Cyber and IT business cover

Cyber insurance, with an IT package option

Cyber cover for Australian businesses, plus a coordinated option for technology and IT service firms.

Cyber insurance may help an Australian business respond to insured cyber incidents through access to incident specialists and selected cover for response costs, data restoration, interruption, privacy liability, extortion and cybercrime. Cover differs materially by insurer and is not a substitute for security controls, an incident-response plan, legal advice or compliance with the Privacy Act and Notifiable Data Breaches scheme.

Reviewed by John Andrew Law, Authorised Representative 1262267.

Discuss cyber or an IT package

Cyber security specialist reviewing computer systems in a server room

IT package: cyber, PI and general liability

For IT consultants, software developers, managed service providers and other technology businesses, we can review one coordinated insurance option across three connected risks.

  • CyberIncidents, interruption, privacy liability and cybercrime, where insured.
  • Professional indemnityClaims linked to professional services, advice, errors or omissions, subject to the wording.
  • General liabilitySelected third-party injury and property-damage liability arising from business activities.

The available structure, insurer, limits, exclusions and cover sections depend on the business, insurer acceptance and the final policy wording.

Policy review

What can cyber insurance respond to?

Cyber policies are not standardised. The following areas are useful review headings, not promises that a particular policy will respond.

Incident response

Forensic investigation, breach counsel, notification support, credit monitoring, public relations and other approved response costs may be available after a covered event. Check panel-provider and insurer-consent requirements before appointing suppliers.

Data restoration and interruption

Cover may address approved restoration costs and loss from an insured interruption after the waiting period. Review the trigger, indemnity period, calculation method, system-failure extensions and dependent-provider cover.

Privacy and network liability

Selected defence costs, damages and regulatory-response costs may be covered for insured privacy or network-security claims. Fines and penalties are covered only where the wording includes them and the law permits insurance.

Cybercrime and social engineering

Fraudulent transfers, invoice manipulation and business email compromise may require a separate insuring clause and often have lower sublimits. Definitions, call-back procedures and voluntary-payment exclusions matter.

Cyber extortion

Policies may fund approved negotiation, specialist advice and certain payments following a covered threat. Sanctions, criminal law, notification, consent and policy conditions can restrict any response.

Technology and supply-chain dependencies

Cloud, managed-service, payment, telecommunications and software outages may not be covered automatically. Identify critical providers and compare dependent-system triggers, sublimits and waiting periods.

Security controls

Which cyber controls should a business be ready to explain?

The Australian Signals Directorate's small-business guidance recommends multi-factor authentication, software updates and information backups as starting measures, followed by implementation of Maturity Level One of the Essential Eight where appropriate. The Essential Eight also addresses application control, Microsoft Office macros, user application hardening and restriction of administrative privileges.

  • Multi-factor authentication: document where it is enforced, including email, remote access, cloud services, privileged accounts and sensitive customer portals.
  • Patching and supported systems: record asset discovery, vulnerability management, patch timeframes and removal of unsupported software.
  • Backups: keep secure and resilient backups, restrict access, and test restoration of data, applications and settings.
  • Privileged access: minimise administrator rights, validate access requests and separate privileged from ordinary user activity.
  • Email and payment verification: train staff to identify suspicious messages and independently verify payment requests or changed bank details using known contact information.
  • Incident response: maintain an offline contact list, assign decision-makers, test the plan and know how the business will operate if critical systems are unavailable.

These controls reduce risk but do not guarantee that an incident will be prevented or that insurance will be offered. Application answers should be checked with the people who operate the systems, such as internal IT staff or a managed service provider.

Privacy and breach response

When does the Notifiable Data Breaches scheme matter?

Not every cyber incident is an eligible data breach. For an entity covered by the Privacy Act, the OAIC explains that a breach is eligible when personal information is accessed or disclosed without authorisation, or lost, the incident is likely to cause serious harm to one or more people, and remedial action has not prevented that likely risk.

If a breach is suspected

The entity must conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days. The OAIC treats 30 days as a maximum and expects assessments to finish sooner where possible.

If an eligible breach is established

The entity must prepare the required statement, give it to the OAIC and notify affected people as soon as practicable, subject to the statutory process and exceptions. Obtain privacy legal advice for the particular incident.

A policy's incident-response service can support the process, but the policy does not transfer the organisation's legal duties. Privacy Act coverage also depends on the entity and information involved, so a turnover below $3 million does not by itself settle the question.

Renewal preparation

Cyber insurance review checklist

  • Map critical systems, sensitive data, technology providers and maximum tolerable outage.
  • Have IT personnel verify every security-control answer before the proposal is submitted.
  • Quantify likely restoration costs, interruption exposure and the time needed to rebuild systems.
  • Compare incident-response panels, notification requirements and consent before costs are incurred.
  • Compare overall limits with sublimits for cybercrime, social engineering, dependent systems, extortion and regulatory response.
  • Check excesses, waiting periods, retroactive dates, territorial scope, sanctions provisions and exclusions.
  • Disclose prior incidents, known circumstances, control gaps and material changes accurately.
  • Keep the insurer, broker, bank, legal adviser, IT provider and ASD Cyber Security Hotline contacts available offline.

Frequently asked questions

Cyber insurance questions

What does cyber insurance cover?

Cyber insurance can provide selected first-party and third-party cover for incident response, data restoration, business interruption, privacy and network security liability, cyber extortion and cybercrime. Every policy has its own triggers, limits, sublimits, waiting periods, exclusions and security conditions.

Does cyber insurance cover business email compromise?

Some policies include or offer cybercrime and social engineering cover for business email compromise, but scope and sublimits vary. Confirm whether fraudulent transfers, invoice manipulation, voluntary payments and verification procedures are covered. Contact the bank, broker and insurer immediately after a suspected loss.

Is cyber insurance compulsory in Australia?

Cyber insurance is not generally compulsory for Australian businesses. A contract, client, lender, industry arrangement or risk-management framework may require it. Privacy, data-security and breach-notification duties can still apply whether or not a business buys insurance.

Does cyber insurance replace Notifiable Data Breaches obligations?

No. Insurance does not replace cyber security, incident response or legal compliance. Entities covered by the Privacy Act must assess suspected eligible data breaches and notify the OAIC and affected individuals when the statutory threshold is met. Legal advice should determine obligations for a specific incident.

Can an IT business combine cyber, PI and general liability?

Yes, we can review a coordinated IT insurance option that brings the three areas together. The available structure, limits, exclusions and insurer appetite depend on the business and the offered wording.

Broking For You review focus

Connect the security controls to the cover

We map multi-factor authentication, privileged access, patching, endpoint protection, backups, email and payment verification, incident response, third-party dependencies and AI-use controls to the insurer's questions and the policy sections that may respond.

The review also isolates cybercrime and social-engineering sublimits, interruption waiting periods, response-panel requirements and security conditions. Insurance remains one part of the response and does not replace cyber security or privacy compliance.

Review cyber or an IT insurance package

Tell us about your services, systems, data, security controls and contracts. We can help organise the risk information and compare available terms.

Start an insurance enquiry