A Practical Guide to Cyber Insurance

Cyber insurance doesn't have to be complicated.
Handwriting

No organisation is too small to be targeted by cyber criminals. In fact, smaller organisations and not-for-profits are increasingly in the crosshairs of cyber-attacks because they often have fewer defences in place. A single incident can result in significant financial loss, reputational damage and operational downtime costs that many cannot absorb.

Even with strong security defences, no organisation can eliminate risk entirely and this is where cyber insurance comes in. The good news is that cyber insurance is currently more accessible and affordable than ever.

This guide will walk you through what cyber insurance is, how to weigh up whether it is right for your organisation and what to look for when comparing policies.

What is cyber insurance and how does it benefit your organisation?

Cyber insurance is a type of insurance policy that is designed to help organisations manage the financial fallout of a cyber incident, whether it's a data breach, ransomware attack or a staff member being tricked into transferring funds to a scammer.

Security tools and policies work to prevent incidents; insurance is there to help you recover and protect your balance sheet when prevention is not enough.

What does it usually cover?

While policies vary from one insurer to another, cyber insurance policies often include:

  • incident response costs, which includes costs of investigation, damage containment, and getting your systems up and running
  • business interruption costs, which relate to lost income or operational downtime
  • data breach notification and regulatory costs, which covers the cost of notifying affected individuals and regulators in line with Australian privacy obligations
  • reputation management costs through professional public relations support to protect your organisation's image
  • cyber extortion covering costs associated with responding to ransomware attacks
  • third-party liability costs, which protects your organisation from claims if a breach impacts partners or clients

Many insurers also include access to incident response support as part of the policy. When an incident occurs, you can call your insurer's hotline and they will deploy professionals to help with forensic investigation, containment, legal guidance and public relations support.

For not-for-profits without an in-house security team, this can be particularly useful.

Weighing risk versus cost when deciding to purchase cyber insurance

Not-for-profits operate on limited resources, so it's reasonable to question if cyber insurance is necessary to spend money on. The answer boils down to weighing your organisation's specific risks against the cost of a policy.

Understanding the risk

Start by asking some honest questions about your organisation:

  • Do you store any personal or sensitive information? This includes donor details, client records, employee data, health information, or financial details. What would happen if this data were breached.
  • How reliant are you on digital systems? If your email, financial systems or website went down for a week, how would this impact operations?
  • Do you process any financial transactions? Organisations that handle payments like payroll, grants, or donations are often lucrative targets for cyber attacks.
  • Do you share data with third parties? If a breach occurred through your systems, what would the financial and relational fallout look like?

Understanding the cost

The cost of cyber insurance varies depending on your organisation's size, revenue, data holdings and existing security measures. That said, the market is quite favourable right now:

  • The market is in a "soft" cycle meaning insurers are competing for business, resulting in better pricing options and more comprehensive coverage.
  • Good security practices can lower your premiums. So, implementing measures like multi-factor authentication (MFA), regular backups, staff training, and following the Essential Eight may make you eligible for better rates.
  • Coverage can be tailored to your needs. You can adjust sublimits to match your actual risk profile. You do not need to over-insure.

Essentially, whether cyber insurance is appropriate will depend on your organisation's risk profile, budget and existing controls.

What to look for when purchasing cyber insurance

Not all cyber insurance policies are the same. Here are the key things to look out for:

Check whether social engineering is covered

Social engineering, where criminals manipulate someone into transferring money or sharing credentials, is one of the most common threats facing organisations. Not all policies automatically include it, so ask your broker or insurer explicitly whether social engineering and funds transfer fraud are covered.

Insurance is just one step towards cyber security transformation

Cyber insurance isn't a replacement for good cyber security practices, but it can act as a safety net to help protect your organisation's finances, reputation and ability to continue operations.

If you're unsure where to start, consider speaking with an insurance broker who has experience with not-for-profits. And if you haven't already, our Cyber Security Essentials guide can help you strengthen your security foundations.

Rate this guide

No votes yet