You don't need to be a target. You just need an inbox.
The costliest cyber incidents rarely start with a hacker breaking in. They start with a fake invoice that looked exactly like the real one.
Cyber insurance covers two different things and most people have only heard of one: what happens to your own business, and what you owe someone else.
If you are insuring a home or a car rather than a business, start here instead.
You've probably told yourself your business is too small to be worth a hacker's time. Fair enough, most small businesses aren't hand-picked. They're caught in a net. Someone gets into a supplier's email account, watches how invoices are worded, then sends you one that looks identical to the real thing, with new bank details. Your bookkeeper pays it, because it looked right. That's the claim. Australian small businesses reported an average loss of $56,600 per cybercrime incident in 2024-25 (Australian Signals Directorate, Annual Cyber Threat Report), and it rarely takes a sophisticated attacker to cause it. Cyber insurance exists to pay for the mess that follows: the money, the IT bill to work out what happened, and the fallout if customer data went with it. We'll walk you through what a policy actually pays for, in plain English, before you sign anything.
What does cyber insurance actually pay for?
Quick answerCyber insurance covers two different things, and most people have only heard of one. First-party cover pays for what happens to your own business: the money stolen through a scam, the IT specialist who works out how the attacker got in, the cost of getting your systems running again, and the income you lose while you're offline. Third-party cover pays when someone else, a customer, a client, a supplier, comes after you because their information or their money was caught up in the incident.
- Funds lost to a scam such as a fake invoice or redirected payment, where the policy allows it.
- IT forensic investigation to work out what happened and shut the door behind it.
- Data recovery and getting your systems and website working again.
- Loss of income while your business can't trade normally because your systems are down.
- Ransom negotiation and payment where the policy provides it, and the costs of dealing with an extortion demand.
- The cost of notifying customers if their data was exposed, and setting up a call centre or credit monitoring if the breach is big enough to need it.
- A customer or client suing you because their personal or financial information was exposed on your systems.
- The cost of defending a regulatory investigation, for example from the Office of the Australian Information Commissioner, if a data breach is reported.
- Claims from a business partner whose systems were compromised through yours (a supply-chain claim).
- Costs if content on your website or social media is alleged to infringe copyright or defame someone, where that section is included.
The mix of sections you actually need depends on what your business holds and does online. A tradie with a booking app and a supplier's bank details needs a very different shape of policy to a business holding thousands of customer records. That's a conversation, not a tick-box form. Most of the small and medium businesses we place cyber cover for land on somewhere between $500,000 and $1 million of cover once the premium is weighed against the risk, shaped around the sections that actually matter to them rather than a generic limit.
What's the biggest cyber risk for a small or medium Australian business?
Quick answerThe biggest risk isn't a sophisticated hack. It's business email compromise, where a criminal gets into (or spoofs) an email account in your supply chain and uses it to redirect a real payment. The second risk is one most owners never see coming: the application form itself, where an honest-sounding guess about your own IT setup can be used against a claim later.
Losses to business email compromise reached $152.6 million across Australia in 2024, up 66% on the year before (National Anti-Scam Centre, Targeting Scams Report 2024), and it works precisely because everything about the email looks right: the logo, the invoice number, the tone. Nobody has to break into your systems. They just have to be convincing for one email.
The second risk is one most business owners never see coming, and it isn't your security setup, it's the form you fill out to buy the policy. Insurers still ask about things like multi-factor authentication and tested backups, the basic controls the Australian Cyber Security Centre's Essential Eight framework recommends every business have in place. But we've checked the actual policies we place, clause by clause, and here's what we found: none of them cancel your cover because those controls turn out to be less than perfect. What can go wrong is the application itself. When you answer a question about your security, that answer is treated as a promise, not a guess, and if the true answer was different, an insurer can use that gap to challenge your claim later, even on a part of the loss that had nothing to do with the gap. Most business owners genuinely don't know what's backed up, what's tested, or what "multi-factor" even covers across every system they use, so answering confidently isn't the same as answering correctly. That's exactly why we place cyber cover with insurers whose application is written so you can answer it honestly, without guessing at your own IT setup, rather than one that asks a string of detailed technical questions and hopes you get every one right.
