Cyber insurance for Australian SMBs. Eight components. Six premium drivers.
Post-Optus + Medibank, cyber insurance for Australian SMBs is increasingly required by customers + regulators + lenders. Premiums rose 40-100% from 2022-2024 then stabilised. Below is the 8-component coverage breakdown + the 6 premium drivers + the practical insurance broker selection checklist.
Why this lives on XIntelliSync, not on a cyber-insurance broker's site
Cyber insurance underwriters care about YOUR Essential 8 maturity — MFA on admin accounts, patch SLA compliance, backup verification, incident response plan currency — none of which XIntelliSync tracks. We do not generate your Essential-8-self-assessment template, do not maintain your IR plan, and do not consolidate evidence for your claim package. Those sit with your IT stack and your insurance broker. What XIntelliSync DOES: the platform itself is subject to Essential 8 (XGVS code-audit gates enforce platform-side cyber posture), which means the financial data flowing through us is held to the same control class your underwriter cares about. The article below is the cyber-insurance market structure post-Optus + Medibank, premium drivers, and what underwriters actually ask for.
Eight coverage components
What a typical cyber policy covers (and what it doesn't).
First-party data breach + recovery costs
Forensic investigation, legal advice, notification costs (NDB notification, customer communication), credit monitoring, public relations. Typical sub-limit: $250k-$2M depending on policy size.
Cyber extortion + ransomware
Ransom payment (subject to AUSTRAC + sanctions screening + insurer approval), negotiator engagement, decryption + recovery costs. Increasingly sub-limited or excluded post-2022; some insurers require separate cyber-extortion endorsement.
Business interruption from cyber event
Lost net profit + ongoing fixed expenses during system outage. Typically 24-72 hour waiting period before cover engages. Sub-limit: $250k-$5M; period-of-indemnity 6-12 months.
BEC (business email compromise) fraud
Funds transferred to attacker bank via email-compromise scam. Increasingly sub-limited at $250k-$500k; some policies exclude entirely. Critical for finance + legal + real-estate where settlement values are high.
Privacy liability + third-party costs
Defence costs + damages awarded to affected individuals + class actions. Includes APP / NDB regulatory investigation costs + any administrative penalty (where insurable). Sub-limit: $1M-$20M.
Network security liability
Third-party damages from your network being used to attack others (e.g. supply-chain compromise where your customer is breached via you). Sub-limit: $1M-$10M.
Cyber crime / theft of funds
Direct theft from your accounts via cyber means (different from BEC which involves payment redirection). Often combined with BEC sub-limit. Sub-limit: $250k-$1M.
PCI-DSS fines + assessments
Card-brand fines, forensic-investigation costs, re-issuance costs imposed after PCI-DSS data breach. Sub-limit: $250k-$2M. Often requires standalone PCI-DSS endorsement.
Six premium drivers
What insurers underwrite on.
Industry vertical
Healthcare + finance + tech + legal pay highest premium per $1M cover. Hospitality + retail mid-range. Construction + agriculture + creative lower. Driven by sensitive-information exposure + regulatory overlay.
Annual revenue + employee count
Revenue + employees drive base rate. Revenue under $5M typically pays $5k-$15k for $1M cover. $5M-$50M revenue: $15k-$50k for $5M cover. $50M+: $50k+ for $10M+ cover.
Essential 8 maturity
Insurers require ML 1 minimum; ML 2 unlocks better terms; ML 3 unlocks lowest premium tier. Insurer audit at policy inception. Lapses in maintained controls between renewals can void cover at claim time.
Data sensitivity
Health records + payment cards + government identifiers (TFN, Medicare) attract higher premium. Pure B2B with limited PII attract lower premium. Insurers underwrite on data-classification + record count.
Prior claims history
Prior cyber claim within 5 years: 30-100% premium uplift. No prior claims + ML 2+ controls: 10-20% discount. Insurers share claims data via underwriter associations.
Geographic + regulatory exposure
GDPR exposure (EU customers), HIPAA exposure (US healthcare data), CCPA exposure (California) all add premium. Multi-jurisdictional cover requires endorsements. Pure-domestic AU operations have lowest premium.
Where to engage cyber insurance
NIBA brokers + ICA + APRA + ACSC sources.
NIBA — niba.com.au (National Insurance Brokers Association)
Find a NIBA-accredited cyber-specialist broker via the broker finder. Look for cyber-specific underwriting expertise + relationships with multiple cyber underwriters + incident-response panel access.
