All insights
Cyber Risk & Strategy May 28, 2026 7 min read

Cyber Insurance: What It Covers and What It Won’t

Cyber insurance has moved from a niche product to a board-level discussion in just a few years, driven by the rising frequency and cost of incidents, particularly ransomware. Used well, it transfers some of the financial shock of a breach and gives you access to expert help when you most need it. Misunderstood, it becomes an expensive source of false comfort that fails at the worst possible moment, when a claim is denied because of something in the fine print.

This guide explains what cyber insurance actually covers, what it commonly excludes, what underwriters now demand, and how to make sure a policy pays out when you need it.

What cyber insurance typically covers

Cyber policies generally split into first-party cover, for your own losses, and third-party cover, for claims others make against you. The specifics vary considerably between insurers, but the common elements are reasonably consistent.

First-party cover usually includes incident response and forensic investigation to determine what happened and contain it; data recovery and system restoration; business interruption losses while you are unable to operate; cyber extortion and, where lawful, ransom payments; and the costs of notifying affected individuals and regulators. Many insurers provide access to a panel of specialists, lawyers, forensic firms and public-relations advisers, which for smaller organisations can be as valuable as the financial cover itself.

Third-party cover responds to claims arising from a breach: liability to customers or partners whose data was exposed, regulatory investigations and defence costs, and in some cases media liability. Given the strengthening of Australian privacy penalties and the Notifiable Data Breaches regime, this exposure is significant.

What it commonly excludes

The exclusions are where many organisations come unstuck, because they assume cover is broader than it is. While wordings differ, several exclusions appear frequently.

  • War and state-sponsored attacks. War exclusions, increasingly relevant given attribution of major attacks to nation states, can be used to deny claims. The scope of these clauses has been a contested area, so the precise wording matters.
  • Prior known incidents. Anything you were aware of before the policy began is typically excluded.
  • Failure to maintain controls. If you attested to certain security measures and did not actually have them in place, the insurer may decline.
  • Uninsurable fines. Some regulatory penalties cannot be insured as a matter of law.
  • Infrastructure and third-party failures. Outages of utilities or upstream providers outside your control may be excluded or sub-limited.
  • Unencrypted data. Some policies reduce or exclude cover for breaches of data that was not encrypted.

The lesson is simple: read the exclusions as carefully as the cover, and ideally have a broker or adviser who understands cyber risk interpret them for you.

The underwriting requirements have tightened

A few years ago, cyber cover was relatively easy to obtain. After a wave of costly ransomware claims, insurers tightened dramatically. Today, obtaining cover, and obtaining it at a reasonable price, depends on demonstrating a baseline of security controls. Common requirements now include:

  • Multi-factor authentication on remote access, email and privileged accounts.
  • Tested, segregated backups, ideally with an offline or immutable copy.
  • Endpoint detection and response on devices.
  • A disciplined patching programme for applications and operating systems.
  • Email filtering and protection against phishing.
  • Security awareness training for staff.
  • A documented and tested incident response plan.

These map closely to the Essential Eight, which is one reason maturing against that framework also improves your insurability and can reduce premiums. Our Essential Eight guide sets out those controls in detail. The proposal form you complete is not a formality; it is a representation the insurer relies on, and inaccuracies can void cover.

Why claims get denied

The most painful outcome is paying premiums for years and then having a claim refused. The common causes are avoidable.

The first is misrepresentation during underwriting: stating you had MFA everywhere or tested backups when you did not. If a breach exploits the very gap you misrepresented, the insurer has strong grounds to decline. The second is failing to maintain the controls you attested to; a control that lapsed after the policy was issued can be just as fatal to a claim. The third is failing to follow the policy’s conditions during an incident, particularly the requirement to notify the insurer promptly and to use their approved response providers. Engaging your own forensic firm before calling the insurer can jeopardise cover.

The defence against all of these is honesty at underwriting, discipline in maintaining controls, and a clear internal understanding of exactly what your policy requires you to do when an incident occurs.

Understanding the key policy terms

Cyber policies are full of terms that materially affect what you actually receive, and it pays to understand them before you sign rather than during a crisis.

