All insights
Local Government May 25, 2026 7 min read

Cyber Insurance for Local Government: What Underwriters Want

Cyber insurance used to be a simple box to tick at renewal. For Australian councils it is now one of the harder line items to secure, and the application itself has become a de facto audit of your security program. Underwriters have been burned by public sector ransomware claims, and they price that experience into every quote. The good news is that the controls insurers reward are the same ones that genuinely reduce your risk, so the work pays off twice.

How the market changed and why it matters to councils

After a wave of costly ransomware and data breach claims, insurers re-underwrote the entire cyber market. Premiums climbed, sub-limits and exclusions multiplied, and the application questionnaires grew from a single page to detailed control attestations. Councils sit in a category insurers watch closely because of the sensitive data they hold, the essential services they run, and a sector-wide reputation for legacy systems and stretched IT teams.

The practical effect is that cover is no longer guaranteed at any price. Some councils have been declined, others quoted premiums that strain already tight budgets, and many have had ransomware coverage capped or carved out. Treating the renewal as an annual scramble is a losing strategy. The councils getting reasonable terms are the ones that can produce evidence, not just assurances.

The controls underwriters look for first

Underwriters do not expect perfection, but they do expect a credible baseline. A handful of controls carry disproportionate weight because they are the ones that historically stop or limit a claim. Expect close questioning on each of these:

  • Multi-factor authentication. On email, remote access, privileged accounts and admin interfaces. This is the single biggest pass-or-fail factor.
  • Backups that are tested and offline. Insurers want to know your backups are isolated from the network and that you have actually restored from them, because that is what defeats a ransomware demand.
  • Endpoint detection and response. Modern endpoint protection that detects and contains threats, not just legacy antivirus.
  • Patching discipline. Evidence that you apply security patches to operating systems and applications within a defined timeframe, especially for internet-facing services.
  • Privileged access management. Limiting who has administrator rights and how those accounts are protected and monitored.
  • Email filtering and awareness training. Because phishing remains the most common entry point.
  • An incident response plan. A documented, tested plan signals that a claim will be managed competently and contained quickly.

Why the Essential Eight is your shortcut to a strong application

If that list looks familiar, it should. It maps almost directly onto the Australian Signals Directorate’s Essential Eight. Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, configure macro settings, harden user applications and regular backups together cover most of what an underwriter wants to see. Working towards a defined Essential Eight maturity level is the most efficient way to prepare for an insurance application, because it gives you both the controls and the documentation in one program of work.

If you are early in that journey, our Essential Eight explained guide walks through each mitigation strategy and the maturity levels in plain language. For councils that want a structured implementation tied to a roadmap, our Essential Eight service is built for lean government teams.

Understand what the policy actually covers

Before you focus only on getting approved, make sure the cover you are buying matches the risks a council actually faces. Cyber policies vary widely, and two quotes at similar premiums can offer very different protection. Read the schedule carefully and have your broker explain each component in plain language. The elements that matter most to councils include:

  • Incident response costs. Funding for forensic investigation, legal advice and crisis communications, often through the insurer’s panel of providers.
  • Business interruption. Cover for lost revenue and extra costs when services are disrupted, which for councils can include the cost of running manual workarounds.
  • Data recovery and system restoration. The expense of rebuilding systems and recovering data after an attack.
  • Notification and credit monitoring. The cost of meeting your obligations to affected residents after a data breach.
  • Third-party liability. Claims from individuals or organisations whose data you held.
  • Cyber extortion. Cover related to ransomware, which is increasingly capped, sub-limited or excluded, so check this closely.

Pay particular attention to exclusions, waiting periods and sub-limits. A policy that looks comprehensive can quietly cap the very cover you would rely on most. If ransomware is sub-limited to a fraction of the total, you need to know that before, not after, an incident.

Evidence beats assurances

One of the most important shifts in cyber underwriting is the move from “do you have this control” to “prove it”. When you complete an application, you are making attestations the insurer relies on. If you declare that MFA covers all remote access and a later claim reveals a gap, the insurer can reduce or deny the payout. That makes accuracy a governance issue, not just an IT one.

