Cyber risk is no longer an exposure limited to large corporations and technology companies. Small and medium Australian businesses increasingly rely on email, cloud systems, online banking, accounting software, customer databases, websites and digital communication to operate every day.
A cyber incident can interrupt those systems, compromise sensitive information, redirect payments, lock a business out of its data or stop the business from operating altogether.
Insurance 2U arranges Cyber Insurance for Australian businesses and professionals. We look beyond the headline premium and consider how the business operates, what information it holds, the technology it relies upon and the financial consequences if those systems are compromised.
Cyber incidents can occur in many different ways. Depending on the business, exposures can include:
A cyber claim is rarely about the physical computer itself.
The larger cost can arise from identifying what happened, containing the attack, restoring systems, recovering data, dealing with affected customers and getting the business operating again.
Depending on the insurer and policy selected, Cyber Insurance can provide access to specialist incident-response services and cover for various first-party and third-party cyber losses.
When a serious cyber incident occurs, many business owners do not know who to call first.
Depending on the policy, cyber insurers can provide access to specialist incident-response teams who may coordinate experts such as:
Having access to experienced specialists quickly can be one of the most valuable features of a Cyber Insurance policy.
Ransomware can encrypt or disable critical systems and potentially prevent a business from accessing its own information.
Cyber extortion can also involve threats to publish stolen data, disrupt systems or cause other harm unless demands are met.
Depending on the policy, circumstances and applicable legal requirements, Cyber Insurance may provide assistance with the investigation and management of a covered cyber extortion event.
Terms, conditions, exclusions and insurer response protocols vary, so this is an area where the policy wording is particularly important.
One of the most serious consequences of a cyber attack can be the inability to trade.
A business may lose access to:
Depending on the policy selected, Cyber Business Interruption cover may respond to certain financial losses following a covered cyber event, subject to the policy’s waiting period, indemnity period, limits and other conditions.
For a business that relies heavily on technology, every hour offline can matter.
Following a cyber attack, systems and data may need to be restored or reconstructed.
Depending on the policy, cover may be available for certain costs associated with restoring data, software or systems following an insured cyber event.
This can be particularly important where the business relies on specialised software, customer databases or operational information that would be difficult or expensive to reconstruct.
Businesses can hold significant amounts of personal, commercial and confidential information.
This can include:
If that information is accessed, disclosed or lost, the business may face legal, regulatory and reputational consequences.
Depending on the circumstances and applicable Australian privacy requirements, the business may also need to consider whether notification obligations arise.
Not every cyber loss involves sophisticated malicious software.
One of the most damaging exposures for SMEs can involve criminals compromising or impersonating email accounts and convincing someone to transfer money to a fraudulent bank account.
Examples can include:
Cybercrime, funds-transfer fraud and social-engineering cover varies significantly between insurers. Some policies may provide cover subject to specific sub-limits, verification procedures and other conditions, while other policies may not provide the same protection.
This is an important area to examine rather than assuming that every financial loss involving a computer is automatically insured.
A cyber incident can also result in allegations from customers, clients or other third parties.
Depending on the policy, Cyber Insurance may provide protection for certain claims arising from privacy breaches, network security failures or other covered cyber liabilities.
Defence costs can be significant even where the business disputes the allegation.
Cyber Insurance can be particularly relevant for professional and service businesses holding confidential client information.
This can include:
Real estate agencies, for example, can hold substantial amounts of personal information while also processing rental payments, deposits, supplier invoices and property transactions — making email and payment-security controls particularly important.
A smaller business may not have an internal IT department, cybersecurity team, privacy specialist or legal counsel available when an incident occurs.
This can make access to the insurer’s specialist cyber response services particularly valuable.
A cyber event at a small business can still result in significant costs and disruption, even where the business does not consider itself a likely target.
Cyber insurers increasingly want to understand the security controls a business has in place before offering cover.
Depending on the insurer and business, underwriting questions may include:
Stronger cybersecurity does not eliminate risk, but it can influence insurer appetite, available coverage and premium.
Cyber Insurance policies can differ materially between insurers.
When comparing available options, relevant differences may include:
This is why we do not believe Cyber Insurance should be compared on premium alone.
A cyber claim can move quickly and may require specialist assistance immediately.
For clients whose insurance we manage, Insurance 2U can assist with:
With cyber incidents, speed matters. Our role is to help our client engage the insurer and appropriate response resources quickly rather than leaving the business owner to navigate the insurance process alone during a crisis.
If you discover suspicious activity, ransomware, unauthorised access, a potential data breach or another cyber incident, contact Insurance 2U promptly.
Where Cyber Insurance is in place, the policy may contain specific incident-response and notification requirements. Significant steps or expenditure should not be undertaken without considering the insurer’s requirements and obtaining appropriate advice.
Insurance 2U can access major insurers and specialist underwriting markets offering Cyber Insurance to Australian businesses.
The markets available depend on factors such as:
Insurer appetite and policy coverage can vary materially, particularly for businesses with weaker cybersecurity controls or higher-risk technology exposures.
Whether you operate a professional practice, real estate agency, consultancy, retail business, technology company or another Australian SME, talk to Insurance 2U about your Cyber Insurance requirements.
Cyber Insurance — protecting your systems, information and business operations, backed by experienced claims support when every hour matters.