Cyber Insurance: What It Covers and Why It Matters in 2026
Cyber incidents are no longer rare events. In 2025, Australian organisations reported over 1,200 data breaches to regulators, the highest number since mandatory notification began in 2018. Ransomware attacks are occurring every six minutes according to Australia’s cyber threat reports. Yet many businesses still operate without dedicated cyber insurance, exposing themselves to costs that can reach hundreds of thousands of dollars.
Cyber insurance is designed to transfer the financial impact of cyber incidents from your business to an insurer. It covers costs directly arising from data breaches, ransomware attacks, system failures, and the investigations and notifications that follow. Combined with strong security practices, cyber insurance is an essential part of managing cyber risk in 2026.
This guide explains what cyber insurance covers, how it works in Australia, who needs it, and what to look for when choosing a policy.
The Cyber Threat Landscape in Australia
Why Businesses Are Being Targeted
Cyberattacks are not random. Attackers target businesses because data has value, whether for financial gain, identity theft, competitive advantage, or extortion. Small and mid-sized businesses are increasingly targeted because they often have valuable data (customer information, financial records, intellectual property) but fewer resources to defend it than large enterprises. See our article ’10 Biggest Cyber Attacks in History’.
What Types of Attacks Are Happening
Ransomware and extortion: Attackers encrypt business systems and demand payment for the encryption key. Often, they also steal and threaten to publish sensitive data unless paid. Ransom demands have increased 47% in recent years, averaging over $1.4 million AUD, though most organisations refuse to pay. See our guide ‘What is Human-Operated Ransomware’.
Data breaches: Unauthorised access to customer data, employee records, financial information, or intellectual property. Breaches can occur through weak passwords, unpatched vulnerabilities, phishing emails, or insider actions.
Business email compromise: Attackers impersonate senior staff or trusted suppliers to trick employees into transferring funds or revealing confidential information. These attacks accounted for 58% of all cyber insurance claims globally in 2025. For an explanation of how social engineering works see our guide ‘What is Social Engineering and Why is it so Effective?’
System failure: Cyberattacks can bring down critical systems (websites, databases, production equipment), leaving a business unable to operate until systems are restored.
The Cost of Not Having Insurance
When a cyber incident occurs without insurance coverage, your business bears all costs directly. These include forensic investigation ($15,000 to $50,000+), notifying affected customers, credit monitoring services, system restoration, lost revenue during downtime, and potential regulatory fines. Small businesses report average incident costs around $56,600; larger organisations facing serious attacks can face costs exceeding $400,000. Many businesses do not recover from incidents of this magnitude.

How Cyber Insurance Works
Claims-Made Basis
Cyber insurance is almost always written on a “claims-made” basis. This is different from some other insurance policies. It means the policy in force when you first notify the insurer of an incident is the one that responds, not the policy in force when the breach originally occurred.
This has an important implication: if you change insurers or let your policy lapse, incidents that occurred during a previous policy period but were discovered (and reported to the insurer) after the policy ended may not be covered. Many businesses address this by purchasing “tail cover” (also called run-off cover) when their cyber policy ends, ensuring incidents discovered later are still covered.
What Triggers a Claim
A claim is triggered when you become aware of a cyber incident and notify your insurer. “Becoming aware” is important. It does not mean the incident must be confirmed or investigated first. As soon as you reasonably suspect a breach or cyber event has occurred, you should notify your insurer promptly. Delayed notification can complicate claims or affect coverage.
Most cyber policies require notification within a defined timeframe (often 30 to 90 days), with specific conditions attached. Check your policy wording for these notification requirements.
Coverage Territory
Cyber insurance is typically issued on a worldwide basis, meaning incidents occurring anywhere in the world are covered. However, policies often exclude certain countries or regions. Some policies include specific coverage for business interruption affecting Australian operations even if systems are hosted overseas.
What Cyber Insurance Covers
Modern cyber insurance policies typically include both first-party coverage (direct losses to your business) and third-party coverage (liabilities to others). The exact scope depends on the policy wording and which optional coverages you select.
