Call NowFree Quote
Cybersecurity

Cyber Insurance for Perth Businesses: What You Need to Know

Cyber insurance has shifted from an optional extra to a business necessity for Perth SMBs. But buying a policy is not the same as being protected - insurers have dramatically tightened their requirements, and claims are increasingly denied when basic security controls aren't in place. Here's what you need to know before you sign.

What Cyber Insurance Actually Covers

A comprehensive cyber insurance policy for a Perth business typically covers:

  • First-party losses - your own costs from an incident: business interruption revenue loss, data recovery costs, ransomware negotiation fees, forensic investigation, and crisis communications
  • Third-party liability - claims made against you by clients or partners whose data was compromised in a breach you were responsible for
  • Regulatory defence costs - legal costs if the OAIC or another regulator investigates a notifiable data breach
  • Notification costs - the cost of notifying affected individuals, which can be significant if a large customer database is exposed
  • Cyber extortion - ransom payment assistance and negotiation support (though paying is still not recommended as a first resort)

What It Doesn't Cover

Read the exclusions carefully - this is where Perth business owners are frequently surprised:

  • Known vulnerabilities - if you had an unpatched system that the insurer asked about and you said was patched, the claim may be denied
  • Social engineering without specific endorsement - some base policies exclude Business Email Compromise fraud unless you add a specific social engineering endorsement
  • Prior incidents - breaches that began before your policy start date, even if discovered later
  • War and nation-state exclusions - some policies exclude attacks attributed to state-sponsored actors, which is increasingly common in ransomware
  • Failure to follow security requirements - this is the big one (see below)

What Insurers Now Require - And Check

The cyber insurance market hardened significantly after the wave of ransomware claims in 2021–2023. Insurers now conduct genuine security assessments, and premiums - and coverage - directly reflect your security posture. Controls that were optional two years ago are now mandatory for many insurers:

  • Multi-factor authentication - on email, remote access (VPN, RDP), and admin accounts. This is the most common requirement and the most common reason claims are denied.
  • Endpoint Detection and Response (EDR) - basic antivirus is no longer sufficient; many insurers require a named EDR product
  • Regular, tested, offline backups - immutable backups that ransomware cannot reach
  • Patch management - evidence that systems are kept up to date, particularly for internet-facing services
  • Privileged access management - admin accounts not used for day-to-day browsing and email
  • Staff security awareness training - documented, recurring training programs

When you submit a claim, insurers forensically examine your environment. If you ticked “yes” to MFA on your application but it wasn't actually enabled, the claim will be denied and the policy may be voided entirely.

Check your business against these exact requirements with our free, 2-minute self-assessment.

Take the Self-Assessment →

Our cybersecurity services cover the MFA, EDR, and backup controls insurers now require, plus the documentation to prove it.

Cybersecurity Services →

How Much Does It Cost for a Perth SMB?

Premiums vary significantly based on revenue, industry, data held, and security posture. Rough ranges for Perth small businesses:

  • 1–10 staff, low data sensitivity: $1,200–$2,500/year
  • 10–50 staff, moderate data: $2,500–$6,000/year
  • 50+ staff or healthcare/legal/financial: $6,000–$20,000+/year

Having strong security controls in place - MFA, EDR, managed backups - materially reduces premiums. The cost of getting your security right often pays for itself in reduced insurance premiums alone.

Cyber Insurance vs Good Security - Which Comes First?

Cyber insurance is not a substitute for security - it's a backstop for when security fails. The right order is: implement solid security controls first, then buy insurance to cover the residual risk. Businesses that try to buy insurance as a replacement for security investment find their claims denied and their premiums unaffordable.

Working With Your IT Provider on Insurance Readiness

Your managed IT provider should be able to provide documented evidence of your security controls - the kind of documentation insurers ask for at renewal. If your current IT provider can't tell you whether you're meeting insurer requirements, that's worth addressing before your next renewal.

Frequently Asked Questions

What does cyber insurance typically not cover?

Common exclusions include known vulnerabilities you told the insurer were patched but weren't, prior incidents that started before the policy began, and Business Email Compromise fraud unless you've added a specific social engineering endorsement. It's worth reading the exclusions carefully with your broker or insurer rather than assuming a policy covers everything.

What security controls do insurers expect before they'll pay a claim?

Multi-factor authentication is the most commonly required control and the most common reason claims get denied when it turns out not to actually be enabled. Insurers increasingly also expect endpoint detection tools, tested offline backups, and documented staff security training, though requirements vary by insurer so it's worth confirming exactly what yours expects.

What happens if we said we had MFA on our insurance application but we didn't?

Insurers can and do forensically examine your environment after a claim, and if what you declared doesn't match reality, the claim can be denied and the policy potentially voided entirely. This is why it's worth getting an honest assessment of your actual security setup before renewal, not just before a claim.

Should we get cyber insurance instead of investing in security?

No, insurance works best as a backstop for when security fails, not a replacement for having decent controls in place. Businesses that treat insurance as a substitute for security investment tend to find their claims denied and their premiums become unaffordable over time.

Want to know if your Perth business meets cyber insurance requirements?

Call 0433 087 091 - we'll review your security controls and provide the documentation your insurer needs.

Book a Security Review

For related reading, see our guides to Essential Eight and Cyber Insurance: What Perth Businesses Need to Know, How Often Should Staff Cyber Security Training Happen?, and Third-Party Vendor Risk.

Share this article