Cyber insurance

.... now you're covered

What is cyber insurance?

Cyber insurance helps protect your business from the financial fallout of a cyber incident, such as computer hacking, ransomware or a data breach.

If your business holds electronic records or relies on a website, it's exposed to this risk. A cyber incident can cost more than money too, putting intellectual property and customers' personal information at risk, with follow-on effects for your reputation.

That exposure is growing — the Australian Signals Directorate's Annual Cyber Threat Report 2024–25 found the average self-reported cost of a cybercrime report for small business rose 14% to $56,600 over the 2024–25 financial year.

Businesses covered by the Privacy Act also carry notification obligations if a data breach is likely to cause serious harm, and cyber insurance is designed to meet exactly these costs — from restoring systems and data to responding to a regulator and a ransom demand.

What's covered by cyber insurance

Cyber cover varies more between insurers than most business insurance, so what follows are covers that are commonly included rather than guaranteed on every policy. Your broker can confirm what applies to a specific policy and walk you through other benefits that can be added to your cyber cover.

Incident response costs

Costs of IT forensic investigation, legal advice and public relations support following a cyber incident.

Data recovery costs

Costs to restore, recover or replace data and systems affected by a cyber incident.

Third-party liability

Cover for claims and regulatory costs arising from a privacy breach or failure of network security.

Cyber extortion

Cover for costs associated with responding to a ransomware or extortion demand.

Why you might need cyber insurance

Growing exposure
Most businesses now hold electronic records or rely on connected systems, and incidents affect businesses of every size, not just large ones.
Regulatory obligations
Businesses covered by the Privacy Act must notify affected individuals and the regulator if a data breach is likely to cause serious harm, which can be costly to manage.
Third-party costs
A breach involving customer or client data can lead to legal claims or regulatory action, on top of the cost of fixing the breach itself.
Business disruption
A cyber incident can take systems offline, disrupting operations while it's investigated and resolved.

Cyber policy types

Cyber cover is usually written as its own standalone policy rather than bundled into a broader business package, reflecting how specialised and fast-moving this risk is. Limits and the extent of first-party and third-party cover can vary significantly, and policies are often shaped around a business's size, industry and the type of data it holds.

Cyber key considerations

Exclusions and conditions are common on this product, particularly around system patching, staff training and multi-factor authentication, so it's worth understanding what's expected of the business to keep cover in place. Cover for business interruption following an incident is often structured differently between insurers, and some benefits, such as social engineering fraud, may only be available as an added extra. Reviewing these details with your broker before cover is needed means there's time to close any gaps.

The breach is rarely the biggest bill

A cyber incident doesn't need to be sophisticated to be costly — a single phishing email or a locked system can halt operations and trigger notification obligations under the Privacy Act at the same time. Cyber insurance is built to cover what happens next, not just the headline ransom or repair bill.

Ask your broker whether cover extends to business interruption following an incident, what security measures such as patching and multi-factor authentication are required to keep cover in place, and whether social engineering fraud is included or needs adding as an extra.

Let's get you covered