First-Party Coverage: Direct Business Losses
Incident response and investigation costs
When a cyber incident occurs, your first step is to contain the damage and understand what happened. This requires specialists such as forensic investigators who examine systems to determine how the breach occurred, legal advisers who assess regulatory obligations, and incident response coordinators who manage the recovery process. These costs can reach $15,000 to $50,000 for a serious incident. Cyber insurance typically covers these investigation and professional fees.
Data restoration and recovery
After an incident, your business needs to rebuild systems, restore data from backups, and recover lost information. This includes the technical effort to restore operations, replacement of damaged hardware or software, and software licensing costs. Cyber insurance covers these restoration costs, helping you return to normal operations as quickly as possible.
Business interruption
If a cyberattack disables critical systems, your business cannot operate normally. You lose revenue during downtime while still incurring ongoing expenses such as staff wages, rent, and utilities. Cyber insurance business interruption coverage reimburses lost revenue and continuing expenses during the period while systems are being restored. This can be the single largest claim cost in a serious incident.
Breach notification and public relations
When personal information is exposed, affected individuals must be notified. This involves drafting notification letters, operating a call centre to handle inquiries, offering credit monitoring services, and managing media relations if the incident attracts public attention. These costs can reach tens of thousands of dollars. Cyber insurance covers breach notification expenses and crisis communication costs.
Cyber extortion and ransom
If attackers demand payment to release encrypted data or to prevent publication of stolen information, cyber insurance can cover the cost of professional negotiators who attempt to reduce the demand, and in some cases, the ransom payment itself. However, ransom payment coverage varies between policies and is subject to specific conditions (see the Common Exclusions section below). See our practical prevention guide: Ransomware: 5 Ways to Protect Your Business.
Third-Party Coverage: Liabilities to Others
Privacy breach liability and claims
When your business is sued by individuals or regulators following a data breach, cyber insurance covers legal defence costs and damages awarded. This includes claims under privacy law, negligence, or breach of contract where the claim arises from a cyber incident.
Regulatory investigation and penalty support
Following a serious data breach, regulators (such as the Office of the Australian Information Commissioner) may investigate whether your business met its Privacy Act obligations. Cyber insurance can cover the legal costs of responding to regulatory investigations and, in some cases, regulatory penalties or corrective action costs (though coverage of fines varies by policy and jurisdiction).
Media liability
If your website or systems are used to defame someone or infringe copyright, cyber insurance can cover the resulting claims and defence costs.
Australian Regulatory Requirements and Privacy Obligations
The Mandatory Data Breach Notification Scheme
Australia’s Privacy Act requires organisations to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when a data breach is likely to result in “serious harm.”
Who must comply
From 10 December 2026, the small business exemption is being removed. Currently, organisations with annual turnover over $3 million must comply. From December 2026, the requirement expands to include organisations with any turnover that hold personal information covered by the Privacy Act. If your organisation collects personal information (customer records, employee details, financial data, health records), you will need to consider these obligations.
The “eligible data breach” test
A data breach is notifiable only if all three conditions are met:
- Unauthorised access or disclosure: Personal information held by your organisation was accessed or disclosed without authorisation (or is at risk of being accessed if lost)
- Likely to result in serious harm: The breach is reasonably likely to cause significant damage to one or more individuals
- No successful remedial action: Your organisation cannot prevent the likely risk of serious harm through immediate action (such as remotely deleting the compromised data before attackers can access it)
All three conditions must be met. If you can successfully remediate the breach before serious harm occurs, it does not become notifiable.
What counts as “serious harm”
“Serious harm” is not defined in the Privacy Act. The standard is objective: would a reasonable person in your position, properly informed of the facts, consider serious harm likely? Serious harm includes serious financial, physical, psychological, emotional, or reputational harm.
Serious harm does not include mere distress or upset at learning a breach occurred. It typically arises when breached information is sensitive, such as financial details, identity documents, health records, or tax file numbers, or when it can facilitate follow-on attacks, such as contact information combined with a phishing attack.
