How Much Does Cyber Insurance Cost in Australia?
How much does cyber insurance cost for a small business?
Quick answerFor the small and medium businesses we arrange cyber cover for, indicative premiums run from around $1,400 a year for $500,000 of cover, up to around $4,000 a year for $2 million of cover. Those figures come from our own placements for businesses with annual turnover between $500,000 and $2 million. They are indicative, not a quote: what your business pays depends on what you hold, how money moves through it, and the cover sections you choose, and the only way to know your number is to get a quote against your actual risk.
We are usually the first to tell you that a price table on an insurance website is a trap. So why are we giving you numbers here? Because at the small business end, cyber pricing behaves differently to something like commercial building insurance, where six independent factors can stretch the range five times wider than any table admits. For a business with turnover under a couple of million dollars, cyber premiums cluster tightly enough around turnover, data and cover choices that a real band, taken from real placements, tells you something honest: this cover costs about the same per year as one decent laptop, against an incident that costs the average Australian small business $56,600 (Australian Signals Directorate, Annual Cyber Threat Report 2024-25).
What the band cannot do is price your business. A cafe taking card payments, a bookkeeper holding years of client financials and an online retailer processing thousands of orders sit at very different points inside it, and a business outside that turnover range sits outside the band entirely. Treat the numbers as orientation, not an offer.
What decides where your premium lands in that range?
Quick answerFive things move a small business cyber premium more than anything else: your turnover, what data you hold, how money moves through your systems, the limit of cover you buy, and the optional sections you add. Your security setup then decides something just as important as the price: which insurers are prepared to offer you terms at all.
Turnover. The single biggest input at the small end of the market. It is the insurer's shorthand for how much activity, how many transactions and how much fallout your business could generate. Growing businesses often forget to tell anyone: a policy priced two years ago against half your current turnover is mispriced today, in nobody's favour.
What you hold. A business holding thousands of customer records, health information or client financials carries more third-party exposure than one holding a supplier list and a job calendar. More records means more people to notify, more fallout to manage and a bigger target, and the premium follows.
How money moves. If your business regularly pays suppliers by bank transfer, or invoices customers who pay you the same way, you carry the risk insurers now price hardest: payment redirection fraud. Business email compromise cost Australians $152.6 million in 2024, up 66% on the year before (National Anti-Scam Centre, Targeting Scams Report 2024), and insurers price that exposure through a specific optional section, which is where the next factor comes in.
The limit and sections you choose. Most of the small and medium businesses we place cyber cover for land between $500,000 and $1 million of cover once premium is weighed against risk. Cover for scam payments and redirected transfers is usually a specific add-on with its own sub-limit rather than something bundled in automatically, and adding it moves the premium. So does hardware replacement, and that one is worth asking about either way: on some of the covers we place it is included at the full limit, on others it is an optional add-on you pay for.
Your security setup. Multi-factor authentication, tested backups, software that gets updated, staff who know what a fake invoice looks like. These are the basics the Australian Cyber Security Centre's Essential Eight framework recommends for every business, and insurers ask about all of them. What most owners do not realise is that the answers do more than nudge the price. They decide which insurers will offer you terms at all, which is worth its own section below.
Why isn't cyber cover already in my business insurance pack?
Quick answerBecause a business pack is built around physical loss: fire, storm, theft, a customer slipping on a wet floor. A cyber incident destroys nothing physical, so the pack's property and business interruption sections, which trigger on physical damage, mostly never respond. Cyber cover has to be bought as its own policy or its own deliberate section, and many owners only discover that after the incident.
This is the assumption that catches more small businesses than any hacker does. You hold a good business pack, you pay real premiums every year, so surely a scam or a breach is covered somewhere in there. Mostly, it is not. The business interruption section of a pack pays when physical damage stops you trading; a ransomware attack that locks every computer in the building has not physically damaged anything, so that section stays silent. The liability section responds to injury and property damage, not to a customer whose card details left through your booking system.
Some packs offer a small cyber extension. Check the limit before you take comfort from it: a token sub-limit against a $56,600 average incident is a gesture, not a plan. If cyber risk is real for your business, it deserves a policy shaped for it, sitting alongside the pack rather than buried inside it. Our business insurance page covers how the two fit together.