Before you sign, make sure the person completing the questionnaire actually understands the current state of your environment, including any shadow systems, third-party connections and exceptions granted for legacy applications. Where a control is partially implemented, say so and describe your remediation timeline rather than overstating. Honest, well-documented applications tend to secure better terms than optimistic ones, and they protect you at claim time.

Practical steps for a lean council team

You do not need a large security function to present well to an underwriter. You need to start early and be methodical:

  1. Begin three months before renewal. Gathering evidence and closing gaps takes longer than expected on a stretched team.
  2. Run a gap assessment against the questionnaire. Use last year’s application or a current insurer template to find your weak points now.
  3. Close the high-impact, low-cost gaps first. Enabling MFA on remote and admin access and verifying offline backups often move you from uninsurable to insurable.
  4. Assemble an evidence pack. Screenshots, policy documents, backup test results and your incident response plan, ready to attach.
  5. Brief your broker. A broker who can articulate your control improvements to the market will get you better quotes than a bare questionnaire.

Know how the policy behaves during a real claim

An insurance policy is only as useful as the way it performs when you actually need it, so understand the claims mechanics before you sign. Most cyber policies require you to notify the insurer promptly and to use their approved panel of forensic and legal providers. If you call your usual IT contractor first and start rebuilding systems before notifying the insurer, you can inadvertently breach the policy conditions and jeopardise the claim. Make sure your incident response plan names the insurer’s hotline as one of the first calls.

It also pays to know who holds the relationship internally. The person who manages the renewal, the person who would notify a claim, and the person who leads your technical response are often three different people, and in a crisis they need to act in concert. Walk through a claim scenario as part of your annual tabletop exercise so the insurer’s requirements are baked into your muscle memory rather than discovered under pressure.

Insurance is a backstop, not a strategy

It is worth being clear-eyed about what cyber insurance does and does not do. It can help fund recovery, legal advice, forensic investigation and notification costs after an incident. It does not prevent the incident, restore community trust, or guarantee a payout if your declared controls were not in place. As coverage narrows and exclusions grow, the smartest investment a council can make is in the controls themselves, with insurance covering the residual risk that remains.

CISO Advisory helps councils prepare for renewals, close the control gaps underwriters care about, and present a credible application without the cost of a full-time security hire. A Virtual CISO engagement can run your gap assessment, build the evidence pack and align your program to the Essential Eight ahead of renewal. To get ahead of your next renewal, call 07 2112 8502 or explore our work in government and council cybersecurity.

Frequently asked questions

Why has cyber insurance become so hard for councils to get?

Insurers paid out heavily on ransomware claims across the public sector, so they tightened underwriting sharply. Premiums rose, coverage narrowed, and applications now require evidence of specific controls. Councils that cannot demonstrate basics like multi-factor authentication and tested backups may be declined or quoted at uneconomic rates.

What single control most affects whether we can get cover?

Multi-factor authentication is the clearest dividing line. Underwriters expect MFA on email, remote access, privileged accounts and administrative interfaces. Many insurers will simply decline a council that cannot confirm MFA on remote and admin access, regardless of how strong the rest of the application looks.

Will having cyber insurance let us relax on prevention?

No. Cover is shrinking, exclusions are growing, and a claim can be reduced or refused if the controls you declared were not actually in place. Insurance is a backstop for residual risk, not a substitute for prevention. Underwriters now reward councils that invest in controls with better terms.

Does the Essential Eight help with insurance applications?

Yes, significantly. The Essential Eight maps closely to the controls underwriters ask about, including patching, backups, MFA, application control and restricting admin privileges. Working towards a defined maturity level gives you ready answers to most application questions and demonstrable evidence to support them.

How long before renewal should we start preparing?

Begin at least three months out. Gathering evidence, closing control gaps and assembling documentation takes time, especially for a lean team. Starting early also means you can fix a missing control before it costs you a higher premium or a declined renewal rather than scrambling in the final week.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act