A bookkeeper at a thirty-person engineering consultancy paid a supplier invoice on a Friday afternoon. The bank details had changed, the email came from an address one character different from the supplier’s, and the money was gone through three accounts before Monday. There was no malware, no ransomware note, and no breach of the firm’s network. Whether that loss is recoverable depends almost entirely on which sublimit and which warranty sit in the cyber policy.
Cyber insurance is now standard for mid-sized Australian businesses, but it is bought badly more often than any other line. Organisations compare headline limits and premiums, sign, and then discover at claim time that funds transfer fraud carried a $100,000 sublimit inside a $5 million policy, or that the business interruption cover never engaged because the outage lasted ten hours and the waiting period was twelve.
This is a practical guide to what the cover actually does, what the law obliges you to do alongside it, and the specific policy terms that decide whether a claim is paid.
What the policy actually pays for
Cyber policies are written in two halves, and the halves behave very differently at claim time.
First-party cover: your own losses
This responds to costs your organisation incurs directly. It typically includes forensic investigation to establish what was accessed, legal advice from a breach coach, the cost of notifying affected individuals, credit and identity monitoring where offered, data restoration, crisis communications, and business interruption for lost income during the outage. Extortion cover addresses ransom demands and the negotiation specialists who handle them.
The heavily negotiated part is business interruption. Two numbers matter more than the limit: the waiting period, commonly six to twelve hours, before cover engages at all, and the indemnity period, often thirty to one hundred and eighty days, over which loss is measured. Dependent or contingent business interruption, covering an outage at your cloud provider or a key supplier rather than at your own systems, is frequently sublimited or absent.
Third-party cover: what others claim against you
This is closer to conventional liability coverage. It responds to privacy liability claims by individuals whose data you held, network security liability where your compromised systems harmed someone else, regulatory investigation defence costs, and media liability for content-related claims. Where a business processes card payments, cover for payment card industry assessments and fines is a separate insuring clause worth checking by name.
One distinction to understand before you buy: regulatory defence costs are almost always covered, while regulatory penalties are covered only where insurable by law, which varies by jurisdiction and is often not the case in Australia for statutory penalties.
The first seventy-two hours, and why the policy dictates them
Nearly every cyber policy contains a consent clause: costs incurred before the insurer approves the provider are not covered. This catches businesses constantly. The IT firm you have used for a decade begins remediating on Saturday morning, and the invoice is later declined because the insurer has a panel and was never called.
Build the response sequence around that reality:
- Call the insurer’s twenty-four hour incident hotline before engaging anyone. The number belongs on a printed card, not only in an email inbox you may be locked out of.
- Accept the panel breach coach. Legal professional privilege over the forensic report often depends on the investigation being instructed through lawyers rather than commissioned directly.
- Isolate rather than wipe. Rebuilding a compromised server destroys the evidence needed to determine whether personal information was actually accessed, which is the question the regulator will ask.
- Move communications out of band. If email and file shares are compromised, executives should not coordinate over them.
- Preserve logs immediately. Default retention on many systems is thirty days or less, and the absence of logs frequently forces a worst-case notification assumption.
The out-of-band point is more literal than it sounds. Businesses running a serious incident routinely need somewhere off their own network and away from staff to run response meetings for a week, and firms in regional centres often arrange neutral space such as meeting room hire newcastle rather than convene in an office where the response itself becomes visible before customers have been told. Policies fund the specialists, but the logistics are yours. Our coverage of what happens when incident response services fail an affected individual is a useful reminder of what is at stake downstream.
What Australian law requires alongside the policy
Insurance does not displace statutory obligations, and the deadlines are shorter than most boards assume.
Under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988, an entity that becomes aware of reasonable grounds to suspect an eligible data breach must carry out a reasonable and expeditious assessment within thirty days, and where the breach is likely to result in serious harm must notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable. Australian Privacy Principle 11 separately requires reasonable steps to protect personal information, which is the standard against which your controls will be judged after the fact.
Penalty exposure changed materially in 2022, when the maximum civil penalty for serious or repeated interference with privacy by a body corporate rose to the greater of $50 million, three times any benefit obtained, or thirty per cent of adjusted turnover in the relevant period. Operators of critical infrastructure assets have separate and much faster reporting duties to the Australian Signals Directorate under the Security of Critical Infrastructure Act 2018, measured in hours rather than days. More recently, the Cyber Security Act 2024 introduced a ransomware payment reporting obligation for businesses above a turnover threshold, requiring a report within seventy-two hours of a payment being made.
Paying a ransom also carries legal risk independent of the policy, because a payment to a sanctioned entity can breach Australian sanctions law regardless of the commercial pressure. That question belongs with counsel before any transfer, not after.
