Cyber insurance conditions: staying on the right side of your policy

We read four published Australian cyber insurance wordings end to end. This is what they ask of you before, during and after an incident, and where they differ.

By the Gary team · Updated · 16 min read

Gary reading a thick cyber insurance policy wording through a magnifying glass

General information only

This guide explains what published policy wordings say and what Australian law requires. It is general information, not advice, and it doesn’t consider your objectives, financial situation or needs. Policies differ, and wordings change: the PDS, policy wording and schedule for your own cover are the documents that count. The insurers quoted here are examples we could read in full; they are not necessarily on our panel.

The short version

  • Your proposal answers usually become part of the policy. Describe your security as it really is.
  • Several wordings require you to keep your security at least as good as it was when cover started.
  • Old, unsupported or unpatched software can shrink or remove cover, depending on the wording.
  • Call the insurer first when something happens. Using your own providers without consent can cost you the claim.
  • Admit nothing, pay nothing and settle nothing without the insurer’s written consent. That includes a ransom.
  • Payment-redirection fraud is often optional cover, with its own short reporting deadline.

Why cyber insurance conditions matter more than the headline cover

Most people buy cyber insurance by reading the list of what it covers: incident response, data restoration, business interruption, liability. That list matters. But when a claim is assessed, the part that decides the outcome is usually further back, in the conditions: the obligations the policy places on you before and after something goes wrong.

Cyber is unusual here. A fire policy asks little of you once the smoke alarm is fitted. A cyber policy prices your business on how you run your IT, and most wordings expect you to keep running it that way. They also ask a lot of you in the first hours of an incident, which is exactly when a business owner is least likely to be reading a policy document.

The stakes are real. The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 puts the average self-reported cost of a cybercrime for a small business at $56,600, up 14% on the year before. A claim reduced or declined over a condition leaves most of that with the business.

Australian law softens some of this. The Insurance Contracts Act generally limits an insurer’s ability to refuse a claim because of something you did or didn’t do after the policy started, to the extent that act actually caused or contributed to the loss. It is a real protection, but it is an argument you have after a claim is reduced, not a reason to skip the conditions. And some wordings label particular obligations “conditions precedent”, language that signals the insurer treats them as essential to paying at all.

The four cyber wordings we read

We downloaded four Australian small-business cyber wordings that are published on their insurers’ own websites and read each one in full. Where we quote them below, the words are theirs, with the clause reference.

InsurerProductVersion
EmergenceCyber Event ProtectionCEP-005.1, Feb 2026
ChubbCyber Enterprise Risk Management 2.2Chubb10-571-0722, Jul 2022
DUALCyber Liability and Privacy Protection11.20, Nov 2020
DeltaCyber LiabilityDIA CYB 0226, Feb 2026

Two of these (Chubb’s and DUAL’s) are older versions that were still hosted by the insurer when we read them; a newer edition may be on sale. Limits, excesses and waiting periods live in each policy’s schedule, which isn’t published, so where we mention a number it is one the wording itself states.

Before you buy: what you tell the insurer

A cyber insurance proposal form on a clipboard with ticked boxes and a fountain pen
The proposal form: usually part of the contract, not a formality

Every one of the four wordings reproduces the duty of disclosure under the Insurance Contracts Act: you must tell the insurer anything you know, or could reasonably be expected to know, that may affect its decision to insure you and on what terms. The same duty applies again at renewal. The consequences are also the same across all four:

“we may cancel your contract or reduce the amount we will pay you if you make a claim, or both”Emergence, Chubb, DUAL and Delta, duty of disclosure notice

With cyber, disclosure goes further than the usual notice, because the questions are so specific. Chubb’s wording defines the policy itself as “collectively, the Schedule, the proposal, this policy form and any endorsements” (clause 3.51), and DUAL’s includes “all other supporting documentation and attachments” (6.42). In plain terms: if the proposal asked whether you use multi-factor authentication on email and you ticked yes, that answer is part of your contract.