Insurance Council of Australia — insurancecouncil.com.au
Industry body for general insurers. Authoritative source on General Insurance Code of Practice + claims-handling standards. Useful for understanding insurer obligations + dispute pathways.
ACSC — Ransomware Guidance
ACSC's authoritative guidance on ransomware prevention + response + payment considerations. Joint advisory with AFP on ransomware payment risks.
AUSTRAC — AML/CTF + Sanctions Screening
Required reading before considering ransomware payment. Sanctions screening + AML/CTF compliance applies to any payment to a sanctioned entity. Paying without screening is a criminal offence regardless of duress.
AFCA — Australian Financial Complaints Authority
External dispute resolution for insurance claims. If insurer denies a cyber claim and internal dispute resolution fails, lodge with AFCA. Free for consumers + small business with claims under threshold.
All 22+ industries served
Cyber insurance + regulatory overlay per industry.
Construction
Insurance + regulatory overlay — Cyber insurance market mature for construction. $1M-$5M policy typical for mid-size builder. BEC fraud cover usually sub-limited at $250k-$500k.
Healthcare
Insurance + regulatory overlay — Cyber insurance often required for AHPRA-registered practices. APP 11 reasonable security + NDB overlap. PI insurance separate. $2M-$10M policy typical.
Hospitality
Insurance + regulatory overlay — Cyber insurance increasingly common post-major-AU-hospitality-breaches. PCI-DSS overlap for card data. $500k-$2M policy typical for single-venue.
Retail
Insurance + regulatory overlay — Cyber insurance standard for online retailers. PCI-DSS overlap for card data. NDB exposure typically large-numbers (1000+ customers). $1M-$10M policy typical.
Professional Services / Consulting
Insurance + regulatory overlay — PI + cyber insurance usually bundled. Client-contract-required cyber cover increasingly common. $2M-$10M cyber policy typical.
Digital / Tech / SaaS
Insurance + regulatory overlay — Cyber insurance + tech E&O insurance standard for SaaS. SOC 2 Type II + ISO 27001 + APP 11 + customer-contract requirements drive maturity. $5M-$50M policy typical.
Finance / Mortgage Brokers
Insurance + regulatory overlay — APRA CPS 234 mandatory for APRA-regulated entities. AFSL holders subject to ASIC RG 78 breach reporting. Cyber insurance + crime insurance + PI all required. $5M-$50M typical.
Legal
Insurance + regulatory overlay — PI + cyber insurance + Law Society fidelity fund overlap. Client-contract-required cyber cover increasingly common. Trust-account breach triggers separate Law Society + ASIC + criminal scrutiny. $3M-$20M typical.
Childcare / Early Learning
Insurance + regulatory overlay — Cyber insurance + PI + cyber-extortion cover. APP 11 + sensitive-information overlay + ACECQA compliance. $2M-$10M typical.
Education / RTOs
Insurance + regulatory overlay — Cyber insurance + ASQA/CRICOS compliance. NDB notification for SIS breaches. $2M-$10M typical.
Manufacturing
Insurance + regulatory overlay — Cyber insurance + business-interruption + product-liability overlap. CPS 234 if APRA-regulated subsidiary. $3M-$20M typical.
Transport / Logistics
Insurance + regulatory overlay — Cyber insurance + business-interruption + cargo cover. NDB exposure for telematics/customer data. $2M-$10M typical.
Mining / Resources
Insurance + regulatory overlay — SOCI Act 2018 mandatory cyber risk management for critical infrastructure. APRA + ASIC + ACSC overlap. Cyber insurance + business-interruption + war-exclusion considerations. $10M-$100M+ typical.
Agriculture / Primary Production
Insurance + regulatory overlay — Cyber insurance increasingly common for larger operations. NDB exposure for farm employee + buyer data. $500k-$5M typical.
Fitness / Health Clubs
Insurance + regulatory overlay — Cyber insurance increasingly common for franchise operators. NDB exposure for sensitive health data. $1M-$5M typical.
Not-for-Profit
Insurance + regulatory overlay — Cyber insurance often discounted via NFP-specific schemes. ACNC governance standards if registered as charity. $500k-$5M typical.
Events / Conferences
Insurance + regulatory overlay — Cyber insurance + event-cancellation insurance. NDB exposure for attendee + speaker + sponsor PII. $500k-$5M typical.
Creative / Photography / Production
Insurance + regulatory overlay — Cyber insurance + IP + drone-liability cover. NDB exposure for client deliverables + model release data. $500k-$3M typical.
