Small Businesses
Tech Companies
Motor & Fleet
Cyber Insurance

What is cyber insurance? An Australian small business guide

June 15, 2026
a list item
12 Mins Read
What is cyber insurance? An Australian small business guide

Cyber insurance in Australia may help a business recover when something goes wrong online: a hacked email account, stolen customer data, a ransomware demand, or systems locked at 9am on invoice day. It can help with the costs of responding, the losses while you are down, and claims from customers whose data was exposed.

One thing it is not: a replacement for cyber security. Cyber insurance is the financial and response layer for the incidents your controls do not prevent. Businesses that depend on email, online payments, cloud systems or customer data should seriously consider it, even though no law makes it compulsory.

Cyber insurance for small businesses at a glance

Question Answer
Is cyber insurance compulsory? No. Some client contracts and tenders require it
Who typically holds cyber insurance? Businesses handling customer data, online payments or bookings
What does cyber insurance help with? Incident response, data breach costs, ransomware response, lost income, claims from affected customers
What might a policy exclude or limit? Prior known incidents, some social engineering losses, and conditions around security controls, depending on the wording
What do insurers check before offering cover? Basics like multi-factor authentication, backups and software patching

Swipe left or right to see the full table.

Does a small business need cyber insurance?

No law requires it, but the exposure is real and measurable. The Australian Signals Directorate's ACSC received more than 84,700 cybercrime reports in FY2024-25, roughly one every six minutes. The average self-reported cost for a small business was about $56,600 per report. You do not need to be a tech company. You need an inbox, a payment system, or a customer list.

Three situations put cover on the table. You hold customer data, because names, emails, payment details or health records create exposure under Australia's privacy rules. You depend on systems to trade, because downtime is a direct financial loss. Or a client contract or tender asks for it, which is increasingly common for IT providers.

How does cyber insurance work in Australia?

Most policies combine two kinds of protection, and the split matters when you compare them. For a walk-through of a policy document itself, see what is a cyber insurance policy.

First-party cover helps with your own losses. That can include investigating the incident, restoring data and systems, and notifying affected customers. It can also include ransomware response and income lost while your business could not trade.

Third-party cover helps with claims made against you. If customer data is exposed and the affected people claim compensation, this part of the policy may help with legal defence costs and settlements. As always, that is subject to the policy terms.

Notification matters in cyber more than most covers. Requirements vary between policies, and first-party event sections and liability sections may operate differently. Notify your insurer promptly, and do not incur major response costs without checking what the policy requires first. Using the insurer's response line fast is often the difference between a bad day and a bad month.

What does cyber insurance cover?

Cover varies between insurers, but a small business policy may help with:

  • Incident response: IT forensics, legal guidance and PR support after an attack
  • Data breach costs: notifying customers, credit monitoring, and responding under the Notifiable Data Breaches scheme
  • Ransomware and cyber extortion: specialist negotiation and response costs. Any payment would generally require insurer consent, compliance with Australian law and sanctions checks, and payment is not a standard or preferred response
  • Business interruption: income lost while systems are down after a covered event
  • Data and system restoration: recovering or recreating lost data and software
  • Third-party claims: compensation claims and defence costs when others suffer loss from a breach on your side

Business email compromise deserves a mention because it is one of the most common attacks on small businesses. A criminal takes over or imitates an email account and redirects a payment. Policies treat this differently: some cover it under cyber crime or social engineering sections, others exclude it or cap it at a low limit. If invoices and payments run through your inbox, this is one of the most important sections to check.

Handling customer data or payments? You can get a cyber insurance quote through upcover.

What does cyber insurance not cover?

Every policy has limits, and it helps to know how exclusions, sub-limits and conditions each work. Common exclusions include incidents you knew about before the policy started, and fines or penalties that are uninsurable at law. A sub-limit is different again: the loss is covered, but under a lower cap within the policy, which is how many insurers treat email payment fraud.

Conditions work differently. A policy may require you to maintain certain security controls. Failing to maintain a control the insurer required, or answering proposal questions inaccurately, may affect a claim. That is not the same as an automatic exclusion, but the practical effect can be similar. Treat the proposal form and any security conditions seriously.

None of this makes the cover pointless. It means the policy wording matters more in cyber than almost any other cover. Two policies at the same price can respond very differently to the same attack.

What cyber security controls do insurers check?

Insurers increasingly ask about your security basics before offering cover, and better controls can mean better terms. Before you apply, expect questions about:

  • Multi-factor authentication on email, remote access and privileged accounts
  • Backups that are tested and kept separate from your main systems
  • Software and patching: supported software versions, updated regularly
  • Endpoint protection on business devices
  • Staff awareness: whether your team can spot phishing and payment fraud
  • Incident response: whether you have a basic plan for a bad day

Answer the proposal form truthfully. Overstating your controls is worse than admitting a gap, because inaccurate answers can affect a claim later. If you cannot confirm some of these controls, that is worth a conversation with a broker rather than a guess on a form.