  • Limits and sub-limits. The overall policy limit is the maximum payout, but individual cover types, such as social-engineering fraud, ransom payments or regulatory defence, often carry lower sub-limits. A headline limit can mask thin cover where you need it most.
  • Retention or deductible. The amount you bear before cover responds. A higher retention lowers premiums but increases your out-of-pocket exposure per incident.
  • Waiting period. For business interruption, there is usually a waiting period, often measured in hours, before lost income is covered. Short outages may fall entirely within it.
  • Claims-made basis. Most cyber policies cover claims made during the policy period, which makes continuity of cover and the retroactive date important. Gaps in cover can leave incidents unclaimable.
  • Panel providers. The insurer’s pre-approved lawyers, forensic and PR firms you are generally required to use. Knowing who they are in advance avoids friction during an incident.

Comparing two policies on price alone is meaningless without comparing these terms. A cheaper policy with restrictive sub-limits and a long waiting period may offer far less real protection than a slightly dearer one.

Cyber insurance and your regulatory obligations

Insurance does not discharge your legal duties; it sits alongside them. If you suffer an eligible data breach, you must still meet your Notifiable Data Breaches obligations to assess and report, regardless of what your policy covers. Regulated entities have additional duties: APRA-regulated organisations must notify APRA of material information security incidents under CPS 234, and that obligation is independent of any insurance claim. Critical infrastructure entities have their own mandatory reporting timeframes. Your incident response plan must therefore satisfy both your insurer’s notification requirements and your regulatory ones, which can run on different clocks. Our CPS 234 explainer covers the regulatory notification expectations that operate in parallel with any policy. Treating insurance as a substitute for compliance is a serious misunderstanding; the two are separate obligations that you manage together.

How to buy well

Treat cyber insurance as one component of a risk-management strategy, not a substitute for security. A few practical steps make a real difference.

  1. Understand your exposure first. Know what data you hold and what an incident would actually cost you, so you can size cover sensibly rather than guessing.
  2. Strengthen controls before you apply. Better security means better terms, lower premiums and a more defensible claim. The investment often pays for itself.
  3. Answer the proposal accurately. Involve the people who actually know your environment, and never overstate your posture.
  4. Scrutinise the wording. Compare cover, sub-limits, exclusions and waiting periods, not just headline price.
  5. Plan for the claim now. Make sure your incident response plan reflects your policy’s notification and approved-provider requirements.

Insurance is a backstop, not a strategy

Cyber insurance can soften the financial blow of an incident and provide expert help when you are under pressure, and for most organisations it is worth carrying. But it does not stop attacks, it does not restore lost trust, and it pays only when you have met your obligations. The organisations that get the most from it are those that invest in strong controls first, then use insurance to transfer the residual risk they cannot eliminate.

CISO Advisory helps Australian organisations improve their security posture to meet underwriting requirements, interpret policy wordings, and align their incident response with their cover. If you want to make sure your controls and your policy actually fit together, explore our Virtual CISO service and cyber due diligence support, or call 07 2112 8502.

Frequently asked questions

What does cyber insurance typically cover?

Most policies cover first-party costs such as incident response, forensics, data recovery, business interruption losses, ransom payments where lawful, and notification costs, plus third-party liability for claims by affected customers and regulatory defence. Coverage varies significantly between insurers, so the policy wording matters more than the headline category.

What does cyber insurance usually exclude?

Common exclusions include acts of war and certain state-sponsored attacks, prior known incidents, failure to maintain represented security controls, unencrypted data in some policies, infrastructure failures outside your control, and fines that are uninsurable by law. Reading the exclusions carefully is as important as reading what is covered.

Can an insurer deny my claim?

Yes. Claims are most often disputed when the insured misrepresented their security posture during underwriting, failed to maintain controls they attested to, or did not follow the policy's incident notification and response requirements. Accurate proposal answers and adherence to policy conditions are essential to a payable claim.

What security controls do underwriters require?

Underwriters now commonly require multi-factor authentication on remote access and privileged accounts, tested and segregated backups, endpoint detection and response, prompt patching, email filtering, security awareness training and an incident response plan. Without these baseline controls, cover may be unavailable, restricted or far more expensive.

Is cyber insurance worth it?

For most organisations, yes, as part of a broader risk strategy rather than a substitute for controls. Insurance transfers some financial impact and often provides valuable incident response support, but it does not prevent breaches or protect reputation. It works best alongside strong security, not instead of it.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act