Brought to you by:

ICA plugs cyber cover to inquiry

The value of cyber insurance has been promoted by the Insurance Council of Australia in its response to a Parliamentary inquiry.

But the submission to the House Select Committee on Cyber Security for Small to Medium Sized Businesses stops short of calling for any specific actions.

The ICA said it welcomed the committee’s interest in the role of cyber insurance within the broader cyber security ecosystem for small and medium sized organisations.

It warns that “the volume of cyber threats small businesses face will not dissipate, and as the Australian economy increasingly digitises, we should expect that volume to grow.

It says the Australian cyber insurance industry, which offers first and third-party cover, is “highly innovative and has responded to the emerging needs of businesses”.

“Many cyber insurers actively assist their policyholders by incentivising proactive resilience that help customers build stronger defences and improve their own understanding of the cyber risks. In other words, prevention is now built into the policy, not sold as an add-on.”

But it concedes that “around the world, cyber insurance take-up among small businesses is understood to be low. This is particularly concerning given the vulnerabilities facing small business, which are hit much harder by cyber incidents, with severity of claims increasing and more and more small businesses targeted.”

The ICA warns that, increasingly, a small business’ cyber maturity is likely to have a material impact on its capacity to participate in the supply chains of large corporates, as governments and regulators require stricter cyber protocols of big companies in certain industries.

The submission says “it is incumbent on government and larger entities to be transparent about the impact these regulations will have on smaller organisations to meet the relevant requirements and participate in same supply chains".

The Australian Institute of Company Directors mentions cyber insurance in its submission, saying it can "form a useful part of a broader cyber risk management framework, and may encourage organisations to adopt stronger controls”.

“However, affordability, exclusions and minimum eligibility requirements can make suitable cover difficult for smaller organisations to obtain. Insurance should complement, rather than substitute for, investment in prevention, preparedness and resilience.”

Click here to read the submissions.