Marketing / Advertising Agencies
Insurance + regulatory overlay — PI + cyber + media liability bundled. Client-contract-required cyber cover increasingly common. $1M-$10M typical.
HR / Recruitment
Insurance + regulatory overlay — PI + cyber + crime insurance bundled. NDB exposure for candidate + employer data across multiple clients. $2M-$10M typical.
Insurance Brokers / Underwriters
Insurance + regulatory overlay — APRA CPS 234 mandatory for APRA-regulated entities. AFSL holders subject to ASIC RG 78 breach reporting. Cyber + PI + crime insurance + extra-territorial cover. $10M-$100M+ typical.
Real Estate / Property Management
Insurance + regulatory overlay — PI + cyber + crime insurance bundled. State licensing + trust-account audit overlap. $3M-$20M typical for mid-large agencies.
FAQs
Cyber insurance — answered.
How much cyber insurance do I need?
Rule of thumb: cover should be at least 2x your worst-case combined first-party + third-party exposure. For an SMB with 5,000 customer records + $500k turnover: $1M-$2M cover typical. For a SMB with 50,000 records + $5M turnover: $5M-$10M cover. For finance + healthcare + tech with 100,000+ records: $10M-$50M+. Engage a NIBA-registered cyber-specialist broker to model the exposure properly.
What is excluded from typical cyber insurance?
Common exclusions: war + terrorism (post-NotPetya the cyber-war exclusion has tightened — most policies exclude state-actor-attributed attacks; recent court cases challenging this), regulatory fines that are uninsurable by law (criminal penalties), prior known breaches, intentional misconduct by senior officers, infrastructure failures by third-party cloud providers (separate cover for cloud-failure), bodily injury or property damage (general liability covers these), pre-existing system vulnerabilities not disclosed at policy inception. Read the policy schedule — exclusions vary widely.
Should I pay a ransom if attacked?
Three considerations. (1) Legal: AUSTRAC AML/CTF + sanctions screening required before any payment — paying a sanctioned entity is a criminal offence regardless of duress. (2) Insurance: most policies require insurer approval before payment + insurer typically requires a registered ransomware negotiator. (3) Practical: only ~50-70% of payments result in working decryption + ~30-40% of paid victims face follow-on attacks within 12 months. ACSC + AFP advice: do not pay if avoidable; seek expert advice before any payment decision.
How does cyber insurance interact with NDB scheme + APP 11?
NDB scheme requires notification to OAIC + affected individuals within 30 days of awareness. APP 11 reasonable security is the underlying compliance standard. Cyber insurance covers the NOTIFICATION COSTS + forensic investigation + legal advice + credit monitoring offered to affected individuals — but does NOT eliminate the regulatory obligation or risk of OAIC penalties. Insurer requires you to maintain the controls + cooperate fully with the regulator.
What is APRA CPS 234 and does it affect my cyber insurance?
APRA CPS 234 (Information Security Prudential Standard) mandates information-security capability for APRA-regulated entities (banks, insurers, super funds, RSE licensees). 5 sub-requirements + mandatory 72-hour incident reporting. APRA-regulated entities cannot use cyber insurance as a substitute for the underlying capability — controls must be in place AND insured. Non-regulated SMBs are not subject to CPS 234 directly, but increasingly customers (especially financial-services customers) require their suppliers to demonstrate similar capability.
How do I find a good cyber insurance broker?
Use NIBA (National Insurance Brokers Association) accredited brokers with cyber specialisation — search nipa.com.au broker finder. Ask for: cyber-specific underwriting expertise (not general business insurance), relationships with multiple cyber underwriters (not single insurer), incident-response panel access (forensic + legal + PR partners), claims support track record. Avoid brokers who treat cyber as an add-on to general liability — cyber underwriting is a specialism.
How does XIntelliSync help with cyber insurance compliance?
XIntelliSync does NOT surface your Essential 8 maturity status, does NOT track your customer-side controls (MFA / patches / backups / IR plan), does NOT generate the Essential-8-self-assessment template, and does NOT consolidate evidence for your insurance claim package. Those sit with your IT stack and your insurance broker. What XIntelliSync IS: a platform itself subject to Essential 8 (XGVS code-audit gates enforce platform-side cyber posture), which means the financial data flowing through XIntelliSync is held to the same control class your underwriter cares about. The customer holds the policy and the controls; XIntelliSync is one component of your overall control environment, not a tracking layer for your other controls.
Continue reading