[nonimo]
EN
Download

Cyber insurance in Australia: what it covers and what it excludes

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Cyber insurance in Australia, as sold to a small business, pays for two separate things: your own costs after an incident, and what you end up owing other people because of it. Both halves are wider than most owners expect. What decides a claim, though, is five exclusions and one disclosure duty rather than the list of covers in the brochure, and they live in a document that most insurers in this market will not let you download.

So I downloaded the ones you can. Four Australian cyber wordings, read in full on 16 September 2026: Chubb, AIG, DUAL and Emergence. This guide is what they actually say, what cover costs, and how to compare one policy against another, and it ends in a checklist you can take to a broker.

If you are here because a renewal pack has landed and somewhere inside it there is a question about artificial intelligence, that is a different guide with a different job. If somebody has already put a client file into a chat window, that one has a clock running on it.

What cyber insurance in Australia costs a year, before anything else

Almost every insurer here will only name a price once you ask for a quote. One number is published with a date attached, and it is an average rather than a starting price, so the table shows what it covers and where a business of your size is likely to sit. The detail is further down.

BusinessWhat is actually publishedOur estimate, a year
Sole trader or a practice of 2 to 5nothing published at this size; BizCover sells cover levels from $100,000 upwards$700 to $1,600
The BizCover customer average$134 per month on average for BizCover customers, about $1,608 a year, measured 1 July 2023 to June 2024 and two years old$1,600 to $3,500
21 to 50 people, or holding client recordsnothing published; cover levels run to $2 million and placement goes through a broker$3,500 to $8,000

The middle column is quoted from the source named in it, and the right column is our own estimate: not a quote, and not an insurer’s figure.

How we got there: we placed the published prices on the three bands that two independent European sources both use, Amrae’s LUCY study of 20,996 policies for 2025 (average premiums of €645, €1,600 and €5,000 by company size) and AIG’s own Irish service tiers (€899 or less, €900 to €4,999, €5,000 or more). Your premium comes out of your proposal form, not out of this table.

What cyber insurance actually pays for, in two halves

Every wording read for this guide is built the same way, and once you see the split the brochures stop being confusing. The first half is money spent on you. The second half is money spent because of you.

Chubb’s Australian wording sets out six insuring agreements and sorts them exactly that way: four cover your own losses and two cover your liability to third parties. The four are incident response, business interruption, data and system recovery, and cyber extortion. The two are privacy and network security liability, and media liability.

The other three arrive at the same split by other routes. Emergence separates “Losses to Your Business” from “Loss to Others”. DUAL has three insuring clauses, response costs and business interruption on one side and liability on the other. AIG spreads it across coverage sections but sorts the same way.

What it paysWhich halfWhat that means in practice
Incident response and forensicsYoursGetting somebody who has done this before onto it in the first day
Business interruptionYoursIncome lost while you are not trading, after a waiting period
Data and system recoveryYoursRebuilding what was destroyed, not upgrading it
Cyber extortionYoursNegotiation costs, and the payment where the law allows it
Privacy and network security liabilityOther people’sDamages and legal costs when somebody sues over your breach
Regulatory investigation costsOther people’sResponding to a regulator, which is a cost even when you win
Media liabilityOther people’sDefamation and infringement arising from your own content

Sources: Chubb Cyber Enterprise Risk Management Version 2.2, insuring agreements 1.1 to 1.6; Emergence Cyber Event Protection CEP-004.2, sections A to C; AIG CyberEdge Commercial 2020; DUAL Australia Cyber Liability and Privacy Protection 1120.

One thing the table above leaves out on purpose, because it is usually not in the base policy: theft of your own money. Chubb carries cyber crime as an extension rather than an insuring agreement, and AIG splits it into separate social engineering, funds transfer, computer fraud and cryptojacking covers.

Check whether yours is switched on. Chubb’s short proposal form gives social engineering fraud an optional section of its own, and asks whether you confirm changes to vendor bank details and require dual authorisation on payments, which tells you what the underwriter expects to pay out on.

The half that gets used is the first one

For a business of ten people, the second half is the one that sounds frightening and the first half is the one that gets claimed. Nobody sues a practice of five people over a fortnight of downtime.

