Skip to content
CYBER INSURANCE

Cyber insurance for Australian businesses

Cyber incidents can disrupt systems, expose information and create significant financial and operational consequences. RMA Insurance Brokers helps businesses review cyber exposures and arrange insurance around the systems, data and technology they rely on.

Support for businesses before and after a cyber incident.

Australian business owner reviewing computer systems in a regional office

Overview

Cyber insurance overview

Cyber insurance is designed to help businesses manage certain financial consequences of a cyber incident, data breach or disruption to business systems.

Depending on the policy, cover may respond to the business’s own losses as well as certain claims, regulatory costs or response expenses arising where customers, clients or other third parties are affected.

Access to experienced incident-response services is also an important part of the insurance arranged.

Where risk arises

Where can cyber risk arise?

Cyber risk is not limited to technology businesses or large organisations. Most exposures sit in the everyday systems a business relies on.

  • Email and online banking
  • Cloud-based systems
  • Customer or client records
  • Accounting and payroll systems
  • Websites and online services
  • Laptops, mobile devices and remote access

Malware, phishing and ransomware are among the more common threats facing smaller businesses, and they may expose an organisation to data theft, extortion and significant disruption.

Cyber insurance is therefore relevant to SMEs, professional businesses, trades, agribusinesses, transport operators, property businesses and many others. For most businesses it sits alongside broader Business Insurance. Our Insight on cyber insurance for Australian small business looks at these considerations in more detail.

Cover

What cover may be available?

Cyber policies differ significantly in the protection and response services they provide. The sections selected, limits arranged and conditions shown in the policy schedule determine how the insurance applies.

The areas below are commonly considered when cyber insurance is reviewed, subject to the insurer and the policy wording.

Incident response & crisis management

A cyber incident often requires specialist assistance immediately.

Depending on the policy, cover may assist with costs associated with investigating and managing an insured cyber event, including specialist cyber-response services.

Many cyber policies arrange incident-response services through providers approved by the insurer, so early notification following an incident is important.

Business interruption

Cyber business interruption cover may respond to certain financial losses where an insured cyber event disrupts systems and prevents the business from operating normally.

Depending on the policy, cover may also respond to certain accidental system failures or human errors. The applicable trigger, waiting period, calculation method and period of cover vary between policies.

Data recovery

Cover may be available for certain costs associated with recovering, restoring or, in some cases, replacing electronic business data and software following an insured cyber incident.

Cyber extortion

Some cyber policies may provide assistance following an insured cyber-extortion or ransomware event.

Depending on the policy, this may include access to specialist advisers and certain costs associated with responding to the extortion event.

Where cover extends to an actual ransom payment, insurer consent and legal requirements may apply.

Privacy & security liability

A cyber incident may affect personal, confidential or other third-party information held by the business.

Depending on the policy, cover may respond to certain claims arising from a security or privacy breach.

Notification & defence costs

Following an insured data breach, cover may be available for certain notification, monitoring, investigation, regulatory-response and legal defence costs.

The scope of these expenses varies between cyber policies.

Boundaries

Where other insurance applies

Cyber privacy and security liability is distinct from broader Public and Products Liability Insurance, which generally addresses third-party personal injury and property damage arising from business activities or products.

Traditional Business Interruption cover, commonly arranged as part of Business Insurance, generally follows insured physical damage, while cyber business interruption responds according to the cyber-specific triggers in the policy.

Security

Cyber insurance and cyber security work together

Insurance is one part of managing cyber risk. It does not replace appropriate security controls.

  • multi-factor authentication and access controls

  • software updates and patching

  • staff awareness and phishing training

  • endpoint and device security

  • current and appropriately protected backups

  • cyber incident response planning

The controls required by insurers vary according to the business and cyber risk.

Some insurers may require particular security measures before offering cover or may apply conditions to the insurance arranged, so a cyber insurance review considers both the policy and the security information insurers ask for.

Theft of funds

Cyber insurance does not necessarily cover stolen money

One area worth checking carefully is the difference between a cyber incident and the direct financial loss caused when money is fraudulently transferred or stolen.

Direct theft of money should not automatically be assumed to be covered simply because email, online banking or another digital system was involved.

Depending on the policy, cover for social engineering, fraudulent instructions or other theft-of-funds exposures may be optional, subject to separate limits or subject to specific conditions.

Separate or additional insurance may need to be considered for some fraudulent-transfer exposures. RMA Insurance Brokers helps clients identify how the cyber and business insurance arranged treats these exposures.

Information

What information may be needed for a review?

When reviewing cyber insurance, we usually look at:

  • nature, size and turnover of the business

  • types of information held and reliance on technology

  • systems, cloud services and critical outsourced technology providers

  • multi-factor authentication, access and endpoint security information

  • backup and incident-response arrangements

  • previous cyber incidents, breaches or known circumstances

Additional information may be required depending on the business, data held and cyber limits requested.

Accurate answers about security controls are important because insurers may rely on this information when deciding whether to offer cover and on what terms.

