Cyber insurance
Cyber Insurance for Australian businesses.
Cyber incidents can interrupt operations, compromise data, damage systems and create significant response costs. Mercantile helps businesses arrange cyber insurance around their technology dependence, data exposures, revenue profile and operational risks.
Digital risk protection
Insurance designed for the financial impact of cyber incidents.
Cyber insurance is designed to respond to specified first-party losses and third-party liabilities arising from cyber events. Cover varies between insurers, so the scope of incident response services, business interruption, data recovery, cybercrime, liability and sublimits should be reviewed carefully against the way your business operates.
Common areas of cyber cover
- Cyber incident response and specialist forensic costs
- Data restoration, system recovery and malware remediation
- Cyber business interruption and extra expense
- Privacy and network security liability
- Cyber extortion and ransomware response, subject to policy terms and applicable restrictions
- Regulatory investigation and defence costs where covered and insurable
- Crisis communications and reputational support where included
- Cybercrime and social engineering losses where specifically insured
- Dependent business interruption arising from specified technology providers where included
Incident response
A major feature of many cyber policies is access to an insurer-appointed incident response panel. Depending on the policy, this can include cyber forensic specialists, breach response professionals, crisis communications advisers and other specialist providers. The available services, approval requirements and policy limits differ between insurers.
Business interruption and system recovery
A cyber event can prevent a business from accessing systems, processing transactions, communicating with customers or operating key equipment. Cyber business interruption cover may respond to insured loss of income and additional costs following a covered interruption, while system recovery cover may assist with restoring data, software and systems. Waiting periods, indemnity periods, calculation methods and sublimits can materially affect the outcome of a claim.
Privacy and network security liability
Third-party cyber liability can provide cover for certain claims alleging failures in the handling of data or the security of computer systems and networks. Policies may also provide cover for specified investigation or response costs associated with an insured privacy or network security event. Exact triggers, definitions and exclusions vary between policies.
Cyber extortion and ransomware
Cyber extortion cover may provide access to specialist response services and cover certain costs arising from an insured extortion event. Any payment, reimbursement or response involving an extortion demand remains subject to policy terms, insurer consent and applicable restrictions. We focus on explaining the insurance terms and available cover rather than providing legal, sanctions or regulatory advice.
Cybercrime and social engineering
Not every cyber policy automatically covers theft of money, fraudulent transfers or social engineering. Some insurers include cybercrime cover, while others apply separate insuring clauses, lower sublimits, additional deductibles or specific verification conditions. These differences are important where the business regularly transfers funds or relies on email instructions for payments.
Dependent technology and supply-chain exposure
Many businesses rely on cloud providers, outsourced software, payment platforms, managed service providers and other external technology. Some cyber policies can extend business interruption cover to specified failures or cyber events affecting third-party providers, but the trigger and scope vary significantly. Widespread or systemic cyber events may also be subject to specific definitions, sublimits or exclusions.
Key policy differences we review
- Overall policy limit and section sublimits
- Deductibles and business interruption waiting periods
- Incident response services and panel-provider requirements
- Business interruption and dependent business interruption triggers
- Data restoration and system recovery cover
- Cybercrime, funds transfer fraud and social engineering provisions
- Cyber extortion provisions and insurer consent requirements
- Privacy, network security and media liability sections
- Territorial limits and overseas exposures
- Prior incidents, known circumstances and continuity provisions
- Widespread event, infrastructure and systemic-risk clauses
- Security-control requirements, warranties and policy conditions
Businesses that can benefit from a cyber insurance review
Cyber exposure is not limited to technology companies. Businesses that rely on computer systems, store sensitive or commercially important information, transact electronically or depend on external technology providers can face material cyber losses. This can include professional services firms, healthcare businesses, property and real-estate groups, manufacturers, wholesalers, retailers, financial services businesses, associations and technology companies.
Information insurers commonly request
- Annual turnover and business activities
- Number of employees and geographic operations
- Type and volume of personal, sensitive or payment data held
- Critical systems and key outsourced technology providers
- Multi-factor authentication and remote-access controls
- Backup arrangements and recovery testing
- Endpoint security, patching and vulnerability-management practices
- Prior cyber incidents, claims or known circumstances
- Requested limits, sublimits and existing insurance arrangements
Cyber insurance versus technology professional indemnity
Cyber insurance and technology professional indemnity address different exposures. Cyber insurance focuses primarily on cyber events, data, systems, incident response and related liabilities. Technology professional indemnity is generally concerned with claims arising from alleged errors, omissions or failures in technology products or services. Technology businesses may require both, depending on their activities and contractual exposures.
Important note about cover
Cyber insurance policies are not identical. Cover is subject to the insurer’s policy wording, schedule, limits, sublimits, deductibles, conditions and exclusions. Our role is to help you understand and compare insurance options and arrange cover; legal, privacy, sanctions and regulatory advice should be obtained from appropriately qualified advisers where required.


