Business Insurance
Cyber Liability
Insurance.
Cipher Insurance is a dedicated insurance broker helping Australian businesses arrange cyber liability cover. Here is what it covers, what it costs and how we work.
What It Is
The straightforward version.
Cyber liability insurance is designed to protect your business from the financial impact of a data breach, ransomware attack or other cyber incident. If something goes wrong with your systems or data, this is the cover designed to step in.
It generally covers two areas: your own costs following an incident such as forensic investigation, breach notification, data restoration and business interruption losses; and claims made against your business by customers, suppliers or other parties whose data or systems were affected. Cipher Insurance works with a panel of specialist cyber insurers to find cover suited to your business size, industry and risk profile.
Talk to a BrokerWhat It Covers
A standard cyber liability policy generally covers the following. Exact scope varies by policy and insurer.
Common Examples
Situations where cover may be required.
The following are some common examples of situations where businesses may hold cyber liability cover. This is not an exhaustive list and requirements depend on your specific circumstances.
You hold customer or employee data
If your business collects, stores or processes personal information about customers, patients, employees or other individuals, a data breach can trigger significant costs and obligations under Australia's Notifiable Data Breaches scheme and the Privacy Act 1988.
Your operations depend on digital systems
If your business depends on software, cloud platforms or connected systems, a ransomware attack, system outage or data loss event could prevent normal trading. Cyber liability cover can respond to the financial impact of those events.
You operate online or handle card payments
If your business transacts online, processes card payments or manages financial data, a payment breach or system compromise could result in third-party claims from customers or counterparties. Cyber liability cover is designed to respond to those claims.
Cost
What does cyber liability insurance cost in Australia?
Cyber liability premiums are primarily rated on the number of personal information (PII) records a business holds and the industry it operates in, alongside annual revenue and the security controls in place. Businesses holding a small number of records with strong security practices such as multi-factor authentication, endpoint protection and staff training can see premiums starting from as low as around $600 per year, while businesses holding larger volumes of sensitive data or operating in higher-risk industries generally pay more.
A ransomware event that prevents a business from trading for a period of days or weeks, combined with regulatory investigation costs and third-party claims, can result in total incident costs of hundreds of thousands to millions of dollars. The frequency and severity of ransomware incidents at Australian businesses across all industries has increased materially in recent years.
Every business is different. The only way to get an accurate figure is to talk through your specific business and cyber risk profile with us.
Get in TouchWhat drives your premium
Our insurer panel
We work with a panel of insurers for cyber liability cover including AIG, QBE, Chubb, Coalition and Keystone. If your business falls outside their standard market criteria, we have access to further insurers who can help.
Learn more about Cipher Insurance →How We Work
From enquiry
to settled claim.
Get in touch
Tell us about your business, the types of data you hold, the systems you rely on, your annual revenue and any cyber security measures you have in place.
We search the market
Cipher Insurance assesses your exposure and goes to our panel of insurers to identify suitable options on both coverage and price.
We bind your policy
Once you are happy with the terms, we arrange and bind the policy. Your Certificate of Currency is issued once payment is confirmed.
Ongoing support
We manage renewals, mid-term changes and any claims end-to-end throughout the life of your cover, from first notification through to resolution.
Common Questions
Questions people ask us.
Every business is different. These answers reflect general market practice. Speak with a Cipher Insurance broker for guidance specific to your situation.
Information last reviewed: July 2026
What is cyber liability insurance?
Cyber liability insurance is designed to respond to the financial consequences of a cyber incident, including data breaches, ransomware attacks and other malicious or accidental events involving digital systems or data. It generally has two components: first-party cover for the insured's own losses such as data restoration, business interruption and breach response costs, and third-party cover for claims made by customers, suppliers or other parties whose data or systems were affected by the incident.
What does cyber liability insurance not cover?
