Cipher Insurance
Running a business · Guide

What Does Cyber Liability Insurance Not Cover?

Cyber liability cover has real limits. Ransomware is usually covered, but social engineering fraud and physical hardware damage often aren't, unless you've specifically added them.

Jack O'Hagan

By Jack O'Hagan, Co-Founder & Insurance Broker

Published 27 July 2026 · 4 min read

In this guide
  1. Does cyber insurance cover social engineering or invoice fraud?
  2. Does cyber insurance cover ransomware payments?
  3. Is a cyber attack excluded as an act of war?
  4. Does cyber liability insurance cover physical damage to hardware?
  5. Is a data breach I already knew about covered?
  6. Are regulatory fines and penalties covered?
  7. Footnotes

Cyber liability insurance covers a lot, but not everything. Standard policies commonly exclude physical damage to your hardware, incidents you already knew about before taking out cover and social engineering fraud unless you’ve specifically added it. The exact list varies by insurer, so the policy wording is what actually decides a claim, not the product name.1

Prior known incidents

A vulnerability or incident you knew about but didn't disclose is treated like non-disclosure on any policy.

Physical hardware damage

Cyber cover responds to data and systems, not the physical device itself.

Social engineering fraud

Often excluded or sub-limited unless you've added a specific extension.

Does cyber insurance cover social engineering or invoice fraud?

Not always, and this is one of the more common gaps businesses discover after the fact. Social engineering fraud happens when a scammer tricks a staff member into making a payment or sharing access, rather than breaching a system directly, for example a fake invoice from what looks like a regular supplier. Many standard cyber policies exclude this outright or cap it well below the main limit. Cover is often available as a specific extension, but it has to be requested and priced on its own.

Does cyber insurance cover ransomware payments?

Generally yes. Cyber extortion and ransomware response, including negotiation and payment costs where legally permitted, are core parts of most cyber liability policies, not an add-on.2 Whether to actually pay a ransom is a different question again. It involves legal, ethical and practical considerations that sit outside what any insurance policy decides.

The exclusions schedule is what actually decides a claim. It's worth reading before the coverage summary, not after something happens.

Is a cyber attack excluded as an act of war?

Often, though the wording here matters more than in almost any other exclusion. Most cyber policies exclude broad acts of war, but many carve back a narrower cyber terrorism definition that stays covered. Whether a specific large-scale or state-linked attack falls inside or outside that carve-back depends entirely on the individual policy’s definitions. It’s an area insurers have been actively rewriting in recent years.

Does cyber liability insurance cover physical damage to hardware?

No, generally not. Cyber liability cover is built to respond to data, systems and the financial fallout of an incident. It isn’t designed to replace a damaged laptop, server or point-of-sale terminal. That’s usually the role of a separate policy, such as electronic equipment insurance or a business pack.

Is a data breach I already knew about covered?

No. Cover is priced against the risk profile disclosed when the policy was arranged.3 An incident or vulnerability you already knew about but didn’t disclose is treated the same way non-disclosure is treated on any other insurance policy. It generally falls outside what the policy will respond to.

Are regulatory fines and penalties covered?

Only to the extent Australian law allows. The costs of a regulatory investigation following a breach, including legal advice and the process of responding to the regulator, are commonly covered as a standard part of cyber liability policies. The fines and civil penalties themselves are a different matter. Those are only insurable where the law permits it. What’s actually insurable varies depending on which regulator and which penalty is involved. It’s worth checking specifically if your business is covered by the Notifiable Data Breaches scheme, since a serious breach can trigger both an investigation and a possible penalty at the same time.

  • Ransomware and cyber extortion are usually covered as standard, not an add-on.
  • Social engineering and invoice fraud are commonly excluded or sub-limited unless specifically added.
  • Physical damage to hardware generally isn't a cyber liability claim, it's a job for electronic equipment or business pack cover.
  • An incident or vulnerability you already knew about but didn't disclose generally falls outside cover.
  • Regulatory investigation costs are commonly covered, but fines and penalties are only insurable where Australian law permits it.
  • Exact exclusions vary by insurer. The policy wording, not the product name, is what actually decides a claim.

If a gap like this is sitting between your cyber liability cover and another policy, such as professional indemnity or your equipment cover, Cipher can review them together rather than in isolation. Get in touch.

The information in this article is general in nature and does not constitute legal, financial or insurance advice. Please speak with a qualified adviser about your specific circumstances.

Footnotes

  1. Insurance explained, Insurance Council of Australia

  2. Cyber liability insurance, business.gov.au

  3. Protect your customers’ information, business.gov.au

Not sure how this applies to your situation?

Frequently asked questions

What does cyber liability insurance not cover?

Standard cyber liability policies commonly exclude incidents you already knew about before taking out cover, physical damage to hardware and losses from social engineering fraud unless you've specifically added that cover. Exact exclusions vary by insurer, so the policy wording is what actually decides a claim, not the product name.

Does cyber insurance cover social engineering or invoice fraud?

Not always by default. Many standard cyber policies exclude or place a lower sub-limit on social engineering and invoice fraud losses, where a scammer tricks someone into transferring funds rather than breaching a system directly. Cover for this is often available as a specific extension, but it needs to be requested and priced separately.

Does cyber insurance cover ransomware payments?

Generally yes. Cyber extortion and ransomware are core parts of most cyber liability policies, including negotiation and payment costs where legally permitted. Whether to actually pay a ransom is a separate decision involving legal, ethical and practical considerations beyond what any insurance policy covers.

Is a cyber attack excluded as an act of war?

Often, though the exact wording matters a great deal here. Most cyber policies exclude broad acts of war, but many carve back a narrower definition of cyber terrorism that stays covered. Whether a specific large-scale or state-linked attack falls on one side of that line or the other depends entirely on the policy wording and is an active area of change across the market.

Does cyber liability insurance cover physical damage to my computers or servers?

No, generally not. Cyber liability cover responds to data, systems and the financial fallout of an incident, not the physical hardware itself. Physical damage to computers, servers or other equipment is usually a job for a separate policy, such as electronic equipment or business pack insurance.

Is a data breach I already knew about covered?

No. Cover is priced against the risk profile disclosed when the policy was arranged, so an incident or vulnerability you already knew about but didn't disclose is treated the same way undisclosed information is treated on any other insurance policy. It generally falls outside what the policy responds to.

What covers a cyber-related loss if my cyber liability policy excludes it?

It depends on the exclusion. Physical hardware damage is usually a job for electronic equipment or business pack cover. A professional error connected to how client data was handled may sit with professional indemnity instead. Reviewing these policies together, rather than cyber liability in isolation, is the best way to avoid a gap sitting between two products.

Are regulatory fines and penalties covered by cyber liability insurance?

Only to the extent Australian law allows. The costs of a regulatory investigation following a breach are commonly covered, but the fines and civil penalties themselves are only insurable where the law permits it. What's actually insurable varies depending on which regulator and which penalty is involved. This is worth checking specifically if your business is covered by the Notifiable Data Breaches scheme, since a serious breach can trigger both an investigation and a possible penalty.

Keep reading

Where this guide fits

Business Insurance

This guide sits alongside our Business Insurance cover pages.

Browse Business Insurance

Written by

Jack O'Hagan

Jack O'Hagan

Co-Founder & Insurance Broker

Jack spent 6+ years across law, finance and insurance, seeing the impact insurance can have on the growth of a business. With a strong focus on advocacy, he firmly believes insurance broking does not stop after the policy has been placed. It continues when a claim is lodged. He co-founded Cipher Insurance to help Australian businesses get the right broker experience.