Skip to content

Cyber Insurance: What SMEs Need

What a policy actually covers, what insurers now demand of you, and when it's worth buying.

The decision you're actually making

Cyber insurance isn't a substitute for security — it's the layer for the risk you can't engineer away. The real comparison for an SME is between three postures: prevention only (controls, no policy), insurance only (a policy over weak controls — increasingly not even purchasable), and controls plus cover. This page compares those honestly.

What cyber policies typically cover

Policies split into two halves, and SMEs often only think about one:

  • First-party cover — your own losses: incident response and forensics, data recovery, business interruption while systems are down, cyber extortion response, and customer notification costs after a data breach.
  • Third-party cover — claims against you: liability to customers or partners whose data you lost, regulatory investigation costs, and payment-card industry penalties where relevant.

For most SMEs the first-party side does the heavy lifting — the days of downtime after a ransomware event usually hurt more than any lawsuit. The incident-response panel that comes with a good policy (lawyers, forensics, PR on call) is often worth as much as the payout itself, because few SMEs could assemble that team at 2am.

What policies commonly exclude

  • Losses from controls you claimed to have but didn't — misstatements on the proposal form are the classic reason claims fail.
  • Social-engineering and funds-transfer fraud, unless specifically added — the "fake invoice, changed bank details" scam that actually hits SMEs most often sits here.
  • Prior known incidents, unpatched systems past a stated window, and sometimes acts attributed to nation-states.
  • Betterment — insurers restore you to where you were, not to the upgraded systems you should have had.

Read the funds-transfer fraud position especially carefully; for many SMEs it's the single most likely loss event.

What insurers will require of you

Underwriters have hardened. Expect the proposal to ask, in detail, about multi-factor authentication on email and remote access, tested backups kept separate from the network, patching cadence, staff awareness training, and administrative access controls — essentially the territory of the Australian Cyber Security Centre's Essential Eight. Weak answers now mean declined cover or heavy exclusions, not just higher premiums.

This has a useful side effect: the checklist an insurer imposes is a decent minimum security standard even if you never buy the policy. If you can't answer the proposal questions confidently, that gap is the finding — fix it first. This is a systems-and-ownership problem as much as a technology one, which is why it belongs in your operations rhythm rather than in a drawer marked IT.

Prevention only vs controls-plus-cover

  • Prevention only makes sense when your data footprint is small, downtime is survivable, and you hold little customer information. You're self-insuring the residual risk — do that consciously, not by default.
  • Controls plus cover makes sense when downtime would be expensive, you hold customer or health data, you take payments online, or contracts with larger customers require it (increasingly common in tenders and supply chains).
  • Insurance over weak controls is the posture to avoid: premiums are worse, exclusions bite hardest, and a claim built on inaccurate proposal answers can be denied when you most need it.

Buying it well

  • Use a broker who places SME cyber regularly — wordings differ far more between insurers than in mature classes like property.
  • Match the business-interruption waiting period and indemnity period to how long a realistic outage would actually run for you.
  • Check whether the policy covers incidents at your key software providers, since most SMEs' worst outage is a supplier's outage.
  • Answer the proposal accurately and diarise re-checking those answers at each renewal — controls drift.

Also remember the Privacy Act's notifiable data breach obligations apply regardless of insurance — the OAIC sets out the current requirements. Insurance pays for the response; it doesn't take the legal duty off you. As with anything at the intersection of law and risk, treat this as general information and get advice on your own exposure.