The gotchas: where cyber policies pay less than owners expect
Quick answerThe four traps that matter most: scam-payment cover is usually an optional add-on with its own much smaller sub-limit; on part of the market it only pays if you already had a written procedure for verifying changed bank details; an internet or phone provider outage is generally not a cyber claim at all; and whether a laptop bricked by an attack is covered depends on the policy, included at the full limit on some of the covers we place and an optional add-on on others.
The sub-limit on the risk you are most likely to meet. Here is the mismatch nobody points out at quote time. The most common way an Australian small business loses money to cybercrime is a redirected payment or fake invoice, yet cover for exactly that loss usually sits in an optional section with its own capped limit, separate from and far smaller than the headline sum insured. On the covers we typically arrange, that sub-limit is commonly between $25,000 and $250,000 depending on the insurer and the exact fraud type, confirmed at quote stage for your situation. A policy with $1 million on the front page can pay $25,000 on the loss you were statistically most likely to have, if your sub-limit sits at the bottom of that range. That is not a scandal, it is how the market prices its most frequent claim, but you should know the real number for the real risk before you buy, not after. And the number does not move just because you buy more cover: on covers we place, we have priced the same business at two different headline limits and watched every catastrophe section step up while the scam-payment sub-limit stayed exactly where it was. If a redirected payment is what worries you, the figure that decides your claim is that sub-limit, not the one on the front page.
The procedure condition. On part of the market, the scam-payment section only responds if your business already had a written procedure for verifying any change in bank details, by phone, on a number you already trusted, before paying. No documented procedure, no payout on that part of the claim, however convincing the scam was. If you take one practical step from this whole page, write that procedure this week. It costs nothing, it defeats most invoice fraud on its own, and on some policies it is the difference between a paid claim and a declined one. It can also cut what you pay: in a live quote test we ran on the covers we place, a documented payment-verification procedure was worth around 17% of the base premium. That was one test on one risk rather than a market rate, so treat it as a reason to ask what it is worth on your own quote rather than a discount you can bank on. It came off as a share of the premium rather than a flat amount, so the bigger the policy, the more it is worth in dollars.
The outage that feels like a cyber attack but is not one. If your internet provider, phone company or a major cloud platform goes down and your business goes down with it, that is generally not what a cyber policy responds to, even though from your chair it looks identical to an attack. Cyber policies are commonly written to exclude losses caused by a utility or infrastructure provider's outage. Worth knowing before you assume a day of lost trading is claimable.
The machine itself. Cyber insurance is mostly about the mess and the money: the forensic IT bill, the lost income, the notification costs, the stolen funds. The physical hardware an attack ruins is treated differently from policy to policy. On some of the covers we place it is included at the full limit; on others it is an optional add-on, so ask which one you are being quoted rather than assume it comes bundled.
One more assumption worth retiring: your IT provider's insurance does not protect you. If their systems are breached and your customer data goes with it, the notification, the regulator and your customers are still yours to face. Their policy is written to protect them. The full list of mistakes we see with cyber cover is on the product page, including the application trap that quietly decides more claims than any exclusion.
What security controls do insurers require for cyber insurance?
Quick answerInsurers ask about the same short list almost everywhere: multi-factor authentication, backups that actually get tested, software kept up to date, and staff trained to spot a fake invoice or login page. Fall short and most insurers will decline you or load the premium heavily. What most owners do not know is that the market is not uniform: we know which insurers will still cover a business while it gets those controls in place, usually for a modest premium difference, and most brokers never look past the first decline.
The list itself holds no surprises. It is the Essential Eight territory every IT provider has been recommending for years: MFA on your email and key systems, backups that exist somewhere an attacker cannot reach and that someone has actually tested restoring, updates applied rather than postponed, and staff who pause before paying a changed invoice.
The surprise is what happens when you cannot honestly tick every box, which describes a large share of real small businesses. Maybe MFA is on email but not the accounting platform. Maybe backups run but nobody has ever tested a restore. Answer a big-market online form honestly in that state and the common result is a decline, or a premium loaded so hard it reads like one. At that point most owners conclude they cannot get covered until the IT project is finished, and most brokers, faced with the same first decline, tell them exactly that. Both are wrong. The market is not uniform, and we deliberately place cover with insurers who will take a business as it actually is, imperfections declared honestly, while the controls catch up, usually for a modest premium difference rather than a refusal. To our knowledge no other brokerage works this part of the market the way we do, and it means the answer to "can I get covered before my security is perfect" is usually yes.
