Skip to content

Cyber insurance for Australian small business: easing premiums, ongoing risk

23 July 2026

Cyber premiums have eased for many buyers while cyber threats to small businesses remain. What cyber cover commonly includes, where the gaps tend to sit and what to check before your next renewal.

Cyber insurance pricing has eased for many buyers, even as the cyber threats facing Australian small businesses remain. A lower renewal premium should not be read as evidence that the exposure has reduced. It may instead reflect insurer appetite, available capacity and competition, with the outcome still depending on the business’s risk profile and security controls.

Why cyber cover looks cheaper right now

Cyber is a relatively young class of insurance in Australia. After sharp price increases in earlier years, increased capacity and insurer competition have placed downward pressure on premiums for many buyers. Recent market reporting has continued to describe favourable conditions, although pricing and terms still vary according to the business, its security controls and its loss history.

Market conditions can move in either direction. Terms available at one renewal are not a guide to what will be offered at the next, and an easier market is often the better time to review scope rather than simply accept a lower price. The same principle applies more broadly, as covered in why some insurance premiums keep rising.

Why the exposure has not moved with the price

Small businesses hold customer records, bank details, payroll data and supplier information, and most now depend on cloud accounting, online bookings or a point of sale system to trade at all. That dependence is what creates the loss, because a business that cannot invoice, quote or dispatch for several days carries a cost whether or not any data is stolen.

Cyber risk has also drawn policy attention. In February 2026, the Insurance Council of Australia lodged a dedicated cyber insurance submission to the Parliamentary Joint Committee inquiry into small business insurance. The Council said cyber insurance take-up among small businesses remained low despite rising threats and called for measures to strengthen cyber resilience.

What a cyber policy commonly includes

Wordings differ between insurers, and the sections available to a small business will depend on the policy arranged. Broadly, cyber policies are commonly built around two ideas: the cost of responding to an incident, and the loss the business suffers because of it.

A common path into a small business cyber loss is an email that looks ordinary.

Response costs can include specialist incident response, forensic investigation to establish what occurred, legal advice on reporting obligations, notification of affected individuals, and support with restoring systems and data. Loss cover can include business interruption while systems are unavailable, and in some wordings cyber extortion or ransomware costs, subject to the limits, sublimits and conditions in the policy.

Funds transfer fraud, where a payment is redirected after an email account is compromised, is often the exposure a small business feels first. Whether it responds, and to what extent, depends on the wording and on whether that cover sits under a cyber policy or a crime section elsewhere in the programme, such as within management liability.

Where the gaps tend to sit

The first gap is assuming the cover already exists. A business pack or commercial property policy may include a limited cyber extension, and that is not the same as a standalone cyber policy. It is worth checking what is held rather than assumed.

The second is the security conditions attached to the policy. Insurers increasingly ask about multi-factor authentication, backups, patching and how administrator access is controlled. Answers given at application form part of the information the insurer relies on, so they need to reflect how the business genuinely operates.

The third is the limit and the interruption period. A modest limit may be absorbed quickly by response costs alone, before any interruption loss is considered.

The fourth is what happens after an incident. Where a business is covered by the Privacy Act, the Notifiable Data Breaches Scheme may require notification to affected individuals and the OAIC if an eligible data breach is likely to cause serious harm. Whether those obligations apply depends on the business and the circumstances of the breach.

What to review before your next renewal

A useful starting point is to work through how the business would trade if its main system were unavailable for a week, who would need to be called in the first day, what customer information is held and where, how payments are approved and verified, and whether the current limit reflects those answers rather than the limit chosen when the policy was first arranged.

Where a broker fits

Cyber policy wordings can vary considerably between insurers, so comparing policies on price alone rarely gives a full picture. A broker can review what is held, explain how the sections and sublimits may respond, arrange terms suited to the way the business operates, and assist through the claims process if an incident occurs. More on that role is set out in what an insurance broker does.

If your business holds customer data, takes online payments or depends on its systems to trade, contact the RMA Insurance Brokers team to review whether your current cyber arrangements are suited to the way you operate and how they may respond to an incident.

Share this article
Talk to us

Need help understanding how this may affect your cover?

Contact the RMA Insurance Brokers team before making changes to your insurance arrangements.

Disclaimer

Any financial product advice in this content is provided by Insura Broking Group T/as RMA Insurance Brokers AR No. 1267581. This material is general in nature and has been prepared without taking into account your objectives, financial situation or needs. Accordingly, before acting on it, you should consider its appropriateness to your circumstances. RMA Insurance Brokers is an AR of McCormick Harris Insurance AFSL No. 238979.

Information is current as at the date the article is written as specified within it but is subject to change. RMA Insurance Brokers make no representation as to the accuracy or completeness of the information. Various third parties may have contributed to the production of this content. All information is subject to copyright and may not be reproduced without the prior written consent of RMA Insurance Brokers.

Stay informed

Receive insurance updates worth reading.

Receive broker-led insurance updates covering rural, business and emerging risk issues affecting Australian clients.

We only use your details to send relevant updates from RMA Insurance Brokers. You can unsubscribe at any time. View our Privacy Policy.