Cyber insurance renewals have changed. Where strata buildings were once asked a handful of broad questions about data storage and IT systems, insurers and brokers are now asking for specifics: is your network segmented? Do you have a firewall? Who manages your remote access? How are cameras accessed from outside the building?
If you are a strata manager fielding these questions for a building's owners corporation, the honest answer to most of them may be "I don't know" — because the network infrastructure was installed by separate contractors over many years and nobody has ever assessed it as a whole. That is not an admission of negligence; it is the reality of how most Australian strata buildings have been built out technologically. But it is a problem when an insurance underwriter is waiting for documented answers.
This article explains what insurers are actually looking for, why strata buildings are now firmly in scope for cyber insurance scrutiny, and what having a managed network infrastructure provider means for your ability to answer those questions accurately.
Why Strata Buildings Are Now in Scope for Cyber Insurance
Until recently, cyber insurance was primarily a concern for businesses holding customer data — healthcare providers, accountants, retailers with e-commerce systems. Strata buildings sat outside that frame. They were property assets, not IT businesses.
That framing has shifted, for several interconnected reasons.
Modern strata buildings run IP-connected infrastructure across multiple systems: CCTV, electronic access control, intercoms, building management systems (BMS), and in many cases resident Wi-Fi networks. Each of these is a connected device or network, and connected devices are attack surfaces. The security posture of most of these systems — factory-default passwords, firmware that has not been updated since installation, no network segmentation, and direct internet exposure through port forwarding — makes them straightforward targets for automated scanning tools that probe public IP addresses continuously.
Compromised access control is not just a data breach; it is a physical security breach. If an attacker gains control of an electronic door access system, they can unlock doors, disable credentials, or lock residents out. That is a materially different threat profile from a stolen spreadsheet, and it is one that insurers have started pricing into policies.
Australian data breach reporting obligations — and the ongoing broadening of what counts as a reportable incident — have also moved the goalposts. Strata management companies hold resident data: levy payment records, personal contact details, direct debit authority records. That data creates regulatory exposure. Insurers writing cyber policies for strata managers, or for the corporations they manage, now ask about the technical controls protecting that data.
For related context on how smart building systems create cyber risk, see the Pickle article on cyber security in smart buildings.
The Questions Insurers Are Actually Asking
The following categories reflect the real structure of cyber insurance questionnaires as they apply to strata buildings. For each, we have explained what the insurer is actually trying to assess — because understanding the intent behind a question is the only way to answer it accurately rather than optimistically.
Network Segmentation
The question: Are your building systems — CCTV, access control, intercoms, BMS — on a separate network from resident internet access and any administrative systems?
What the insurer is assessing: Whether a compromise of one system can spread laterally to others. On a flat, unsegmented network where IP cameras share a switch with the building manager's computer and the resident broadband connection, a single point of entry gives an attacker access to everything. VLAN segmentation — where building systems, resident networks, and management systems each exist on logically separated network segments with controlled inter-segment routing — is what insurers want to see. A verbal "yes we have separate networks" is unlikely to satisfy underwriters at renewal; they want to see configuration documentation.
For a deeper look at how segmentation applies to apartment building network design, see secure network design for apartment buildings.
Firewall Controls
The question: Is there a managed firewall between the building's network infrastructure and the internet?
What the insurer is assessing: Whether there is an active, maintained barrier controlling inbound and outbound traffic. A consumer-grade router — the kind that comes with a broadband connection — does not qualify. Insurers are looking for a dedicated firewall appliance or platform with documented policy rules, active management, regular firmware updates, and someone accountable for its configuration. A firewall running default settings or firmware from several years ago is treated by underwriters as substantially equivalent to no firewall.
Remote Access Security
The question: How are cameras, access control systems, and other building infrastructure accessed from outside the building?
What the insurer is assessing: Whether building systems are directly exposed to the internet through port forwarding, or whether access is controlled through a VPN or cloud-managed relay.
