Cyber insurance is not legally required for most Australian businesses. It is worth serious consideration if you hold personal or client data, send or receive payments by email, or cannot trade when your systems are down. A policy pays for expert help, recovery and some liabilities after an incident, which a general business pack often limits or excludes.
Reviewed by Ben Webster
Any business that uses email and holds customer information can have a cyber incident. The businesses that tend to feel it most are those where one of these is true:
Small businesses are not too small to be a target. In its Annual Cyber Threat Report 2024–25, ASD reports an average self-reported cost of cybercrime of about $56,600 per report for small businesses, and lists email compromise and business email compromise fraud among the most commonly reported cybercrimes affecting businesses.
Policies differ between insurers, so treat this as a general picture and check your own policy wording.
Exclusions vary, but commonly include incidents that started before the policy, failure to maintain security controls you said you had on the proposal, war and infrastructure outages, and physical damage. Losses from someone tricking your staff into paying a fake invoice are often covered only under a specific extension, if at all.
Often only in a limited way. Many business packs exclude cyber losses or include a small sub-limit that does not stretch to incident response, data restoration or lost income. Some cover none of it. The only way to know is to read the policy wording, or ask your broker to show you what is and isn't covered.
Proposal forms usually ask about a handful of basic controls, and gaps can affect the price, the excess or whether you are offered cover at all:
These overlap heavily with ASD's Essential Eight.
If you answer yes to two or more of these, it is worth a conversation with a broker:
If you do decide to get cover, see how much cyber insurance costs in Australia.
Not for most businesses. No general law requires an Australian business to hold cyber insurance. A client contract, a tender or an industry body can still ask for it, so check the agreements you have signed.
Often only in a limited way, and sometimes not at all. Many business packs exclude or cap cyber losses, and a sub-limit may not cover incident response, data restoration or lost income. Read the policy wording or ask your broker what is actually covered.
It is getting harder. Insurers commonly ask about multi-factor authentication, backups and patching on the proposal form. Missing controls can mean a higher premium, a higher excess, restricted cover, or a decline, depending on the insurer.
If you have a policy, call the insurer's incident response line before you do much else, because many policies expect you to use their panel. You can also report cybercrime to ASD through ReportCyber at cyber.gov.au, and check whether the breach needs to be notified under the Privacy Act.
General information only, not financial or insurance advice. Talk to a licensed broker about your situation.
Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.
More answers: What is the Essential Eight? · How much does cyber insurance cost in Australia? · A customer sent me a cyber security questionnaire. Where do I start? · Can someone send email pretending to be my business?