Insurers need a clear understanding of the actual Defence-related activities before they can assess the risk.
What business information is normally required? #
You may need to provide:
- Business name and ABN.
- Business postcode.
- Years operating.
- Turnover.
- Staff numbers.
- Qualifications and experience.
- Current insurance.
- Claims history.
What information is needed about Defence work? #
Insurers may ask about:
- Services provided.
- Percentage of turnover from Defence work.
- Direct Defence contracts versus subcontract work.
- Prime contractors involved.
- Project values.
- Professional services.
- Products manufactured or supplied.
- Work at Defence facilities.
- Overseas work.
What contract information may be required? #
Provide relevant details such as:
- Required insurance policies.
- Required limits.
- Liability caps.
- Indemnities.
- Contract duration.
- Required period of PI cover after completion.
Insurers may request copies of significant contracts.
What cyber or security information could be required? #
Depending on the exposure, insurers may ask about:
- DISP membership.
- Information classifications handled.
- Cyber security controls.
- Essential Eight maturity.
- Previous cyber incidents.
- Use of subcontractors or cloud providers.
Security compliance and insurance remain separate assessments.
Providing a complete description of the business helps reduce unnecessary underwriting delays.