Port forwarding — the practice of exposing a device directly to the internet on a fixed port number so that installers or building managers can access it remotely — is a known, documented vulnerability class. The ports used for common CCTV and access control brands are publicly indexed. Automated scanning tools probe these ports globally, continuously. Some insurers now specifically exclude coverage for incidents originating through exposed port-forwarded devices. VPN-based remote access, or cloud-relay access through the manufacturer's own platform without direct internet exposure, is what underwriters want to see.
This is one of the areas where strata buildings most commonly have undocumented risk — CCTV installers routinely configure port forwarding as a default, and once the installer is gone, nobody changes it. See the Pickle article on CCTV network security for buildings for more on this specific risk.
Patch Management
The question: Are the firmware and management software on building network devices updated regularly? When were they last updated?
What the insurer is assessing: Whether devices have unpatched known vulnerabilities. IP cameras, NVRs (network video recorders), access control controllers, and managed network switches all receive security firmware updates from their manufacturers — often in response to disclosed vulnerabilities. Devices running firmware from 2019 or earlier on a live building network today are carrying known, publicly documented vulnerabilities. Insurers increasingly ask for evidence of a patch management process, not just a yes/no answer.
Credential Controls
The question: Have factory-default passwords been changed on all network devices in the building?
What the insurer is assessing: Whether the most basic layer of access control is in place. Default credentials for IP cameras, NVRs, and access control systems are publicly documented — they are listed in manufacturer manuals and indexed on the internet. Automated tools scan for devices running default credentials and exploit them trivially. This is not a sophisticated attack; it is a script running against a list of known default username/password pairs. Insurers now ask this question explicitly, and an honest "we don't know" or "some may not have been changed" is a material disclosure.
Incident Response
The question: Who is responsible for responding to a cyber incident affecting the building's network? Is there a documented incident response plan?
What the insurer is assessing: Whether there is a real, contactable, technically capable entity that can respond if something goes wrong — not just a name on a piece of paper. "We would call the CCTV installer" is not an incident response plan. Insurers want to see a managed IT provider or security operations capability that can isolate compromised systems, investigate the incident, preserve evidence for any insurance claim, and restore services. Without that, any claim made after an incident will face questions about whether the building took reasonable steps to mitigate harm.
The Honest Audit: Where Most Buildings Actually Stand
Most strata buildings, if assessed honestly against these six criteria, would fail on at least two or three. That is not unusual, and it is not necessarily the result of negligence. It reflects how building technology has historically been installed: by separate contractors (the CCTV company, the intercom installer, the access control provider, the NBN technician), each of whom configured their own piece of the system without a view of the whole. Nobody was ever asked to look at the network as a complete, integrated infrastructure.
The risk of discovering this during a renewal questionnaire — rather than before it — is significant. Inaccurate answers to material questions on an insurance application can void coverage. Accurate answers that reveal significant gaps may result in higher premiums, exclusions, or declined coverage. Neither outcome is good. The value of a pre-renewal network audit is that it gives you the actual picture before you sit down with a questionnaire, so you can address gaps proactively rather than disclose them reactively — or worse, not disclose them at all.
For a structured way to approach this, see the upcoming Pickle technology checklist for strata building audits.
What "Managed Network Infrastructure" Means to an Insurer
When a strata building has a managed network provider — a company that actively monitors, configures, patches, and manages the network infrastructure — it can answer insurer questionnaires with documentation rather than guesswork. That distinction matters at underwriting.
Specifically, a managed network provider should be able to produce:
- VLAN configuration records showing which systems are on which network segments and what routing rules exist between them
- Firewall policy documentation listing the rules governing inbound and outbound traffic, with a date showing the last review
- Patch management logs showing when firmware updates were applied to managed devices and what version is currently running
- Remote access architecture documentation showing how building systems are accessed externally, confirming VPN or cloud-relay access rather than port forwarding
- Credential audit records confirming that default passwords have been changed and that a credential management process is in place
This documentation is what separates a building that can answer an insurer's questionnaire accurately from one that cannot. It is also what supports a claim if an incident occurs — demonstrating that reasonable controls were in place at the time.