Delta’s wording is the most direct about it:

“the particulars and statements contained in the Proposal are true, accurate, and complete”Delta, Cyber Liability DIA CYB 0226, clause 5.8.1

Delta treats those statements as “the basis of this Policy”, and the policy can be void for the business if an executive officer knew a statement was untrue (5.8.2). DUAL takes the opposite approach and is the most forgiving of the four: it agrees not to avoid the policy for any reason and waives its rights for non-fraudulent non-disclosure (8.14). The difference between those two positions is a good illustration of why reading your own wording matters.

Things cyber proposals commonly ask

  • Whether multi-factor authentication is on for email, remote access and admin accounts
  • How often you back up, whether backups are kept off the network, and whether restores are tested
  • How quickly critical patches are applied, and whether anything unsupported is still running
  • How many personal records you hold, and whether you take card payments
  • Any incidents, breaches or suspicious events in recent years, and any claims or declined cover

Our own cyber quote form asks these one by one. Answer them as your business runs today. A control you intend to switch on next month is not a control you have, and the wordings’ prior-knowledge exclusions (below) mean an incident you already know about is generally not covered either way.

While you’re covered: keeping up your controls

Two of the four wordings put the ongoing obligation in writing. Emergence’s general conditions say:

“You must maintain IT security practices and procedures to a standard equal or better than you had in place at the time this policy commenced.”Emergence, Cyber Event Protection CEP-005.1, general condition 3

Helpfully, the same clause says a failure “by an employee or an external supplier shall not constitute a breach”, so one staff member’s mistake is not the business breaking the condition. DUAL asks you to “take reasonable measures to maintain the availability and security of the insured’s systems” and to keep “reasonably regular back-up copies of data”, and to require the same of your service providers (7.10).

Two brass keys and a combination padlock, illustrating multi-factor authentication
Two keys, one door: the idea behind multi-factor authentication

You won’t find a clause in any of the four that says “MFA must be on”. The requirement usually arrives through the proposal: you told the insurer it was on, the proposal is part of the policy, and the maintenance conditions expect it to stay on. The effect is the same, and it is why a lapse in a basic control is the first thing an insurer looks for after an incident.

The controls insurers rate on

The Australian Signals Directorate’s Essential Eight is the reference most Australian proposals are built around. Its eight strategies are: patch applications; patch operating systems; multi-factor authentication; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.

Computer tape reels stored in a steel fireproof lockbox, illustrating offline backups
Backups kept off the network, in their own locked box

Backups deserve their own mention because ransomware targets them. A backup that sits on the same network as everything else can be encrypted along with it. Proposals increasingly ask whether backups are offline or immutable (unable to be altered), and whether a restore has been tested recently. Writing down the date of your last successful test restore is a small habit that makes an honest answer easy.

Old software and unpatched holes

An open red toolbox holding a screwdriver, tape and floppy disks, illustrating software maintenance
Maintenance: the part of cyber cover that never makes the brochure

This is where the four wordings differ most, and where the difference in money can be large. Chubb’s wording defines a “Neglected Software Exploit”: an attack through software that is past its end of life, or through a published vulnerability where a patch “has been available to You, but has not been applied” (3.44). Rather than excluding it, Chubb’s schedule applies a sliding share of the loss that you carry yourself (coinsurance), based on how long the patch had been available:

Patch available forShare of the loss you carry
0–45 days0%
46–90 days5%
91–180 days10%
181–365 days25%
Over 365 days50%

Chubb Cyber ERM 2.2 schedule template, Neglected Software Exploit. A separate sub-limit and excess can also apply.

Delta takes the harder line and excludes the same situations outright. Its wording excludes loss from the “expiration or withdrawal of technical support by a software vendor” publicly announced for more than 60 days (3.10), and from a known, patchable vulnerability that wasn’t patched (3.11). Emergence’s definition of a system failure leaves out outages caused by “software that is past its end-of-life and no longer supported”.

The practical reading is the same across all three: the older the unpatched hole, the smaller the claim is likely to be. Keeping a simple list of the software you run, and which of it has lost vendor support, is the most direct way to keep this clause from mattering.

