Skip to main content
Whitesec AU
Back to Insights

Risk Management31 July 2026

Cyber Insurance Proposal Forms: Where Answers and Reality Diverge

Whitesec Intelligence Team
Executive Summary

A cyber policy is priced on what you declare. When a claim is investigated, the declaration is compared against the environment as it actually was — and Section 28 of the Insurance Contracts Act sits behind that comparison.

Cyber insurance proposal forms look like compliance paperwork. They are closer to a sworn statement. Every control you tick contributes to how the policy is priced, and every control you tick is available to a claims investigator later.

The risk is rarely deliberate misrepresentation. It is that the person completing the form and the person who knows the configuration are usually not the same person.

What Section 28 actually does

Under Section 28 of the Insurance Contracts Act 1984 (Cth), an insurer's remedies depend on the nature of the misrepresentation. Where a failure to disclose or a misrepresentation was fraudulent, the insurer may avoid the contract. Where it was not fraudulent, the insurer's liability may be reduced to the position it would have been in had the disclosure been accurate.

That second limb is the one that catches organisations off guard. There is no need to prove intent. If the environment did not match the declaration, the payout can be reduced to reflect what the insurer would have offered had it known.

The four answers that most often diverge

"Multi-factor authentication is enforced on all remote access"

Usually true for the VPN. Frequently untrue for a legacy webmail path, a vendor jump host, or a break-glass account exempted during a migration and never re-enrolled. The declaration says "all".

"Backups are immutable and stored offline"

Often the backup platform supports immutability and it was enabled for the primary job. Secondary jobs added later inherit different settings. Whether an unprivileged account can delete a backup is a question with a testable answer.

"Endpoint detection and response is deployed across the fleet"

Coverage is usually strong on managed corporate laptops. Servers, contractor devices, and OT-adjacent machines are where gaps sit. A claims investigator will ask for the agent inventory and compare it against the asset register.

"Privileged accounts are reviewed regularly"

The review may genuinely happen. Whether it is documented, dated, and shows accounts being removed is a different question — and documentation is what survives an investigation.

Why the gap is structural, not careless

Proposal forms are typically completed by a broker-facing person under time pressure, drawing on what the IT team said last quarter. The environment, meanwhile, changes weekly. Nobody is being dishonest; the form is simply a snapshot taken from memory rather than from the systems.

The asymmetry only becomes visible after an incident, when the insurer has forensic access to the environment and the organisation has a claim to defend.

Closing the gap before renewal

The practical fix is to treat the proposal form as an audit scope. Before submission:

  • Take each control statement on the form and identify the system of record that proves it
  • Export the evidence — policy configurations, agent inventories, retention settings, review records
  • Note every exception, however small, and decide whether to remediate it or disclose it
  • Keep the evidence pack with the policy documents, dated to the submission

Disclosed exceptions are manageable. Undisclosed ones are the problem. An insurer that knows about a legacy authentication path can price it; an insurer that discovers it during a claim investigation has a different conversation.

What this is worth commercially

Brokers negotiate better terms when control maturity is demonstrable rather than asserted. More importantly, the organisation knows what it actually has — which is the same information you need for an Essential Eight assessment, an ISO 27001 Statement of Applicability, or a supply chain questionnaire.

The evidence gathered for one of these exercises answers most of the others. The proposal form is simply the version with a legal consequence attached.

WS

Written by Whitesec Intelligence Team

Offensive Security Practitioners & ISO 27001 Auditors

Whitesec AU is an accredited Australian cybersecurity firm providing VAPT, Essential Eight gap analysis, CPS 234 compliance, and vCISO governance out of Perth, WA.

Need Technical Verification for Your Security Posture?

Speak with our Perth-based consultants to discuss your audit, tender, or penetration testing requirements.