WebInsure brokers assess your business risks, compare multiple insurers, and provide tailored cover with ongoing support and claims advocacy, ensuring better protection than direct insurer policies.
Cyber Insurance — What It Covers and What It Doesn’t
Cyber Insurance — What It Covers and What It Doesn’t
Cyber insurance has moved from a niche product to a boardroom conversation in a few short years. For Australian businesses, the question is no longer whether cyber risk is real — it’s whether the cover you have (or are considering) actually responds to the incidents most likely to affect you.
This post explains how cyber insurance policies are typically structured, what they cover, where the gaps commonly appear, and what to look for when reviewing a policy.
How cyber policies are structured
Most cyber insurance policies are split into two broad categories of cover:
First-party cover
This addresses costs your own business incurs directly as a result of a cyber event. Common first-party sections include:
- Incident response costs — IT forensics to identify the breach, legal advice, and specialist consultants to manage the response
- Data restoration — costs to recover or recreate data that has been corrupted, deleted or encrypted
- Business interruption — loss of income and increased costs while your systems are down following a covered cyber event
- Cyber extortion — costs associated with managing a ransomware demand, including negotiation support and, where covered, ransom payments
- Notification costs — costs to notify affected individuals where required by the Privacy Act or other regulation
- Crisis communications — reputational management costs following a breach
Third-party cover
This addresses your legal liability to others arising from a cyber event. Common third-party sections include:
- Privacy liability — claims from individuals whose personal information was exposed in a breach
- Network security liability — claims from third parties who suffered loss because your systems were compromised and used to attack them
- Media liability — claims arising from online content, including defamation or intellectual property infringement
- Regulatory investigations — costs to respond to an investigation by the Office of the Australian Information Commissioner or similar body
What cyber insurance typically does not cover
Understanding the exclusions is as important as understanding the cover. Common exclusions include:
- Infrastructure outages — loss caused by failure of a third-party service provider’s systems (internet outages, cloud provider failures) is often excluded unless the policy has a specific contingent business interruption extension
- War and state-sponsored attacks — cyber events attributable to nation-state actors may be excluded under war exclusions, though the definition is contested and has been the subject of litigation internationally
- Prior known circumstances — claims arising from a breach that was known or should have been known before the policy incepted are generally excluded
- Voluntary data sharing — losses where you intentionally provided data that was then misused are typically not covered
- Intellectual property theft — the loss of your proprietary information or trade secrets is generally excluded (liability arising from your inadvertent disclosure of someone else’s IP may be a different matter)
- Betterment — policies generally won’t pay to upgrade your systems beyond their pre-incident state, only to restore what existed
Social engineering and funds transfer fraud
Business email compromise — where a criminal impersonates a supplier or executive to redirect payments — is one of the most common and costly cyber incidents affecting Australian businesses. Whether it’s covered depends heavily on the policy wording.
Some policies cover social engineering fraud as a first-party section; others exclude it or cover it only up to a sublimit. This is worth asking about specifically when comparing policies, particularly for businesses that make regular electronic payments or have staff with payment authority.
Waiting periods and sublimits
Business interruption cover under a cyber policy typically has a waiting period — a period of downtime that must pass before cover kicks in. Waiting periods vary (commonly 8 to 24 hours) and the right choice depends on how quickly your business would feel the financial impact of a system outage.
Sublimits also apply to specific sections within a policy. You might have $5 million of total cyber cover, but only $250,000 available for ransomware payments or $500,000 for notification costs. Reviewing the sublimits alongside the overall limit is important.
What to review before buying or renewing
- Does the policy cover social engineering and funds transfer fraud, and what are the sublimits?
- What is the waiting period for business interruption, and is it appropriate for your operations?
- Does the policy cover contingent business interruption arising from outages at third-party providers?
- How does the policy define a “cyber event” — is it broad enough to cover the scenarios most relevant to your business?
- What are the incident response obligations — do you need to use the insurer’s panel providers, and is that acceptable to you?
- Are there any security warranties or conditions that you need to maintain (such as multi-factor authentication or patch management) to keep cover valid?
If you’d like to compare cyber insurance options for your business, contact WebInsure. We can help you assess what cover is appropriate for your size, sector and risk profile.
This post provides general information only and does not constitute personal advice. Cover availability, terms, exclusions and premiums vary by insurer, product and individual circumstance. Always review the Product Disclosure Statement and confirm suitability before making a decision.
WebInsure Pty Ltd ABN 32 054 247 666 is an Authorised Representative 000271148 of Community Broker Network Pty Ltd ABN 60 096 916 184 AFSL 233750.