses alone.
Costs vary with the systems affected, how long trading is interrupted, what data was exposed and the response required. A national average does not establish a suitable cyber insurance limit for your business, which is a question for your broker.
What decides which one you get comes down to three things: whether the attacker got past the login, whether the backup restored, and how quickly somebody noticed.
There is a regulatory duty running underneath all of it, and it applies whether or not you hold cover. Where there are reasonable grounds to believe a privacy breach has caused, or is likely to cause, serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and the people affected as soon as practicable, subject to the exceptions in the Act. A privacy breach is not only exposure of information, because loss of access to it can also count. Cyber insurance may fund some of the response costs. It does nothing about the duty itself, so assess that separately from whether the event is covered.
Who Should You Ask About Cover, Limits and Wording?
A broker, and not us. Which policy suits your business, what limit is sensible, how a particular wording treats a particular loss, and whether an endorsement is worth buying are regulated financial advice, which has to be provided under a licensed financial advice provider.
If you do not have a broker, IBANZ lists its members and insurers will point you the same way.
Exodesk helps with the technical questions: which systems are covered, which controls are operating and where limitations remain. We can confirm the environment we manage, identify where another party has to supply part of the answer, and agree what to do about any gaps. We do not sell cyber insurance or recommend policies or limits.
Keep that division clear in your own mind too. If somebody offers to advise you on the controls and the cover in the same breath, ask how their advice service is authorised and what it covers.
Put both parties in one conversation before renewal rather than after a claim. The broker knows what the market is asking this year, and your managed IT provider can confirm what is actually running.
What Should You Do Before Your Next Renewal?
Before renewal, compare the previous cyber insurance application with your current systems and with the new questions. Sit the people responsible for each system beside you, mark every answer that has moved or was written hopefully, confirm the answers with them, explain any changes or gaps, and agree the next actions with your broker.
Deal with the straightforward ones first. A multi-factor authentication gap and a restore test nobody has run are the two that come up most often. Agree the remediation scope and a realistic timeframe rather than assuming either is a quick job, because how long they take depends on the environment they sit in.
Ask for those records in writing while you are there, because the habit is easier to build now than during the week something has gone wrong. A security review is another way to get a considered picture of where you stand.
Then hand the broker an accurate picture of what a cyber insurance underwriter would find. A business that can evidence its controls is a better risk, and being a better risk is the only lever in this whole arrangement that you control.
Good controls support risk management. They do not guarantee that cover will be available, that terms will improve, or that a cyber insurance claim will be paid, and your broker is the person who can say what they are worth in the market this year.
Review material changes during the year according to what the policy requires, rather than waiting for renewal, and put a reminder in for the same exercise next year. Questions and conditions change between renewals, and nobody writes to tell you.
The point of all this was never the premium. It is that the cover behaves the way you assumed it would, on the one day you find out.
Frequently Asked Questions
What is cyber insurance?
Cyber insurance can help pay specified costs following a covered incident: investigation, recovery, business interruption, liability claims, notification and, where the policy allows, extortion. It prevents nothing and removes none of your obligations under the Privacy Act. What it pays depends on the policy, its limits and conditions, and the circumstances of the loss, so that conversation belongs with a broker.
What controls do insurers expect to see?
There is no single list. Insurers may ask how you protect email and remote access, manage security updates, back up data, train staff and respond to incidents, and the questions and required controls vary by insurer and by business. Work from the actual form with the people responsible for each system, and ask your broker which controls have to be maintained during the period of cover.
What is the most common reason a claim is refused?
There is no published ranking to draw on. A claim may be disputed, or fall outside cover, because of the type of event or loss, an exclusion, inaccurate information given at application, an unmet condition, or notification and consent requirements. Which of those applies depends on the facts, the policy and the applicable law.
Does cyber insurance cover invoice fraud and business email compromise?
That depends on the policy. Losses where your own deceived staff authorised a payment are usually treated as social engineering, which may be included, optional, limited or excluded. QBE lists social engineering losses among the categories its New Zealand cover includes, which shows it varies by product. Ask your broker about sublimits and any verification conditions, and get the answer in writing.
What is the average cost of a breach in New Zealand?
QBE puts the average New Zealand SME breach at NZ$173,000 and reports that one in two cyber events here target small and medium businesses. QBE does not publish what that average includes, and a national average does not establish a suitable limit for your business. Costs vary with the systems affected, how long trading is interrupted, what data was exposed and the response required.
Do we still have to notify the Privacy Commissioner if we are insured?
Yes. Insurance does not remove your Privacy Act obligations. Where there are reasonable grounds to believe a privacy breach has caused, or is likely to cause, serious harm, notification to the Privacy Commissioner and the affected people is required as soon as practicable, subject to the exceptions in the Act. Assess that separately from whether the event is covered by your policy.
What evidence should we keep for a cyber insurance claim?
Follow the information your broker and your insurer actually ask for. In practice that often means how much of the estate is patched, who holds administrative rights, which alerts were raised and how each was resolved, and when a restore was last proved to work. Keep the signed proposal form too, with a note of who answered what and on what date.
Can our IT provider fill in the cyber insurance proposal form?
They should be involved, because they hold part of the answer, though internal staff, software suppliers and the business owner may hold other parts. The business signs the form, so the answers need to be accurate and complete, with exceptions and limitations described. If something is partly done, record it that way and keep a planned rollout separate from a control already operating.
Does having cyber insurance mean we can spend less on security?
No. Insurers assess the controls you can evidence, so weaker controls can mean a higher premium, tighter conditions or no offer. Good controls support risk management, and they do not guarantee that cover will be available or that a claim will be paid. Cover also does nothing about your regulatory obligations.
Can an IT company advise on which policy to buy?
Recommending a product, a limit or an interpretation of wording is regulated financial advice, which has to be provided under a licensed financial advice provider. That turns on the authorisation and scope of the advice service rather than on whether the organisation also does IT. Exodesk does not provide it. IBANZ lists broker members if you do not already have one.
How does Exodesk help with cyber insurance?
We work on the technical side. We can tell you and your broker which systems are covered, which controls are operating and where limitations remain, confirm the environment we manage, and identify where another party has to supply part of the answer. We do not sell cyber insurance or recommend policies, limits or wording.
Which losses are usually excluded from a policy?
That is a question about your wording rather than a general rule. Ask how losses authorised by deceived staff are treated, how an incident that began before inception is handled given the act, discovery, claim and notification dates, any prior-knowledge exclusion and any retroactive date, and how the security conditions apply to a known unpatched vulnerability. Contractual penalties are often treated differently from regulatory ones, and the cost of improving security afterwards is not automatically excluded.
NEXT STEP
Get the technical answers ready before renewal
Ask Exodesk to help check the security questions in your cyber insurance application. We can confirm the controls within our agreed scope and discuss the gaps that need attention, while your broker handles cover, limits and policy terms.
Start with an IT assessment.