What Pickle Provides for Strata Buildings
Pickle manages network infrastructure for strata buildings across Australia. That includes managed switches with VLAN configuration to segment building systems from resident and administrative networks, dedicated firewalls with active management and documented policies, remote access configured via VPN or cloud-managed paths rather than port forwarding, firmware patching for managed network devices on a regular schedule, and complete documentation of the network architecture.
When an insurance questionnaire asks about network segmentation, Pickle can provide the answer and the supporting evidence. When it asks about remote access security, Pickle can produce an architecture diagram. When it asks about patch management, Pickle can provide logs.
Pickle also conducts technology audits for strata buildings — a structured review of the building's network infrastructure that produces a written report suitable for tabling with an insurer or broker as evidence of due diligence. For strata managers preparing for a renewal, that report is a practical starting point.
To understand the broader scope of what Pickle delivers for strata buildings, visit the Pickle strata management communications page. For context on how Pickle's approach compares to general managed IT services, see managed IT services for small business in Australia.
Frequently Asked Questions
Q: Is an owners corporation legally required to have cyber insurance?
A: There is currently no legislation in Australia that mandates cyber insurance for owners corporations specifically. However, strata managers operating under management agreements may have contractual obligations that effectively require it, and the broader legal landscape around data breach notification is expanding. More practically, as owners corporations hold resident personal data and operate increasingly connected building infrastructure, the question is less whether they are legally required to have it and more whether they can afford the financial and reputational consequences of a significant incident without it.
Q: What is port forwarding and why do insurers dislike it?
A: Port forwarding is a network configuration method that allows an external user to connect directly to a device inside a building — such as a CCTV NVR or access control system — by routing incoming internet traffic on a specific port number to that device. It is commonly used by installers because it is quick to set up. The problem is that it exposes the device directly to the public internet, where automated scanning tools continuously search for and attempt to exploit such devices. Insurers view port-forwarded building systems as a significant uncontrolled risk, and some policies now explicitly exclude incidents originating through this type of access configuration.
Q: Can a small strata building with 10 lots really be a cyber target?
A: Yes. Automated attack tools do not distinguish between a 200-lot high-rise and a 10-lot walk-up. They scan IP address ranges looking for exposed devices, open ports, and default credentials. A small building with a poorly secured CCTV system or access control panel connected to the internet is as visible to a scanning tool as any other exposed device. The attack is often not targeted at the building specifically — it is opportunistic. The building's size does not reduce its exposure; its security configuration does.
Q: What documentation should we provide with a cyber insurance application?
A: Insurers and brokers increasingly accept — and in some cases request — technical documentation alongside questionnaire responses. Useful documents include a network architecture diagram showing system segmentation, firewall policy documentation, remote access configuration records, firmware version and patch log records, and any recent IT audit reports. If a managed network provider manages the building's infrastructure, a letter or report from that provider confirming the controls in place can be submitted as supporting evidence. This documentation reduces underwriting uncertainty and can support more accurate (and potentially more favourable) premium assessments.
Q: How does a managed network provider help with insurance renewals?
A: A managed network provider turns questionnaire answers from guesswork into documented fact. Instead of a strata manager estimating whether the building has network segmentation, the provider can produce VLAN configuration records that confirm it. Instead of uncertainty about whether firmware is current, the provider can produce patch logs. This matters both for the accuracy of the application — which is a legal obligation — and for the building's ability to demonstrate due diligence to an insurer in the event of a claim. A provider like Pickle also conducts structured technology audits that produce formal reports expressly suited to this purpose.
Ready to prepare your strata building for a cyber insurance renewal — or find out where your current network actually stands? Contact Pickle for a technology audit.
Call 1300 688 588 or email [email protected]