Cyber insurers have moved from asking about security awareness training to demanding evidence of it. Australian broker guidance for SMBs summarises the 2026 underwriting baseline: a minimum of annual training for everyone in the company with proof of completion, regular phishing simulations, and supporting controls such as multi-factor authentication across email, remote access and cloud applications. Miss the training question and the consequences are concrete — higher premiums, exclusions, or a declined application.
Key takeaways
- Insurers now expect annual training for all staff with proof of completion, plus regular phishing simulations and documentation — not a policy document saying training happens.
- MFA is near-universal on underwriting questionnaires; SMS-based MFA is increasingly rejected for privileged accounts.
- The evidence pack is buildable in 90 days: completion records, simulation results, report-rate trends and a short policy.
- Human risk reporting gives you the numbers underwriters accept — click rate trending down, report rate up — instead of assurances.
What underwriters actually ask
Cyber insurance applications have converged on a common set of human-layer questions:
- Training coverage and frequency. Who is trained, how often, and can you prove it? Annual is the stated minimum; recurring training with records scores better.
- Phishing simulation program. How often you simulate, and — increasingly — what your click rate is and whether it is improving.
- MFA. On email, VPN or remote access, cloud admin consoles and financial systems.
- Backups and incident response. Immutable, tested backups and a response plan, with training named as the human half of the plan.
- Reporting processes. How staff report suspicious emails and what happens next — an unreported phish is how a claim quietly becomes a breach.
The pattern is clear: underwriters price the human layer because human error — a clicked link, a changed bank detail, an approved MFA prompt — is the opening move in most of the claims they pay.
Building the evidence pack
What satisfies an underwriter is documentation you can hand over:
- Completion records for every staff member, dated within the policy period.
- Simulation results — dates, volumes, click and report rates, ideally showing a downward trend over at least two quarters.
- A short written policy covering training frequency, phishing reporting and verification of payment changes.
- Control evidence: MFA enabled across email and remote access, with screenshots or an auditor confirmation.
Cyber Aware's training produces the first three automatically: monthly lessons with completion tracking, phishing simulations with recorded results, and human risk reporting that exports the trend lines an underwriter wants to see.
Start at least 90 days before renewal
Trends matter more than snapshots. An underwriter shown two quarters of falling click rates is looking at a managed risk; one shown a simulation run last week is looking at a checkbox. Working backwards:
- 90+ days out: run a gap assessment against the controls your renewal will ask about, and start monthly training and simulations.
- 60 days out: complete MFA coverage on the systems named above and document it.
- 30 days out: assemble the pack — completion records, simulation trend, policy, MFA evidence — and send it with the application rather than waiting for a follow-up request.
Organisations that start this late end up paying more for the same cover, because the underwriter prices what they can see.
If you have failed the question before
A loading, an exclusion or a rejection on training grounds is fixable, and the fix is the same either way: establish a documented, recurring program and let it build a track record. Two to three quarters of recorded monthly training and improving simulation results is usually enough to revisit terms at the next renewal — that is a far cheaper conversation than the alternative of a claim declined over an untrained workforce.
FAQ
Do cyber insurers require security awareness training? Most Australian cyber policies now ask about it, and an increasing number treat evidence of annual training plus phishing simulations as a condition of the quote. The requirements vary by insurer and sum insured, but the direction is uniform.
What evidence of training do insurers accept? Completion records per staff member, phishing simulation results with click and report rates over time, and a short policy describing the program. A training certificate from three years ago does not.
Does a high phishing click rate raise premiums? Underwriters price what the application shows. A measured, improving click rate reads as a managed program; no data at all reads as unknown risk, and unknown risk is priced at the top of the range.