Five signs your cybersecurity is strong but unprovable

Your security tools might be doing their job. The question is whether you can demonstrate that to anyone who asks.

There’s a version of cybersecurity that feels solid from the inside but falls apart the moment someone asks you to account for it. The tools are there. The IT team or provider is on top of things. Nothing has gone wrong. And yet, if a cyber insurer, an enterprise client, or your own board asked you to demonstrate your security posture tomorrow, you’d struggle to know where to start.

This is more common than most business owners realise, and it’s becoming a genuine liability. Here are five signs you might be in this position.

1. You rely on your IT provider to answer security questions on your behalf

Cyber insurance is the most immediate place this shift is showing up. Not long ago, insurers would run through a checklist at renewal: multifactor authentication, regular patching, offsite backups. A yes across the board and you’d get your policy.

That process has changed substantially. Australian cyber insurance underwriting tightened significantly through 2024 and 2025. The informal tick-and-flick application form has been replaced by detailed technical questionnaires, and for higher cover, evidence of controls. SMEs that haven’t invested in structured security practices are increasingly finding that cyber insurance is either expensive or simply unavailable.

The market is also about to get more costly. After two years of softening rates, S&P Global forecasts a 15 to 20 per cent premium increase in 2026. Organisations with strong, documented security postures will be better placed to negotiate favourable terms. Those without them won’t.

There’s also a significant coverage gap that most SME owners aren’t aware of. Only 10 to 20 per cent of SMEs currently carry cyber insurance, compared to 40 to 50 per cent of mid-market firms. That means the majority of small businesses are carrying a risk they’ve largely left unquantified – and uninsured.

The procurement picture is similar. If your business sells to enterprise clients or operates in regulated industries like financial services or healthcare, you may already be fielding questions about your security posture from clients or partners. Insurers are increasingly requesting third-party security attestations, such as framework certifications or maturity assessments, for cover above $1 million. That expectation is spreading beyond the insurance conversation into tenders, contracts, and supplier assessments. It only moves in one direction.

2. Your security training happens once at onboarding and never again

Staff awareness training is one of the most consistently underestimated controls in a small business security program. It’s also one of the first things that gets asked about in an insurance renewal or a client security questionnaire.

A single induction session from two years ago doesn’t count. Neither does a policy document that lives in a shared drive nobody reads. What insurers and certification frameworks are looking for is evidence of regular, completed, documented training: monthly or quarterly cycles, completion tracking, and accountability for non-completion. If you can’t point to records showing your team is actively engaged with security awareness on an ongoing basis, that’s a material gap regardless of how good your technical controls are.

Cybersecurity Scorecard 1200x675

3. Your security policies exist but nobody has reviewed them in years

Most businesses at the 30-to-100-staff mark have some version of a password policy, an acceptable use policy, and possibly an incident response plan. What’s less common is any evidence that those documents are current, reviewed regularly, or actually reflect how the business operates.

Outdated policies are a problem for two reasons. First, they may no longer cover the tools, platforms, and working arrangements the business actually uses. A policy written before the shift to hybrid work and cloud storage is almost certainly missing something. Second, they signal to anyone reviewing your security posture that governance is informal, not a managed process. A document dated 2021 that hasn’t been touched since tells its own story.

4. You have no documented process for when something goes wrong

Most small businesses have a rough idea of what they’d do in the event of a cyber incident: call the IT provider, shut things down, figure it out from there. What most don’t have is a documented, tested incident response plan that assigns roles, defines communication protocols, and sets out a recovery sequence.

This matters more than it might seem. Cyber insurers ask about it directly. More practically, when something goes wrong is the worst possible time to be working out who does what. Businesses that have rehearsed their response, even in a basic tabletop exercise, consistently handle incidents faster and with less collateral damage than those that haven’t. The plan doesn’t need to be long. It needs to exist and be known.

5. You’ve never had an independent assessment of your security posture

Internal confidence is not the same as verified maturity. Most businesses that haven’t had an external assessment tend to overestimate their position in some areas and have genuine blind spots in others. That’s not a criticism. It’s simply what happens when you’re assessing your own work without a reference standard.

An independent gap assessment against a recognised framework gives you something internal review can’t: a clear, objective picture of where you stand, what’s missing, and how significant the gaps are. For most businesses, the result is more reassuring than expected. The foundations are usually stronger than they think. The gaps tend to be in documentation and formalisation, not in the underlying controls. But until you’ve done the assessment, you’re operating on assumption.

What this comes down to

Good cybersecurity and demonstrable cybersecurity are not the same thing. You can have genuinely strong security practices and still be unable to account for them in any meaningful way to an insurer, a client, or a board. That gap is closing as expectations rise, and the businesses that close it proactively are in a significantly better position than those that wait until someone asks.

If any of the five signs above felt familiar, it’s worth understanding where your business actually sits. An independent assessment is a reasonable first step, and for most businesses, the picture is clearer and more manageable than they expect.

Ready to move from research to action? The first step is understanding where you currently stand. A baseline security assessment can break decision paralysis by giving you concrete starting point. Contact us today to discuss your current cybersecurity posture and next best steps forward. 

Is Your Cybersecurity Good Enough, and Can You Prove It?

“Pretty secure” isn’t good enough anymore.

That’s the uncomfortable truth we put to our LinkedIn audience recently, and the response told us it landed. Because most businesses answer the cybersecurity question the same way: do we have antivirus, backups, MFA? Yes, yes, yes. So we’re pretty secure, right?

The problem is that “pretty secure” is doing a lot of heavy lifting. Cyber insurers don’t accept pretty secure. Enterprise clients putting you through procurement don’t accept pretty secure. And when something goes wrong, pretty secure won’t hold up in a board conversation either.

