Cyber insurance was once something only large enterprises thought about. In 2026, it is a standard part of commercial insurance for any Australian business that handles client data, processes payments online, or depends on IT systems for operations. And it has changed dramatically.
Policies that were renewed automatically a few years ago are now subject to detailed security questionnaires. Coverage that was once broad now carries specific exclusions for incidents where basic controls were not in place. And premiums have risen significantly as the insurance industry has processed years of large ransomware claims.
This guide explains what Australian cyber insurers now require, what exclusions you need to know about, and how your IT environment affects both your ability to get cover and the cost.
What Does Cyber Insurance Cover?
A standard cyber insurance policy for an Australian SMB typically covers some or all of:
- Incident response costs — forensic investigation, legal advice, and crisis management fees following a breach
- Business interruption losses — revenue lost during system downtime caused by a cyber incident
- Ransomware payments — ransom demands (subject to legal review and insurer approval)
- Data breach notification costs — OAIC notification, affected individual notifications, credit monitoring
- Third-party liability — if a breach exposes client data, defence costs and settlements in claims against your business
- Cyber crime losses — Business Email Compromise, social engineering fraud (often as a sublimit)
What Do Australian Cyber Insurers Now Require?
The security questionnaire you complete at renewal is effectively an audit of your IT controls. The following questions appear consistently across Australian cyber insurance applications in 2026:
| Control | Insurer Requirement | Risk if Not in Place |
|---|---|---|
| Multi-Factor Authentication | MFA on email, remote access, and privileged accounts | Coverage denial or exclusion for credential-based incidents |
| Endpoint Protection | EDR on all endpoints (not just basic AV) | Higher premiums or sublimits on malware claims |
| Backup | Offline/immutable backups, tested regularly | Ransomware coverage may be void or sublimited |
| Patch Management | Defined patching process with SLAs for critical patches | Exclusion for incidents exploiting known vulnerabilities |
| Email Security | Anti-phishing, DMARC, spam filtering | BEC fraud sublimits or exclusions |
| Staff Training | Annual security awareness training | Higher risk loading; social engineering exclusions |
What Are the Most Common Cyber Insurance Exclusions?
Exclusions are the clauses that allow an insurer to deny a claim after an incident. The most important ones for Australian SMBs to understand are:
- "Failure to maintain security controls" exclusion — if the insurer asked whether MFA was in place and you said yes, but a breach occurs because MFA was not actually enforced, the claim can be denied on the basis of misrepresentation
- Known vulnerability exclusion — some policies exclude incidents that exploit a publicly known, unpatched vulnerability if the patch was available for more than a defined period (often 30 days)
- Unsupported systems exclusion — incidents on devices running end-of-life operating systems (Windows 10 after October 2025, Windows Server 2012, etc.) may be excluded
- Social engineering sublimits — Business Email Compromise and deepfake fraud losses are often covered at a sublimit (e.g., $100,000 within a $1 million policy) rather than full policy limits
- War and nation-state exclusion — incidents attributed to state-sponsored actors are typically excluded
How to Ensure Your Business Qualifies for Meaningful Coverage
The most important steps to qualify for comprehensive cyber coverage at a competitive premium are:
- Enforce MFA everywhere — not just on some systems. Email, remote desktop, privileged accounts, and any cloud platform must have MFA enabled and enforced, not just available
- Deploy EDR, not just antivirus — basic antivirus is no longer sufficient evidence of endpoint security for most insurers
- Implement immutable backup — backup must be stored in a way that ransomware cannot delete it; offline or immutable cloud storage qualifies
- Eliminate end-of-life systems — remove or isolate unsupported operating systems before your next renewal
- Document your security controls — being able to show your insurer evidence (screenshots, reports from your MSP's monitoring platform) of controls in place is increasingly important at renewal
- Work with an MSP who can provide attestation — some insurers now accept or request a letter from your managed IT provider confirming the security controls that are in place
Cyber Insurance Readiness Support — Gold Coast and Brisbane
Xen Technologies helps Gold Coast and Brisbane businesses implement the security controls that cyber insurers now require, and can provide documentation of your security posture to support your renewal. We assess your current environment, identify gaps against insurer requirements, and implement the controls through our managed IT and cybersecurity services. Contact us at (07) 5619 6555.
Frequently Asked Questions
What do Australian cyber insurers require in 2026?
Cyber insurers in Australia now consistently require: MFA on email and all remote access; EDR on all endpoints; offline or immutable backup that is tested regularly; patch management with defined SLAs for critical patches; email security (anti-phishing, DMARC); annual staff security awareness training; and an incident response plan. Businesses that cannot demonstrate these controls face coverage exclusions, premium loading, or policy denial.
Does cyber insurance cover ransomware attacks in Australia?
Cyber insurance can cover ransomware, but coverage is contingent on having the required security controls in place at the time of the incident. Many policies include exclusions for ransomware incidents where basic controls — particularly MFA and up-to-date patching — were absent. Policies typically cover ransom payments, incident response costs, business interruption, and data breach notification. Always read your exclusion clauses carefully before a claim.
How much does cyber insurance cost for a small business in Australia?
For a 10–50 employee professional services firm with reasonable security controls in place, cyber insurance premiums typically range from $2,000–$8,000 AUD annually for $1–2 million in coverage. Premiums vary significantly based on industry, revenue, data sensitivity, and demonstrable security controls. Businesses with strong controls (MFA, EDR, tested backup) typically qualify for lower premiums and higher limits.
Can my MSP help me qualify for cyber insurance?
Yes. A good MSP can implement the security controls that cyber insurers require, maintain evidence of those controls, and provide documentation to support your renewal. Some Australian insurers now accept a letter from your managed IT provider attesting to the controls in place. Xen Technologies can provide this documentation for clients as part of our managed security services.