Why Cyber Insurance Is Getting Tougher — And What NZ Businesses Can Do About It

Why Cyber Insurance Is Getting Tougher — And What NZ Businesses Can Do About It

If your cyber insurance renewal feels more demanding this year, you’re not alone. Across New Zealand, businesses are facing longer questionnaires, stricter requirements, and higher premiums. The cyber insurance market has shifted — and it’s not shifting back.

Here’s what’s driving the change, and what you can do to stay ahead of it.

Why Insurers Are Tightening the Rules

1. Claims Are Rising — Fast

Cyber incidents are now one of the most common types of insurance claims globally. Ransomware payouts, business interruption costs, and data breach remediation have all increased sharply.

Insurers are responding by:

  • Raising premiums
  • Increasing excesses
  • Requiring stronger controls
  • Scrutinising claims more closely.

They’re no longer treating cyber as a niche risk — it’s now one of their biggest exposures.

2. Attackers Are Targeting Smaller Businesses

Automated attacks don’t care about company size. Tools that once required skilled hackers are now available as subscription services on the dark web.

Small and mid‑sized NZ businesses are being hit because:

  • They often have weaker controls
  • They rely heavily on email and cloud services
  • They’re part of larger supply chains
  • They’re less likely to detect an attack early

Insurers know this — and they’re pricing the risk accordingly.

3. Underwriters Want Evidence, Not Assumptions

Gone are the days of ticking “yes” to every question and hoping for the best. Insurers now expect:

  • Documented MFA policies
  • Patch management logs
  • Backup test results
  • Incident response plans
  • Proof of M365 security configuration.

If your answers don’t match your actual environment, insurers can decline claims – and they are doing so more often.

What NZ Businesses Can Do to Prepare

1. Start Early

Don’t wait for the renewal form to arrive. By then, it’s too late to fix gaps without delaying cover or increasing premiums.

2. Focus on the Controls Insurers Care About Most

These are the big five:

  1. MFA everywhere
  2. 30‑day patching
  3. Tested backups
  4. Documented incident response plan
  5. Secure M365 configuration

If you can confidently demonstrate these, your renewal becomes much smoother.

3. Document Everything

Insurers love evidence. Keep:

  • Screenshots
  • Policies
  • Logs
  • Test results
  • Change records

Good documentation reduces friction and builds trust with underwriters.

4. Get an Independent Readiness Assessment

An external review gives you:

  • A clear picture of your current posture
  • A list of gaps to close
  • Documentation you can hand directly to your insurer
  • Confidence that your answers are accurate

It also shows insurers you’re taking risk seriously — which can positively influence premiums.

Cyber insurance isn’t becoming harder because insurers want to be difficult. It’s becoming harder because the threat landscape has changed, and the cost of cyber incidents has skyrocketed. Businesses that prepare early, document thoroughly, and invest in the right controls will find the process far less painful — and far more valuable. strengthen your setup today can prevent costly incidents tomorrow. Because when it comes to cybersecurity, it’s not just about having the right tools – it’s about using them properly.

Find out how we can work together

Contact us