The shift happening right now is from cybersecurity as a tool checklist to cybersecurity as something you can actually demonstrate. Not describe. Demonstrate. That’s a different question entirely – and most SMEs aren’t ready for it yet.

We spent the last six months getting ready for it ourselves. Here’s what that looked like, and what it means for your business.

02 The Numbers

The numbers that put this in context

Before we get to the insurance conversation, it helps to understand the baseline. The ASD’s 2024-25 Annual Cyber Threat Report recorded over 84,700 cybercrime reports in Australia last financial year – one every six minutes – with the average cost to small businesses rising 14 per cent to $56,600 per incident. That’s not the cost of a catastrophic breach at a large organisation. That’s the average cost hitting businesses like yours and ours.

What’s notable is how many of those businesses thought they were pretty secure right up until they weren’t.

Why demonstrable security is becoming the new standard

Cyber insurance is the most immediate place this shift is showing up. Not long ago, insurers would run through a checklist at renewal: multifactor authentication, regular patching, offsite backups. A yes across the board and you’d get your policy.

That process has changed substantially. Australian cyber insurance underwriting tightened significantly through 2024 and 2025. The informal tick-and-flick application form has been replaced by detailed technical questionnaires, and for higher cover, evidence of controls. SMEs that haven’t invested in structured security practices are increasingly finding that cyber insurance is either expensive or simply unavailable.

The market is also about to get more costly. After two years of softening rates, S&P Global forecasts a 15 to 20 per cent premium increase in 2026. Organisations with strong, documented security postures will be better placed to negotiate favourable terms. Those without them won’t.

There’s also a significant coverage gap that most SME owners aren’t aware of. Only 10 to 20 per cent of SMEs currently carry cyber insurance, compared to 40 to 50 per cent of mid-market firms. That means the majority of small businesses are carrying a risk they’ve largely left unquantified – and uninsured.

The procurement picture is similar. If your business sells to enterprise clients or operates in regulated industries like financial services or healthcare, you may already be fielding questions about your security posture from clients or partners. Insurers are increasingly requesting third-party security attestations, such as framework certifications or maturity assessments, for cover above $1 million. That expectation is spreading beyond the insurance conversation into tenders, contracts, and supplier assessments. It only moves in one direction.

The two frameworks worth knowing

Australia has two well-regarded cybersecurity frameworks that help businesses move from informal security practices to something documented, structured, and verifiable.

The first is the Essential Eight, developed by the Australian Signals Directorate. Most businesses have heard of it. It covers eight technical mitigation strategies across three maturity levels and is designed to reduce the most common attack vectors. It’s a strong technical foundation.

The second is SMB1001, developed by Dynamic Standards International and backed by the Council of Small Business Organisations Australia. It’s less well known, but it was built specifically for businesses of 200 staff or fewer, which makes it more practical for most SMEs. SMB1001 runs across five certification tiers – Bronze, Silver, Gold, Platinum, and Diamond – and covers both technical controls and business processes and policies. Where the Essential Eight focuses primarily on technical hardening, SMB1001 takes a broader view of what a mature security posture looks like across an organisation.

They’re not competing frameworks. They overlap significantly, and pursuing one naturally builds toward the other. The right starting point depends on where your business is now and what your most pressing compliance or assurance needs are.

03 Framework Comparison

What our certification process actually looked like

Gold Default

We recently achieved SMB1001 Gold, the third of five tiers. The process took around six months and covered technical uplifts, policy documentation, and third-party vendor accountability.

What it revealed wasn’t a long list of gaps. It was how much good practice we already had in place that simply wasn’t documented. Cyber awareness training that engineers were completing but nobody was formally tracking. Password governance that existed informally but hadn’t been written down. Account management processes that were sound but undocumented. The certification process forced us to formalise what we were already doing, and in doing so, made it auditable, repeatable, and demonstrable to anyone who asked.

That’s a pattern we see consistently across businesses at the 30-to-100-staff mark. The foundations are often stronger than people think. What’s typically missing is the structure and documentation to prove it.

The question worth sitting with

If your cyber insurer, your biggest client, or your board asked you to demonstrate your cybersecurity maturity tomorrow – not describe it, but demonstrate it – what would you be able to show them?

If the honest answer is not much, that’s worth taking seriously. Not because a breach is necessarily imminent, but because the window for getting ahead of this expectation is narrowing. Businesses that can produce evidence of structured, certified security practices are increasingly differentiated in insurance conversations, in procurement processes, and in client confidence.

The good news is that for most SMEs, the starting point isn’t as far away as it looks. A gap assessment against either framework will typically show that a significant portion of requirements are already being met. The work is usually in formalisation and documentation, not in building security from scratch.

Where to start

If you’re not sure where your business sits, a gap assessment is the logical first step. It gives you a clear picture of what you have, what you’re missing, and what a realistic certification pathway looks like, without committing to anything before you understand the scope.

We’re also hosting a webinar shortly that will walk through both frameworks in detail, compare them side by side, and outline what a practical pathway to certification looks like for a Brisbane SME. If this is something your business is starting to think about, it’s a worthwhile hour.

Ready to move from research to action? The first step is understanding where you currently stand. A baseline security assessment can break decision paralysis by giving you concrete starting point. Contact us today to discuss your current cybersecurity posture and next best steps forward. 

 

Sources

Australian Signals Directorate, Annual Cyber Threat Report 2024-25, cyber.gov.au
Cliffside, Cyber Insurance Requirements Australia, cliffside.com.au (March 2026)
4iT, Cyber Insurance for Australian SMEs in 2026, 4it.com.au (May 2026)

Logo

Fill Out Details To Download The Program Overview