Security awareness training requirements for cyber insurance

What cyber insurers ask about security awareness training in 2026, the evidence pack underwriters expect, and how to build it before renewal.

Cyber insurers have moved from asking about security awareness training to demanding evidence of it. Australian broker guidance for SMBs summarises the 2026 underwriting baseline: a minimum of annual training for everyone in the company with proof of completion, regular phishing simulations, and supporting controls such as multi-factor authentication across email, remote access and cloud applications. Miss the training question and the consequences are concrete — higher premiums, exclusions, or a declined application.

Key takeaways

What underwriters actually ask

Cyber insurance applications have converged on a common set of human-layer questions:

The pattern is clear: underwriters price the human layer because human error — a clicked link, a changed bank detail, an approved MFA prompt — is the opening move in most of the claims they pay.

Building the evidence pack

What satisfies an underwriter is documentation you can hand over:

  1. Completion records for every staff member, dated within the policy period.
  2. Simulation results — dates, volumes, click and report rates, ideally showing a downward trend over at least two quarters.
  3. A short written policy covering training frequency, phishing reporting and verification of payment changes.
  4. Control evidence: MFA enabled across email and remote access, with screenshots or an auditor confirmation.

Cyber Aware's training produces the first three automatically: monthly lessons with completion tracking, phishing simulations with recorded results, and human risk reporting that exports the trend lines an underwriter wants to see.

Start at least 90 days before renewal

Trends matter more than snapshots. An underwriter shown two quarters of falling click rates is looking at a managed risk; one shown a simulation run last week is looking at a checkbox. Working backwards:

Organisations that start this late end up paying more for the same cover, because the underwriter prices what they can see.

If you have failed the question before

A loading, an exclusion or a rejection on training grounds is fixable, and the fix is the same either way: establish a documented, recurring program and let it build a track record. Two to three quarters of recorded monthly training and improving simulation results is usually enough to revisit terms at the next renewal — that is a far cheaper conversation than the alternative of a claim declined over an untrained workforce.

FAQ

Do cyber insurers require security awareness training? Most Australian cyber policies now ask about it, and an increasing number treat evidence of annual training plus phishing simulations as a condition of the quote. The requirements vary by insurer and sum insured, but the direction is uniform.

What evidence of training do insurers accept? Completion records per staff member, phishing simulation results with click and report rates over time, and a short policy describing the program. A training certificate from three years ago does not.

Does a high phishing click rate raise premiums? Underwriters price what the application shows. A measured, improving click rate reads as a managed program; no data at all reads as unknown risk, and unknown risk is priced at the top of the range.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.