Cyber liability insurance does not typically cover losses arising from prior known incidents or vulnerabilities, fraudulent transfers resulting from social engineering where the insured was not directly deceived, physical property damage caused by a cyber event or losses that fall outside the specific coverage triggers in the policy. War and state-sponsored cyber attacks may be excluded under some policies, though market practice on this is evolving. Regulatory fines and penalties are only insurable to the extent permitted by Australian law. Each policy has its own exclusions and definitions and these should be reviewed carefully.
What is Australia's Notifiable Data Breaches scheme?
The Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 requires organisations covered by the Act to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when a data breach is likely to result in serious harm. Organisations covered by the Privacy Act include those with an annual turnover of $3 million or more, health service providers and certain other entities regardless of turnover. A failure to comply with the notification obligation can result in regulatory investigation and civil penalties. Cyber liability insurance typically covers the cost of breach response and notification as a first-party expense. This information is general in nature and does not constitute legal advice. If you are unsure whether your business has obligations under the Privacy Act or the NDB scheme, speak with a qualified legal professional.
Who needs cyber liability insurance in Australia?
Any business that holds personal information about customers, employees or other individuals, relies on digital systems to operate or processes electronic payments may have a cyber liability exposure. The Notifiable Data Breaches scheme creates specific legal obligations for businesses covered by the Privacy Act. Whether cyber liability cover is right for your business depends on the volume and sensitivity of data you hold, how much your operations depend on connected systems and your ability to absorb the financial impact of an incident. This information is general in nature and does not constitute legal advice. If you are unsure about your specific obligations under the Privacy Act, speak with a qualified legal professional.
Is cyber liability insurance mandatory in Australia?
Cyber liability insurance is not a statutory requirement for most Australian businesses. However, some government contracts, enterprise customer agreements and industry regulations may require you to hold a minimum level of cyber liability cover. The Australian Cyber Security Centre (ACSC) and several regulatory bodies have increasingly referenced cyber insurance in guidance materials as part of a broader cyber resilience posture. Whether cover is mandatory for your business depends on your contracts and regulatory obligations. This information is general in nature and does not constitute legal advice. If you are unsure whether any contract or regulation requires your business to hold cyber liability cover, speak with a qualified legal professional.
What is ransomware and does cyber insurance cover it?
Ransomware is a type of malicious software that encrypts a victim's files or systems and demands payment in exchange for the decryption key. It is one of the most common causes of cyber insurance claims globally and in Australia. A cyber liability policy typically covers ransom payment costs, negotiation costs, the cost of restoring or recovering data and business interruption losses sustained while systems are offline. Whether to pay a ransom is a decision that involves legal, ethical and practical considerations beyond the scope of insurance. Get in touch and we can walk you through what a specific policy covers and how a claim would work.
What is a first-party cyber insurance claim?
A first-party cyber insurance claim relates to the insured's own losses from a cyber incident, rather than claims made against the insured by third parties. First-party cyber cover typically responds to costs such as forensic investigation to identify the source and scope of the breach, notifying affected individuals and regulators, public relations and crisis management, restoring or replacing data and systems and the business interruption losses incurred while systems are offline. The specific first-party covers available vary by policy and should be reviewed against the business's actual exposure.
What is a third-party cyber insurance claim?
A third-party cyber insurance claim arises when a customer, supplier, business partner or other party makes a claim against the insured for loss or damage caused by a cyber incident. For example, a customer whose payment details were compromised in a data breach at a business may claim compensation for financial losses. A supplier whose systems were infected via the insured's network may claim for the cost of remediation. Third-party cyber liability cover addresses the cost of defending those claims and any damages or settlements that result.
How much does cyber liability insurance cost in Australia?
Cyber liability premiums are primarily rated on the number of personal information (PII) records a business holds and the industry it operates in, alongside annual revenue, the security controls in place and the limit of cover required. Businesses holding a small number of records with strong security controls such as multi-factor authentication, endpoint protection and staff training can see premiums starting from as low as around $600 per year, while businesses holding larger volumes of sensitive data or operating in higher-risk industries such as healthcare or financial services generally pay more. Every business is different. The only way to get an accurate figure is to talk through your specific situation with us.
How much can a cyber liability claim cost?