When something happens: the first hour

A red rotary telephone with the handset lifted, illustrating an insurer’s incident hotline
The first call is to the insurer’s incident line

Every wording asks you to tell the insurer quickly, and the language gets stricter the closer you read. Emergence’s first claims condition is to “immediately ring the Emergence cyber event reporting line” or notify it in writing. Chubb asks for written notice “as soon as reasonably practicable”. Delta makes prompt notice a condition precedent: as soon as practicable after an executive officer first becomes aware, and in any event no later than 30 days after the policy expires (4.1.1).

The reason is practical. Most cyber policies come with an incident response team (lawyers, forensic IT specialists, breach coaches) and the earlier they are involved, the smaller the damage. Emergence says its own incident response costs don’t erode your limit and carry no excess; DUAL says the same of its incident response manager’s triage fees (7.3). If your policy was placed through a broker, they are the second call: how claims work with Gary sets out what we do from there.

Using your own IT provider

This is the trap that catches the most well-meaning business owners. When systems go down, the natural first call is to your own IT person. DUAL’s wording is blunt about it:

“An insured must only engage approved providers… we will not be liable for any response costs, defence costs… for services provided by any third party who is not an approved provider.”DUAL, Cyber Liability and Privacy Protection 11.20, clause 7.4

An “approved provider” can include one the insurer consents to in writing, so your own IT firm may well be approved, but only if you ask first. Emergence won’t reimburse costs “unless approved by us”. There is some room for emergencies: Delta approves incident costs retrospectively for the first 72 hours, and Chubb’s emergency incident response covers expenses in the first 48 hours after discovery. Those windows are the exception, not the rule.

Preserve the evidence

Emergence’s claims conditions ask you to preserve evidence and cooperate fully. Wiping and rebuilding an infected machine feels like the fastest fix, but it can destroy the forensic trail the insurer (and sometimes the police) need to establish what happened and what was taken. Isolate first; rebuild when told.

Ransom demands

A leather wallet wrapped in a chain and padlock, illustrating ransom payments that need the insurer’s consent
Nothing leaves the wallet without the insurer’s consent

Ransomware is where the pressure to act alone is highest, and where acting alone is most expensive. The wordings that cover an extortion payment all tie it to consent. Emergence covers “cyber extortion costs paid with our agreement and consent”. DUAL reimburses money paid “with our prior written consent and which payment is legally permitted” (3.7b). Chubb covers amounts paid “where legally allowed and insurable” (3.14), and its schedule can apply a separate ransomware sub-limit, excess and coinsurance.

Chubb’s is the only one of the four with a written duty to tell the police:

“You shall report a Ransomware to the appropriate law enforcement agencies as soon as reasonably practicable.”Chubb, Cyber ERM 2.2, clause 5.10F

All four carry sanctions clauses. A payment to a group subject to Australian or international sanctions can be illegal, and no policy will reimburse an illegal payment. That is one of the reasons insurers insist on handling negotiation through their own specialists.

The law, separately from your policy

Since 30 May 2025, the Cyber Security Act 2024 requires a business with annual turnover of $3 million or more to report a ransomware payment to the Australian Government within 72 hours of making it, including a payment made on its behalf. None of the four wordings mentions it; it applies whether or not you are insured.

Payment redirection and social engineering

Two tin-can telephones joined by string, illustrating calling a supplier back to verify bank details
Call back on a number you already hold, not the one in the email

The invoice that arrives from a real supplier’s email address with new bank details is one of the most common losses small businesses report. It is also one of the least consistently covered. A business pack’s theft section is written for physical theft, and cyber wordings treat this risk very differently. Of the four:

  • Emergence offers it as optional cover (criminal financial loss), including deception “through deepfake or… artificial intelligence”, with its own sub-limit.
  • DUAL offers an optional social engineering and cyber fraud extension, paying only loss “not recoverable from any financial institution”.
  • Chubb’s cyber crime cover responds to theft through a third party’s malicious access, and excludes acts by your own employees and contractors.
  • Delta excludes the transfer of, or failure to transfer, funds (3.6).

