Skip to content
Operations HubIT & Cybersecurity

Cyber Insurance for Australian SMEs: What It Covers and What Insurers Now Expect

Cyber insurance has quietly become one of the most scrutinised covers an Australian SME can buy.

By Nick Lucock·24 July 2026·5 min read

The short answer

A solid SME cyber policy typically covers four things: incident response (forensics, legal and communications support), first-party losses (system restoration, business interruption and extortion costs), third-party liability (claims from affected customers and regulatory costs), and cybercrime extensions for social engineering and funds transfer fraud. After years of ransomware losses, insurers now expect demonstrable controls before they will quote, commonly aligned to the ASD Essential Eight. Read the proposal form honestly, because misrepresenting your controls can void a claim.

Cyber insurance has quietly become one of the most scrutinised covers an Australian SME can buy. The market hardened after years of ransomware losses: premiums rose, proposal forms grew teeth, and insurers started declining businesses — and claims — that would have sailed through a few years ago. That makes it worth understanding properly: what it covers, what it doesn't, and what insurers now expect from you before they'll take the risk.

What a cyber policy actually covers

Policies vary, but a solid SME cyber policy typically combines four things:

Incident response — the part you'll value most. Access to a 24/7 response team: forensic specialists to work out what happened, legal advice on your notification obligations, and communications support. For a business with no IT department, this panel is arguably worth more than the cheque. The hours after discovering a breach are chaotic, and knowing who to call is half the battle.

First-party losses. Your own costs: restoring systems and data, business interruption while you're down, and — subject to conditions — cyber extortion costs in ransomware events.

Third-party liability. Claims from others arising out of the incident — customers whose data was exposed, partners affected through your systems — plus regulatory investigation costs. With mandatory data breach notification in force and privacy penalties having risen sharply in recent years, this limb matters more than it used to.

Cybercrime extensions. Social engineering and funds-transfer fraud — the fake-invoice email that redirects a payment. Check this one specifically: it's sometimes an optional extension with a sub-limit, and for many SMEs it's the most likely loss they'll ever suffer.

What it doesn't cover

The exclusions that surprise people: bettering (the insurer restores what you had, not the upgraded systems you wished you had); losses flowing from failures you declared you didn't have — more on that below; often prior known incidents and sometimes events traced to unpatched systems where patches were long available; and the uninsurable costs — customer trust, your team's lost month, the deals that went elsewhere while you were rebuilding. Insurance funds recovery; it doesn't undo the event.

What insurers now expect before they'll quote

The proposal form is now effectively a security audit, and the baseline expectations are consistent across the market:

  • Multi-factor authentication on email, remote access and critical systems — for many insurers this is non-negotiable; without it you may not get a quote at all.
  • Backups that are separated from your network and actually tested. "We have backups" is no longer the question; "when did you last restore from them?" is.
  • Patching discipline — supported software, updates applied promptly.
  • Some form of staff awareness training, because most incidents start with a person, not a firewall.
  • Increasingly, endpoint protection beyond basic antivirus for larger SMEs.

Here's the part that matters most: answer the proposal form truthfully, and treat it as a living document. If you declare that MFA is enforced everywhere and a breach later walks in through an account that didn't have it, you've handed the insurer grounds to deny the claim. The form isn't paperwork — it's the foundation of the contract. If you're not sure whether a control is genuinely in place across the whole business, find out before you sign, not during a claim.

The right way to think about it

Cyber insurance is the last layer, not the first. The controls insurers demand — MFA, tested backups, patching, training — prevent the majority of incidents an SME will ever face, and they cost a fraction of one bad week. Put the controls in first (they'll also cut your premium), then buy the policy for the tail risk that controls can't eliminate. A business that buys the policy instead of the controls has insured a house it's left unlocked — and these days, the insurer has usually noticed.

FAQ

How much cover does an SME need?

It depends on your data, your downtime tolerance and your contracts (some clients now mandate minimum cyber cover). A broker who writes cyber regularly can benchmark you against similar businesses — limits that looked generous five years ago are often light against today's incident costs.

Will a policy pay a ransom?

Many policies can cover extortion payments in defined circumstances, subject to conditions and law — but insurers, responders and government all push hard toward recovery without payment, which is exactly why tested, offline backups are the control they care about most.

We're small. Are we really a target?

You're the preferred target. Attacks are automated and indiscriminate, and SMEs combine real money with lighter defences. Most incidents we see aren't sophisticated — they're a guessed password without MFA, or a convincing email on a busy Friday.


Want to know whether your security basics would pass an insurer's checklist? Our free Business Health Check covers technology risk alongside finance and operations — five minutes well spent.

About the author

Nick Lucock

Chief Executive Officer, Valont

Nick leads Valont's day-to-day operations across Finance, People, Operations and Growth. He writes about how the work actually gets done — the processes, systems, and tools that keep Australian SMEs compliant and growing.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.