The bill that actually arrives is the response: the forensics, the lawyer who tells you whether this is notifiable, the week of not invoicing. That is the part worth buying properly, and it is the part an organisation of any size will recognise straight away.

Recovery is not an upgrade

One phrase to look for in the recovery cover is betterment. Chubb’s wording carries it as a separate extension, which tells you what the base position is: the policy puts back what you had, and improving on it is either an optional extra or your own money. Emergence writes the same idea into its definition of system failure, which does not respond to an outage caused by software that the wording describes as “past its end-of-life and no longer supported”.

The five exclusions that decide whether you get paid

An exclusion list looks like boilerplate until you read two side by side and find they are not the same. These five are where the Australian wordings actually differ, and they are the five to compare line by line.

ExclusionWhat it turns onWhere the four differ
War and attacks backed by a stateWhether a state actor is behind it, and whether war has to be physicalFour wordings, four different positions, set out below
Liability assumed by contractWhether you would have owed it anywayAll four exclude it and all four carve part of it back, but not the same part
Software past its end of lifeWhether it was still supportedEmergence writes it into system failure; others handle it in conditions
Prior knowledgeWhat you knew before inceptionChubb tests what the control group knew or could reasonably have foreseen
Fines not insurable by lawWhether Australian law allows the paymentChubb excludes them by definition; Emergence’s loss definition includes fines and penalties generally

Sources: Chubb Cyber ERM v2.2 exclusions 4.1, 4.6 and 4.11 and its Regulatory Fines definition; AIG CyberEdge Commercial 2020 exclusion 3.10; Emergence CEP-004.2 definitions of loss and system failure.

The war clause is the one that has changed

This is the clause the market rewrote after 2022, and the four documents show three stages of that rewrite sitting on the shelf at once.

WordingWhat the war exclusion reachesThe test
Chubb Cyber ERM v2.2, 2022An attack “by or on behalf of a sovereign State or state-sponsored actor”A G7 leader or another state ordering force, or a Security Council resolution authorising force or sanctions
Emergence CEP-004.2, 2022Any “physical act of war”, and terrorismTerrorism carve back names the cyber events it does not reach, from hacking to cyber extortion
DUAL 1120, 2020War, hostilities and acts of terrorism“This Exclusion shall not apply to cyber terrorism”
AIG CyberEdge Commercial, 2020“Any war (whether war is declared or not), terrorism (except Cyber Terrorism), invasion, use of military force”None. No state actor test at all

Sources: Chubb exclusion 4.11; Emergence exclusions 12 and 13; DUAL exclusion 5.25; AIG exclusion 3.10.

Read the second row again, because it is the one that surprises people. Emergence excludes a physical act of war, and the words sovereign, cyber war and cyber operation do not appear anywhere in its wording. Chubb’s, drafted the same year, spends most of a page on exactly that scenario.

Four policies with materially different answers to the same attack, all of them on offer in Australia this week. The year printed on the wording is not trivia. On this point only the clause counts, and no internal policy about who may use what will change what it says.

The contract exclusion, and the carve back that matters

All four wordings exclude liability you took on by contract, which sounds like it would swallow every client agreement you have signed. All four then carve part of it back, and the part differs.

The common floor is the same everywhere: the exclusion does not apply to liability you would have had anyway. Chubb puts it as “any liability or obligation You would have in the absence of such contract”, AIG as liability that “would have attached to the Insured in the absence of such contract or agreement”, Emergence as a liability “independent of the contract”.

Confidentiality is where the four part company

Above that floor, Chubb adds an indemnity you gave a client about failing to preserve the confidentiality of that client’s customers’ personal data. DUAL goes furthest and carves back “any obligation of confidentiality assumed by the insured under any agreement”, full stop, which is the widest of the four.

That carve back is the one professional services firms need, and it is the one to check word for word, because a confidentiality clause in a client contract is the promise you are most likely to be sued on. For a solicitor that promise is also rule 9 of the Conduct Rules, and what the Law Society of NSW says about client material in a chatbot explains why one paste can break it.