The assessment timeline
When you become aware of a suspected data breach, you have 30 calendar days to assess whether it meets the eligible data breach test. This is the assessment window only. It is not the notification deadline. If you confirm the breach is notifiable, you must notify the OAIC and affected individuals “as soon as practicable,” typically within days, not weeks.
Notification requirements
If a breach is notifiable, you must inform:
- The OAIC with details of the breach, the kind(s) of information involved, and steps individuals should take
- Affected individuals directly (by email, letter, phone, or SMS) with the same information in plain language
You can notify only individuals at direct risk of serious harm, or if direct notification is impractical, publish a statement on your website and take reasonable steps to publicise it. Simply posting a notice on your website is insufficient if direct contact is practical.
Cyber insurance relevance
The costs of assessing a data breach, conducting the investigation, drafting notification letters, offering credit monitoring, and engaging legal counsel to assess regulatory obligations can be substantial. Cyber insurance covers many of these notification and investigation costs. However, it does not cover regulatory penalties imposed by the OAIC, these are generally not insurable under most policies.
Ransomware Payment Reporting
From 30 May 2025, organisations with annual turnover over $3 million must report ransomware or cyber extortion payments to the Australian Signals Directorate (ASD) within 72 hours of making the payment.
The reporting requirement applies regardless of whether cyber insurance covers the ransom payment. Before paying any ransom, consult legal counsel regarding sanctions law compliance and reporting obligations applicable to your business.
ASIC and APRA Regulatory Context
If your business is an Australian Financial Services Licensee or holds an APRA authorisation, regulatory expectations around cyber governance may affect your cyber insurance requirements and claims.
ASIC and APRA now require certain governance frameworks around cyber risk management. Insurers increasingly assess whether your business has governance structures in place (board accountability, incident response plans, vendor assessment). Cyber insurance is not legally mandatory, but it is increasingly expected as part of a comprehensive risk management approach.
For specific governance obligations applicable to your business, consult your regulator or a compliance adviser. Cyber insurers can discuss which governance elements they assess at underwriting. See our governance perspective: 4 Reasons to Manage Cyber Security Risk.
Common Cyber Insurance Exclusions
Not everything related to a cyber incident is covered by cyber insurance. Understanding common exclusions helps you assess whether your policy leaves gaps.
War and Terrorism
Cyberattacks attributed to state-sponsored actors or designated terrorist organisations are typically excluded. This is a market-wide exclusion across most Australian insurers.
Pre-Existing Vulnerabilities
If your business was aware of a security vulnerability before the incident but did not disclose it to the insurer, the insurer may deny the claim. This is why accurate disclosure of your security posture at underwriting is critical.
Insider Threats
Some policies exclude or limit coverage for incidents caused by employee misconduct, sabotage, or fraud. Coverage varies by policy; check your wording.
Failure to Maintain Security Standards
Many policies include a “due diligence” or “reasonable security” clause. If forensic investigation reveals that your business failed to implement basic security controls (multi-factor authentication on privileged accounts, endpoint detection on servers, immutable backups, patching critical vulnerabilities), the insurer may deny the claim or reduce the settlement. This exclusion transforms cyber insurance into a shared-responsibility model: the insurer expects you to maintain minimum standards.
Contractual Liability
Some policies exclude losses arising from contractual obligations. For example, if a customer contract requires you to maintain specific security standards and you failed to do so. Coverage of contractual liability varies by policy.
Sub-Limits
Many policies include sub-limits for specific coverage types. For example, a $1 million overall policy might have a $500,000 business interruption sub-limit. Business interruption claims are capped at $500,000 even though the overall limit is $1 million. Read your policy schedule carefully to understand sub-limits that may apply to your coverage.
Prior Incidents
If your business has experienced a previous cyber incident and did not notify the insurer at the time, subsequent incidents may not be covered. Prompt notification of any suspected breach is essential, even if you later determine it was not notifiable under the NDB scheme.
When to Consider Cyber Insurance
Cyber insurance may be appropriate for many businesses, depending on your industry, business model, and data exposure.
