Cyber risk insurance pays the costs your business faces when a cyber incident hits — forensics, legal fees, notification expenses, ransom payments, and business interruption losses. If you run an Australian business with 10 to 50 staff, you should be looking at cover now. Attackers are increasingly targeting smaller firms because larger organisations have hardened their defences, and the average self-reported cost of a cybercrime incident to a small business has reached $56,600. Most SMBs cannot absorb that from cash flow.
Here is what a standard policy covers at a glance:
First-party cover (your own losses):
- Incident response and forensic investigation
- Data recovery and system restoration
- Business interruption and lost revenue
- Ransom and extortion payments
- Customer notification and credit monitoring costs
- Crisis PR support
Third-party / liability cover (claims against you):
- Regulatory fines and defence costs under the Privacy Act
- Legal defence against client or partner claims
- Privacy liability and PCI-related claims
The practical next step: check your security hygiene before you call a broker. Insurers will ask about MFA, backups, and patching before they quote. If those are gaps, fix them first or you will pay more and cover less.
Table of Contents
- What does cyber insurance actually cover?
- What kinds of incidents actually trigger a claim?
- What do insurers exclude, and what do they expect from you?
- How do insurers price cyber insurance?
- What happens when you have an incident?
- How to choose a cyber insurance policy
- What most businesses get wrong — an MSP perspective
- Key takeaways
- Cyber insurance is not a substitute for security
- How IT Start helps reduce your insurance exposure
- Useful sources
- FAQ
What does cyber insurance actually cover?
Cyber insurance covers two broad buckets: what happens to your own business (first-party) and what happens when someone else comes after you (third-party liability). Most policies bundle both, but the wording varies significantly between Product Disclosure Statements.
First-party cover

This is the part that pays your direct costs after an incident. Standard lines include event recovery costs (forensics, data restoration, system rebuild), business interruption losses while systems are down, extortion and ransom expenses, and the cost of notifying affected customers. Some policies also include PR support to manage reputational fallout, though as one broker resource notes, insurance cannot restore lost reputation or buy back time offline.

Third-party / liability cover
This kicks in when a client, partner, or regulator comes after you. It covers legal defence costs, regulatory investigation expenses under the Privacy Act, damages awarded to claimants, and PCI-related liabilities if you handle card data. Financial and insurance services businesses should pay close attention here: the ACSC’s Annual Cyber Threat Report 2024-2025 identified financial and insurance services as the most frequently reporting non-government sector.
Bundled services most policies include
| Service element | What it means in practice |
|---|---|
| Incident response vendors | Pre-approved forensics firms you can call immediately |
| Legal counsel | Lawyers experienced in privacy and cyber law |
| PR and communications | Crisis communications support during a breach |
| Ransom negotiators | Specialists who negotiate with threat actors |
| Regulatory notification support | Help meeting your obligations under the Notifiable Data Breaches scheme |
Pro Tip: Read the PDS, not the marketing brochure. Insurers often advertise broad cover but bury sublimits and conditions in the policy schedule. A $1 million policy with a $50,000 sublimit on ransomware payments is not a $1 million ransomware policy.
Policy wording examples from Australian insurers show cover for “event recovery costs,” extortion expenses, and defined conditions for when a cyber extortion threat is considered formally made. That last point matters: if you pay a ransom before notifying your insurer, you may not be reimbursed.
What kinds of incidents actually trigger a claim?
Understanding what triggers a claim helps you map your own exposure honestly. These are the incident types we see most often with Australian SMBs.
Ransomware and extortion remain the most common and most expensive. Attackers encrypt your data, demand payment, and sometimes threaten to publish it. Even if you pay, recovery takes weeks.
Data breaches from misconfiguration or human error are underrated as a risk. An S3 bucket left open, a shared password, a staff member clicking a phishing link — these account for a large share of breaches and are entirely preventable.