Where it is covered, the reporting deadlines are short. Emergence’s is the tightest:

“to, respectively, the Australian Cyber Security Centre, your financial institution, and your telephone service provider, within 24 hours of it first being discovered”Emergence, Cyber Event Protection CEP-005.1, claims condition 2

DUAL makes written notice within 60 days of discovering the loss a condition precedent (7.2). None of the four makes a call-back check a written condition, but verifying any change of bank details by phoning a number you already hold is the single control most often recommended against this fraud, and a proposal may well ask whether you do it.

Data breaches and your obligations under the Privacy Act

If personal information is lost or accessed without authorisation, your policy is only half the picture. Under the Notifiable Data Breaches scheme, a breach is “eligible” when it is likely to result in serious harm to the people involved and you haven’t been able to prevent that harm with remedial action. Covered businesses must take all reasonable steps to assess a suspected breach within 30 calendar days, and notify affected individuals and the Australian Information Commissioner as soon as practicable.

The scheme applies to organisations with annual turnover of more than $3 million. Most small businesses are exempt, with exceptions that include businesses providing health services and those that trade in personal information. The OAIC’s guidance is the place to check where your business sits.

The wordings help with the cost. Emergence’s notification cover includes preparing a statement to the Office of the Australian Information Commissioner; DUAL pays to notify affected people and authorities “whether or not such measures are required by law”; Delta’s wording names the Notifiable Data Breaches legislation directly. The legal duty to assess and notify, though, is yours, and so is the clock.

The cyber exclusions worth knowing

Every cyber wording has a list of things it won’t cover. These are the ones that come up most often, and how the four compare.

ExclusionWhat it generally meansAcross the four
Prior knowledgeIncidents or circumstances you knew about before cover startedAll four exclude them; DUAL also excludes anything referred to in the proposal
War and state cyber operationsAttacks carried out as part of war, or by a state against another stateEmergence, Chubb and Delta have specific cyber-operation wording; DUAL’s war exclusion carves back cyber terrorism
Infrastructure failureOutages of power, internet, telecoms or DNS you don’t controlAll four exclude it
Injury and property damageBodily injury and physical damage, left to other policiesAll four exclude them, with narrow carve-backs
Contractual liabilityLiability you only have because a contract says soAll four exclude it; Emergence, Chubb and DUAL carve back card-industry (PCI) obligations
Fines and penaltiesRegulatory fines, which the law may not let anyone insureCovered only where insurable by law, and wordings differ on which

The infrastructure exclusion surprises people. If your business stops because the internet provider for your whole area goes down, that is generally not a cyber event under these wordings, however much it costs you. And a client’s claim that your advice or service cost them money, rather than a breach of your systems, is generally the territory of professional indemnity insurance.

Business interruption: waiting periods and records

An open logbook, a pencil and a small desk clock, illustrating the records a business interruption claim needs
The income you lost has to be shown, not estimated

Cyber business interruption cover generally doesn’t start the moment your systems go down. It starts after a waiting period set in your schedule, measured in hours. The wordings themselves name a few fixed figures: Emergence applies a 72-hour waiting period to its non-IT contingent interruption cover and an 8-hour one to a preventative shutdown; Delta applies 24 hours to interruption caused by an attack on your cloud services, with a $250,000 aggregate sub-limit, and ends the restoration period at most 365 days after the waiting period.

When you claim, you have to show the income you lost. Emergence calculates it from “records of your business”, including bank, GST and tax records. Chubb asks for a computation of the loss supported by “reports, books of accounts, bills, ledgers, invoices”. Up-to-date books are part of your cyber cover, even though no wording says so in those words.

Renewal, circumstances and continuous cover

Cyber liability cover is usually written on a claims-made basis: the policy that responds is the one in force when a claim is made against you, not when the incident happened. The first-party parts (your own response costs, data restoration, interruption) usually respond to incidents first discovered during the policy period.

Two consequences follow. First, if you become aware of something that could lead to a claim, notifying it as a circumstance during the policy period can attach it to that policy. Chubb’s wording deems a later claim to have been made during the period if you gave written notice of the circumstance (5.10E); Delta asks the notice to include reasons, an estimated loss and the likely regulatory consequences (4.1.2).

Second, gaps in cover can cost you. Emergence and DUAL both give some protection for facts known but not notified, but only where you have been continuously insured with them without interruption. Changing insurers or letting a policy lapse can lose that. Extended reporting periods also differ: from 30 days free with Emergence, to 60 days automatically with Chubb and DUAL, with 12 months available to buy.