Your business may benefit from cyber insurance if you:
- Handle customer or employee personal information (names, addresses, contact details, financial data, health records, identification numbers)
- Accept online payments or store payment card information
- Operate a website or online services
- Hold intellectual property or trade secrets
- Are a professional services firm (accounting, law, consulting) holding client confidential information
- Provide technology services or software
- Handle financial transactions or maintain trust accounts
- Have supply chain relationships with larger organisations (which may require evidence of cyber insurance)
Industries with higher exposure to cyber risk include healthcare, legal services, accounting, financial services, technology companies, manufacturing, and government contractors.
Emerging technologies such as artificial intelligence introduce new cyber exposures. As organisations adopt AI tools and systems, they face new security risks and regulatory oversight expectations. Understanding these risks is critical for insurance planning. For an in-depth look at cyber risks associated with AI adoption, see our guide: ‘5 Business Risks to Consider When Using Artificial Intelligence’.
Determining whether cyber insurance is right for your specific business is best done through a risk assessment. An insurance adviser can help you evaluate your cyber exposure and recommend appropriate coverage limits.
Underwriting: What Insurers Assess
When you apply for cyber insurance, underwriters evaluate your security posture as part of their risk assessment. Insurers typically look at whether certain security controls are in place and operational.
Underwriters generally expect to see evidence of:
- Multi-factor authentication on privileged accounts and cloud services
- Endpoint detection systems on servers and workstations
- Regular data backups stored separately from production systems
- Documented processes for patching critical vulnerabilities
- An incident response plan that has been tested
Organisations with strong security controls in place typically receive better rates and broader coverage. Those with significant gaps may face higher premiums, coverage exclusions, or declined applications.
For larger organisations or higher coverage limits, insurers may engage independent security specialists to validate that security controls are operational. This is why transparency about your security posture at underwriting is critical. Discrepancies between what you declare and what verification reveals can affect claim outcomes.
The specific controls your business should implement are best discussed with your IT service provider or security adviser, who can assess your business’s particular risks and needs.

Frequently Asked Questions
How much cyber insurance coverage do I need?
Coverage limits should reflect the maximum financial exposure your business could face from a cyber incident. Consider:
- Your annual revenue (business interruption losses)
- The volume and sensitivity of personal information you hold
- Potential regulatory investigation costs
- Your ability to pay uninsured losses
Most small businesses benefit from $500,000 to $1 million in coverage. Larger organisations often need $2 million or higher. Work with an adviser to assess your specific exposure.
Does cyber insurance cover ransomware?
Most modern cyber insurance policies do cover ransomware-related costs, including forensic investigation, incident response, system restoration, and business interruption during recovery. However, ransom payment coverage varies. Some policies cover ransom payments (subject to conditions), others limit or exclude them, and some require insurer approval before a ransom is paid. Check your policy wording. Remember that if you pay a ransom, you must report it to the Australian Signals Directorate within 72 hours if your organisation has annual turnover over $3 million.
What’s the difference between cyber liability and cyber property?
Cyber liability insurance covers your legal responsibility to others, including third-party claims from individuals whose data was breached, regulatory investigations, or lawsuits alleging negligence. Cyber property insurance (or cyber asset insurance) covers your direct business losses, including data recovery, business interruption, and breach notification costs. Most cyber policies combine both coverages. Some businesses purchase standalone cyber liability policies without the direct loss components; these leave significant gaps.
Does general liability insurance cover cyber incidents?
Typically, no. General liability policies are designed for physical injury or property damage claims. A cyber incident resulting in a data breach or business interruption is usually not covered under general liability wording. Dedicated cyber insurance is needed for cyber-specific exposures.
What if we have strong IT security in place?
Strong security reduces your risk and often results in lower premiums and better coverage terms. However, even well-protected businesses can experience breaches through human error, novel attack methods, or supply chain compromises. Cyber insurance is not a substitute for security. It is a financial backstop when prevention fails. Insurers expect security to be in place; they reward it with better terms.
How is cyber insurance premium calculated?