Business email compromise (BEC) and social engineering fraud are where we see the most financial pain for small businesses. An attacker impersonates a supplier or executive, redirects a payment, and the money is gone. Some policies cover this; many do not, or they apply tight sublimits.
DDoS attacks and service disruptions are less common for small businesses but rising, particularly in financial services. Business interruption cover applies here if the policy includes it.
Supply chain and third-party compromise happen when a vendor or software provider you rely on is breached and the attacker pivots into your environment. This is harder to prevent and increasingly common.
What do insurers exclude, and what do they expect from you?
This is where most businesses get a nasty surprise. Common exclusions in Australian cyber insurance include:
- Incidents caused by failure to maintain basic security controls (MFA, patching, backups)
- Losses from known but unpatched software vulnerabilities
- Insider fraud and deliberate acts by employees
- Physical hardware damage
- Acts of war or state-sponsored attacks
- Prior incidents you did not disclose at application
The security hygiene insurers typically require before they will offer cover includes MFA, tested backups, regular patching, and phishing awareness training. These are not suggestions. They are underwriting conditions. If you told the insurer you had MFA on all admin accounts and you did not, the insurer can decline your claim on grounds of misrepresentation.
Honestly, this is the part that catches SMBs off guard. They assume the policy pays regardless. It does not. Insurers write conditions into policy schedules and endorsements, and if you breach a warranty, they have grounds to reduce or deny the claim.

Pro Tip: The three fixes that give the biggest underwriting lift for small Australian businesses are: enforcing MFA on Microsoft 365 and admin accounts, running and documenting monthly backup restore tests, and applying critical patches within 30 days of release. These three alone can move you from “declined” to “quoted” with most insurers.
How do insurers price cyber insurance?
Premiums for Australian SMBs typically range from $500 to $5,000 per year, though that range is wide for good reason. A professional services firm with 20 staff and solid controls sits at the low end. A healthcare provider holding sensitive patient records with no MFA sits at the high end, or gets declined.
The main factors that push premiums up or down:
| Factor | Effect on premium |
|---|---|
| Annual revenue | Higher revenue = higher exposure = higher premium |
| Industry sector | Healthcare, finance, legal pay more |
| Number of records held | More personal data = more liability |
| Security controls in place | MFA, backups, patching reduce premium |
| Claims history | Any prior incidents increase cost significantly |
| Use of critical third parties | Cloud-heavy or SaaS-dependent businesses carry more risk |
| Policy limits and sublimits | Higher limits cost more; sublimits cap specific payouts |
Limits and sublimits shape the real value of a policy. A $2 million aggregate limit with a $100,000 sublimit on business interruption is not the same as $2 million across the board. Excesses (the amount you pay before the insurer steps in) also vary and affect both price and claim behaviour.
Once your controls are documented and in place, most brokers can move from quote to bind within one to two weeks. If your security posture is unclear, underwriters will ask more questions and the process takes longer.
What happens when you have an incident?
Speed matters more than most business owners realise. Here is the general workflow:
- Isolate affected systems immediately. Disconnect from the network but do not power off — forensic evidence lives in memory and logs.
- Preserve evidence. Do not wipe or rebuild anything before your forensics team has reviewed it.
- Notify your insurer promptly. Most policies require notification within 24 to 72 hours of discovery. Missing this window is one of the most common reasons claims are delayed or denied.
- Engage the insurer’s approved incident response vendors. Using your own IT provider without insurer approval can void reimbursement for those costs.
- Assess your notification obligations. Under Australia’s Notifiable Data Breaches (NDB) scheme (Privacy Act 1988), you must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a breach is likely to cause serious harm. The OAIC expects notification as soon as practicable after you become aware.
- Submit your claim documentation. Keep records of every cost: staff time, vendor invoices, lost revenue calculations, and communications.
Forensic evidence retention and timely notification are critical. Changing logs, delayed notification, or failing to preserve evidence are the most common operational mistakes that damage a claim’s validity.
Failing to notify the insurer promptly or failing to disclose prior incidents are the two most cited reasons for claim denial. Both are avoidable.
