cyber insurance

Everyone Starts at Zero. That's the Good News.

By The Most Secure Man Alive | WISECLICK Ambassador

The national cyber standard is built so that almost every small business fails it on day one. Once you know why, the whole thing gets a great deal easier.

Something shifted in the last couple of years, and you've probably felt it without naming it.

The insurer's form got longer and sterner. A client slipped a security questionnaire into a contract. A tender asked for evidence you'd never been asked for before. None of it arrived as an announcement. It just became the water you were swimming in. What used to be a nice-to-have, the cyber equivalent of a tidy back office, quietly turned into something assumed of you, the way public liability cover or a locked front door is assumed. You aren't behind the times. The times moved, all at once, and everyone running a small business is standing in the same new normal, blinking at the same longer forms.

So here is the thing nobody says out loud, and it's the most freeing fact in this whole subject.

When you finally measure yourself against the national standard, you are going to score zero.

Not because you've been careless. Because it's built that way. The standard is the Essential Eight, kept by the Australian Signals Directorate, and its scale starts every single business at the bottom, at a level the government plainly calls zero. Almost every small business in the country sits there on day one. Zero isn't a report card. It's the starting line, drawn in the same place for everyone, the accountant and the architect and the bloke with the ute alike.

Which changes what the assessment is for. It was never a test you pass or fail. It's a map that shows you where the start line is and which way the hill runs. And the hill is shorter than the forms make it look.


Because the eight things, stripped of their stern language, are not exotic. A couple you switch on once and rarely touch — turning on multi-factor authentication so a stolen password opens nothing, sorting who really holds the keys. A couple are habits more than tasks — letting updates install instead of postponing them, keeping a backup that actually works. And the few that are genuinely technical are the kind a plain step-by-step guide walks you through, not a thing you sit and puzzle out alone. No firm. No audit. No lanyard in the doorway. Most of it is closer to locking up at night than to anything that needs a consultant, and the whole industry would rather you didn't know that, because a customer who feels capable doesn't renew out of nervousness.

So let me just tell you the path. It's short, and your peers are already walking it.

First, see where you stand. Take the Ransomware Readiness Check yourself — thirty minutes, plain English, nobody coming in. You'll most likely land at or near zero, and that's exactly right. Now you've got the map almost nobody bothers to draw.

Then get the relentless stuff off your plate. A WISECLICK membership runs the handful of things that must never stop — your protection, your backups — so they don't quietly lapse the week everything gets loud. That's the part that genuinely wants a partner. Not because it's hard, but because it's constant, and constant is the first thing to slide on a busy desk.

Then do the rest at your own pace. The membership hands you the Essential Eight as plain step-by-step guides, and a Cyber Toolkit alongside them — plain how-tos and tools that make the everyday safer, the café wi-fi, the dodgy-looking invoice, the new phone you've just set up, each explained so you can actually use it. Work through whatever's useful, in whatever order suits you. No deadline but your own.

And the piece that makes it a partnership rather than a purchase: when a question turns up, or a strange email lands, or a form asks something you don't recognise, you have someone to ask. That, more than any single setting, is the whole point of a membership. You stop being the only person in your business who has to know about this.

Where this leaves your cyber insurance. Now watch what happens to that insurance form. Once the eight are in place and quietly maintained, the questionnaire isn't a threat anymore. The answers are simply true. And here's the part I like best: once you've done the work, we hand you a fresh token to take the assessment again, and the new result is yours to send straight to your insurer. Plain-English proof that you're the careful kind, the kind they price gently and pay without a fight. You're protected, and we keep you protected. The form becomes a formality, and the renewal becomes a short conversation.

That's the journey. Start at zero, see the map, hand off the relentless parts, climb the rest at your pace, and keep a partner on the line for the day something looks off.

You were never the weak link the longer forms implied. You'd just never been handed the list, in your own language, by someone with no reason to keep you nervous. The only thing that has ever separated one business from another is that one of them looked at where it stood and started climbing.

Start where everyone starts. The view from a little further up is worth the thirty minutes.

See where you stand. 30 minutes. Plain English. $149.

Take the Ransomware Readiness Check →

Start at zero. Climb at your pace. Keep a partner on the line.

I took mine years ago, scored what everyone scores, and worked down the list over a few unremarkable afternoons. No one came in. I've answered every insurer's form since without a second thought, and barely thought about any of it in between. The least dramatic thing I ever did for the business, and quietly one of the best.

Stay protected, my friends.
— The Most Secure Man Alive


Get articles like this delivered to your inbox


Frequently Asked Questions

Will I score zero on the assessment?

Almost certainly, and so does nearly every small business in the country. The government's scale starts everyone at Maturity Level Zero by design. It's a starting line, not a report card, and the value of the assessment is the map it hands you, not the number.

Do I need an IT company to do the Essential Eight?

No. Most of the eight are settings you switch on once or habits you keep, and the genuinely technical ones come as plain step-by-step guides with a WISECLICK membership. No firm, no audit, no consultant required.

What does a WISECLICK membership actually do?

It runs the things that must never stop — your protection and your backups — and hands you the Essential Eight as plain-English guides plus a Cyber Toolkit for everyday situations. And it gives you someone to ask when a strange email lands or a form asks something unfamiliar.

How does this help with cyber insurance?

Once the eight are in place and maintained, the insurer's questionnaire stops being a threat because the answers are simply true. After you've done the work, we issue a fresh assessment token, and the new result is yours to send straight to your insurer.

Can I just buy more cover instead of doing the security work?

Insurance transfers risk; it doesn't remove it. Insurers increasingly price and pay according to the controls you actually run, and using cover as a substitute for a control is exactly what the standard scores at zero. The work is shorter than the forms make it look, and it's what makes the cover cheap and the claims smooth.

What is the Ransomware Readiness Check?

A thirty-minute, plain-English assessment against Australia's Essential Eight. You leave knowing where you stand, what it means, and what's worth doing first. $149, done yourself, nobody coming in.

Reading next

Leave a comment

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.