What cyber insurance covers when you are a five-person business
We keep customer names and payment details in a shared inbox. What would cyber cover pay for, and what would it leave me to pay?
Your legal obligation comes first, not the insurance
Before any policy question, there is the regulator question. Under the Notifiable Data Breaches scheme, the OAIC states that an organisation or agency must notify affected individuals and the OAIC about an eligible data breach. An eligible data breach occurs when there is unauthorised access to, or unauthorised disclosure of, personal information, or a loss of personal information, that the organisation holds; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that likely risk of serious harm with remedial action.
Three conditions, all of them. And the OAIC is explicit that an organisation that suspects an eligible data breach may have occurred must quickly assess the incident to determine whether it is likely to result in serious harm to any individual. So the first cost of a breach is not legal — it is the assessment you have to be able to do, fast, with whatever evidence you kept.
A shared inbox holding customer names and payment details is squarely in scope for that. The policy does not replace your ability to investigate.
Cyber cover is split into two families, and the split is the point
In an example business pack policy wording, cyber liability is structured into first party and third party insuring agreements. They answer completely different questions, and small businesses are usually weakest exactly where the boundary sits.
First party — your costs, after something happens
The wording provides for four distinct first party heads, each with its own conditions:
- Incident response expenses, by reason of a cyber incident or a business interruption incident, discovered by a member of the control group during the policy period and reported under the general claims conditions.
- Business interruption loss, during the period of indemnity, arising from a business interruption incident whose duration exceeds the waiting period.
- Data and system recovery costs, during the period of indemnity, arising from a business interruption incident.
- Cyber extortion damages and expenses, by reason of a cyber extortion event — with the wording defining extortion damages as money, including cryptocurrency, paid to legally terminate such an event.
Note what is inside that waiting period language, and note the requirement that the incident be discovered by a defined control group member and reported. For a five-person business the practical questions are: who is on our control group, and are we going to actually report this the same day?
Third party — someone claims against you
The third party insuring agreements respond to claims made against you, on a first-made basis: privacy and network security liability for damages and claims expenses arising from a privacy and network security claim first made during the policy period, and media liability for damages and claims expenses arising from a media claim first made during the policy period. First made matters: a matter that was known or reported before the policy started is a different problem, and some wordings treat prior knowledge or prior proceedings as exclusions outright.
What usually falls outside, and would be yours
Reading the example wording’s exclusions gives a realistic picture of the residual exposure for a small business:
- Prior knowledge and pending proceedings — matters that were already the subject of notice, litigation or investigation before the policy started.
- Your own conduct — a knowing or wilful breach of duty, or a deliberate fraudulent or dishonest act. That exclusion generally applies only once such conduct has been established by final adjudication or written admission, which is a real protection, but it is a place to be careful.
- Unauthorised or surreptitious collection of data, and failing to give adequate notice that data is being collected or used — though the wording notes this exclusion does not apply to an unintentional violation of a privacy regulation.
- Contractual liability for breach of an express or implied contract or promise, which matters where you have committed to a service level or a security standard in a client contract.
- Loss of profit in the ordinary sense — business interruption loss is defined as net profit before income taxes that would have been earned had the incident not occurred, less net profit actually earned, so it is not a broader revenue guarantee.
And note the structure: in that wording, expenses incurred through the insurer’s cyber incident response team are part of — not in addition to — the limit of liability for incident response expenses. A single aggregate limit can sit across everything.
Where a shared inbox sits
Your scenario — customer names and payment details in a shared mailbox — is the mainstream case, not an edge case. It is personal information, a breach involving it can be eligible, and it can produce third party claims if you are a service provider to someone else’s business. The value of the policy is less about the ransom than about the response cost and the assessment capability you would otherwise fund out of a five-person payroll.
Ask these before you buy. All five come straight out of the wording:
- What is the waiting period, and does it apply before any recovery payment?
- Is the incident response cost inside the same limit as everything else?
- Is third party cover on a first-made basis, and what happens to matters already known?
- Who must be on the control group, and what does reporting actually require?
- Is intentional or unauthorised data collection excluded, and how does that interact with an unintentional breach?
What to do next
Take this to a licensed broker with the specific answer to “what do we hold, and where?” — and separately, read the OAIC guidance on when to report a breach so you know your obligation independently of any policy. The regulator’s guidance is free and public, and it is the document that matters most in the first 24 hours.
Some pages contain a referral link to BizCover. If you use it and take out a policy, we may receive a commission at no extra cost to you. Referral arrangements do not influence which cover types we explain or how we explain them.
Sources
Regulator guidance and an insurer-published policy wording, both current at the time of writing. Scheme rules and policy wording both change — check the live pages.
- OAIC — Notifiable data breaches
- OAIC — When to report a data breach
- OAIC — Quick reference guide for responding to data breaches
- Chubb — Business Pack policy wording (example PDS)
Cyber policies separate incident response costs, business interruption and recovery, and third-party claims. Small businesses are often weakest exactly where those three differ.
coverage.chat provides general information about business insurance. We are not an insurer, broker, or financial adviser, and we do not hold an Australian Financial Services Licence. Nothing here is personal advice, a quote, or a recommendation to buy a particular policy. Read the Product Disclosure Statement and speak with a licensed broker before you decide.