There is no general legal requirement for Australian businesses to hold cyber insurance. But contracts with government or large clients increasingly require it, and you still carry legal obligations after an incident — including the Notifiable Data Breaches scheme for businesses covered by the Privacy Act, and ransomware payment reporting for businesses above the turnover threshold. Insurers also expect baseline security before they will cover you.
What it depends on
The full answer depends on your specific circumstances. Here’s what matters.
Your data
Businesses holding health, financial or identity information face higher costs after a breach — notification, forensics and potential claims.
Your contracts
Check your client and supplier contracts for insurance clauses. Many specify cyber or professional indemnity cover.
Your controls
Insurers commonly require multi-factor authentication, backups and patching. Weak controls can mean declined cover or declined claims.
The last 10%
What a qualified professional can add
The answer above covers the general position. Here’s where professional judgement — applied to YOUR specific situation — makes the difference.
- Assessing your actual cyber risk and required cover
- Implementing the controls insurers expect
- Preparing an incident response plan that aligns with your policy
Questions to ask before you engage one
If you decide to engage a professional, these questions help you evaluate whether they’re right for your situation.
Do any of my contracts require cyber insurance?
What security controls does the insurer require?
Does the policy cover business interruption and ransomware?
Who do I call first under the policy if an incident occurs?
Did this answer your question?
General Advice Warning
The information on this page is general in nature and does not take into account your personal objectives, financial situation or needs. It is provided by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640) and should not be relied upon as a substitute for professional advice. Consider whether the information is appropriate before acting on it. Read our Financial Services Guide.