What it does not do is underwrite an uncapped indemnity you signed in somebody else’s contract, and the same wording says so in its definition of damages, which excludes amounts arising solely under a contract “to the extent they exceed the amount for which you would otherwise be liable for in absence of the contract”.

Whether it pays a regulator’s penalty, and the sentence that decides

This is the question owners ask first and brochures answer worst, so here is what the wordings say rather than what anyone says about them.

Emergence defines loss to include “regulatory and civil fines and penalties in respect of a claim”. That is about as affirmative as this market gets. Chubb includes regulatory fines inside damages for its privacy liability section, and then narrows them in the definition:

Regulatory Fines shall not include any civil monetary fines or penalties that are not insurable by law, criminal fines, disgorgement of profits or multiple damages.

Read that carefully: it does not answer the question, it moves it somewhere else. Whether a civil penalty under the Privacy Act 1988 is insurable in Australia is a question of Australian law, and the policy declines to name the answer.

So the useful thing to do with this clause is not to decide it yourself. Put it to your broker in writing, before you buy, and keep the reply. The same discipline applies to anyone working out whether an incident is reportable at all.

What the wordings say about AI, which is nothing

I checked this rather than assumed it, and I tested the search on sample text first, so a zero result could be trusted. Across all four Australian wordings, the phrase artificial intelligence does not appear. Neither does machine learning, generative, algorithm, chatbot, large language, automated decision, or the word AI on its own. That is eight terms across four documents, and not one occurrence.

4Australian cyber wordings read in full
0that use the words artificial intelligence
7CFC policies given explicit AI language, June 2026
Chubb, AIG, DUAL and Emergence wordings, read 16 September 2026; CFC announcement, 25 June 2026

Silence is not an exclusion. It means the question of whether your policy responds to a loss connected with AI gets decided later, by people arguing about a clause that was drafted without the possibility in mind. That is a worse position than either a clear yes or a clear no, because you cannot plan around it.

One insurer has started saying it out loud

On 25 June 2026 CFC announced it had added explicit AI language to seven of its policies, including its cyber and technology lines, to address what it listed as “model hallucination, AI generated content and model drift”. Its stated reason is the one above: “Rather than relying on implied or silent coverage, we see value in being explicit about how AI is treated.”

The market is starting to move, but it has not moved yet. One underwriter has published a position; the four wordings you can actually download in Australia still say nothing. If AI use is material to your business, the question to ask is narrow and answerable: is that language on the paper being offered to me, in Australia, this year.

What this has to do with the questionnaire

The questionnaire and the wording pull in opposite directions, and it is worth seeing why. Insurers are starting to ask whether you use AI, while their wordings still do not mention it. Nothing obliges the two to line up, and in the four documents read here they do not. Answering the questionnaire properly starts with knowing what each tool keeps: for ChatGPT, for instance, the deletion clock only starts when you delete.

If the form in front of you has that question on it, the answer belongs in the guide written for that form, not in a general policy comparison.

What it costs, and the only two numbers anyone publishes

Almost every price for cyber insurance in Australia sits behind a quote, which is a polite way of saying nobody will tell you until they have your turnover, your industry and your answers about controls. Two numbers are published with a date attached, and they are the only two worth repeating.

The first is a premium. BizCover states that cyber liability insurance “costs $134 per month* on average for BizCover customers”, and its own footnote pins the measurement window: a customer average monthly payment report covering 1 July 2023 to June 2024. That is roughly $1,608 a year, and it is two years old, which is a fact about the number rather than a criticism of it. The cover levels BizCover sells alongside it run from $100,000 to $2 million.

The second is a loss. The Australian Signals Directorate puts the average cost of cybercrime per report, as reported by the victims themselves, at $56,600 for a small business in the year to June 2025, up 14 per cent on the year before.

$56,600
average cost of cybercrime per report for a small business, as reported by victims, up 14 per cent. ASD Annual Cyber Threat Report 2024-2025, 14 October 2025

Two cautions before anyone puts those side by side. The loss figure is not an expected value: it is what cybercrime costs a small business that had some, not what it costs the average small business per year. And the victims reported it themselves, in the more than 84,700 reports the Australian Signals Directorate received through ReportCyber. Both numbers are real, and neither is a forecast for you.

