Practical guide · As at 28 July 2026

The cyber insurance buyer's guide

How to actually read a policy, what to ask your broker, the red flags that predict claim pain, and a negotiation checklist — written for Australian buyers first, global buyers second.

How to read a cyber policy (in this order)

  1. The schedule first. Limits, excess, retro date, and — critically — every sub-limit and co-insurance percentage. The schedule overrides your assumptions about the wording.
  2. Exclusions second. Especially war/state-actor (which LMA variant?), infrastructure/utility failure, "failure to maintain" security, prior/known circumstances, and dishonesty. What the insuring clauses give, exclusions take away.
  3. Conditions third. Anything called a "condition precedent", notification deadlines, consent requirements before incurring costs, and panel/vendor obligations.
  4. Definitions fourth. "Computer system" (does it include cloud/SaaS you rely on?), "insured", "claim", "cyber event", "direct financial loss" — Inchcape turned on the word "direct".
  5. Insuring clauses last. Map each of your top five realistic loss scenarios (ransomware, BEC, privacy breach, supplier outage, insider) to the exact clause you'd claim under, at what sub-limit, minus what excess and co-insurance.
  6. Then the proposal form. Re-read every answer as if an insurer's lawyer will audit it post-breach — because after a large claim, one may. See Travelers v ICS.

Questions to ask your broker

Cover shape

  • Which war/state-actor exclusion is used — LMA5564, LMA5567A/B, or a proprietary clause? Who bears the burden of attribution?
  • List every sub-limit and co-insurance percentage in one table. Which apply to ransomware payments, BEC/social engineering, and systemic events?
  • Is cybercrime/social engineering cover included or an optional extension? (In some AU products, e.g. Emergence CEP, it's optional.)
  • What's the retroactive date, and does switching insurers reset it?
  • Does "computer system" include our cloud, SaaS and managed service providers? Is contingent BI (supplier outage) covered, at what sub-limit and waiting period?

Claims mechanics

  • Are any obligations conditions precedent? What exactly is the notification deadline and whose knowledge starts the clock?
  • Can we endorse our preferred IR firm, lawyers and forensics onto the policy now? What emergency costs can we incur before consent?
  • What is this insurer's claims record — has it litigated coverage against its own insureds? (Ask for specifics, not vibes.)
  • Who signs the proposal, and have our IT leads verified every security answer as true enterprise-wide, not aspirational?

Australian specifics

  • How do s54 Insurance Contracts Act protections interact with this wording's conditions precedent? (AFCA's approach to s54.)
  • Does the policy's breach-response cover align with our Privacy Act / OAIC notifiable data breach obligations and (if applicable) APRA CPS 234 incident reporting and SOCI Act obligations?
  • Sanctions check: will the insurer/negotiator verify a ransom payment isn't to a sanctioned entity, and who carries that risk?

Red flags

Negotiation checklist

  1. War exclusion: LMA5567A/B-type threshold wording, collateral-victim carve-back, attribution mechanics agreed.
  2. Warranties: knowledge-qualified, severable, scoped to named systems; application co-signed by the control owner.
  3. Sub-limits: cybercrime/BEC raised to match real payment exposure; ransomware and BI at full limit.
  4. Co-insurance: removed, or traded for a higher fixed excess.
  5. Panels: your IR firm, forensics and legal counsel endorsed pre-bind; emergency-cost carve-out confirmed.
  6. Notice: "as soon as practicable after senior officer awareness"; circumstance notification before each renewal.
  7. Retro date: earliest available; continuity preserved on any insurer switch.
  8. Betterment: carve-back for security upgrades required to restore safely.
  9. Dishonesty: limited to senior management with final-adjudication trigger and innocent-insured protection.
  10. Aggregation: run your worst-case scenario through the clause; consider limit reinstatement.

Glossary

Condition precedent
An obligation you must satisfy before the insurer's obligation to pay arises. Breach can defeat the claim regardless of merit (in Australia, s54 ICA may soften this where the breach didn't cause the loss).
Warranty
A promise that something is and will remain true (e.g. "MFA is enabled"). Breach can void cover; misstatement on the proposal can support rescission of the whole policy.
Sub-limit
A lower cap inside your headline limit for a particular loss type (e.g. $250k for social engineering inside a $5m policy).
Co-insurance
A percentage of each loss you must bear yourself on top of the excess.
Retroactive date
Events originating before this date aren't covered, however recently discovered.
Betterment
Improvement beyond pre-incident state during rebuild — typically excluded.
Aggregation
Rules deciding whether multiple events count as one claim (one limit/one excess) or several.
Condition subsequent / claims-made
Cyber policies generally respond to claims made and notified during the period — late notification of known circumstances is the classic trap at renewal.
PDS
Product Disclosure Statement — the Australian retail disclosure document. Read the full policy wording too; the PDS is a summary.
LMA clauses
Model wordings from the Lloyd's Market Association, e.g. the cyber war exclusion suite mandated across Lloyd's cyber since Bulletin Y5381.
Panel
The insurer's pre-approved incident response, legal and forensic vendors, often mandatory or consent-gated.
Rescission
Unwinding the policy as if it never existed, typically for misrepresentation — the outcome in Travelers v ICS.

The regulatory backdrop (Australia)

Cyber insurance sits inside a tightening regulatory frame: APRA now collects standalone cyber insurance claims data in the National Claims and Policies Database, APRA-regulated entities carry CPS 234 information-security obligations, and ASIC has signalled enforcement interest in cyber risk governance — boards increasingly need to show both real controls and coherent risk transfer. Insurance is the residual-risk layer, not a substitute for the controls your insurer will audit after a claim anyway.

Disclaimer. This guide is general information only, prepared without regard to your objectives, financial situation or needs. It is not legal or financial advice and not a recommendation for any product or insurer. Policy wordings change frequently and vary by product and endorsement — always read the current PDS and full wording and obtain advice from a licensed insurance broker, adviser or lawyer. As at 28 July 2026.