Cyber incident costs vary enormously depending on the size and nature of the business, the data affected and the type of incident. A small business data breach requiring individual notifications and some system remediation may involve tens of thousands of dollars. A ransomware event at a larger organisation that prevents trading for days or weeks while also triggering regulatory investigation and customer claims can run into millions of dollars. The Notifiable Data Breaches Annual Report consistently records incidents at Australian businesses across all industry sectors.
What is the difference between cyber liability and professional indemnity insurance?
Professional indemnity insurance responds to claims arising from professional errors, omissions or negligent acts in the delivery of professional services or advice. Cyber liability insurance responds to the financial consequences of a cyber incident involving data or digital systems. A professional services firm that suffers a data breach affecting client data may have both a cyber liability exposure (the cost of the breach response and potential claims from affected clients) and a professional indemnity exposure (if the breach was related to the handling of client information in the course of providing services). Whether one or both covers apply to a specific incident depends on the policy wordings.
What cyber security controls do insurers look for?
Insurers generally look for a range of baseline controls before offering cyber liability cover. Multi-factor authentication (MFA) on email and remote access systems is now considered a minimum requirement by most cyber insurers. Regular backups stored separately from the main network, up-to-date endpoint protection, patching and vulnerability management and staff awareness training are also commonly assessed. Some insurers conduct pre-binding security scans. If your business does not have basic controls in place, you may find it difficult to obtain cover or face significantly higher premiums.
What information do I need to get a cyber liability insurance quote?
Insurers typically require information about the nature of the business, the annual revenue, the types and volumes of data held, the security controls in place (including whether MFA is deployed), prior cyber incidents, any known vulnerabilities and the limit of cover required. When you get in touch, we will guide you through the proposal and make sure your risk is presented accurately to our insurer panel.
What should I do if I experience a cyber incident?
Notify us as soon as you become aware of a cyber incident. Most cyber policies have a panel of incident response specialists such as forensic investigators, legal advisers and public relations firms that can be engaged immediately. Do not attempt to remediate or restore systems without first consulting us, as doing so could compromise forensic evidence. If the incident involves personal information, consider your obligations under the Notifiable Data Breaches scheme. We will be actively involved throughout the response.
Can I get cyber liability insurance if I have been the subject of a prior cyber incident?
A prior cyber incident does not automatically prevent your business from obtaining cover, but it is likely to affect the terms and premium offered. Insurers will want to understand what happened, what remediation was undertaken and what controls are now in place. We have access to a wider range of insurers beyond the standard market. Get in touch and we will present your situation to our insurer panel in a way that gives them the context they need to make a fair assessment.
Related Covers
Other cover types to consider.
Professional Indemnity Insurance
Clear guidance on professional indemnity insurance for Australian businesses. What it covers, what it costs and when you may need it, arranged by a dedicated insurance broker.
Management Liability Insurance
Clear guidance on management liability insurance for Australian businesses and directors. What it covers, what it costs and when you may need it, arranged by a dedicated broker.
Business Pack Insurance
Clear guidance on business pack insurance for Australian SMBs. What it covers, what it costs and how we arrange the right sections for your business, by a dedicated broker.
General Advice Only
The information on this page is general in nature. It does not take into account your individual objectives, financial situation or specific needs and is not personal advice. Before acting on any of this information, consider whether it is appropriate for your circumstances and read the relevant Product Disclosure Statement before making any decision to purchase an insurance policy. If you need advice tailored to your situation, speak with a Cipher Insurance broker directly.
Read our Financial Services Guide →Start the conversation.
Tell us about your business and we will come back to you directly. No call centres, no automated responses, no waiting.
Taking card payments or holding customer data in a shop?See Store-Based Retailing →
Holding candidate and client personal information as a recruitment or HR consultant?See Recruitment & HR Consultants →
Holding borrower or investor financial data as a lender or fund manager?See Financial Institutions →
Holding access to client systems as an IT or technology consultant?See IT & Technology Consultants →
Managing a client's ad accounts or marketing platforms as an agency?See Marketing & Digital Consultants →