Skip to content
CYBER INSURANCE

Cyber insurance for Australian businesses

Ransomware, phishing and data breaches can interrupt systems quickly and create financial, operational and reputational consequences. RMA Insurance Brokers helps businesses review and arrange cyber insurance around their systems, data and operations.

Cyber insurance at a glance

Cyber insurance is designed to help businesses manage certain financial consequences of a cyber attack, data breach or network compromise.

Depending on the policy, cover may respond to the business’s own losses as well as certain claims or costs arising where customers, clients or other third parties are affected.

The response services available following an incident can be just as important as the financial cover.

Key areas

  • Incident response
  • Business interruption
  • Data recovery
  • Cyber extortion
  • Privacy liability
  • Notification & defence costs

Where can cyber risk arise?

Cyber risk is not limited to large organisations or technology businesses.

  • Email and online banking
  • Cloud-based systems
  • Customer or client records
  • Accounting and payroll systems
  • Websites and online services
  • Laptops, mobile devices and remote access

Malware, phishing and ransomware are among the common cyber threats facing smaller businesses and can expose organisations to data theft, extortion and significant disruption.

Cyber insurance may therefore be relevant to retailers, professional businesses, trades, agribusinesses, transport operators, property businesses and other SMEs.

For many businesses, cyber insurance should be considered alongside broader Business Insurance.

What can cyber insurance cover?

Cyber insurance policies vary significantly in the protection and response services they provide. Depending on the policy arranged and the circumstances of an incident, cover may include some of the following.

Incident response & crisis management

A cyber incident can require specialist assistance immediately.

Depending on the policy, cover may assist with costs associated with investigating and managing an insured cyber event, including specialist cyber-response services.

Business interruption

Cyber business interruption cover may respond to certain financial losses where an insured cyber incident disrupts systems and prevents the business from operating normally.

The applicable trigger, waiting period, calculation method and period of cover depend on the policy.

Data recovery

Cover may be available for certain costs associated with recovering or restoring electronic business data following an insured cyber incident.

Cyber extortion

Some cyber policies may provide assistance following an insured cyber-extortion or ransomware event.

Depending on the policy, this can include access to specialist advisers and certain costs associated with responding to the extortion event.

Privacy & security liability

A cyber incident may affect personal, confidential or other third-party information held by the business.

Depending on the policy, cover may respond to certain claims arising from a security or privacy breach.

Notification & defence costs

Following an insured data breach, cover may be available for certain notification, monitoring, investigation and legal defence costs.

The scope of these expenses varies between cyber policies.

Cyber privacy and security liability is distinct from broader Liability Insurance, which generally deals with third-party injury and property damage arising from business activities or products.

Our Insights article on cyber insurance for Australian small business covers these considerations in more detail.

Cyber insurance and cyber security work together

Insurance is one part of managing cyber risk. It does not replace appropriate security controls.

Important controls may include:

  • enabling multi-factor authentication
  • keeping software and systems updated
  • training staff to recognise phishing and other scams
  • using appropriate security and anti-malware protection
  • maintaining current backups
  • securing laptops, mobile devices and other endpoints
  • using stronger passphrases
  • maintaining a cyber incident response plan

The controls required by an insurer vary according to the business and the cyber risk.

Some insurers may require particular security measures before offering cover or may apply conditions to the insurance arranged.

A cyber insurance review should therefore consider both the insurance policy and the controls protecting the business.

Cyber insurance does not necessarily cover stolen money

One of the areas businesses should clarify is the difference between a cyber event and the financial loss caused when money is fraudulently transferred or stolen.

Some cyber policies may exclude losses where criminals use the internet to steal money from the business.

This means a phishing email, fraudulent payment request or compromised email account should not automatically be assumed to create a covered theft-of-funds claim simply because technology was involved.

Depending on the insurance program, separate or additional cover may need to be considered for certain crime or fraudulent-transfer exposures.

Where theft-of-funds or social-engineering cover is available, it may be optional, subject to a separate sub-limit and subject to conditions around how payment instructions are verified.

RMA Insurance Brokers can help identify how the available cyber and business insurance arrangements treat these risks.

What information may be needed for a cyber insurance review?

When reviewing cyber insurance, RMA Insurance Brokers may need information about:

  • the nature and size of the business
  • annual turnover and dependence on computer systems
  • the types of customer or business information held
  • systems, cloud services and technology used
  • multi-factor authentication and access controls
  • backup arrangements
  • staff cyber-security training
  • previous cyber incidents, breaches or known circumstances

Additional information may be required depending on the business, data held and cyber limits requested.

Accurate answers about security controls are important because insurers may rely on this information when deciding whether to offer cover and on what terms.

When should cyber insurance be reviewed?

