Personal Insurance
Business Insurance
- Business Insurance
- Industrial Special Risk (ISR) Insurance
- Commercial Property Owner Insurance
- Business Interruption Insurance
- Public Liability Insurance
- Professional Indemnity Insurance
- Management Liability Insurance
- Contract Works/Construction Insurance
- Marine Insurance
- Cyber Insurance
- Commercial Motor Insurance
- Faith & Not-for-Profit Organisations Insurance
Industry Insurance
Business Insurance
Cyber Insurance
Cyber insurance for data breaches, ransomware and other digital threats, so your business keeps trading and recovers its costs.
What Cyber Insurance Covers
Cyber insurance protects your business against the financial loss, legal liability and operational disruption that follow a cyber attack, data breach, ransomware incident or system failure.
Australian businesses of every size now depend on digital systems, cloud platforms and online payments, so cyber risk is no longer a concern for large corporations alone. A well-structured cyber policy funds the response to an incident and protects cash flow, reputation and regulatory standing while systems are restored.
If you store customer data, take payments online or rely on IT systems to trade, cyber insurance belongs alongside your core business insurance. It also complements management liability insurance, because directors can be held accountable for how a breach is handled. It sits within our business insurance range at Fortis Risk Solutions.
Cyber Insurance: Cover Sections and Benefits
What Cyber Insurance does not cover
Cyber insurance responds to incidents, not to the state of your systems before one. Most policies exclude losses that come from problems you already knew about or from basic controls that were never in place. Common exclusions include:
- Breaches that began before the policy started, or incidents you knew about and did not disclose
- Losses caused by software that was out of support or patches that were left uninstalled after a warning
- Fines and penalties where the law does not allow them to be insured
- Bodily injury and property damage, which belong to public liability or property cover
- Loss of future contracts or reputation beyond the defined business interruption period
- Funds transfer fraud where the policy has no social engineering extension
- Infrastructure failure outside your control, such as a telecommunications outage, unless specifically included
FRS reads the exclusions against how your business actually operates, so a gap such as an unpatched server or an outsourced IT provider is dealt with before renewal rather than at claim time.
How Cyber Insurance premiums are set
Insurers price cyber insurance on the questions they ask in the proposal, and the answers matter more than turnover alone. The main factors are:
- The volume and type of personal or payment data you hold, and whether cardholder data is stored or only processed
- Multi-factor authentication on email and remote access, which many insurers now treat as a minimum condition
- Backup practice: how often, whether copies are kept offline, and whether restores have been tested
- Industry and exposure, such as healthcare records, legal files or online payments
- Claims history and any prior incident, including near misses
- The limit of liability and the excess chosen
- Whether staff receive phishing awareness training
Answering these accurately is the fastest way to a fair premium. FRS prepares the proposal with you so the security position is stated correctly and the insurer has no grounds to dispute a claim later.
How to claim on Cyber Insurance
Speed decides the outcome of a cyber claim. Most policies give you access to an incident response team, and the clock on notification obligations starts when you become aware of a breach. The FRS claims process:
- Call FRS, or the insurer’s incident response line outside business hours, as soon as you suspect a breach, before restoring systems where you safely can
- Preserve evidence: logs, affected devices and the phishing email if there was one
- Do not pay a ransom or contact the attacker without the insurer’s response team involved
- FRS lodges the claim, briefs the insurer’s forensic and legal panel and keeps the notification timeline on track
- Costs for restoration, notification and lost income are documented and submitted
- Settlement is negotiated and the security lessons are written into the next renewal
The steps and contact details are also set out on our make a claim page.
Cyber Insurance compared with Professional Indemnity
| Question | Cyber Insurance | Professional Indemnity |
|---|---|---|
| What triggers it | A breach, attack or system failure in your own systems | A client claims your advice or service caused them loss |
| Who it pays | Your own response costs, lost income and third-party claims from the breach | Compensation and defence costs for the client’s loss |
| Who buys it | Any business holding data or trading online | Firms that give advice, design or manage projects |
| Sits with | Business pack and management liability | Public liability and management liability |
Advice firms usually hold both. A breach that exposes client files can trigger the cyber policy for the response and the professional indemnity policy if a client then sues over the advice or the confidentiality breach.
Cyber Insurance FAQs
Yes. Small and medium-sized businesses are frequent targets because they rarely have dedicated IT security staff. An incident can mean days of downtime, a ransom demand and, for many businesses, notification obligations under Australia's Notifiable Data Breaches scheme, whatever the size of the company.
Yes, provided the policy specifically includes cyber fraud or funds transfer loss cover. Not every policy does, which is why we check the wording rather than the headline premium.
Cyber policies differ widely in what triggers a claim, which costs are covered and how the incident response is managed. As your broker, FRS helps you disclose your systems and data accurately, structure limits that match your exposure, compare specialist cyber insurers and coordinate the response if an incident occurs. Firms that give advice should also check how this cover sits beside their professional indemnity insurance.