Better Networks
Cyber insurance compliance for a Geelong small business

27 June 2026 · Better Networks

Do You Need Cyber Insurance? A Guide for Geelong Businesses

GEO: This guide is written for small and mid-sized businesses in Geelong, on the Bellarine Peninsula, and across the Surf Coast who are weighing up cyber insurance for the first time or reviewing a policy at renewal.

Cyber insurance has gone from a niche product to a normal line item for Australian small businesses. A decade ago most local firms had never heard of it. Now clients, suppliers, and landlords increasingly ask for proof of cover before they will sign a contract. The problem is that plenty of Geelong business owners buy a policy, tick the box, and assume they are protected - only to find out at claim time that they were never actually covered for the thing that happened.

This guide explains what cyber insurance is, what it covers, what it costs in Australia, what insurers require before they will pay, and how to make sure a claim does not get knocked back.

What is cyber insurance?

Cyber insurance is a policy that covers losses caused by digital incidents - ransomware, business email compromise, data breaches, and similar events. It pays for the response, recovery, and fallout, rather than the cost of the stolen device itself.

It is different from general liability or professional indemnity cover. General liability tends to exclude anything caused by a computer or network. If a scammer tricks your bookkeeper into paying a fake invoice, or ransomware locks your files, your standard business policy will almost certainly not respond. Cyber cover is what fills that gap.

What cyber insurance usually covers

Policies vary, but most small-business cyber policies cover some combination of the following:

  • Incident response and crisis support. Access to forensic investigators, lawyers, and a breach coach who coordinate the response from the moment you realise something is wrong.
  • Ransom and extortion costs. The ransom payment itself (where legal) plus negotiator fees, in policies that include this cover.
  • Business interruption. Lost income while systems are down, typically paid after a waiting period of 8 to 12 hours.
  • Data restoration and recovery. The labour to rebuild systems and restore data from backups after an attack.
  • Legal costs and liability. Defence costs and settlements if customers or third parties sue you over a breach.
  • Notification costs. The cost of telling affected individuals and regulators, which under Australian privacy law is often mandatory.

Read the product disclosure statement carefully. Some policies bundle all of the above; others split them into optional add-ons. The cheapest policy on the market is usually cheap for a reason.

What it does not cover

Every policy has exclusions, and these are the ones that catch Geelong businesses out:

  • Losses stemming from poor security hygiene that you said was in place but was not.
  • Attacks through known vulnerabilities you had not patched, especially if a fix had been available for weeks or months.
  • Incidents that began before the policy started, or that you already knew about when you applied.
  • Regulatory fines and penalties in some cases, depending on the policy and the jurisdiction.
  • The long-term value of intellectual property or lost competitive advantage - insurers pay for the response, not for what the stolen data was worth to you.

What does cyber insurance cost in Australia?

Premiums have come down from their 2022 peak but are still meaningful. For a typical small business in Geelong, indicative ranges are:

  • AUD $600 to $1,500 a year for a basic policy covering a small team with limited customer data.
  • AUD $2,000 to $5,000 a year for businesses that hold more sensitive data, process payments, or rely heavily on online systems.
  • AUD $5,000 to $15,000+ a year for mid-sized firms with complex networks, large customer databases, or regulatory obligations.

These are indicative figures only - your actual premium depends on your insurer, your excess, and your specific risk profile. According to guidance from the Australian Cyber Security Centre and industry reporting, the main price drivers are annual revenue, the volume and sensitivity of data you hold, the number of staff, and the security controls you can prove you have in place. A business that can show MFA, tested backups, and current patching will almost always pay less than one that cannot.

What insurers require before they pay

Insurers no longer take your word for it. Most Australian policies now include a list of warranties - security controls you must have in place for the cover to apply. If a control was missing when the incident happened, the insurer can deny the claim, even if you have paid every premium on time.

The controls insurers typically require include:

  • Multi-factor authentication (MFA) on email, remote access, and admin accounts.
  • Offline or immutable backups that a ransomware attacker cannot reach or delete.
  • Regular patching of operating systems and key applications.
  • Endpoint detection and response (EDR) or business-grade antivirus on all devices.
  • Staff security awareness training with some record of completion.
  • Written security policies covering acceptable use, password management, and incident response.