Premiums depend on your industry, revenue, employees, security controls, claims history, coverage limits, and the scope of data you hold. Underwriters assess each of these factors. A small professional services firm with $500,000 revenue might pay $1,200 to $2,500 annually for $1 million in coverage. A technology company with $10 million revenue might pay $8,000 to $15,000+. Exact pricing varies by underwriter and your specific risk profile.
What’s the Privacy Act mandatory data breach notification scheme?
It is Australia’s legal requirement (under the Privacy Act 1988) for organisations to notify regulators and affected individuals when a data breach is likely to cause serious harm. The requirement applies to organisations with annual turnover over $3 million (expanding to all sizes from December 2026). Notification must occur “as soon as practicable” after confirming the breach is notifiable. Failure to comply can result in civil penalties.
Can we get cyber insurance if we’ve had a previous breach?
Yes, but the underwriting process will be more rigorous. You will need to demonstrate that you have identified the cause of the previous breach, implemented remediation measures, and strengthened your security controls. Undisclosed previous breaches can result in claim denials under “prior incident” exclusions, so transparency is important.
What’s included in “business interruption” cyber coverage?
Business interruption covers lost revenue your business would have earned during the period when systems are down due to a cyber incident, plus continuing expenses (rent, utilities, staff wages) that you must pay even though you cannot operate. It does not cover new expenses you incur to expedite recovery. Business interruption sub-limits are common, so check what your policy covers.
Does cyber insurance cover regulatory fines?
Coverage of regulatory fines and penalties varies significantly by policy. Some policies exclude penalties entirely. Others cover penalties imposed by data protection regulators (like the OAIC) in certain circumstances, but typically only where the penalty results from the breach itself, not from pre-existing compliance failures. Criminal penalties are almost never covered. Check your policy wording and discuss with your adviser.
What happens if we don’t have cyber insurance and get breached?
Your organisation bears all costs directly: investigation, notification, system restoration, lost revenue, potential fines, and legal defence costs. For many small and mid-sized businesses, a serious cyber incident without insurance is catastrophic. Costs often exceed the business’s ability to pay, leading to closure. Having no cyber insurance is a significant business continuity risk.
How do we choose between cyber policies?
Compare coverage scope (what is included), exclusions (what is not), limits and sub-limits (what is the maximum payout), premium cost, insurer reputation for claims handling, and whether optional coverages (such as ransomware payment cover) align with your needs. Seek advice from an insurance adviser who specialises in cyber coverage. The wording differences between policies can be substantial and may not be obvious from marketing materials.
Industry-Specific Guidance
Cyber risks and insurance needs vary by industry. For risk and insurance considerations tailored to your business sector, refer to our industry-specific pages listed in our menu bar. We have listed a few below:
- Clubs & Hospitality
- Professional Services
- Technology & Start-Ups
- Manufacturing
- Not-for-Profits
- Allied Health
Next Steps
If you’d like advice or a no-obligation risk and insurance review tailored to your business, contact Clear Insurance on 1300 721 132 or email info@clearinsurance.com.au. Clear Insurance specialises in cyber insurance advice for professional services, technology businesses, manufacturing, and other sectors facing evolving cyber risks.
General Advice Warning
This information is general advice only. It does not take into account your objectives, financial situation, or individual circumstances. You should consider whether the information is appropriate for you and your personal circumstances before making any decision about whether to acquire cyber insurance. Before you acquire any cyber insurance policy, you should obtain and read the relevant Product Disclosure Statement from the insurer. Different policies have different coverage, exclusions, and terms. If you would like personal advice tailored to your specific situation, or if you are uncertain about your cyber insurance needs, contact an insurance adviser. Clear Insurance Pty Ltd operates under Australian Financial Services Licence 548953, ABN 41 601 916 689. For more information about our services and how we can help you, contact us or read our Financial Services Guide.
Disclaimer
The information in this guide is current as of August 2026 and reflects Australian privacy law, regulatory guidance, and market practice at that time. Cyber threats, insurance products, and regulations change regularly. You should verify current terms with your insurer and seek professional advice before making insurance decisions.