Cyber Insurance for SMEs: What You Need in 2026
Why Cyber Insurance Is No Longer Optional for Australian SMEs
In 2023-24, the Australian Signals Directorate (ASD) received over 87,400 cybercrime reports -- one every six minutes. The average cost of cybercrime for small businesses rose to over $49,600 per incident, according to the ASD Cyber Threat Report 2023-2024. For many SMEs, a single cyber incident can threaten the survival of the business itself.
Cyber insurance has moved from a "nice to have" to a critical component of business risk management. Yet many Australian SME owners remain unsure about what cyber insurance actually covers, what it costs, and whether they even qualify. This guide breaks it all down.
What Does Cyber Insurance Typically Cover?
Cyber insurance policies vary between providers, but most Australian policies cover two broad categories: first-party losses (costs you incur directly) and third-party liability (claims made against you by others).
First-Party Coverage
- Incident response costs: Forensic investigation, IT recovery, legal advice, and crisis management consultants. These costs alone can run $20,000-$100,000+ for a small business.
- Business interruption: Lost revenue while your systems are down. Policies typically cover the period from incident to restoration, subject to a waiting period (often 8-12 hours).
- Ransomware payments: Some policies cover ransom payments, though this is increasingly contentious and may require insurer approval before payment.
- Data restoration: Costs to recover or rebuild lost data from backups or from scratch.
- Notification costs: Under Australia's Notifiable Data Breaches (NDB) scheme, you must notify affected individuals and the OAIC. This gets expensive fast with printing, postage, and call centre costs.
- Credit monitoring: Providing affected customers with identity protection services.
Third-Party Coverage
- Privacy liability: Defence costs and settlements if customers or employees sue over a data breach.
- Regulatory fines and penalties: Coverage for fines from the OAIC or other regulators (where legally insurable).
- Media liability: Claims arising from defamation or IP infringement through your digital channels.
What Cyber Insurance Does NOT Cover
Understanding exclusions is just as important as understanding coverage. Common exclusions in Australian cyber policies include:
- Prior known incidents: Any breach or vulnerability you were aware of before the policy started.
- Unpatched systems: If you failed to apply a critical security patch within a reasonable timeframe (typically 30-60 days), your claim may be denied.
- Social engineering losses: Some policies exclude losses from business email compromise (BEC) unless you have specific "crime" or "social engineering" endorsements. Check our BEC protection guide for prevention strategies.
- Infrastructure failures: Outages caused by your internet provider or cloud platform (e.g., AWS or Azure going down) are usually excluded.
- War and terrorism: Nation-state attacks may be excluded under "war exclusion" clauses -- a grey area tested in courts globally.
- Bodily injury or property damage: Cyber insurance covers digital losses, not physical ones.
How to Qualify: Minimum Security Requirements
Here is where many SMEs get caught out. Insurers in 2026 are far more rigorous about underwriting than they were even two years ago. Most Australian cyber insurers now require evidence of baseline security controls before they will offer coverage -- or at least before they will offer affordable premiums.
Common requirements include:
- Multi-factor authentication (MFA) on all remote access, email, and admin accounts. This is almost universally required. See our MFA setup guide for step-by-step instructions.
- Regular backups following the 3-2-1 rule (3 copies, 2 media types, 1 offsite), with tested recovery procedures.
- Endpoint protection: Up-to-date antivirus/EDR on all devices.
- Email filtering: Anti-phishing and anti-spam controls on business email.
- Patch management: A documented process for applying critical patches within 14-30 days.
- Employee training: Evidence of cyber awareness training for staff, at least annually.
- Incident response plan: A documented plan for how you will respond to a cyber incident.
Pro tip: If you cannot tick these boxes, do not assume you cannot get insurance. Some brokers specialise in helping SMEs improve their security posture to meet underwriting requirements. Getting these controls in place also reduces your risk -- which is the whole point.
Notably, the governance and risk management practices that insurers look for -- documented policies, regular reviews, evidence of compliance -- all fall under what the IDIA framework calls the Assurance pillar. IDIA organises every cybersecurity control into four pillars (Identity, Data, Infrastructure, Assurance), and it is the Assurance pillar that ensures you can demonstrate your security posture to underwriters, not just implement it. If you can show an insurer a structured approach to governance and continuous improvement, you are far more likely to secure favourable terms.
What Does Cyber Insurance Cost for Australian SMEs?
Premiums vary significantly based on your industry, revenue, data holdings, and security maturity. As a rough guide for Australian SMEs in 2026:
| Business Size | Annual Revenue | Typical Annual Premium | Typical Coverage Limit |
|---|---|---|---|
| Sole trader / micro | Under $500K | $800 - $2,000 | $250K - $500K |
| Small business | $500K - $5M | $2,000 - $7,000 | $500K - $2M |
| Medium business | $5M - $50M | $5,000 - $25,000 | $1M - $10M |
Compare these premiums to the average cost of a cyber attack on an Australian small business -- the maths speaks for itself.
How to Compare Cyber Insurance Policies
Not all policies are created equal. When comparing quotes, focus on these key factors:
- Coverage limits and sub-limits: Check whether business interruption, ransomware, and notification costs have separate sub-limits that are lower than the headline cover amount.
- Waiting periods: For business interruption, how many hours must pass before coverage kicks in? Shorter is better.
- Retroactive date: Does the policy cover incidents that occurred before the policy start date but were discovered during the policy period? Look for "unlimited retroactive date" or the earliest date possible.
- Incident response panel: Many policies include access to a pre-approved panel of forensic investigators, lawyers, and PR firms. Check who is on the panel and whether you can choose your own providers.
- Social engineering cover: Is BEC and invoice fraud included, or does it require an add-on? What is the sub-limit?
- Excess (deductible): What is your out-of-pocket before the insurer pays? Typical excesses range from $1,000 to $10,000 for SMEs.
- Regulatory coverage territory: Ensure the policy covers Australian regulatory actions (OAIC, state regulators) and not just US/EU regulations.
Cyber Insurance Is Not a Substitute for Cyber Security
This is the most important point in this entire guide. Cyber insurance is a financial safety net -- it helps you recover from an incident. It does not prevent incidents from happening. The ASD's Essential Eight framework, good staff training, and a solid incident response plan are your frontline defences.
Think of it like car insurance: you still need to drive carefully, maintain your brakes, and wear your seatbelt. Insurance is there for when things go wrong despite your best efforts.
Next Steps
If you are considering cyber insurance -- or if your renewal is coming up -- start by understanding your current security posture. Platforms like How's My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard -- including the ones your insurer cares about most. Start with the free CYBER9 assessment to benchmark your business across nine critical domains in under 10 minutes. The results give you a clear, jargon-free snapshot you can take straight to your broker -- potentially securing better coverage at a lower premium.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free