What Australian data breach rules apply in 2026?

The Office of the Australian Information Commissioner received 1,205 notifications under the Notifiable Data Breaches scheme in 2025. That is the highest since the scheme began, and up 8% on the year before. The scheme generally applies to organisations with annual turnover over $3 million and to all health service providers. Some smaller businesses are also covered, including certain credit-related entities and businesses that trade in personal information.

Ransomware payments now carry a reporting rule. Since 30 May 2025, the rule applies to businesses operating in Australia with previous-year turnover of more than $3 million, and to specified critical infrastructure entities. They must report a ransomware or cyber extortion payment made by them or on their behalf within 72 hours of becoming aware of it.

Privacy penalties have also increased. For a body corporate, the maximum civil penalty for a serious or repeated interference with privacy is steep. It can reach the greater of $50 million, three times the benefit gained, or 30% of adjusted turnover. These are maximums for serious cases, not typical small business fines, but they show where the regulatory weight now sits.

Cyber insurance does not make these obligations go away, and holding a policy does not make you compliant. What it may do is help with certain forensic, notification and legal response costs, subject to the cover. Meeting the obligations remains the business's responsibility.

How should a small business compare cyber insurance policies?

Comparing on price alone is the classic mistake, because the wordings differ more than in almost any other cover. Five things to check side by side:

  1. Security requirements: what controls the insurer expects, and whether you genuinely meet them
  2. Business email compromise and social engineering: included, sub-limited, or excluded?
  3. Business interruption trigger and waiting period: how long must systems be down before cover starts?
  4. Incident response: is there a 24/7 response line, and who runs it?
  5. Limits and excess: does the limit fit the data you hold, and can you wear the excess?

Before you start a quote, have these ready: your ABN, what your business does, annual turnover, the kind of data you hold, the security controls above, and any client contract requirements. Not sure about your controls? Speak with a broker rather than guessing on the form. When you are ready, you can get a cyber insurance quote through upcover.

Wondering about cost? Across cyber policies reviewed by upcover, small business premiums typically ran from around $400 to $700 a year at the entry level, with a median around $1,192. The full breakdown by industry, from real policies, is in upcover's guide to cyber insurance costs in Australia.

How upcover can help

upcover is a digital-first insurance broker helping Australian small businesses arrange insurance online. upcover arranges cyber and privacy liability insurance for small businesses, with access to 80+ insurance partners.

If a week offline would hurt, cyber cover belongs on your shortlist. Get a cyber insurance quote through upcover.

upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.

Frequently asked questions

Is cyber insurance mandatory in Australia?

No law makes cyber insurance in Australia mandatory. Some client contracts, tenders and industry schemes require it as a condition of engagement, particularly for IT providers and businesses handling client data or systems.

How much does cyber insurance cost for a small business?

Based on policies reviewed by upcover, cyber cover for small businesses typically starts from around $400 to $700 a year, with a median around $1,192, and technology and professional services businesses tend to sit higher given their data risk. See the full industry breakdown in upcover's cyber insurance cost guide.

What is the difference between cyber insurance and professional indemnity?

Cyber insurance responds to attacks and data incidents: breaches, ransomware, system outages and the claims that follow them. Professional indemnity responds to claims that your professional advice or services caused financial loss. A software consultant whose error corrupts a client system may need professional indemnity, while the same consultant hit by ransomware needs cyber. Many service businesses hold both, so check how the two interact.

Does cyber insurance cover ransomware?

Many policies may help with ransomware response, including specialist negotiation, restoration costs and lost income, subject to the policy terms. Any payment generally requires insurer consent and must comply with Australian law. Businesses over the $3 million turnover threshold must also report any payment within 72 hours.

What is the difference between business and personal cyber insurance?

Business cyber insurance covers a business's data, systems and liability to customers. Personal cyber products cover individuals and households for things like identity theft. A sole trader running a business needs business cover, because personal products generally will not respond to business losses or customer claims.

Does cyber insurance cover scam payments and invoice fraud?

Sometimes. Cover for business email compromise varies more between policies than almost anything else: full cover, a sub-limit, or an exclusion are all common. If payments run through your email, read that section of the wording before you buy.

The information in this article is general in nature and provided for informational purposes only. It does not constitute personal insurance, legal, tax, or business advice. Cyber insurance policies differ significantly between insurers, and regulatory obligations, thresholds and penalties can change. Premium figures reflect policies arranged through upcover and are indicative only; your premium will depend on your circumstances. Always confirm current obligations with the OAIC, the Australian Signals Directorate, or a qualified professional. All insurance products arranged through upcover are subject to the terms, conditions, limits and exclusions contained in the relevant policy wording and Product Disclosure Statement. Before deciding whether a particular insurance product is right for you, please read the relevant PDS and consider your personal circumstances. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078. upcover arranges insurance products with selected insurers and underwriters and does not compare all general insurers or insurance products available in the market.

We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.