Cyber insurance pays for the costs of a cyber incident, such as ransomware, a hacked email account or a data breach: getting expert help to contain it, restoring systems and data, notifying affected customers, the income you lose while you can't trade, and claims or regulatory action from people whose information was exposed. Most small business policies combine that first-party cover with third-party liability cover.
It is not compulsory, and it's usually not included in a standard business package, so a business that takes payments, holds customer records or can't trade without its systems should look at it on its own merits. The value is in the detail: what the policy calls an incident, the sub-limits on payment fraud, the waiting period before income cover starts, and the security steps you promise on the proposal form.
By Better Rate Mate Editorial Team ยท Last reviewed
Policies split into two halves. First-party cover pays your own costs after an incident; third-party cover pays claims made against you by others. The table sets out what each part usually responds to. Names and limits differ between insurers, so the policy wording decides.
| Part | What it usually pays for | What to check |
|---|---|---|
| Incident response | IT forensic specialists, lawyers and crisis support to contain the incident and work out what happened | Whether there is a 24/7 hotline and whether you must use the insurer's panel of providers |
| Data and system restoration | Recovering or rebuilding data, software and systems damaged by the incident | Whether hardware replacement is included or excluded |
| Business interruption | Lost profit while your systems are down because of a covered incident | The waiting period in hours before cover starts, and the indemnity period |
| Notification and monitoring | Telling affected individuals and regulators, and credit or identity monitoring for customers | Whether regulator-required notifications are covered in full |
| Cyber extortion | Specialist negotiation and, where lawful and agreed by the insurer, an extortion payment | The insurer's consent conditions and the ransom payment reporting rule (below) |
| Privacy and network liability | Claims by customers or others whose information was exposed, and the legal cost of defending them | The limit, and whether it is shared with your first-party costs |
| Regulatory defence | Legal costs of responding to a regulator's investigation after a breach | Whether fines and penalties are covered at all, and only where insurable by law |
| Payment diversion (social engineering) | Money sent to a criminal after a fake invoice or a hacked supplier email | Often a small sub-limit or an optional extension, sometimes only under crime cover |
Two sets of legal obligations can land on a business in the days after an incident, and a good policy funds the help you need to meet them.
The first is the Notifiable Data Breaches scheme, run by the Office of the Australian Information Commissioner (OAIC) under the Privacy Act. Organisations covered by it must notify the OAIC and the people affected when a data breach is likely to result in serious harm, and must take all reasonable steps to assess a suspected breach within 30 calendar days. The scheme covers businesses and not-for-profits with an annual turnover of more than $3 million, and some smaller businesses regardless of turnover, including private health service providers, businesses that trade in personal information and Commonwealth contractors. The small business exemption was still in place at the time of writing, although the government released an exposure draft privacy bill for consultation in 2026, so check the OAIC for changes.
The second is ransomware payment reporting under the Cyber Security Act 2024. Since 30 May 2025, a business with an annual turnover of $3 million or more in the previous financial year must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it, or of becoming aware that someone paid on its behalf. The obligation applies to the payment, not to the demand: an incident where nothing was paid does not have to be reported under this rule, although the government encourages voluntary reports through cyber.gov.au.
Every policy has exclusions, and a few catch small businesses more often than others:
Ask what a week without your systems, or a leaked customer list, would actually cost. A business that takes bookings or payments online, keeps health, financial or identity records, or can't invoice or trade when its email and accounts are locked is exposed, whatever its size. A tradie who keeps job details in a notebook and takes bank transfers is exposed too, but mostly to payment diversion, which is often only lightly covered.
Cyber cover sits alongside good security rather than replacing it. The Australian Cyber Security Centre's small business guide recommends three measures as a starting point: turn on multi-factor authentication, keep software updated, and back up your information. Insurers ask about the same basics on their proposal forms, so getting them in place helps both your security and your cover.
Usually not in full. Some business packages and management liability policies include a small cyber or crime section, and some professional indemnity policies respond to a claim that your error caused a client's data loss. None of those normally pays for your own incident response, restoration or lost income. If you are relying on one, check its limit and what it actually lists as covered before you decide you don't need a standalone policy.
Cyber policies are harder to compare on price than most business cover, because the structure varies so much. Put the quotes side by side on these points:
| Detail | Why it matters |
|---|---|
| Overall limit, and whether first- and third-party cover share it | A shared limit can be used up by your own costs before a customer claim arrives |
| Sub-limits for payment diversion, extortion and regulatory matters | These are where small-business losses concentrate |
| Business interruption waiting period | A long waiting period can mean a short outage is never covered |
| Excess (sometimes called a retention) | Check whether it applies per claim and whether a separate time excess applies to interruption |
| Claims-made basis and retroactive date | Cyber is usually written on a claims-made basis; an unknown intrusion that began before the retroactive date may not be covered |
| Incident response service | Access to specialists in the first hours is often the most valuable part of the policy |
| Security conditions | The warranties you give on MFA and backups; a false answer can defeat a claim |
Your own costs after a cyber incident (incident response, data and system restoration, lost profit while systems are down, notifying affected customers) and claims or regulatory investigations brought against you because of it. Payment diversion fraud is usually sub-limited or needs an extension.
No. No law requires a business to hold cyber insurance. Some clients, particularly government and larger businesses, ask their suppliers to hold it as a contract condition.
Some policies can cover an extortion payment where it is lawful and the insurer consents in advance; others exclude it. Separately, a business with an annual turnover of $3 million or more must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours.
Sometimes, under a social engineering or payment diversion section, but it is often a small sub-limit or an optional extra, and some insurers place it under crime cover instead. Check the wording rather than assuming the headline limit applies.
If your business is covered by the Notifiable Data Breaches scheme, yes: breaches likely to result in serious harm must be notified to the OAIC and the people affected. The scheme covers businesses with an annual turnover of more than $3 million, and some smaller ones regardless of turnover, such as private health service providers.
The ATO lists insurance premiums among the operating expenses a business can generally deduct. Check your own situation with your accountant or the ATO.
This page explains how cyber insurance generally works in Australia. It is not advice about your business or any particular policy. Read the Product Disclosure Statement and Target Market Determination before you buy, and speak to a licensed adviser or broker if you are unsure what you need.