We have tested that rather than assumed it. In live testing on the covers we place, answering every security question at its worst still produced a quote with no added conditions and no cover removed; the honest answer changed the price, not the protection. That is worth sitting with if you have been putting off getting a quote until the IT work is done, because the gap you are worried about is a pricing question, not a locked door.
Two things that framing never means. First, it is cover first, controls second, never cover instead of controls: the controls are what make the incident less likely, insurance only pays for the mess afterwards, and you want both. Second, it never means fudging an application. Every answer you give an insurer is treated as a promise, not a guess, and an optimistic answer is precisely how claims get challenged later. The whole point of choosing the right insurer is that you can answer honestly, including the honest "not everywhere yet", and still be covered. How application answers decide claims is covered properly on the product page.
Does your business actually need it?
Quick answerIf your business pays suppliers by bank transfer, takes electronic payments, stores customer details anywhere, or would struggle to trade for a week without its systems, you carry the risk this policy exists for. Whether the cover is worth $1,400 to $4,000 a year is then a comparison against a $56,600 average incident, and against what a week of your own downtime actually costs you.
The full needs question, including who is legally required to report data breaches and why "too small to matter" is the costliest assumption in this whole area, is answered on our cyber insurance page. The short version for a busy owner: criminals do not pick targets, they cast nets, and a small business with one distracted bookkeeper and no verification procedure is exactly what the net is designed to catch.
Get a real number for your business
Or call us on 07 3292 1111 and ask what cyber cover would actually cost for your business. For new enquiries we reply within 90 minutes during business hours, 8am to 6pm Monday to Friday.
FAQ
Is $500,000 of cyber cover enough for a small business?
For many of the small and medium businesses we arrange cover for, yes: most land between $500,000 and $1 million once the premium is weighed against what the business holds and could lose. But the headline limit is only half the answer. The section limits underneath it, particularly the sub-limit on scam payments, are where a policy quietly gets smaller, so the right question is not "how big is the number on the front page" but "how much would this policy pay on the loss I am most likely to have".
If I double my cyber sum insured, does my scam-payment cover double too?
Usually no, and it is an expensive thing to assume. On covers we place, stepping the headline limit up moves the big catastrophe sections, the ones that pay for a full system rebuild or a serious liability claim, while the sub-limit on scam payments and redirected transfers commonly stays exactly where it was. Buying a bigger number on the front page is not how you get more cover on the loss you are most likely to have. The question worth asking at quote stage is what that sub-limit actually is, section by section.
Does a payment-verification procedure make cyber insurance cheaper?
It can, and it is the rare security step that costs you nothing to put in place. In a live quote test we ran on the covers we place, a documented payment-verification procedure was worth around 17% of the base premium. That is one test on one risk rather than a market rate, so ask what it is worth on your own quote, but the procedure pays for itself twice over: it defeats most invoice fraud on its own, and on part of the market it is the condition that decides whether that section of a claim gets paid at all.
Does my turnover change what cyber insurance costs?
Yes, more than any other single factor at the small business end. Turnover is the insurer's shorthand for your activity and exposure, so a $2 million turnover business pays more than a $500,000 one for the same limit. It also means a policy priced against your turnover from two years ago is mispriced today, so tell your broker when the business grows.
Can I get cyber insurance if I don't have multi-factor authentication everywhere?
Often, yes. Most insurers will decline or heavily load a business that cannot tick every security control box, but the market is not uniform, and we place cover with insurers who will cover a business honestly declared as a work in progress, usually for a modest premium difference. What you cannot do is guess your way through the application: an answer that turns out to be wrong is how claims get challenged later, whatever the state of your security.
Why does adding scam-payment cover change the premium?
Because it is usually a distinct optional section, not part of the base policy, and it covers the single most frequent way Australian businesses lose money to cybercrime: redirected payments and fake invoices. Insurers price it separately, cap it with its own sub-limit, and on part of the market require a written payment-verification procedure before it responds. It is also, for most businesses that pay or receive money by bank transfer, the section most worth having.
Is it cheaper to buy cyber insurance online, direct from an insurer?
Sometimes the sticker price is lower, and that is exactly the trap. A ten-minute online form prices you fast by asking blunt yes/no security questions, and every confident answer you give becomes a promise the insurer can test after a claim. Nobody on the direct path checks whether your answers match reality, whether the scam-payment section carries a sub-limit that fits how you actually move money, or whether a different insurer's application is one your business can pass honestly. That checking is the product. The premium difference, where one exists at all, is rarely worth what it costs at claim time. More on the difference in direct insurer vs broker.