Finally, the duty of disclosure applies again at every renewal. If you have changed how you run IT, moved systems to a new provider, started taking card payments or had an incident, the renewal is when the insurer expects to hear about it. If you’re unsure whether something counts, ask a broker before you sign.

Want to test yourself on all of this? The Monday Morning Test puts you in the chair for one bad week.

A cyber insurance checklist to keep beside the policy

Gary and a business owner working through a checklist on a clipboard together
Ten minutes with a checklist, once a year, at renewal

Drawn from the conditions above. It is not a substitute for your own wording, which may ask for more, or less.

Before you buy

  • Answer every proposal question about your controls as things stand today, not as planned
  • Mention any incident, near miss or suspicious event you already know about
  • Keep a copy of the proposal you signed, with the PDS and schedule

While you’re covered

  • Keep MFA, backups and patching at least as good as you described
  • Retire or isolate software its vendor no longer supports
  • Test a restore from backup, and write down that you did
  • Save the insurer’s incident line and claims email where staff can find them
  • Tell the insurer before renewal about any change to how you run IT

When something happens

  • Call the insurer’s incident line (or the one named in your policy) straight away
  • Preserve evidence: don’t wipe or rebuild machines before you’re told to
  • Use the insurer’s response providers, or get written consent for your own
  • Admit nothing, pay nothing and settle nothing without written consent
  • For a redirected payment, call your bank at once, and report it as the policy asks

Afterwards

  • Keep records that show the income you lost: bank, GST and accounts
  • Report a ransom payment within 72 hours if the reporting law applies to you
  • Assess a data breach within 30 days if you are covered by the NDB scheme
  • Answer the insurer’s requests fully and honestly; the duty to cooperate continues

Questions people ask about cyber insurance conditions

If I forget to turn MFA back on, is my claim automatically refused?

Not automatically. None of the four wordings we read makes MFA a stand-alone condition; it usually enters the policy through your proposal answers. Australian law also limits when an insurer can refuse a claim because of something you did or didn’t do, generally to the extent it caused or contributed to the loss. But a gap between what you declared and what you run is exactly what an insurer looks at after an incident, and a policy can reduce a claim for it.

Can I use my own IT provider after an attack?

It depends on the wording. DUAL’s says you must only engage approved providers and it won’t pay for others; Emergence’s says it won’t reimburse costs it hasn’t approved. Most wordings leave room for your own provider with the insurer’s consent, so the first call is to the insurer, and the second is to your IT person.

Does cyber insurance pay a ransom?

Some policies can reimburse an extortion payment, but only with the insurer’s prior consent, only where paying is legal (sanctions laws can forbid it), and often under a separate sub-limit, excess or coinsurance. Paying first and claiming later is the pattern every wording we read is written to prevent.

Is a fake invoice or changed bank details covered?

Often only as an optional extra, sometimes not at all. Emergence and DUAL offer it as optional cover with their own sub-limits and reporting deadlines; Delta’s wording excludes funds-transfer loss; Chubb’s covers theft by a third party’s malicious access but excludes employees’ own acts. The schedule is what tells you whether yours has it.

Is this advice for my business?

No. This guide is general information about what published policy wordings say. It doesn’t consider your objectives, financial situation or needs. Read the PDS and policy wording for any cover you are considering, and talk to a broker if something in yours is unclear.

Sources

Policy wordings, read in full in September 2026:

Public information:

More plain-English reading in Gary’s guides.

Important

This guide is general information only and is not personal advice. It doesn’t take into account your objectives, financial situation or needs. It summarises published documents as they stood when we read them; insurers change their wordings, and a policy’s schedule and endorsements can change how its wording applies. Quotations are reproduced for commentary and are accurate to the versions listed. Before deciding on any cover, read the PDS, policy wording and Target Market Determination for that product. Gary is not suggesting any of the insurers named is, or isn’t, right for your business.

Want to see what cyber cover costs you?

One form, the PDS beside every price, and a broker to ask when a condition doesn’t make sense.