Cyber insurance is a business insurance policy that covers the costs of a data breach, ransomware attack, or other digital incident - things like forensic investigation, legal fees, customer notification, and business interruption. Most small business owners have never needed to think hard about it. That's changing fast in 2026, and the reason isn't just rising cybercrime - it's AI.
The Allianz Risk Barometer 2026 found artificial intelligence is now Australia's number one ranked business risk, cited by 61% of respondents - up from eighth place and just 12% the year before. Andy Doran, General Manager Underwriting at Allianz Australia, put it plainly:
"AI and Cyber our top two risks here in Australia. Australian businesses in all sectors and sizes are being influenced by this new technology." — Andy Doran, General Manager Underwriting, Allianz Australia
Key Takeaways
- AI is now Australia's #1 ranked business risk (61% of respondents), up from 8th place in 2025, according to the Allianz Risk Barometer 2026.
- An estimated 25% of Australian SME owners say cybercrime affected their business in the past 12 months, and the average reported cost is now $56,600 (Australian Institute of Criminology; ASD/ACSC).
- Insurers now routinely benchmark applicants against the ACSC's Essential Eight - Maturity Level 1 is becoming the baseline for affordable cover.
- Typical 2026 SME premiums range from roughly $3,000 to $50,000+ a year for $500,000 to $5 million in cover, depending on revenue, sector, and security controls.
- Cyber insurance uptake has actually fallen two years running even as risk rises - the gap isn't insurer profitability, it's awareness and cost.
How exposed are Australian small businesses to cybercrime?
An estimated one in four Australian SME owners - 25.0% - say cybercrime affected their business in the past 12 months, according to the Australian Institute of Criminology's Cybercrime in Australia 2025 report (Statistical Report 59, released 30 June 2026). This isn't a niche problem hitting one industry - it's broad-based, and small businesses are targeted precisely because their defences tend to be thinner than a large enterprise's.
Of the SME owners affected, the AIC found disruption to everyday business function was the most common harm (28.7%), followed by additional business expenses like forensic and legal costs (16.4%), loss of information (15.9%), damage to reputation or revenue (14.1%), impacts on staff (10.0%), and legal or regulatory issues (7.9%). The financial toll backs this up: the ASD's Annual Cyber Threat Report 2024-25 found the average self-reported cost of cybercrime for small business rose 14% year-on-year to $56,600, against $80,850 across all business sizes. The Australian Signals Directorate received over 84,700 cybercrime reports that year - about one every six minutes.
Pro tip
Common mistake: Assuming your business is "too small to target." Attackers aren't singling out individual small businesses - they're running automated attacks at scale and taking whoever responds. The AIC's 25% exposure figure and the ASD's one-report-every-six-minutes rate both point the same way: this is a volume game, not a targeted one, which is exactly why insurers now price it as a near-certainty rather than a remote risk.
What do insurers actually require before they'll cover you?
Insurers now routinely benchmark applicants against the Australian Cyber Security Centre's Essential Eight maturity model before offering cover, and Maturity Level 1 is becoming the threshold for reasonably priced policies. That baseline covers multi-factor authentication (MFA) on email, remote access and admin accounts, application control, prompt patching, Office macro hardening, restricted admin privileges, and regular, tested backups.
Expect specific questions, not a tick-box form: how many staff actually have MFA enabled, how quickly known vulnerabilities get patched, and whether backups have been test-restored recently rather than just scheduled. Falling short doesn't just push your premium up - insurers are increasingly declining cover outright for businesses that can't evidence these controls. The upside is that none of the Essential Eight requires enterprise budgets: MFA, a patching routine, and a tested backup plan are achievable for almost any small business within a few weeks, and they're the same controls that reduce your odds of ever needing to claim in the first place.
How much does cyber insurance cost for a small business in Australia?
Premiums for Australian SMEs typically run from around $3,000 to $50,000+ a year, for policy limits (aggregates) usually between $500,000 and $5 million. Where a business sits in that range depends heavily on revenue, sector, claims history, and - increasingly - how well it can evidence the Essential Eight controls above.
| Risk profile | Typical indicators | Illustrative annual premium* |
|---|---|---|
| Lower risk | Modest revenue, MFA enforced organisation-wide, tested backups, clean claims history | Lower end of the $3,000-$50,000+ range |
| Moderate risk | Mid-size revenue, partial controls (e.g. MFA in place but backups untested), no major prior incidents | Mid-range |
| Higher risk | Larger revenue or a data-sensitive sector, gaps in Essential Eight controls, or a claims history | Upper end of the range |
*Ranges are directional and vary by insurer, sector, and underwriting year - always get quotes from more than one broker rather than budgeting off a single figure.
Given the average cyber incident already costs a small business $56,600, even a premium at the higher end of that range is often a fraction of the potential loss. The businesses that get the best pricing are consistently the ones that can hand an underwriter evidence, not just assurances, that MFA, patching, and backups are actually happening.
Why is cyber insurance uptake falling even as risk rises?
Counterintuitively, cyber insurance uptake has fallen for two years running even as exposure grows. The AIC's Australian Cybercrime Survey - a national survey of 10,593 online Australians, not an SME-only sample - found the share holding cyber insurance dropped from 4.6% in 2024 to 3.7% in 2025. It's a general population figure rather than a small-business-specific one, but alongside the SME exposure data above it points to the same widening protection gap: awareness and cost are outpacing willingness to buy, even as the risk itself climbs.
