Better Rate Mate koala mascot
Compare
Open menu
Compare everything
Car Insurance
Home Insurance
Health Insurance
Life Insurance
Income Protection
Business Insurance
Travel Insurance
Pet Insurance
Overseas Visitor Cover

Cyber insurance for small business: what it covers and what to check

Cyber insurance pays for the costs of a cyber incident, such as ransomware, a hacked email account or a data breach: getting expert help to contain it, restoring systems and data, notifying affected customers, the income you lose while you can't trade, and claims or regulatory action from people whose information was exposed. Most small business policies combine that first-party cover with third-party liability cover.

It is not compulsory, and it's usually not included in a standard business package, so a business that takes payments, holds customer records or can't trade without its systems should look at it on its own merits. The value is in the detail: what the policy calls an incident, the sub-limits on payment fraud, the waiting period before income cover starts, and the security steps you promise on the proposal form.

By Better Rate Mate Editorial Team ยท Last reviewed

What cyber insurance covers

Policies split into two halves. First-party cover pays your own costs after an incident; third-party cover pays claims made against you by others. The table sets out what each part usually responds to. Names and limits differ between insurers, so the policy wording decides.

The two halves of a cyber policy
PartWhat it usually pays forWhat to check
Incident responseIT forensic specialists, lawyers and crisis support to contain the incident and work out what happenedWhether there is a 24/7 hotline and whether you must use the insurer's panel of providers
Data and system restorationRecovering or rebuilding data, software and systems damaged by the incidentWhether hardware replacement is included or excluded
Business interruptionLost profit while your systems are down because of a covered incidentThe waiting period in hours before cover starts, and the indemnity period
Notification and monitoringTelling affected individuals and regulators, and credit or identity monitoring for customersWhether regulator-required notifications are covered in full
Cyber extortionSpecialist negotiation and, where lawful and agreed by the insurer, an extortion paymentThe insurer's consent conditions and the ransom payment reporting rule (below)
Privacy and network liabilityClaims by customers or others whose information was exposed, and the legal cost of defending themThe limit, and whether it is shared with your first-party costs
Regulatory defenceLegal costs of responding to a regulator's investigation after a breachWhether fines and penalties are covered at all, and only where insurable by law
Payment diversion (social engineering)Money sent to a criminal after a fake invoice or a hacked supplier emailOften a small sub-limit or an optional extension, sometimes only under crime cover
A general guide to how cyber policies are structured. Cover, sub-limits and exclusions differ between insurers; read the Product Disclosure Statement or policy wording before you buy.

The reporting rules a cyber incident can trigger

Two sets of legal obligations can land on a business in the days after an incident, and a good policy funds the help you need to meet them.

The first is the Notifiable Data Breaches scheme, run by the Office of the Australian Information Commissioner (OAIC) under the Privacy Act. Organisations covered by it must notify the OAIC and the people affected when a data breach is likely to result in serious harm, and must take all reasonable steps to assess a suspected breach within 30 calendar days. The scheme covers businesses and not-for-profits with an annual turnover of more than $3 million, and some smaller businesses regardless of turnover, including private health service providers, businesses that trade in personal information and Commonwealth contractors. The small business exemption was still in place at the time of writing, although the government released an exposure draft privacy bill for consultation in 2026, so check the OAIC for changes.

The second is ransomware payment reporting under the Cyber Security Act 2024. Since 30 May 2025, a business with an annual turnover of $3 million or more in the previous financial year must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it, or of becoming aware that someone paid on its behalf. The obligation applies to the payment, not to the demand: an incident where nothing was paid does not have to be reported under this rule, although the government encourages voluntary reports through cyber.gov.au.

What cyber insurance usually does not cover

Every policy has exclusions, and a few catch small businesses more often than others:

Does my business need cyber insurance?

Ask what a week without your systems, or a leaked customer list, would actually cost. A business that takes bookings or payments online, keeps health, financial or identity records, or can't invoice or trade when its email and accounts are locked is exposed, whatever its size. A tradie who keeps job details in a notebook and takes bank transfers is exposed too, but mostly to payment diversion, which is often only lightly covered.

Cyber cover sits alongside good security rather than replacing it. The Australian Cyber Security Centre's small business guide recommends three measures as a starting point: turn on multi-factor authentication, keep software updated, and back up your information. Insurers ask about the same basics on their proposal forms, so getting them in place helps both your security and your cover.

Is cyber cover part of my business package?

Usually not in full. Some business packages and management liability policies include a small cyber or crime section, and some professional indemnity policies respond to a claim that your error caused a client's data loss. None of those normally pays for your own incident response, restoration or lost income. If you are relying on one, check its limit and what it actually lists as covered before you decide you don't need a standalone policy.

How to compare cyber insurance quotes

Cyber policies are harder to compare on price than most business cover, because the structure varies so much. Put the quotes side by side on these points:

Comparing cyber insurance like for like
DetailWhy it matters
Overall limit, and whether first- and third-party cover share itA shared limit can be used up by your own costs before a customer claim arrives
Sub-limits for payment diversion, extortion and regulatory mattersThese are where small-business losses concentrate
Business interruption waiting periodA long waiting period can mean a short outage is never covered
Excess (sometimes called a retention)Check whether it applies per claim and whether a separate time excess applies to interruption
Claims-made basis and retroactive dateCyber is usually written on a claims-made basis; an unknown intrusion that began before the retroactive date may not be covered
Incident response serviceAccess to specialists in the first hours is often the most valuable part of the policy
Security conditionsThe warranties you give on MFA and backups; a false answer can defeat a claim

What to watch for

Common questions

What does cyber insurance cover?

Your own costs after a cyber incident (incident response, data and system restoration, lost profit while systems are down, notifying affected customers) and claims or regulatory investigations brought against you because of it. Payment diversion fraud is usually sub-limited or needs an extension.

Is cyber insurance compulsory in Australia?

No. No law requires a business to hold cyber insurance. Some clients, particularly government and larger businesses, ask their suppliers to hold it as a contract condition.

Does cyber insurance pay ransoms?

Some policies can cover an extortion payment where it is lawful and the insurer consents in advance; others exclude it. Separately, a business with an annual turnover of $3 million or more must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours.

Does cyber insurance cover scam invoices and fake bank details?

Sometimes, under a social engineering or payment diversion section, but it is often a small sub-limit or an optional extra, and some insurers place it under crime cover instead. Check the wording rather than assuming the headline limit applies.

Do small businesses have to report data breaches?

If your business is covered by the Notifiable Data Breaches scheme, yes: breaches likely to result in serious harm must be notified to the OAIC and the people affected. The scheme covers businesses with an annual turnover of more than $3 million, and some smaller ones regardless of turnover, such as private health service providers.

Is cyber insurance tax deductible?

The ATO lists insurance premiums among the operating expenses a business can generally deduct. Check your own situation with your accountant or the ATO.

General information only

This page explains how cyber insurance generally works in Australia. It is not advice about your business or any particular policy. Read the Product Disclosure Statement and Target Market Determination before you buy, and speak to a licensed adviser or broker if you are unsure what you need.

Related guides