Limits

What may not be covered?

Not every loss or circumstance will be covered under a cyber insurance policy. Exclusions, limits, excesses and conditions differ between insurers, so some areas are worth checking carefully when reviewing your cover:

  • physical damage to computer hardware, except where the policy provides limited repair or replacement cover following a cyber event
  • deliberate, dishonest or criminal acts by the insured business
  • incidents or circumstances known before cover commenced
  • theft of money where the relevant financial-loss cover has not been arranged
  • loss connected with war or certain state-backed cyber operations
  • general power, telecommunications or internet outages that are not themselves the result of an insured cyber event
  • incidents where applicable policy conditions have not been met

This is not a complete list.

The policy wording, schedule, endorsements and circumstances of the cyber incident determine how the insurance responds.

Australian small business owners reviewing cyber risk information on a laptop

When should cyber insurance be reviewed?

A review is particularly worthwhile when a business has:

  • introduced a new business system or cloud platform
  • increased the amount of customer or personal information held
  • materially changed remote-access arrangements
  • expanded online services or e-commerce
  • significantly increased turnover or transaction values
  • acquired or merged with another business
  • experienced a cyber incident or attempted compromise
  • materially changed its cyber-security arrangements

Annual renewal is also an opportunity to confirm that the security information supplied to the insurer remains accurate.

Broker support

Cyber insurance support built around your business

Cyber insurance varies significantly between insurers, particularly around incident response, business interruption, cyber extortion, privacy liability, fraudulent transactions and security requirements.

We help businesses understand the information insurers require, compare available policy structures and consider how cyber cover relates to the systems, data and technology the business relies on.

RMA Insurance Brokers works with businesses across rural, regional and metropolitan Australia. Through our relationship with rma network Livestock & Property Agents, we have connections throughout regional Australia. We also support clients outside the rma network and across other parts of Australia.

How we help

How we help businesses

  • identify the cyber exposures affecting the business

  • review the cyber-security information required by insurers

  • gather information required for underwriting

  • consider appropriate limits and policy sections

  • compare available policy structures and incident-response arrangements

  • clarify business interruption, data recovery and theft-of-funds boundaries

  • assist with policy changes, renewals and cyber insurance claims

Our focus is on understanding how the business relies on technology and helping arrange insurance relevant to those exposures.

What happens after you enquire?

We contact you

A broker from RMA Insurance Brokers will get in touch to understand the business, the systems and information it relies on, current cyber-security arrangements and whether cyber insurance is already in place.

We confirm what is needed

We will explain what information is needed, answer your questions and confirm the next step before approaching insurers.

Useful information to have available
  • current cyber policy, if applicable
  • business activities and turnover
  • systems and cloud-service information
  • cyber-security information requested by insurers
  • backup and incident-response information
  • previous cyber incidents or claims

FAQs

Frequently asked questions

What does cyber insurance cover?

Cyber insurance may provide cover for certain first-party losses, third-party liabilities and incident-response expenses arising from an insured cyber event.

Depending on the policy, this may include business interruption, data recovery, cyber extortion, security and privacy liability, defence costs, crisis management and notification expenses.

The exact cover depends on the policy arranged.

Does cyber insurance cover ransomware?

Cyber insurance may provide cover for certain costs arising from an insured ransomware or cyber-extortion event.

Depending on the policy, this may include specialist response services, data recovery, business interruption or other insured expenses.

Where cover extends to an actual ransom payment, insurer consent and legal requirements may apply. Other conditions and exclusions also vary between insurers.

Does cyber insurance cover lost income if my systems are unavailable?

Cyber business interruption cover may respond to certain financial losses where an insured cyber event disrupts business operations.

Depending on the policy, cover may also respond to certain accidental system failures or human errors. The trigger, waiting period, calculation of loss and period of cover vary between policies.

Does cyber insurance cover money stolen through phishing or email fraud?

Not necessarily.

Some cyber policies may exclude the direct theft of money even where the fraud involves email, online banking or another digital system.

Where this cover is available, it may be optional, subject to a separate limit or subject to specific conditions.

Separate or additional insurance may need to be considered depending on the exposure.

What cyber-security measures should a business have?

Appropriate measures depend on the business, but insurers commonly ask about multi-factor authentication and access controls, software updates and patching, staff awareness and phishing training, endpoint and device security, current and appropriately protected backups, and cyber incident response planning.

Insurers may also have their own minimum security requirements before they will offer cyber cover.

Australian business owner reviewing computer systems in a regional office
Get in touch

Review your cyber insurance

Technology, systems and cyber threats continue to change.

RMA Insurance Brokers helps businesses review whether their cyber insurance and the information provided to insurers still reflect the way the business operates today.

The information on this page is general information only and does not take into account your objectives, financial situation or needs. Cover is subject to the terms, conditions, limits and exclusions of the relevant policy. Insurance products and available cover vary between insurers. Please review the relevant policy documentation and obtain advice appropriate to your circumstances before making a decision.