In our own placement records, a quarter of cyber policies came in at roughly $500 or less. One in ten came in above $8,100. Same product name on the schedule, wildly different price.

That’s not a pricing error. It’s how cyber insurance cost in Australia actually works, and the spread in our own records is proportionally wider than for any comparable product we track. Here’s what the numbers look like, what sits at each end, and which levers actually move the price.

How much does cyber insurance cost in Australia?

Across Tank Insurance’s cyber placements from 2023 to 2026, the median premium was approximately $1,100. Ranking every premium from cheapest to priciest: a quarter sat at or below approximately $500, three-quarters sat at or below approximately $4,100, and nine in ten sat at or below approximately $8,100. The middle half of our cyber book alone spans roughly 8x, from about $500 to about $4,100. These are observed figures from our own placements, not market-wide rates. This is a modest sample compared to our other lines, and the businesses behind it differ in revenue, limits and security controls, so treat the figures as a reference point rather than a quote.

Chart showing the cyber insurance premium spread from $500 for the cheapest quarter to $8,100 for the priciest one in ten, compared against median premiums for Public Liability, Professional Indemnity and Business Pack

Source: Tank Insurance placement records, 2023-2026. Figures are observed values from our book, not market-wide rates. Rounded up to the nearest $100.

For context from the same dataset: Public Liability had a median of approximately $800, Professional Indemnity approximately $1,700, and Business Pack approximately $2,800. Cyber’s median sits below Business Pack’s, but its priciest one in ten runs more than seven times the median, a wider proportional spread than any of those three lines showed in our book. That’s the story of this product. The label tells you almost nothing about the price.

What puts a business at the cheap end of the spread?

The roughly $500 quotes in our book tend to belong to small businesses with modest revenue, a low limit, minimal sensitive data and solid basic controls.

Cyber premiums are built from a handful of rating inputs:

  • Revenue. Bigger turnover means bigger potential business interruption loss, so it’s the first number on every proposal form.
  • Limit chosen. A $250,000 limit and a $2 million limit are different products in cost terms, even for the same business.
  • Data held. A trades business holding invoices is rated differently to a firm holding health records, identity documents or payment card data. The cost of notifying and remediating a breach scales with what you store.
  • Industry. Insurers price the exposure that comes with the work itself. A software business with production access to client systems carries a different profile to a retail shop running a point-of-sale terminal.
  • Security controls. MFA, backups, endpoint protection. More on these below, because they’re the lever you actually control.

What pushes a premium towards $4,100 or $8,100?

The top quartile of our cyber book reflects some combination of higher revenue, higher limits, sensitive data and weaker or unverified controls.

Stack the inputs and the price compounds. A $10 million revenue firm holding client financial data, wanting a $2 million limit, with patchy MFA coverage, is being priced for a genuinely different risk than a $500,000 revenue consultancy with hardened systems.

Both buy “cyber insurance”. Only one costs $8,000.

The useful takeaway: if your quote lands at the expensive end, ask which input is driving it. Sometimes it’s structural (your revenue, your data) and the premium is simply the cost of your exposure. Sometimes it’s a control gap you can close before renewal.

Which security controls influence your premium?

Insurers rate cyber risk heavily on a short list of controls: multi-factor authentication, backups, endpoint protection, patching and staff training.

The recurring items on cyber proposal forms:

ControlWhat insurers look for
Multi-factor authenticationEnforced on email, remote access and admin accounts, not just “available”
BackupsRegular, tested, and stored offline or segregated from the main network
Endpoint protectionDetection and response software on company devices
PatchingOperating systems and software updated on a defined schedule
Staff trainingSecurity awareness training, including phishing simulation
Access managementAdmin rights restricted, leavers’ accounts closed promptly

Some insurers treat items on this list as minimum requirements, meaning no terms offered without them, and others price around them. Either way, improving them is one of the few concrete actions that can move a cyber premium down rather than up. The Australian Cyber Security Centre publishes free, practical guidance on implementing these controls at cyber.gov.au, and we’ve covered the basics in our guide to cyber security for Australian small businesses.

What does a cyber policy actually cover?

A typical cyber policy combines first-party costs (your losses) with third-party liability (claims against you), plus incident response support.

Common coverage sections:

  • Incident response: IT forensics, legal advice and PR support after a breach, often via the insurer’s response panel
  • Business interruption: loss of income while systems are down
  • Data recovery: the cost of restoring data and systems
  • Cyber extortion: ransomware response, where lawful
  • Privacy liability: claims and regulatory investigations arising from a data breach
  • Social engineering and funds transfer fraud: often sub-limited or optional, so worth checking rather than assuming

Common exclusions to check: incidents that started before the policy period, failure to maintain the controls declared on your proposal, unencrypted portable devices, and infrastructure failures outside your network. Wording varies by insurer, which is exactly where comparing policies rather than premiums earns its keep. Our cyber insurance page covers the product in more detail.

Frequently asked questions

Is cyber insurance mandatory in Australia?

No. There’s no general legal requirement for Australian businesses to hold cyber insurance. Some client contracts and supplier agreements require it as a condition of doing business, so check your contractual obligations even though it isn’t legislated.

What security controls do cyber insurers ask about?

Proposal forms typically cover MFA on email and remote access, backup frequency and segregation, endpoint protection, patching practices and staff security training. Your answers directly influence whether an insurer offers terms and at what price.

Can I get cyber insurance after a cyber incident?

Often yes. Insurers will ask about prior incidents and assess what’s changed since, if the vulnerability has been remediated, cover can still be available, though terms may reflect the history. A new policy won’t respond to an incident that occurred before cover started.

How much does cyber insurance cost for a small business in Australia?

In Tank Insurance’s placement records from 2023 to 2026, the cheapest quarter of cyber premiums came in at approximately $500 or less, the middle of the book sat around $1,100, the pricier quarter reached approximately $4,100, and the top one in ten came in at $8,100 or more. Smaller businesses with modest revenue, low data sensitivity and solid security controls tended to sit at the lower end.

Does a low cyber insurance quote mean thin cover?

Not automatically, but check the limit, the sub-limits (especially social engineering fraud) and the excess before comparing on price. Two quotes hundreds of dollars apart can differ by far more in what they’d actually pay in a claim.

Want a cyber quote grounded in real numbers?

We place cyber for businesses across the spread, from sub-$1,000 policies for small operators to larger firms holding sensitive data. We’ll tell you which rating inputs are driving your price and whether a control fix could move it.

Call us on 02 9000 1155, email [email protected], or get in touch through our contact page.

Feedback

Was this helpful?