Skip links
Green code streaming down a dark screen, the data breach risk cyber insurance covers
Business Insurance

Cyber Insurance

Cyber insurance for data breaches, ransomware and other digital threats, so your business keeps trading and recovers its costs.

What Cyber Insurance Covers

Cyber insurance protects your business against the financial loss, legal liability and operational disruption that follow a cyber attack, data breach, ransomware incident or system failure.

Australian businesses of every size now depend on digital systems, cloud platforms and online payments, so cyber risk is no longer a concern for large corporations alone. A well-structured cyber policy funds the response to an incident and protects cash flow, reputation and regulatory standing while systems are restored.

If you store customer data, take payments online or rely on IT systems to trade, cyber insurance belongs alongside your core business insurance. It also complements management liability insurance, because directors can be held accountable for how a breach is handled. It sits within our business insurance range at Fortis Risk Solutions.

Cyber Insurance: Cover Sections and Benefits

What Cyber Insurance does not cover

Cyber insurance responds to incidents, not to the state of your systems before one. Most policies exclude losses that come from problems you already knew about or from basic controls that were never in place. Common exclusions include:

  • Breaches that began before the policy started, or incidents you knew about and did not disclose
  • Losses caused by software that was out of support or patches that were left uninstalled after a warning
  • Fines and penalties where the law does not allow them to be insured
  • Bodily injury and property damage, which belong to public liability or property cover
  • Loss of future contracts or reputation beyond the defined business interruption period
  • Funds transfer fraud where the policy has no social engineering extension
  • Infrastructure failure outside your control, such as a telecommunications outage, unless specifically included

FRS reads the exclusions against how your business actually operates, so a gap such as an unpatched server or an outsourced IT provider is dealt with before renewal rather than at claim time.

How Cyber Insurance premiums are set

Insurers price cyber insurance on the questions they ask in the proposal, and the answers matter more than turnover alone. The main factors are:

  • The volume and type of personal or payment data you hold, and whether cardholder data is stored or only processed
  • Multi-factor authentication on email and remote access, which many insurers now treat as a minimum condition
  • Backup practice: how often, whether copies are kept offline, and whether restores have been tested
  • Industry and exposure, such as healthcare records, legal files or online payments
  • Claims history and any prior incident, including near misses
  • The limit of liability and the excess chosen
  • Whether staff receive phishing awareness training

Answering these accurately is the fastest way to a fair premium. FRS prepares the proposal with you so the security position is stated correctly and the insurer has no grounds to dispute a claim later.

How to claim on Cyber Insurance

Speed decides the outcome of a cyber claim. Most policies give you access to an incident response team, and the clock on notification obligations starts when you become aware of a breach. The FRS claims process:

  1. Call FRS, or the insurer’s incident response line outside business hours, as soon as you suspect a breach, before restoring systems where you safely can
  2. Preserve evidence: logs, affected devices and the phishing email if there was one
  3. Do not pay a ransom or contact the attacker without the insurer’s response team involved
  4. FRS lodges the claim, briefs the insurer’s forensic and legal panel and keeps the notification timeline on track
  5. Costs for restoration, notification and lost income are documented and submitted
  6. Settlement is negotiated and the security lessons are written into the next renewal

The steps and contact details are also set out on our make a claim page.

Cyber Insurance compared with Professional Indemnity

QuestionCyber InsuranceProfessional Indemnity
What triggers itA breach, attack or system failure in your own systemsA client claims your advice or service caused them loss
Who it paysYour own response costs, lost income and third-party claims from the breachCompensation and defence costs for the client’s loss
Who buys itAny business holding data or trading onlineFirms that give advice, design or manage projects
Sits withBusiness pack and management liabilityPublic liability and management liability

Advice firms usually hold both. A breach that exposes client files can trigger the cyber policy for the response and the professional indemnity policy if a client then sues over the advice or the confidentiality breach.

Cyber Insurance FAQs

Yes. Small and medium-sized businesses are frequent targets because they rarely have dedicated IT security staff. An incident can mean days of downtime, a ransom demand and, for many businesses, notification obligations under Australia's Notifiable Data Breaches scheme, whatever the size of the company.

Yes, provided the policy specifically includes cyber fraud or funds transfer loss cover. Not every policy does, which is why we check the wording rather than the headline premium.

Cyber policies differ widely in what triggers a claim, which costs are covered and how the incident response is managed. As your broker, FRS helps you disclose your systems and data accurately, structure limits that match your exposure, compare specialist cyber insurers and coordinate the response if an incident occurs. Firms that give advice should also check how this cover sits beside their professional indemnity insurance.

Related reading

Explore
Drag