How to choose a cyber insurance policy
Before you call a broker, do a quick self-assessment. The questions below are what a good broker will ask you anyway.
Checklist: what to verify in any policy
- Does it cover both first-party costs and third-party liability?
- What are the sublimits for ransomware, BEC, and business interruption specifically?
- What is the retroactive date? (Cover for incidents that started before the policy began matters.)
- Is there a waiting period before business interruption kicks in?
- What is the excess, and does it apply per incident or per claim?
- Does it cover supply chain or vendor-caused incidents?
- Are your client contracts requiring you to hold a minimum limit?
Questions to ask a broker
- Which incident response vendors are on the insurer’s panel, and can I see their response SLAs?
- Can you show me examples of claims in my sector that were paid and claims that were denied?
- What exclusions are most likely to apply to a business like mine?
- Does the policy cover social engineering fraud, and what is the sublimit?
- What documentation will the insurer want at renewal to maintain current pricing?
Red flags to walk away from
- Vague PDS wording that does not define “cyber event” clearly
- No access to forensic support or mandatory use of a single panel provider with no alternatives
- Unlimited sublimits advertised without clear policy schedule confirmation
- Brokers who cannot answer questions about specific exclusions
Improving your hygiene and shopping for insurance at the same time is the right approach. Better controls mean better terms. A cyber risk management strategy built before you apply gives you something concrete to show underwriters.
What most businesses get wrong — an MSP perspective
We see this constantly. A client calls after an incident and says they had backups. We check. The backup job had been failing silently for four months. The restore had never been tested. The insurer asks for evidence of tested backups as a policy condition. There is none. The claim is complicated.
The biggest cost after a cyber event is often operational downtime and lost customer trust, not the ransom itself. Insurance can cover forensics and response costs, but it cannot recover the time you spent offline or rebuild client confidence.
Here are the mistakes we see most often, and what actually fixes them:
- No MFA on Microsoft 365. This is the single most common gap we find. Attackers know it. Insurers know it. Enable MFA on every account, especially admin accounts, before you do anything else. The ACSC Essential Eight lists multi-factor authentication as a top mitigation strategy.
- Backups that have never been restored. A backup you have never tested is not a backup. Run a restore test monthly and document it. Keep a copy offsite or in a separate cloud tenant.
- End-of-life servers still running. We regularly find Windows Server 2012 or older hardware in SMB environments. Insurers ask about this. Running unsupported software on a network that holds customer data is an underwriting red flag.
- No centralised logging. If you cannot show what happened during an incident, you cannot prove your claim. Centralised logs are what forensic investigators use to reconstruct an attack.
Pro Tip: Before you apply for cover, ask your MSP to document your current controls in writing. Insurers respond well to a one-page security summary showing MFA status, backup schedule, patch cadence, and endpoint protection. It signals that you take this seriously.
Businesses that fix these four things before applying typically see better terms and fewer questions from underwriters. Those that do not fix them often find out the hard way that their policy does not pay what they expected.
For Brisbane businesses, understanding your local cyber security risks is a useful starting point before approaching insurers.
Key takeaways
Cyber risk insurance only pays when your security hygiene meets the conditions written into your policy schedule — so fixing controls before you apply is as important as the policy itself.
| Point | Details |
|---|---|
| Average SMB incident cost | The average self-reported cost of a cybercrime incident to a small business in Australia is $56,600. |
| Controls are policy conditions | MFA, tested backups, and timely patching are underwriting requirements, not optional extras. |
| Typical premium range | Australian SMBs typically pay between $500 and $5,000 per year, but this varies by sector, revenue, and controls. |
| Notify your insurer fast | Most policies require notification within 24 to 72 hours of discovery; missing this window risks claim denial. |
| IT Start can help | IT Start helps Brisbane SMBs document and implement the controls insurers require, reducing both risk and premium. |
Cyber insurance is not a substitute for security
Here is an opinion that might be unpopular with some brokers: too many small businesses treat cyber insurance as a reason to delay fixing their security. They think the policy will cover the gap. It will not, and here is why that thinking is dangerous.