Premium, per year$1,608
Cost of cybercrime, per report$56,600
BizCover customer average, July 2023 to June 2024, annualised; ASD Annual Cyber Threat Report 2024-2025

Why the same business gets four different prices

Turnover, industry, claims history and cover level move the number, and so does the thing you control: your security posture at the moment you answer the proposal. That is also the reason a cheap quote and an expensive quote are rarely the same product, and why a comparison run on price alone tells an organisation very little.

What an insurer wants to see before it quotes you

The proposal form is where the underwriting actually happens, and you can read one before you fill one in. Chubb publishes two. The Standard form is for businesses with revenue between $50 million and $700 million and runs to twenty pages. The Short MarketPlace form is for businesses under $50 million and runs to six.

The second is the one a small business is handed, and four of its questions are the entire security assessment.

The question, as the form puts itWhat has to be true before you tick yes
Whether the network and email can be accessed remotely, and whether MFA is used where they canEveryone with remote access, not only employees
Whether the systems the business depends on are backed up at least weekly and stored offlineThe offline part, which is what survives ransomware
Whether a security tool protects computers and handheld devicesThe phones as well as the laptops
Whether an email security solution is in placeWhatever you actually run, named rather than assumed

Source: Chubb, Cyber Enterprise Risk Management Short MarketPlace Cyber Proposal Form, questions 7 to 10.

None of those four requires buying anything new in most small offices. What they require is that the answer be true of everything, not of the setup you meant to finish. The same goes for settings you believe you changed in an AI tool: in Claude, for example, training depends on the plan and on a switch.

The question most people tick too fast

The same form asks, yes or no, whether to the best of your knowledge you comply with all relevant privacy laws and regulations in the jurisdictions where you operate. It takes a second to tick, and it is a statement inside a document you sign, governed by the duty in the next section. If staff use AI tools such as Copilot, that is harder to answer than it looks, because the name covers several products with different rules.

It is worth an hour before you answer it, and the hour is mostly about where client information actually goes. If some of it goes into tools nobody approved, a written rule about which tools staff may use is a document an underwriter can take into account, and not having one is also an answer.

Three sentences to get in writing before you accept a quote

Ask these by email so the reply is a document rather than a memory of a phone call. The answers will tell policies apart better than any feature list.

Three questions for the broker, before you accept:

  1. Please send me the full policy wording and the schedule, not the summary, and confirm the version number and date printed on it.
  2. Does this wording exclude losses from a cyberattack backed by a state, and if so, what test has to be satisfied before that exclusion applies?
  3. Does this policy pay a civil penalty imposed by an Australian regulator, and if the wording says “insurable by law”, whose view of that law applies?

What you have to tell them, and the section that softens the blow

A cyber policy bought for a business is not a consumer insurance contract. Section 11AB of the Insurance Contracts Act 1984 confines that label to insurance obtained wholly or predominantly for personal, domestic or household purposes, unless the insurer writes to you saying otherwise.

So the duty that applies to you is the older one in section 21: disclose every matter you know to be relevant to the insurer’s decision to accept the risk, and every matter a reasonable person could be expected to know is relevant.

Leaving a question blank works in your favour, but do not rely on it

Section 21 subsection 3 has a provision nobody mentions and everybody should. Where a person fails to answer, or gives an obviously incomplete or irrelevant answer to a question in a proposal form, “the insurer shall be deemed to have waived compliance with the duty of disclosure in relation to the matter”. An unanswered question is a point the insurer is treated as having let go, rather than a trap that springs later.

Section 21(3)
an unanswered proposal question means the insurer "shall be deemed to have waived compliance with the duty of disclosure in relation to the matter". Insurance Contracts Act 1984

That is not an invitation to leave things blank. It is the reason insurers chase incomplete forms, and it is the reason the AI question on a renewal pack is worth answering properly rather than skipping, which is the whole subject of the questionnaire guide.

