Cyber Insurance Is a Buyer's Market Again — But Only If You Can Prove the Basics
Australian SMEs lose an average of $56,600 per cybercrime report. Cover is cheaper than it was, but insurers now want evidence of controls before they sign.
Australian small businesses now lose an average of $56,600 to every cybercrime they report — a 14 per cent jump in a single year, according to the Australian Signals Directorate’s Annual Cyber Threat Report 2024–25. Over the same period the ASD responded to more than 1,200 cyber security incidents, up 11 per cent, and received a cybercrime report every six minutes. For a business turning over a few million dollars, a single ransomware event or fraudulent payment can wipe out a year’s profit. That is the gap cyber insurance is meant to close — and for the first time in several years, the policy to close it is getting easier to buy.
The market has softened — but the door is narrowing
After a punishing few years of rising premiums and shrinking cover, conditions have turned in favour of buyers. Gallagher’s September 2025 cyber market update, reported by Insurance Business Australia, describes a stabilised Australian market with competitive rates and broad access to cover. Underwriters have become faster at assessing risk, and the volatility that defined 2021 and 2022 has eased.
The catch is in the detail. Premium reductions have already started to slow, and sectors carrying heavier claims — healthcare, transport, manufacturing and retail — are seeing far less relief. The reason is straightforward: ransomware claims rose 32.5 per cent in 2024, returning to levels last seen in 2021. Insurers are happy to compete on price, but only for risks they can understand and price with confidence. A business that cannot demonstrate basic security controls is no longer a cheap risk — it is an unknown one, and unknown risks get loaded premiums, ransomware sub-limits, or a polite decline.
What underwriters actually want to see
The questions on a cyber insurance proposal form have become a de facto security checklist, and the same handful of controls come up every time. Insurers want multi-factor authentication on email, remote access and administrator accounts. They want endpoint protection on every device, not just the office server. They want backups that are tested and held offline or in a form that ransomware cannot reach. And increasingly they want evidence of a written incident response plan — proof that if something goes wrong at 2am on a Sunday, someone knows who to call and what to do first.
None of these are enterprise-grade demands. They map closely to Maturity Level One of the ASD’s Essential Eight, which is within reach of a business with one IT person or an outsourced provider. The shift that matters is that insurers now ask for evidence rather than assurances. Ticking “yes” to MFA on a form, then discovering after a breach that it was never enabled on the mailbox that was compromised, is the kind of gap that turns a claim into a dispute.
Sort the four basics before your renewal date
Well before your policy comes up for renewal, confirm four things are genuinely in place: MFA on email and all remote and admin logins; endpoint protection on every laptop and server; a backup you have actually restored from in a test within the last quarter; and a one-page incident response plan listing who to call. These are the controls underwriters ask about — and the same ones that decide whether a claim is paid. Document them now, not in the week before renewal.
An Australian fast-track for small businesses
The link between controls and cover is now formal at the small end of the market. In May 2025, the Council of Small Business Organisations Australia’s Cyber Wardens program — a government-backed initiative led with Telstra and CommBank — partnered with certification provider CyberCert. Small businesses that complete the free Cyber Wardens training can obtain Bronze certification against the SMB1001 standard, which includes continuous vulnerability monitoring and pre-qualification for cyber insurance.
It is a recognition of how the economics work. COSBOA puts the average loss per attack on a small business at $49,600 — money most operators simply do not have spare. A recognised certification gives an underwriter a shorthand for “this business has done the groundwork”, which is exactly what shortens the path to affordable cover. For a firm that has never been able to get a sensible cyber quote, a structured certification is often a more practical starting point than negotiating with a broker from scratch.
Insurance is the backstop, not the strategy
It is worth being clear about what a policy does and does not do. Insurance can fund recovery, legal costs and an incident response team. It cannot restore customer trust, and it does not discharge your legal obligations. Since May 2025, businesses with annual turnover above $3 million have had to report ransomware payments to government, and the OAIC and ASIC have both stepped up enforcement of breach-related failures. A cheque from an insurer does not make any of that go away.
The sensible reading of a softening market is not “cover is cheap, so we can relax”. It is the opposite. The controls that secure a good premium are the same controls that stop the incident from happening in the first place, and the same ones regulators now expect. If your renewal is coming up this year, the question to put to your IT provider is simple: can we prove, with evidence, that the four basics are in place? If the answer is anything other than a confident yes, that is where the next few weeks are best spent.