The scam itself keeps evolving too, from a straight fake invoice to a cloned voice or a deepfaked video call pretending to be someone you trust. Current cyber policies are already being written to keep pace: on at least one of the wordings we place, a loss caused by this kind of AI-enabled deception is covered on the same terms as any other cyber event, rather than sitting outside the wording as some exotic new risk.
What does a broker actually add to a cyber insurance policy?
The single biggest thing: we choose which insurer's application you actually sit, not just which policy you end up with, and that choice decides whether your claim rests on a guess or on the truth. We've educated our brokers to place cyber cover with an insurer whose question set your business can answer honestly, all the way through, rather than one whose questions are so specific that an honest "I'm not sure" ends up looking like a wrong "yes."
A lot of cyber cover gets bought in ten minutes online, where a form asks yes/no questions about your security and nobody checks the answers against what's actually true in your business. That's fine until the year something happens, when an insurer's forensic team can look at exactly what you told them versus what they find, and a mismatch is their opening to challenge the claim, sometimes on a part of the loss that had nothing to do with the gap. Most business owners don't know their own IT setup well enough to answer a detailed technical question with total confidence, and a guess dressed up as a "yes" is what actually creates the risk, not a lack of security smarts.
One trap worth knowing about before you ever need it: on part of the market, the cover that pays out for a fake-invoice or redirected-payment scam only responds if your business already has a written procedure for checking any changed bank details, by phone, on a different number to the one the request came in on, before you pay, not after. Skip that step, or never write it down, and that part of a claim can be declined even though the scam itself was genuinely convincing. Ask us whether your policy carries this condition and exactly what it requires of you, while there's still time to put it in place. It's also worth real money at quote stage, which we break down in how much cyber insurance costs.
We also don't sell cyber cover as an afterthought bundled onto a business pack without checking whether the limits and sections actually match what you hold. A cafe taking card payments and a bookkeeping firm holding years of client financial records are not the same risk, even if they're both "small business," and a one-size policy treats them as if they were.
The structure underneath the limit matters just as much, and almost nobody explains it. On some of the covers we place, the full limit is available again for a second, unrelated incident in the same year, rather than one annual pot that empties and stays empty. If you have a bad year, that difference is the whole claim.
Cyber is one of the newer covers we place, and like most brokers, we haven't yet had a client's cyber claim tested end to end. That's not a gap in what we know, it's exactly why the work happens at the application, before anything goes wrong, rather than after: you can't lean on years of watching a policy pay out, so getting the placement right the first time is what actually protects you.
Does a small business actually need cyber insurance?
Quick answerIf your business takes electronic payments, pays suppliers by bank transfer, stores customer details anywhere (a booking system, a CRM, even a spreadsheet), or would struggle to trade for a week without its computers, you carry cyber risk regardless of your size. Whether you're legally required to report a data breach is a separate, narrower question, and most small businesses assume the answer is yes when it often isn't yet.
Australia's Notifiable Data Breaches scheme, part of the Privacy Act 1988 (Cth), currently only applies to businesses with annual turnover over $3 million, plus specific categories regardless of size (health service providers, credit reporting bodies, businesses that trade in personal information, and a few others). Government has agreed in principle to remove that small business exemption, but it isn't law yet. The net is tightening at the edges, though: since 1 July 2026, the anti-money-laundering rules have brought accountants, lawyers, conveyancers and real estate agents under the Privacy Act for the client information they handle under those rules, whatever their turnover. Outside those groups, many small businesses genuinely sit outside the mandatory reporting regime today. That doesn't mean you're safe from the fallout. A customer whose card details were used fraudulently after buying from you doesn't care whether the Privacy Act technically applied to your turnover, they care that it happened. Contracts with bigger clients increasingly require you to hold cyber cover as a condition of doing business with them, whether or not the law requires it.
What are the most common mistakes businesses make with cyber cover?