Getting it wrong is usually a reduction, not a refusal

Section 28 sets the remedy for a general insurance contract, and it is more proportionate than the folklore. If the failure was fraudulent, the insurer may avoid the contract. If it was not, the insurer’s liability “is reduced to the amount that would place the insurer in a position in which the insurer would have been if the relevant failure had not occurred”.

And the section does not apply at all if the insurer would have written the same policy, on the same terms, anyway.

The section that covers you after the policy starts

Section 54 handles the other half of the worry, the one about something you did after you bought the cover. Its first subsection stops an insurer refusing a claim by reason only of an act that happened after the contract was entered into, reducing the insurer’s liability instead by the amount that fairly represents the prejudice.

Subsection 3 goes further: where you prove no part of the loss was caused by the act, the insurer may not refuse the claim by reason only of it.

Do not read that as a shield against everything. Subsection 2 holds the line: where the act “could reasonably be regarded as being capable of causing or contributing to a loss”, the insurer may refuse. Letting MFA lapse is exactly the kind of act that argument is about, which is why the answer to “will they still pay” is that it depends on whether the lapse is connected to what happened.

Who carries the risk, and whether you can read the wording

The same brands come up wherever you shop for this cover, and what is worth knowing about them is less their feature lists than who actually stands behind the policy, and whether you are allowed to read it before you commit. I checked each on 16 September 2026.

Brand on the quoteWho carries the riskWording downloadable today
ChubbChubb Insurance Australia LimitedYes, on its own Australian site
QBEQBE Insurance (Australia) LimitedNo, broker route
CFCCertain underwriters at Lloyd’sNo, broker route
EmergenceCertain underwriters at Lloyd’s, Emergence as coverholderOnly via a broker’s copy
CoalitionBinding authority from Allianz Australia Insurance LimitedNo, broker route
upcoverNot an insurer, a representative of an AFSL holderVia whichever insurer it places you with
BizCoverNot an insurer, a platform selling a panel of themYes, it publishes the panel’s wordings

Sources: each brand’s own Australian site, checked 16 September 2026; BizCover insurance partners page; Emergence CEP-004.2 “About the Insurer”; upcover website footer; Coalition Australian site.

The platform publishes more than the insurers do

That table has one genuinely odd row, and it is the last one. BizCover does not underwrite anything. It sells other people’s policies, and it publishes their full wordings on a public page, including Chubb’s, AIG’s and DUAL’s. Meanwhile QBE’s own page of policy wordings and PDSs has no cyber entry at all, and its QCyberProtect page offers research reports and a route to a broker.

If you want to read before you buy, and you should, that is where the documents are. It is also a reasonable question to put to any intermediary you deal with: send me the wording, now, not at renewal.

A search result is not an offer

One more reason to check who is behind the quote. QBE’s own product page states a minimum revenue size of $50 million for QCyberProtect, which rules out every business this guide is written for, before the conversation starts.

$50 million
minimum revenue size stated by QBE for QCyberProtect, with capacity up to $10 million. QBE Australia product page, September 2026

QBE still comes up when a small business looks for cyber cover, as do several insurers whose named products start well above the turnover of a suburban practice. The brand in the search result and the insurer who ends up on your schedule are frequently not the same company.

The Code, and the asterisk on Lloyd’s

Whether the insurer subscribes to the General Insurance Code of Practice is worth one minute of your time. Chubb Insurance Australia, QBE Insurance (Australia), AIG Australia and Allianz Australia are all on the Insurance Council of Australia’s current subscriber list.

So is Lloyd’s Australia, but with a condition the ICA prints in a footnote: Lloyd’s adopted the Code on the basis that it applies only to policies issued by an Australian coverholder under a binding authority, with claims managed in Australia. For a product backed by Lloyd’s, that footnote is the thing to ask about.

Why this page has no best column

There is a line in Australian law between telling you things and advising you, and this page sits deliberately on one side of it. ASIC draws that line in Regulatory Guide 244.

Factual information is “objectively ascertainable information, the truth or accuracy of which cannot reasonably be questioned”, and you do not need an Australian financial services licence to give it. Financial product advice, by contrast, generally involves “a qualitative judgement about” a product, or “an evaluation, assessment or comparison of” some or all of its features.

