A fraudulent invoice can empty a trading account before morning. A locked server can stop dispatch, payroll and customer bookings just as quickly. So, does business insurance cover cyberattacks? Sometimes, but a standard business policy is rarely the automatic safety net owners assume it is.
For Australian SMEs, the real question is not whether the policy has the word “cyber” somewhere in its schedule. It is whether the cover responds to the exact loss your business suffers: restoring systems, paying for forensic experts, managing customer notification, defending a claim, replacing lost income or dealing with an extortion demand. The difference can run well into six figures.
Does business insurance cover cyberattacks under a standard policy?
Business insurance is not one product. A business pack can combine property, public liability, theft, business interruption and management liability cover. Each section has a defined trigger, exclusions and limits. A cyberattack does not automatically fit those triggers.
For example, your property cover may insure physical damage to equipment after a fire, storm or break-in. It will not necessarily pay to rebuild corrupted data, investigate a network intrusion or cover revenue lost because ransomware encrypted your files. Likewise, public liability is designed for bodily injury or property damage to third parties, not generally for a customer whose personal information is exposed in a data breach.
Some policies include limited cyber extensions. These can be useful, but they are often tightly capped and may only address a narrow event. A $25,000 extension can disappear fast once lawyers, IT forensics, crisis communications and recovery specialists are involved. Treat it as a possible supplement, not proof that the business is properly protected.
The strongest answer for most businesses that hold customer data, take online payments, rely on cloud software or operate connected vehicles and equipment is a dedicated cyber insurance policy. It is built around digital incidents rather than physical loss.
What cyber insurance can pay for
Cyber cover varies between insurers, but a well-structured policy typically has two broad parts: first-party costs your business incurs directly, and third-party liabilities arising from the incident.
First-party cover may respond to the cost of incident response, including forensic investigation to establish what happened, remove malicious access and restore systems. It can cover data restoration, specialist IT support, legal advice, customer notification and credit monitoring where appropriate. Depending on the wording, it may also cover business interruption after a covered network outage, cyber extortion response costs and reputational support.
Third-party cover is about the claims and regulatory consequences that can follow. If a customer, supplier or other party alleges your failure to protect information caused them loss, cyber liability cover may fund legal defence and damages. It may also assist with certain regulatory investigations and penalties where they are legally insurable. No policy can insure a fine that legislation says cannot be insured, so this needs careful reading rather than assumptions.
A practical example: a Sydney trades business has its email compromised and a scammer sends altered bank details to customers. The immediate loss may be disputed invoices and interrupted cash flow. If customer details were accessed, there may also be legal and notification costs. Whether the policy responds depends on its social engineering, funds transfer fraud, privacy liability and business interruption terms. Calling it simply “a cyberattack” is not enough.
The gaps that catch business owners out
The most expensive surprise is assuming cyber cover includes every form of electronic crime. It does not. Social engineering, invoice interception and fraudulent transfer losses are frequently subject to separate limits, conditions or exclusions. Some insurers require a phone call-back or dual authorisation before payment instructions are changed. If your team bypasses the stated control, the insurer may decline or reduce the claim.
Business interruption is another pressure point. A policy may pay only after a waiting period, and only for income lost because your own network was interrupted. An outage at a key cloud provider, payment platform or software vendor may require contingent business interruption cover. Businesses that rely on one booking platform, warehouse system or managed IT provider should test this scenario before buying.
There are also policy conditions around basic cyber hygiene. Multi-factor authentication, endpoint protection, backups, patching and secure remote access are no longer optional operational extras. Insurers may ask detailed questions at application and renewal. Incorrect answers can put a claim at risk. More importantly, a business that has not implemented these controls is far easier to disrupt.
Be especially cautious with ransomware. Policies may provide access to specialist negotiators and cover certain response costs, but payment outcomes depend on the facts, insurer approval and legal constraints, including sanctions. The objective is not to fund a quick payment and hope for the best. It is to contain the incident, preserve evidence and get operations back under control.
How much cyber cover does an Australian SME need?
There is no sensible one-size-fits-all limit. A sole operator using cloud accounting and holding limited client information has a different exposure from a transport operator with a fleet management system, a medical practice holding sensitive records or an online retailer processing thousands of transactions.
Start with the cost of a bad week. Calculate the gross profit you would lose if systems were inaccessible, then add payroll, urgent IT recovery, replacement devices, legal advice and customer communications. Consider how much personal, financial or commercially sensitive data you retain and whether a supplier outage could halt your business. These figures give a more useful starting point than selecting the cheapest premium.
Also look beyond the overall policy limit. Sublimits can apply to cyber crime, business interruption, incident response, extortion and privacy notification. An apparently generous $1 million policy may have a much lower sublimit for the loss most likely to hit your operation. The excess, waiting period and aggregate limit matter too, particularly if multiple incidents occur in one policy year.
Questions to ask before you bind cover
A broker should push past the headline cover and pressure-test the wording against how your business actually operates. Before accepting a policy, get clear answers to these questions:
- Does it cover ransomware, data restoration and forensic investigation from the first dollar after the excess?
- Are invoice fraud, payment redirection and social engineering covered, and what verification controls must we follow?
- Does business interruption include outages at cloud providers, managed service providers or other critical suppliers?
- What privacy, legal defence and regulatory response costs are covered if customer or employee data is exposed?
- Are directors, employees, contractors and remote workers included when they cause or suffer a cyber incident?
- Which security controls are mandatory, and can we demonstrate that they are in place?
This is not paperwork for paperwork’s sake. It is claim preparation. The policy you can explain and evidence is more valuable than a cheap schedule sitting unread in a drawer.
What to do in the first hours after an attack
Speed matters, but so does discipline. Disconnect affected devices from the network if it is safe to do so, without wiping them or destroying evidence. Contact your IT provider and insurer’s incident response line immediately. Do not negotiate with an attacker, notify customers or make public statements before taking legal and forensic advice.
Preserve emails, screenshots, system logs and payment records. Change compromised credentials from a clean device, then check bank accounts and payment permissions if fraud is suspected. Where personal information may have been accessed, obligations under the Privacy Act and the Notifiable Data Breaches scheme may apply. Your response team can help assess whether notification to affected individuals and the Office of the Australian Information Commissioner is required.
The point is to protect people, contain financial damage and keep the claim on track. Improvised action can make a recoverable event much harder to manage.
Cyber insurance is only one part of the defence
Insurance transfers part of the financial risk. It cannot restore trust instantly, prevent every breach or replace sound controls. Keep offline or immutable backups, use multi-factor authentication across email and finance systems, restrict administrator access and train staff to challenge changed bank details. Test your response plan before you need it, especially if your business cannot trade without its software, mobile devices or connected equipment.
At Co-Pilot, the focus is on matching protection to the way your business earns, stores data and pays suppliers, then fighting for cover that stands up when pressure hits. Do not wait for the first suspicious email to find out what your policy means. Put the right cover and controls in place while you still have the time to choose them properly.