Quick answerThe costliest mistakes with cyber cover almost never involve a sophisticated attacker. They involve an honest-sounding assumption that turns out to be wrong, at exactly the moment it matters.
"We're too small to matter." This is the mistake underneath all the others. Small businesses aren't targeted individually, they're caught by automated scams sent at scale, which makes size irrelevant to whether you get hit.
Answering the application wrong without ever meaning to. This is not about dishonesty. Business owners get a cyber proposal full of IT jargon and answer it the way anyone would: you assume your IT provider is doing the backups, and if there's an authenticator app on your phone, multi-factor authentication must be running everywhere. Often neither is true, and you'd have no way of knowing. The problem is that an application answer is treated as a promise, not a guess, and if the insurer later finds those things weren't actually in place, it can refuse to pay on that basis. In a widely reported US case, an insurer sought to void an entire cyber policy after a ransomware claim showed multi-factor authentication was only switched on for part of the business's systems, despite the application stating it covered all of them. Rather than fight it, the policyholder agreed to let the court rescind the policy (Travelers Property Casualty Co. of America v. International Control Services, Inc., US District Court, Northern District of Illinois, 2022). Australian insurers work from the same principle. The fix is never a better-sounding answer: in live testing on the covers we place, answering every security question at its worst still produced a quote with no added conditions and no cover removed; the honest answer changed the price, not the protection.
Assuming a fake-invoice payout is automatic. Cover for a redirected payment or fake invoice is usually a specific add-on, not something that comes bundled free with every cyber policy, and on part of the market it only pays out if your business already has a written procedure for checking any changed bank details, by phone, on a different number to the one the request came in on, before you pay. No documented procedure, no payout on that part of the claim, no matter how convincing the scam looked.
Assuming your IT provider's insurance has you covered. If your website host, cloud provider or IT contractor is breached and your customer data goes with it, you still own the notification and regulatory fallout to your own customers, they don't. An IT provider's insurance is written to protect the IT provider, not to stand in for your own cyber cover.
Calling your own IT contractor before your insurer. Several cyber policies require the insurer's own incident response team to run point on an incident, and bringing in your own IT contractor first, without asking, can put part of your cover at risk right when you need it most. Know who you're meant to call first, before the day you actually need to make that call.
Telling your customers before you tell your insurer. This one reaches further than most owners expect. On some of the wordings we place, any breach notification you send to customers or a regulator has to go out with the insurer's written consent first, and the insurer's own panel runs the notification so it lands correctly and on time. Getting in front of it yourself, however decent the instinct, can leave you paying for a notification the policy would otherwise have covered. Wordings differ, so ask what yours requires while nothing is happening, not at 9pm on the night you find out.
Buying it once and never reviewing it. What your business holds, how it takes payments, and who runs your IT all change constantly. A policy bought two systems and one IT provider ago, without anyone telling your broker what changed, may no longer match what you'd actually need to recover.
Cyber Insurance Australia: your questions answered
Do I legally have to have cyber insurance in Australia?
What's the difference between first-party and third-party cyber cover?
Does cyber insurance cover invoice fraud and business email compromise?
Does cyber insurance cover an employee stealing money from the business?
Will my cyber insurance claim be declined if I don't have multi-factor authentication?
Does cyber insurance cover ransomware?
Is it illegal to pay a ransomware demand in Australia?
Do I have to report it if my business pays a ransom?
Do accountants and bookkeepers need cyber insurance?
Does a tradie need cyber insurance?
Do allied health providers need cyber insurance?
How much does cyber insurance cost for a small business in Australia?
Related cover and reading
The information on this page is general in nature and does not take into account your objectives, financial situation or needs. Before acting on it, consider whether it is appropriate for your circumstances. Where the information relates to a particular insurance product, consider the relevant Product Disclosure Statement before making a decision.
Last reviewed: 29/07/2026
Find out what your business would actually be covered for.
Call now, most enquiries are settled in one conversation - or leave your details and we'll ring within 90 minutes on a new enquiry (8am–6pm Mon–Fri).