RG 244 includes a worked example that describes this page almost exactly. An organisation without a licence lists financial products on a website with objectively ascertainable factual information about specific product characteristics, and ASIC’s commentary is:

Because the information is factual and does not involve a qualitative judgement about, or an evaluation or assessment of, the features of the products, it is not financial product advice.

The line is finer than that example makes it sound, because the definition of advice does include comparison. So the working rule here is simple: the tables above report what documents say and where to find them, and the moment anything ranks policies or tells you which to buy, it has crossed over. That is why there is no best column, no star rating and no shortlist in any of these guides.

How to read the warning when you see it on somebody else’s site

Comparison sites that do cross the line have to carry a general advice warning, and now you know what it is for. A licensee giving general advice must tell you three things: that the advice was prepared without taking account of your objectives, financial situation or needs, that you should consider whether it suits yours before acting on it, and that you should get and read the product disclosure statement first.

The wording varies, because it is allowed to. The three points do not.

The online platform upcover carries a version of it in its own website footer, and the sentence next to it is the one worth noticing: “upcover does not compare all general insurers or insurance products available in the market.” Almost every platform in this market has a sentence like that somewhere. Find it before you decide that a comparison you have run is a comparison of everything.

If a claim goes wrong: the Code, AFCA and the two years you have

Two safety nets sit behind this market, and neither of them costs you anything.

The first is the General Insurance Code of Practice, which commits subscribing insurers to timeframes for deciding claims and for keeping you informed. The current version was last updated in October 2023, and a redrafted Code went out for public consultation between 24 June and 21 July 2026, so the rules in this paragraph are the ones in force rather than the ones being written.

October 2023when the Code in force was last updated
21 July 2026when consultation on the redrafted Code closed
2 yearsto take a declined claim to AFCA, from the final decision
Insurance Council of Australia; Emergence Cyber Event Protection CEP-004.2

The second is the Australian Financial Complaints Authority, the free external route when an insurer’s internal complaints process has run out. The policy wordings tell you the clock themselves: Emergence’s states that a complaint must be referred to AFCA within two years of the final decision, unless AFCA considers special circumstances apply.

AFCA sets a ceiling on what it can consider and a separate cap on what it can award, and the caps differ by claim type. The current set has applied since 1 January 2024 and is adjusted every three years, so look up the one for a general insurance claim rather than assuming. For most organisations reading this, that ceiling is not the binding constraint. The two years is.

  1. Does your insurer subscribe to the General Insurance Code of Practice?

    YesIt has committed to timeframes for deciding your claim and for keeping you informed.

    NoCheck who carries the risk and, for a product backed by Lloyd's, whether the Code's condition applies.

  2. Has the insurer declined the claim?

    YesTake it to the insurer's internal complaints process first.

    NoThere is nothing to take further.

  3. Has the internal process run out, with a final decision?

    YesThe free external route is the Australian Financial Complaints Authority.

  4. Are you still within two years of that final decision?

    YesAFCA can consider it, within its ceiling for a general insurance claim.

    NoOnly if AFCA considers special circumstances apply.

For most organisations, the ceiling is not what binds. The two years is.

A declined cyber claim, step by step. Insurance Council of Australia; Emergence CEP-004.2 on referral to AFCA; AFCA monetary limits

The checklist: eleven things to settle before you sign

Keep this list. Work through it with the wording open, not the brochure, and write the answers down next to the quote. It takes about an hour and it is the difference between buying cover and buying a document.

The documents, and who carries the risk

  1. The document Do I have the full wording and the schedule, with a version number and a date printed on them? If not, ask, and do not accept until it arrives. A summary is not a policy.
  2. Who the insurer is Which company carries the risk, not which brand sold it? Is that company on the Insurance Council of Australia’s Code subscriber list? If it is a Lloyd’s product, does the Code condition apply?
  3. The two halves Does the policy cover both my own costs after an incident and my liability to other people? Which insuring agreements cover each, and is any of them marked “not covered” on my schedule?

