Cyber insurance requirements in NZ have tightened sharply. A proposal form that once asked whether you ran antivirus and a firewall now demands proof of multi-factor authentication, endpoint detection and response, tested backups and a written incident response plan, and underwriters verify those answers when a claim arrives.
This guide sets out the cyber insurance requirements NZ underwriters apply in 2026, explains why applications and claims get declined, and lists the exact evidence to prepare before your next renewal. It is written for owners and finance managers of businesses with 20 to 200 staff. OxygenIT has delivered IT and security from Christchurch since 2005, holds ISO 27001 and ISO 42001 certification, and completes these proposal forms alongside clients every month.
What do NZ cyber insurers require in 2026?
NZ cyber insurers in 2026 require five baseline controls: multi-factor authentication on email, remote access and administrator accounts, endpoint detection and response on every device, tested backups with an offline or immutable copy, enforced email authentication, and a documented incident response plan. Miss any one and expect a loaded premium, restrictive exclusions or a declined application.
Each of the five carries specific expectations:
- MFA everywhere. Multi-factor authentication on email, VPN and remote access, and every administrator account. Partial rollouts no longer pass. Underwriters increasingly ask for MFA on all users, including contractors and third parties with access to your systems.
- EDR on every endpoint. Endpoint detection and response has replaced traditional antivirus as the baseline. For cyber insurance purposes, EDR means an agent on every workstation and server, with someone watching the alerts and able to isolate a compromised machine.
- Tested, immutable backups. A backup that has never been restored is a hope, not a control. Insurers want an offline or immutable copy that ransomware cannot encrypt, plus a recent, documented restore test.
- Email security. SPF, DKIM and DMARC on every sending domain, with the DMARC policy enforced, plus phishing filtering. Business email compromise drives a large share of NZ claims.
- A documented incident response plan. A dated plan naming who declares an incident, who calls the insurer and broker, and who talks to staff and customers in the first 24 hours.
Ask a broker what do cyber insurers require beyond these five and the answers vary between insurers, but this list is the consistent core across the NZ market. We unpack the individual proposal form questions in our guide to the questions NZ cyber insurance underwriters ask, which pairs each question with the configuration that sits behind a truthful yes.
Why do cyber insurers decline claims?
Cyber insurers decline claims mainly for misrepresentation: the proposal form said a control was in place and the post-incident investigation found it was not. MFA is the most common gap. In serious cases the insurer can rescind the policy entirely, which leaves the business carrying the full cost of the breach.
The cautionary example NZ underwriters cite is American. In 2022, US insurer Travelers issued a cyber policy to International Control Services, an Illinois electronics manufacturer, after the company attested in its application that multi-factor authentication was in place. A ransomware attack in May 2022 triggered a claim, the investigation found MFA had not been deployed as declared, and Travelers filed suit seeking rescission. The matter, Travelers Property Casualty v International Control Services, ended with the policy rescinded, treated as though cover had never existed. It is a United States case, not a New Zealand one, but underwriters here raise it constantly because the same mechanism operates in this market.
Under NZ law an insurer can avoid a policy for material misrepresentation, and an answer about MFA is about as material as it gets. Treat the proposal form like a financial declaration: answer yes only when the control is fully deployed and you hold the evidence. If a control covers most systems but not all of them, say so. A qualified honest answer may cost slightly more in premium. A confident answer that fails investigation can cost the entire claim, and the cover itself.
What should be on your cyber insurance readiness checklist?
A useful cyber insurance checklist pairs every control with the evidence an underwriter accepts. Screenshots, exports and dated logs carry weight; verbal assurances do not. Build the evidence file before you complete the proposal form, so every yes can be proven if the insurer, or an incident investigator, later asks to see the workings.
| Control | Evidence an underwriter accepts |
|---|---|
| MFA on email, remote access and admin accounts | Conditional access policy export or a screenshot showing MFA enforced for every user |
| EDR on every endpoint | Agent deployment report from the EDR console listing all covered devices |
| Backups with an offline or immutable copy | Restore test log showing the date, the data restored and who ran the test |
| Email authentication | DNS record export showing the DMARC policy at p=reject or p=quarantine |
| Incident response plan | Dated document with named roles and the date of the last review or exercise |
| Awareness training | Completion report from the training platform covering all current staff |
Most of this table is a configuration and reporting exercise for whoever runs your IT. Our IT security services generate the evidence as a by-product of normal managed security: the EDR console produces the deployment report, the backup platform logs restore tests, and the training platform tracks completions. If your current provider cannot produce these artefacts within a week, that is itself a finding worth acting on.
How much does cyber risk cost NZ businesses?
Reported direct losses are rising fast. CERT NZ and the National Cyber Security Centre recorded NZ$7.8 million in direct financial losses in the first quarter of 2025, and the NCSC report for the third quarter of 2025 showed NZ$12.4 million, up 118 percent on the NZ$5.7 million recorded the quarter before.
