Security2026-08-26·7 min read

Do I need cyber insurance for my small business?

Often yes - invoice fraud is the loss most likely to hit a small business, and insurance can cover it. But insurers expect the basics first, and the exclusions matter.

For most Australian small businesses, cyber insurance can be worth the premium - but only once you understand what it does and does not do:

  • The real risk is invoice fraud - the loss most likely to hit a 1-30 staff business is a redirected supplier payment or fake invoice, and good policies can reimburse it.
  • Controls come before cover - insurers now expect MFA, tested backups, and patching in place before they will quote or pay; no controls can mean no payout.
  • The exclusions decide the value - social-engineering and business email compromise cover is often a separate, much smaller sub-limit, so the brochure number isn’t the number you can claim.
  • Insurance is a backstop, not a substitute - a policy pays out after an attack, sometimes; it never replaces doing the basic security work first.

Do the basics, then buy the cover - in that order, you’re buying a backstop rather than a false sense of security.

Possibly yes. For a lot of Australian small businesses the most likely cyber loss is not a dramatic breach - it is an invoice or payment redirected to a criminal, and cyber insurance can cover that kind of money. But two honest caveats decide whether a policy is worth the premium: insurers now expect you to already have the basics in place (MFA, backups, patching) before they will pay or even quote, and the exclusions matter - the cover for the exact attack you are most exposed to is often a smaller, separate sub-limit. We sell scanning, not insurance, so this page has no horse in the race. It is here to help you ask the right questions before you buy.

What cyber insurance actually covers

Cyber insurance is a policy that pays for the costs of a cyber incident - the response, the downtime, and sometimes the stolen money. At small-business scale the cover usually breaks into a few parts, and it is worth knowing which one does the heavy lifting for a business your size.

Incident response costs. When something goes wrong, the bill is rarely just the lost data. It is the IT forensics to work out what happened, the legal advice on whether you have to notify anyone, and the cost of telling customers if you do. For a 1-30 staff business with no internal security team, this is often the most valuable part of the policy: it puts experts on the phone at the worst possible moment without you needing a relationship with them in advance.

Business interruption. If an attack - ransomware most obviously - stops you trading, this covers the income you lose while you recover. Whether it pays out depends heavily on the policy's waiting period and how the loss is calculated, so it is one to read closely rather than assume.

Funds-transfer fraud. This is the cover that matters most for the attack small businesses actually face. When a criminal tricks a staff member into paying a fake invoice - see what business email compromise is - some policies will reimburse the money. The catch, covered below, is that this is frequently a sub-limit rather than the full policy amount.

Liability. If the incident exposes other people's data and they suffer a loss, liability cover handles the claims and defence costs. For most small businesses this is the least-used part, but it is not nothing - the OAIC's Notifiable Data Breaches scheme means a mishandled breach can become a legal event, not just an awkward week.

The control requirements insurers now expect

The cyber insurance market has changed. A few years ago you could buy a policy by ticking a box. Now insurers ask questions - sometimes a full questionnaire - about the security controls you have in place, and your answers decide whether they will quote, what the premium is, and whether they will pay when you claim. No controls, no payout, and increasingly no quote.

Three controls come up almost every time.

Multi-factor authentication. Insurers want MFA on email, remote access and admin accounts at minimum. It is the single control most likely to be a hard requirement rather than a nice-to-have, because it blocks the account takeover that starts most claims. If you answer "yes" on the application and it turns out MFA was not actually on, an insurer has grounds to dispute the claim.

Backups. Working, tested backups that survive the office and that you can actually restore from. This is what turns a ransomware attack from a business-ending event into an expensive weekend, and insurers price accordingly.

Patching. Keeping software up to date - operating systems, applications, anything internet-facing. An unpatched system that gets exploited is one of the exclusions insurers reach for first.

The pattern is the same across all three: the controls are not optional extras you can buy your way out of with a higher premium. They are the price of entry. This is the part most owners get backwards - they treat insurance as the thing you buy instead of doing the security work, when insurers increasingly treat the security work as the thing you do before they will insure you.

The exclusions to read carefully

Every insurance policy is defined as much by what it excludes as what it covers, and cyber is no exception. Two exclusions catch small businesses out often enough to call out by name.

Social-engineering / BEC sub-limits. This is the big one. The attack you are most likely to suffer - a staff member tricked into paying a fraudulent invoice - is frequently carved out from the main cover and given its own, much smaller sub-limit. So a policy with a headline limit of $250,000 might cap funds-transfer fraud at $25,000. That is not necessarily a bad deal, but you need to know the real number for the attack you actually face before you sign, not after a claim. If a broker cannot tell you the social-engineering sub-limit off the top of their head, keep asking until you have it in writing.

Unpatched-system and unmet-condition exclusions. Many policies will decline a claim if the incident traces back to a known vulnerability you had not patched, or to a control you said you had but did not. This loops straight back to the section above: the controls are not just the price of the quote, they are the thing the insurer checks before paying. An insurer's representation that you maintain a control becomes, in effect, a warranty - and a breached warranty is a declined claim.

The takeaway is not that exclusions make insurance worthless. It is that the brochure number and the number you can actually claim for your most likely attack are often two different numbers, and only one of them matters.

When it's worth it for a small business

Cyber insurance earns its premium for a small business when two things are true: the most likely loss would genuinely hurt, and you cannot easily absorb it yourself.

For most businesses at 1-30 staff, that describes funds-transfer fraud almost exactly. A redirected supplier payment or a fraudulent invoice can be tens of thousands of dollars gone in an afternoon, with little prospect of recovery once it lands in an offshore account. If losing that amount would be a serious problem - and for most small businesses it would - then cover for it has real value, provided the sub-limit is high enough to mean something.

It is also a sensible call when a contract or customer requires it. Larger clients increasingly ask their suppliers to hold cyber insurance as a condition of doing business, the same way they ask for public liability cover. If that is your situation, the question is not really whether to buy but which policy meets the requirement.

Where it is weaker value is as a substitute for doing the basics. A policy does not stop the attack - it pays out after one, sometimes, subject to conditions. A business that has not done the basic security work is both more likely to claim and more likely to have that claim disputed. Insurance is a backstop for the loss you could not prevent, not a replacement for preventing the ones you can.

What to do before you buy a policy

The order of operations matters here, because the security work and the insurance are not alternatives - the first makes the second cheaper, more likely to pay out, and in some cases possible at all.

Start by getting the controls done. Turn on MFA across email and admin accounts. Set up backups that survive the office and restore-test one. Get a patching routine in place. These are the three the insurer will ask about, and they are also the three most likely to prevent the claim in the first place. The ACSC Small Business Cyber Security Hub walks through all three in plain English and for free - it is the best starting point in the country.

Then evidence them. A scan helps here: running your domain through our scan shows the outside-visible half of your posture - email authentication, certificates, security headers, DNS - against the Australian small business baseline, which is useful both for answering an insurer's questionnaire honestly and for knowing where you actually stand. If you need to prove the basics to a customer or tender rather than just have them, SMB1001 certification, tier by tier is the standard built for small businesses, and DISP membership for small business is the path if you supply the defence sector. Knowing what SMB1001 is is a sensible companion read.

Then read the policy for the number that matters - the social-engineering sub-limit - and make sure your answers on the application are true. A cheap policy you cannot claim on is the most expensive kind there is. Do the controls first, buy the cover second, and you are buying a backstop rather than a false sense of security.

#security#australian-business#small-business