The numbers that actually bind

  1. The limits that actually bind What is the limit for any one incident, what is the aggregate, and which covers sit under a sublimit? A headline limit with a small sublimit on incident response is not the cover it looks like.
  2. The excess and the waiting period What do I pay per claim, and how many hours of downtime pass before business interruption starts counting? The waiting period decides whether short outages are covered at all.

The three exclusions to read word for word

  1. The war clause Does the exclusion require a state actor test to be satisfied, or is it a plain war and terrorism clause? Which version am I being offered, and what year was this wording drafted?
  2. The contract exclusion Does it carve back liability I would have had without the contract? Does it carve back a confidentiality indemnity I gave a client? Read those two sentences word for word.
  3. Regulatory penalties Does the policy pay a civil penalty from an Australian regulator? If the wording says “insurable by law”, ask the broker in writing whose view of that law applies, and keep the reply.

AI, what you have to tell them, and the first hour

  1. AI Do the words artificial intelligence appear anywhere in this wording? If not, the position is silence, not cover. If AI is material to my work, ask whether affirmative wording is available.
  2. What I have to tell them Have I answered every proposal question completely and truthfully, including the ones about controls I do not have? Have I kept a copy of what I told them, on the date I told them?
  3. If it goes wrong What is the notification requirement, and how fast? Who do I call in the first hour, and is that number in my phone rather than in a PDF on the server that just went down?

Run it once and you will know more about your own policy than most people who own one. Run it on two quotes and you will be comparing insurance rather than price.

If the reason you are reading this is that client information is moving through tools you do not fully control, the insurance is the second conversation. The first is which data leaves the building at all, and that is the problem we work on.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

What does cyber insurance cover in Australia?

Cyber insurance in Australia pays for two halves: your own costs after an incident, meaning response, forensics, lost income and ransom handling, and what you owe other people, meaning damages, legal costs and regulatory investigations. The four Australian wordings read for this guide all split cover that way.

What does cyber insurance not cover?

Five things decide most arguments: war and attacks backed by a state, liability you took on by contract, software past its end of life, matters you already knew about before inception, and penalties that are not insurable by law. Each is written differently in each wording.

How much does cyber insurance cost for a small business in Australia?

The only figure published with a date is BizCover's, which puts its customer average at $134 per month, measured between 1 July 2023 and June 2024. Every other number in this market sits behind a quote that depends on your turnover, industry and controls.

Does cyber insurance cover AI?

The four Australian wordings read for this guide do not use the words artificial intelligence, machine learning or AI anywhere. That is silence, not an exclusion, and silence is decided later by whoever is arguing about the claim.

Will an insurer refuse to pay if our MFA had lapsed?

Not automatically. Section 54 of the Insurance Contracts Act 1984 stops an insurer refusing a claim by reason only of an act after the contract started, but subsection 2 lets it refuse where the act could reasonably be regarded as capable of causing the loss.

Can I read the policy wording before I buy?

Sometimes. Chubb publishes its Australian cyber wording, and BizCover publishes the wordings of the insurers on its panel. QBE, CFC and Coalition published none I could download. Ask for the wording in writing before you accept a quote.

Does a cyber policy pay a Privacy Act penalty?

The wordings do not answer it. Chubb's defines regulatory fines to exclude penalties that are not insurable by law, which moves the question to a law the policy does not name. Ask your broker to answer it in writing.

Is QBE cyber insurance available to a small business?

QBE states a minimum revenue size of $50 million for QCyberProtect on its own product page. A business under that will be quoted by another insurer, often through a broker or an online platform, even where QBE appears in a search result.

What do I have to tell the insurer before they quote?

For a business policy, section 21 of the Insurance Contracts Act 1984 requires you to disclose matters relevant to the insurer's decision. Section 21 subsection 3 adds that leaving a proposal question unanswered means the insurer is treated as waiving that point.

What happens if the insurer declines the claim?

Insurers who subscribe to the General Insurance Code of Practice commit to internal timeframes, and the free external route is the Australian Financial Complaints Authority. Policy wordings typically give you two years from the final decision to go to AFCA.