Which cover responds to which incident
| Incident | Cover that usually responds | Common trap |
|---|---|---|
| Ransomware encrypting servers | Extortion, first-party BI, data restoration | Waiting period longer than the outage |
| Supplier invoice fraud by email | Social engineering or funds transfer fraud | Low sublimit; callback verification warranty |
| Cloud provider outage | Dependent business interruption | Often excluded or heavily sublimited |
| Employee emails a client list to a competitor | Privacy liability, sometimes excluded as insider act | Rogue employee exclusions vary widely |
| Website defacement and defamatory content | Media liability | Not present in stripped-back policies |
| State-linked attack on infrastructure | Frequently excluded outright | Attribution is decided by the insurer |
| Stolen unencrypted laptop | Notification costs, privacy liability | Encryption warranty may void cover |
The exclusions that decide whether you are paid
- State-backed attack exclusions. From 31 March 2023 the Lloyd’s market required standalone cyber policies to carry exclusions for state-backed cyber operations. Wordings differ significantly on how attribution is determined, and that clause deserves a lawyer’s eye rather than a broker summary.
- Minimum security warranties. Underwriters now condition cover on multi-factor authentication for remote access and privileged accounts, endpoint detection, offline or immutable backups, and patch cadence. Answering the proposal form optimistically is the fastest route to a declined claim and possible avoidance for misrepresentation.
- Prior known circumstances. Cyber policies are written on a claims-made basis with a retroactive date. Anything you were aware of before inception is excluded, so unresolved security incidents must be disclosed at renewal, not quietly carried forward.
- Betterment. The policy restores you to your pre-incident state. It does not fund the modernisation programme the incident finally justified internally.
- Widespread event clauses. Systemic events affecting many insureds at once may trigger reduced limits, and this is increasingly common wording.
What underwriters expect before they will quote
The Australian Signals Directorate’s Essential Eight has become the de facto underwriting checklist across the market: application control, patching applications, restricting Microsoft Office macros, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Insurers rarely require formal maturity certification, but they do ask questions that map directly onto those eight controls, and a business that can evidence them consistently prices materially better than one that cannot.
Two practical notes. Test a restore from backup rather than confirming backups run, because failed restores are a routine and expensive discovery mid-incident. And ensure that whoever completes the proposal form has authority to verify the answers technically, since the form becomes a contractual representation. Businesses that treat compliance paperwork casually in one industry function tend to do so across all of them.
Frequently Asked Questions
Does my general business insurance already cover cyber losses?
Almost certainly not. Insurers spent several years removing so-called silent cyber exposure from property and general liability wordings, adding express cyber exclusions. A property policy responds to physical damage, and data is generally not treated as tangible property. Assume a standalone cyber policy is required and confirm the exclusion wording in your existing policies rather than hoping.
Will cyber insurance pay a ransom?
Many policies will, subject to consent, a sublimit, and legal clearance, but payment is never automatic. Insurers require negotiation through appointed specialists and sanctions screening of the recipient. Australian businesses above the relevant turnover threshold must also report a payment within seventy-two hours under the Cyber Security Act 2024. Paying is a legal decision as much as a commercial one.
How much cover does a small business need?
Size the limit against the cost of the response rather than the value of the data. Forensics, legal advice, notification, and monitoring for even a modest breach commonly reach six figures before any liability claim exists. Model your own downtime cost per day, add response costs, and compare that against the proposed limit and sublimits, not the premium.
What is the difference between a sublimit and the policy limit?
The policy limit is the maximum payable overall; a sublimit is a smaller ceiling applying to one insuring clause within it. Social engineering fraud, dependent business interruption, and card industry assessments are the clauses most often sublimited far below the headline number. Read the schedule of sublimits before the wording, because that page reflects your real cover.
Does having insurance reduce our legal obligations after a breach?
No. Notification duties under the Privacy Act, sector reporting under critical infrastructure legislation, and directors’ duties operate independently of any policy. Insurance funds the response and may indemnify liability, but the regulator deals with the entity, not the insurer. Boards should treat cyber as a governance obligation, and our Legal Advice section covers the adjacent duties.
How quickly should we notify the insurer?
Immediately, and before engaging any external provider. Notification triggers access to the panel and preserves cover for costs. Late notification is a common ground for reduction or denial, and most wordings require notice as soon as practicable after an executive becomes aware of a circumstance likely to give rise to a claim, not after the situation is understood.
What to Do Next
Pull your current policy schedule and find the sublimits page, then compare the social engineering fraud sublimit and the business interruption waiting period against the two scenarios most likely to hit your business. If the invoice fraud sublimit is smaller than a typical supplier payment, that gap is the one to fix at renewal. Related reading on how professional firms are adapting operationally appears in The Rise of Digital Law Firms: How Technology Is Reshaping Legal Services.
Image credit: Image Source.
This article is general information about insurance and regulatory obligations, not legal or financial advice; consult a licensed adviser about your organisation’s circumstances.