Those figures come from the quarterly cyber security insights reporting published by CERT NZ, whose reporting function now sits within the National Cyber Security Centre. They capture only incidents that were actually reported, and only direct financial loss, so the true cost to NZ organisations is materially higher once downtime, recovery labour and lost customers are counted.
For an owner or finance manager the arithmetic is straightforward. Reported national losses more than doubled inside two quarters, and a single uninsured incident routinely costs a small business tens of thousands of dollars. A cyber policy transfers part of that risk for a defined annual premium, but only if the claim actually pays, which brings the argument straight back to the controls above.
How does SMB1001 Gold answer the underwriting questions?
SMB1001 Gold is a director attested cyber security certification whose 27 controls include every item on the underwriting list: MFA, EDR, offline backups, DMARC enforcement, an incident response plan and, unusually, a current cyber insurance policy. Reaching Gold means the proposal form answers are yes, with an evidence pack behind each one.
SMB1001 is a five tier cyber security certification standard developed by Dynamic Standards International (DSI) and certified through the CyberCert platform. The tiers run Bronze, Silver, Gold, Platinum and Diamond, and the standard is refreshed each year so the controls track current threats rather than a fixed snapshot. It is fast becoming the recognised baseline certification for smaller organisations on both sides of the Tasman. Gold is the tier that lines up with underwriting expectations, and a company director formally attests compliance, in the same way a director signs off the accounts.
Gold requires 27 controls in total. Alongside the underwriting five, it mandates a password manager, restricted admin rights, a digital asset register, an ongoing staff awareness programme and a current cyber insurance policy, which makes the certification and the insurance mutually reinforcing. The CyberCert certificate fee is AUD $395 per year, and implementation cost depends on how far your environment already sits from the 27 controls.
The practical effect is that certification converts the proposal form from a risk into a formality, because every answer is yes and every yes carries evidence a director has signed off. Our SMB1001 Gold certification guide walks through all 27 controls in detail, and our SMB1001 pricing page publishes the package cost for every tier so you can budget before you talk to anyone.
Cyber insurance requirements NZ: frequently asked questions
Is MFA mandatory for cyber insurance in NZ?
In practice, yes. Most NZ cyber insurers now treat multi-factor authentication as a minimum condition of cover, especially on email, remote access and administrator accounts. Some will still quote without it, but expect a loaded premium, ransomware exclusions or a declined application. MFA for cyber insurance is the first control every underwriter checks, so enable it before you apply.
Why was my cyber insurance declined?
The most common reasons are missing MFA, no EDR, untested backups and incomplete answers on the proposal form. Insurers also decline renewals when a business has had an incident it did not disclose. Ask the insurer for the specific reason in writing, close the gap, and reapply with evidence. Many declined businesses become insurable within 90 days.
What is EDR and why do cyber insurers require it?
EDR stands for endpoint detection and response. It watches every computer and server for attacker behaviour rather than just known viruses, and lets responders isolate an infected machine remotely. Insurers require EDR because it shortens ransomware incidents and cuts claim costs. Our managed IT security services include EDR deployment and monitoring for NZ businesses.
Do small NZ businesses need cyber insurance?
Yes, and often more than large ones. Small businesses hold customer data and process payments but rarely employ security staff, which makes them a frequent target in the incidents reported to CERT NZ. A single ransomware event can cost more than a decade of premiums. Cover matters most when it is paired with the baseline controls insurers now expect.
Will SMB1001 Gold certification lower our premium?
It can improve both insurability and terms, although no certification guarantees a cheaper premium. SMB1001 Gold requires the controls underwriters ask about, including MFA, EDR, offline backups and an incident response plan, so certified businesses answer yes with evidence. That removes the usual reasons for loaded premiums, restrictive exclusions or declined cover at renewal time.
How long does it take to become insurance ready?
Most NZ businesses of 20 to 200 staff reach an insurable baseline in 60 to 90 days. MFA and EDR deploy quickly, while DMARC enforcement and a tested restore need a few weeks of monitoring to complete safely. OxygenIT runs this as a structured 90 day programme. Contact us and we will map your current gaps first.
Get insurance-ready with OxygenIT’s SMB1001 Gold in 90 days
OxygenIT has run IT and security for New Zealand businesses for more than 20 years, operating from Christchurch since 2005 with coverage in Wellington. We are ISO 27001 and ISO 42001 certified ourselves, and we take businesses of 20 to 200 staff from gap assessment to a director signed SMB1001 Gold certificate, with an insurer ready evidence pack, in 90 days.
Book a discovery call and we will map your environment against the checklist above, then give you a fixed price and a start date. Or call us on 0800 101 095.