Cyber insurance sits in an awkward spot for a lot of Australian SMEs: it feels like something only big companies with dedicated IT teams need, right up until the day a supplier's invoice gets intercepted or a laptop with client data goes missing. This is a plain-English walk through what a cyber policy actually covers, where the gaps usually are, and how to decide whether it's worth the premium for a business your size.
What cyber insurance actually covers
Most cyber policies split into two broad halves. First-party cover pays for your own losses and recovery: forensic investigation to work out what happened, restoring or rebuilding systems and data, business interruption while you're offline, the cost of notifying affected people, and in many policies the ransom and negotiation costs if you're hit with ransomware. Third-party (liability) cover responds when someone else suffers because of an incident on your watch — a client whose data was exposed, or a regulator asking questions. It typically covers legal defence, settlements, and the cost of responding to a regulatory investigation.
The part owners tend to underrate is the incident-response service that comes attached. A decent policy gives you a phone number that connects you to breach lawyers, forensic IT and PR specialists who've done this before. At 6am when your accounts inbox is locked, that panel is often worth more than the payout itself, because it stops you making expensive mistakes in the first few hours.
Where the real exposure sits for an SME
The headline risk everyone pictures is ransomware, but the more common and more insidious one for small businesses is business email compromise — a scammer sits inside an email thread, waits for an invoice to go out, and quietly swaps the bank details. By the time anyone notices, the money's gone. Read the fine print carefully here, because some policies treat funds transferred by a tricked staff member ("social engineering" or "funds transfer fraud") as a separate, optionally-purchased extension rather than something covered by default.
Other exposures worth mapping against a policy: theft or loss of a device holding client information, a supplier or cloud service you rely on being breached, and your legal obligations under the Notifiable Data Breaches scheme if personal information is compromised. That last one is a genuine cost even when no money is stolen — you may be legally required to notify the OAIC and affected individuals, and doing that properly takes time and advice.
Reading the policy so it actually pays out
The common trap is a mismatch between what the insurer assumes you're doing and what you're actually doing. Look closely at:
- Security warranties and conditions. Many policies now require multi-factor authentication on email and remote access, regular backups, and reasonably current software. If you attest to controls you don't have, a claim can be declined.
- Sub-limits. The big headline cover amount often hides much smaller caps on the parts you're most likely to claim — social engineering fraud, in particular.
- Waiting periods and exclusions. Business interruption usually only kicks in after a set number of hours offline, and known-but-unpatched vulnerabilities are frequently excluded.
- Who runs the response. Some policies require you to use the insurer's appointed panel; call them before you call your own IT provider or you may prejudice the claim.
Do the basics before you buy
Insurance is the backstop, not the strategy. The controls insurers ask about are the same ones that actually reduce your odds of a claim, and most map to the ASD Essential Eight: multi-factor authentication, patching applications and operating systems, restricting admin rights, and tested backups you can actually restore from. Doing these things generally lowers your premium and, more importantly, means a bad day stays a nuisance rather than a catastrophe. If you're building out this side of the business, our guidance on a connected back office and the broader operations hub covers how the pieces fit together.
So — do you need it?
The honest answer depends on what you'd lose. If your business holds customer personal or payment data, moves money by email, or simply couldn't trade for several days without serious harm, cyber insurance usually earns its place — and the premium for a small business is modest against the alternative. If you're a very small operation with minimal data and strong controls already in place, you might reasonably decide the incident-response access is the main thing you're buying. Either way, price it properly: get a broker who understands cyber to run a couple of options, and read the sub-limits, not just the front page.
This is general information, not financial or legal advice — cyber policies vary widely between insurers, so have a broker or adviser review the specific wording against your business before you rely on it.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →