Cyber Insurance

Cyber Insurance for Australian Businesses

Covers what happens after a data breach, a ransomware attack or an online fraud: the specialists who get you running again, your legal obligations to the people whose data was exposed, and the income lost while systems are down.

What it covers

  • Incident response — the specialists who contain it
  • Notifying affected people, where the law requires it
  • Business interruption while systems are down
  • Cyber extortion and ransomware costs

What it does not

  • Upgrading the systems that failed
  • Loss of value in your own intellectual property
  • Incidents that began before the policy started

What an insurer will ask you

These are the real questions, and why each one changes your premium. Our chat walks through them with you.

Is multi-factor authentication enabled on email accounts?

This is close to a pass or fail. Most insurers will not offer terms without it, because compromised email is the entry point for the majority of claims.

Is multi-factor authentication enabled on admin and privileged accounts?

An attacker who reaches an admin account can do far more damage than one in an ordinary mailbox. Insurers ask about these separately for that reason.

Roughly how many personal records do you hold?

Notification costs scale with the number of people affected, so the record count drives both the premium and the limit you should be buying.

What sensitive data types do you hold?

Health and financial records carry stricter obligations and higher costs per record than a list of names and email addresses.

Tell us what you do, and we will take it from there.

No forms. Answer a few questions in chat and an authorised broker takes it to the market for you.

This page is general information only and does not take your objectives, financial situation or needs into account. Consider the Product Disclosure Statement before deciding. Cover is subject to the insurer’s terms and acceptance.