Insurers are getting smarter. Renewal questionnaires are longer than they were two years ago. Underwriters are asking for evidence, not just declarations. A business that ticks “yes” to MFA on the application but has not actually enforced it is not just underinsured. It is exposed to claim denial at the worst possible moment.
The businesses I see come through incidents best are the ones that treated insurance as the last line of defence, not the first. They had MFA enforced. They had tested backups. They had a plan. When something went wrong, the insurance paid quickly because there was nothing to dispute.
The honest advice: get your hygiene right, then get insured. In that order. If you are not sure where your gaps are, a cyber security assessment is a better first call than a broker. And when you do call a broker, ask specifically about exclusions for your sector. The answer will tell you a lot about whether they actually understand your business.
How IT Start helps reduce your insurance exposure
IT Start works with Brisbane SMBs to implement the exact controls insurers ask about: MFA across Microsoft 365, monthly backup restore testing, patch management, endpoint protection, and centralised monitoring. These are not abstract security concepts. They are the specific items on underwriter questionnaires, and having them documented and active makes a real difference to both your insurability and your premium.
If you are preparing to apply for cover or renewing an existing policy, IT Start can run a security gap check against standard insurer requirements and give you a written summary of your current posture. That document is useful both for brokers and for your own records. Our managed cyber security services cover the controls that matter most to underwriters, and our cloud services include backup management and patch scheduling. Get in touch for a free assessment and find out where your gaps are before your insurer does.
Useful sources
These are the primary sources worth bookmarking when reviewing policy wording or preparing for a claim:
- ACSC Annual Cyber Threat Report 2024-2025 — sector-by-sector incident data for Australia
- ACSC Essential Eight Maturity Model — the baseline security controls insurers reference
- OAIC Notifiable Data Breaches scheme — your regulatory notification obligations under the Privacy Act
- Insurance Council of Australia — industry guidance on cyber insurance products available in Australia
- IT Start cybersecurity insurance guide for SMBs — deeper reading on comparing policies and requirements for Australian SMEs
- IT Start cyber liability insurance guide for Queensland SMBs — state-specific guidance for Queensland businesses
The ACSC’s guidance on the Essential Eight is the closest thing Australia has to a universal baseline for cyber security controls. Insurers reference it. Regulators reference it. If your business is not working toward Essential Eight Maturity Level 1, you are behind where underwriters expect you to be.
After an incident, managing how your business is perceived publicly matters as much as the technical response. A practical guide to managing your online reputation after a breach is worth reading before you need it.
FAQ
What is cyber risk in insurance?
Cyber risk in insurance refers to the financial exposure a business faces from cyber incidents such as data breaches, ransomware, and system outages. A cyber insurance policy transfers some of that financial risk to the insurer in exchange for a premium.
What does cyber insurance actually cover?
Most policies cover forensic investigation, data recovery, business interruption losses, ransom payments, legal defence, regulatory fines, and customer notification costs. Coverage varies by policy, so always read the Product Disclosure Statement for sublimits and exclusions.
What are common examples of cyber risks that lead to claims?
Ransomware, business email compromise (BEC) fraud, data breaches caused by phishing or misconfiguration, DDoS attacks, and supply chain compromises are the most common incident types that trigger claims for Australian SMBs.
Is cyber attack insurance worth it for small businesses?
Yes, given that the average self-reported cost of a cybercrime incident to a small business is $56,600, a policy costing $500 to $5,000 per year is financially justified for most SMBs. The key is ensuring your security controls meet the policy conditions so the cover actually pays when you need it.
What security controls do insurers require before offering cover?
Insurers typically require multi-factor authentication, tested and documented backups, regular patching, phishing awareness training, and endpoint protection. Missing these controls can result in declined cover or claim denial after an incident.