That gap isn't there because insurers are struggling to make cyber insurance profitable. APRA data shows gross written premium for the cyber class was $32 million in the March 2026 quarter - under 0.2% of total industry premium, reflecting how small the market still is - yet the class posted positive insurance service results of $17 million, $10 million, and $10 million across the September 2025, December 2025, and March 2026 quarters. Insurers are pricing this class carefully and it's working for them; the shortfall is on the demand side, not the supply side.
How can AI-powered security tools help you get better cover and lower premiums?
The practical answer is evidence: insurers want proof that MFA, patching, and backup testing are actually happening, not just described in a policy document, and AI-powered security tools generate that proof as a byproduct of running them day to day. Our guide to AI cybersecurity tools for small business covers the specific products - AI-driven MDR tools like Huntress and CrowdStrike Falcon Go, and identity platforms like 1Password and Microsoft Entra are common choices for Australian SMBs, and each keeps logs of exactly the things an underwriter asks about: MFA enforcement, anomaly detection, and login monitoring.
That audit trail matters twice. It's what an underwriter wants to see at renewal time, and it's also what genuinely lowers your odds of having to claim in the first place - a business that can show continuous MFA enforcement and tested backups is a fundamentally lower-risk applicant, not just a better-documented one. If you haven't audited where your business actually stands against the Essential Eight, our guide to auditing your business's AI readiness walks through the same kind of gap analysis, and the AI Insights blog covers the mechanics of anomaly-based threat detection if you want the technical detail behind how these tools actually catch something before it becomes a claim. The same MFA and access logging that satisfies an insurer also protects the customer data sitting in your CRM - Sales Mastery's guide to securing customer data in sales tools covers that side of it.
Getting this evidence trail in place is also where the cost of the exercise tends to surprise people - usually favourably. Our breakdown of AI implementation ROI for service businesses covers how to weigh a tooling investment like this against what it actually saves you, whether that's a lower premium, a faster claims process, or - ideally - never needing to claim at all. The staged rollout in our AI implementation playbook works just as well for security tooling as it does for any other AI project - start with one control, evidence it properly, then move to the next. If you'd rather have someone map your specific gaps against the Essential Eight and the controls insurers are asking about, our AI strategy and implementation service is where that kind of audit fits at GrowthGear.
Cyber Insurance for Small Business Australia: Summary
| Question | Answer |
|---|---|
| Why does this matter now? | AI is Australia's #1 ranked business risk (61%, Allianz Risk Barometer 2026), and insurers are tightening requirements in response |
| How exposed are SMEs? | 25% affected in the past 12 months; average cost $56,600 (AIC; ASD/ACSC) |
| What do insurers require? | Essential Eight Maturity Level 1: MFA, patching, macro hardening, admin restrictions, tested backups |
| What does cover cost? | Roughly $3,000-$50,000+/year for $500,000-$5 million in cover |
| Why is uptake still low? | Awareness and cost, not insurer profitability - APRA data shows the class is profitable |
| What helps most? | AI security tools that generate the MFA/patch/backup evidence insurers ask for |
Frequently Asked Questions
Given the average cyber incident costs a small business $56,600 (ASD/ACSC, 2024-25) and roughly 1 in 4 SME owners report being affected within 12 months (AIC, 2025), cover priced from around $3,000 a year is generally a small fraction of the potential loss for most businesses.
Insurers now routinely benchmark applicants against the Essential Eight maturity model, and Maturity Level 1 - MFA, patching, macro hardening, admin restrictions, and tested backups - is becoming the baseline businesses must evidence to get affordably priced cover.
Typical 2026 premiums range from roughly $3,000 to $50,000+ a year for $500,000 to $5 million in cover, depending on revenue, sector, claims history, and how well you can evidence your security controls.
The Allianz Risk Barometer 2026 found 61% of Australian respondents rank AI as their top business risk, up from 8th place (12%) in 2025, reflecting how quickly AI adoption has introduced new operational and security exposure alongside its benefits.
Yes - security tools reduce the likelihood of an incident but don't cover the costs if one still happens, such as legal fees, customer notification, or business interruption. Insurers increasingly view the two as complementary, and evidence from your security tools can help you qualify for better pricing.
The 25% exposure figure comes from SME owners specifically (AIC, 2025), while the 3.7% insurance uptake figure comes from a general population survey of online Australians, not a small-business-only sample - together they illustrate a wide gap between risk and cover, not a single directly comparable statistic.
Insurers may decline cover outright or offer it with higher premiums, higher excesses, or specific exclusions for unpatched systems. Most of the baseline controls - MFA, a patching routine, tested backups - are achievable within a few weeks even without dedicated IT staff.
Sources & References
- Allianz Risk Barometer 2026 — AI ranked Australia's #1 business risk at 61%, up from 8th place (12%) in 2025 (2026)
- Australian Institute of Criminology, Cybercrime in Australia 2025 — 25.0% of SME owners affected by cybercrime in the prior 12 months; cyber insurance uptake fell from 4.6% (2024) to 3.7% (2025) (2026)
- ASD Annual Cyber Threat Report 2024-25 — average self-reported cybercrime cost for small business rose 14% to $56,600; over 84,700 reports received (2025)
- ACSC Essential Eight Maturity Model — the maturity levels insurers now benchmark applicants against (2026)
- Insurance Business Australia, "Cyber insurance uptake falls as online risks remain widespread" — APRA cyber class premium and profitability data (2026)