A review is particularly worthwhile when the business has:

  • introduced a new business system or cloud platform
  • increased the amount of customer or personal information held
  • changed remote-access arrangements
  • expanded online services or e-commerce
  • significantly increased turnover or transaction values
  • acquired or merged with another business
  • experienced a cyber incident or attempted compromise
  • materially changed its cyber-security controls

Annual renewal is also an opportunity to confirm that the security information supplied to the insurer remains accurate.

What may not be covered?

Every cyber insurance policy contains exclusions, limits, conditions and excesses.

Depending on the policy, cover may not apply to:

  • physical damage to computer hardware
  • deliberate or criminal acts committed by the insured business
  • cyber incidents arising from circumstances already known before cover commenced
  • theft of money where that financial loss is not included by the cyber policy
  • losses outside the selected policy sections or limits
  • incidents where applicable policy conditions have not been met
  • costs or losses specifically excluded by the policy

This is not a complete list.

The policy wording, schedule, endorsements and circumstances of the cyber incident determine how the insurance responds.

Example: ransomware disrupts a regional business

Illustrative example

An employee of a regional business receives an email containing a malicious attachment and opens it. Malware enters the business network and encrypts important files, leaving staff unable to access several systems.

The business contacts its cyber-response provider. Specialist IT assistance is required to investigate the incident, contain the attack and restore systems and data. Normal operations are disrupted while this work is completed.

A claim would be considered against the cyber insurance policy, including the cause of the incident, response costs, data-recovery expenses, any insured business interruption loss and the policy’s applicable conditions and limits.

If customer or other third-party information has been affected, additional response and liability considerations may also arise.

Example provided for general illustration only. Policy coverage and the amount of any claim depend on the insurer, policy wording, limits, security controls and circumstances of the cyber incident.

Cyber insurance for rural and regional businesses

RMA Insurance Brokers works with businesses across rural, regional and metropolitan Australia.

Cyber risk applies wherever businesses rely on email, electronic payments, customer information and connected systems.

We also work closely with rma network Livestock & Property Agents, providing strong connections with businesses and communities throughout regional Australia.

Our services are not limited to rma network Members. Businesses across Australia can contact RMA Insurance Brokers for cyber insurance assistance.

Why RMA Insurance Brokers?

Cyber insurance can vary significantly between insurers, particularly around incident response, business interruption, cyber extortion, privacy liability, fraudulent transactions and security requirements.

RMA Insurance Brokers can help you:

  • identify the cyber exposures affecting the business
  • review existing cyber-security controls
  • gather information required by insurers
  • consider appropriate cyber limits and policy sections
  • compare available policy structures and response services
  • clarify how the policy treats business interruption and data recovery
  • identify whether theft-of-funds exposures require separate consideration
  • manage policy changes, renewals and cyber insurance claims

Our focus is on understanding how the business relies on technology and helping arrange insurance relevant to those exposures.

Frequently asked questions

What does cyber insurance cover?

Cyber insurance may provide cover for certain first-party losses, third-party liabilities and incident-response expenses arising from an insured cyber event.

Depending on the policy, this may include business interruption, data recovery, cyber extortion, security and privacy liability, defence costs, crisis management and notification expenses.

The exact cover depends on the policy arranged.

Does cyber insurance cover ransomware?

Cyber insurance may provide cover for certain costs arising from an insured ransomware or cyber-extortion event.

Depending on the policy, this may include specialist response services, data recovery, business interruption or other insured expenses.

The applicable conditions and exclusions vary between insurers.

Does cyber insurance cover lost income if my systems are unavailable?

Cyber business interruption cover may respond to certain financial losses where an insured cyber incident disrupts business operations.

The trigger, waiting period, calculation of loss and period of cover vary between policies.

Does cyber insurance cover money stolen through phishing or email fraud?

Not necessarily.

Some cyber policies may exclude the direct theft of money even where the fraud involves email, online banking or another digital system.

Separate or additional insurance may need to be considered depending on the exposure.

Where this cover is available, it may be optional, subject to a separate sub-limit and subject to conditions around how payment instructions are verified.

What cyber-security measures should a business have?

Appropriate controls depend on the business, but measures may include multi-factor authentication, software updates, staff cyber training, secure devices, appropriate security software, current backups and a cyber incident response plan.

Insurers may also have their own minimum security requirements before they will offer cyber cover.

Get in touch

Review your cyber insurance

Technology, business systems and cyber threats continue to change.

Whether you are considering cyber insurance for the first time, reviewing an existing policy or checking whether your current security controls and cover still reflect the business, RMA Insurance Brokers can assist.

The information on this page is general information only and does not take into account your objectives, financial situation or needs. Cover is subject to the terms, conditions, limits and exclusions of the relevant policy. Insurance products and available cover vary between insurers. Please review the relevant policy documentation and obtain advice appropriate to your circumstances before making a decision.