The bar is not as high as many business owners fear, but it is real. Most of these map directly to the Essential Eight. If you are not sure where you stand, our Essential Eight compliance service will tell you exactly which controls you have, which you are missing, and what an insurer will ask for.

Why claims get denied (and how to avoid it)

The pattern we see, both locally and in industry reporting, is depressingly consistent. A business gets hit, calls the insurer, and the insurer asks for evidence that the warranted controls were in place. The business cannot produce it, and the claim is denied. Common reasons include:

  • No MFA on the mailbox the attacker broke into, even though the application said MFA was enabled everywhere.
  • Backups existed but had not been tested, so they were corrupt or out of date.
  • A server was running an outdated operating system with a known vulnerability that had a patch available months earlier.
  • The application form was filled in quickly, without checking, and the answers did not match reality.

The fix is simple to describe and takes real work to do: document your controls. Keep a short record of MFA coverage, backup test results, patching status, and training completion. When an insurer asks for proof, you can hand it over in an hour instead of scrambling for a week.

How to prepare before you buy or renew

Whether you are buying cyber insurance for the first time or renewing an existing policy, a little preparation makes the cover both cheaper and more likely to pay out. Work through this list before you fill in the application:

  1. Inventory your systems. List every device, server, and cloud account the business relies on. You cannot protect what you have forgotten about.
  2. Implement MFA everywhere it matters. Email, remote access, accounting software, and any admin account. This is the single biggest factor in both premiums and claims.
  3. Set up offline or immutable backups and test a restore. A backup you have never restored from is a hope, not a backup.
  4. Get the Essential Eight basics in place. Patching, application control, MFA, and daily backups cover most of what insurers want. See our managed cybersecurity service for help with this.
  5. Keep evidence.Screenshots, logs, and training records. The insurer will ask, and "trust me" is not a valid answer.

If ransomware is your main worry - and for most Geelong businesses it is - our backup and ransomware protection service is built around exactly the controls insurers look for.

Getting help

Better Networks works with small and mid-sized businesses across Geelong, the Bellarine, and the Surf Coast to get cyber-insurance-ready before a claim is ever on the table. We do not sell insurance - we make sure your security controls match what your policy requires, so that if you ever need to claim, it actually pays out.

Our cyber insurance compliance service maps your current setup against typical insurer requirements and closes the gaps. You can also read more about our managed cybersecurity offering, or just get in touch and we will tell you honestly whether you need cyber insurance and what it would take to be ready for it.

FAQ

Cyber Insurance FAQs

Straight answers, no fluff.

No, it is not legally required for most businesses. But many clients, suppliers, and government contracts now ask for proof of cyber cover before they will sign. Even when it is not mandatory, it is becoming a normal cost of doing business - especially if you hold customer data or rely on email and online banking.

Usually yes, but only if you met the security conditions in your policy at the time of the attack. Most policies cover the cost of incident response, ransom negotiation (where legal), data restoration, and lost income while systems are down. If you had no MFA or untested backups when the attack happened, the insurer can decline the claim.

For a typical Geelong small business, cover starts at roughly AUD $600 to $1,500 a year for a basic policy, and sits between $2,000 and $5,000 a year for businesses that handle more data or rely heavily on online systems. The price depends on revenue, data volume, and the security controls you can prove you have in place.

The most common reasons are no MFA on email or remote access, backups that were never tested, unpatched systems with known vulnerabilities, and information on the application that turned out to be inaccurate. Insurers ask for evidence after an incident - if you cannot show the controls were in place, the claim can be denied.

You do not need all eight controls at the highest level, but insurers increasingly expect the basics - MFA, patching, backups, and application control. Meeting the Essential Eight baseline makes applications easier and claims harder to deny. Most policies will not pay out if the controls you claimed on the application were not actually in place.

Get Started

Make sure your cyber insurance would actually pay out.

Book a cyber insurance readiness review. We will check what your policy requires and close the security gaps before you ever need to claim.

Book a Free Call →