Frontrow Technology
← All insights & guides
Guide

Statistics

Australian cyber insurance statistics 2026: the APRA numbers

Cyber GWP was AUD $32m in the March 2026 quarter, under 0.2% of industry premium, and uptake fell in 2025. APRA and AIC figures. Checked July 2026.

Sam Williams · 8 August 2026 · 8 min read

Australian cyber insurance is small, newly measured and, for the first time, consistently profitable. Cyber gross written premium was AUD $32 million in the March 2026 quarter, under 0.2% of industry premium, with about 6,000 risks written. From 1 July 2026 APRA publishes cyber as a standalone product category, and survey-measured uptake is still falling.

This page exists because the primary source is hard to link to. APRA publishes its cyber figures as spreadsheet downloads, and only carved cyber insurance out as a standalone category in its claims database in July 2026, so most of what circulates online is second-hand and undated. Frontrow maintains this page as a plain-English, sourced summary of the official numbers. Every figure names its source and reporting period, and widely quoted uptake percentages with no traceable primary source have been deliberately left out.

Key statistics at a glance

  • Australian cyber insurance gross written premium was AUD $32 million in the March 2026 quarter, and has never exceeded AUD $73 million in any quarter of APRA's current dataset, which begins in September 2023 (Insurance Business analysis of APRA Quarterly General Insurance Performance Statistics, released 29 May 2026).
  • Cyber accounts for less than 0.2% of total Australian general insurance gross written premium in any quarter (Insurance Business analysis of APRA quarterly data, May 2026).
  • About 6,000 cyber risks were written in the March 2026 quarter, against 4.78 million domestic motor risks and 3.16 million householders risks in the same quarter (Insurance Business analysis of APRA quarterly data, May 2026).
  • The cyber class posted a positive insurance service result in three consecutive quarters: AUD $17 million in September 2025, AUD $10 million in December 2025 and AUD $10 million in March 2026 (Insurance Business analysis of APRA quarterly data, May 2026).
  • From July 2026, APRA publishes cyber insurance and management liability as standalone product categories in the National Claims and Policies Database for the first time, after finalising its response to consultation on 1 July 2026 (APRA, National Claims and Policies Database statistics, July 2026).
  • The share of respondents to the AIC's Australian Cybercrime Survey who said they purchased or continued to have cyber insurance fell from 4.6% in 2024 to 3.7% in 2025 (AIC, Cybercrime in Australia 2025, published June 2026).

How many Australian businesses actually have cyber insurance?

No official statistic answers this directly. The uptake percentages that circulate in vendor marketing have no traceable primary source, so this page omits them. The closest measured signals are APRA's policy volumes and the Australian Institute of Criminology's annual survey, and both point the same way: uptake is very low and not growing.

On volumes, the cyber class recorded about 6,000 risks written in the March 2026 quarter, a rough proxy for policies sold. In the same quarter insurers wrote 4.78 million domestic motor risks and 3.16 million householders risks (Insurance Business analysis of APRA Quarterly General Insurance Performance Statistics, released 29 May 2026). Against the population of Australian businesses carrying digital risk, standalone cyber cover is reaching a very small fraction of the potential market.

On the survey side, the AIC's Cybercrime in Australia 2025 report, published June 2026, surveyed 10,593 online Australians recruited from online panels between May and July 2025. The share of respondents who said they had purchased or continued to have cyber insurance in the previous 12 months fell from 4.6% in 2024 to 3.7% in 2025, a statistically significant decline. That survey measures individual online Australians, including sole traders and SME owner-operators among them, not a census of businesses, so it is a trend indicator rather than a business uptake rate. The direction is consistent with the flat APRA volume figures.

Is cyber insurance profitable in Australia?

Recently, yes, and for the first time consistently. The cyber class posted a positive insurance service result in each of the three most recent reported quarters: AUD $17 million in September 2025, AUD $10 million in December 2025 and AUD $10 million in March 2026 (Insurance Business analysis of APRA quarterly data released 29 May 2026). Across the seven quarters before that run, the result alternated between modest profits and modest losses. Net claims incurred have rarely exceeded AUD $20 million in any quarter of the dataset.

Insurers still price the class as an uncertain one. APRA's risk margin benchmarking shows cyber carrying a weighted average outstanding claims risk margin of 14.7%, roughly double domestic motor's 7.4% (Insurance Business analysis of APRA risk margin data, June 2026). In plain terms, the market is making money on cyber but still reserves for it as one of the harder classes to predict.

That combination is the striking part of the 2026 data: a product line that is consistently profitable, covering a risk that is demonstrably growing, would normally attract premium growth. The APRA volume figures do not yet show it. The constraint is not underwriting economics, it is that most Australian businesses are not buying.

What changed on 1 July 2026?

On 1 July 2026 APRA finalised its response to consultation on a non-confidentiality determination, and days later published its redesigned National Claims and Policies Database statistics with cyber insurance and management liability as standalone product categories for the first time (APRA, 3 July 2026). Until this release, cyber policies were reported inside a broader public liability category and management liability sat within professional indemnity, so neither line was separately visible in published claims data (Insurance Business, July 2026).

  • The NCPD publication is now a set of downloadable files with cyber insurance and management liability broken out as their own product categories (APRA, July 2026).
  • Published figures carry privacy masking, with a process for requesting access to unmasked data (APRA, July 2026).
  • The first refreshed publication covers data reported up to 31 December 2024, with 2025 figures to follow later in 2026 after validation (Insurance Business, July 2026).
  • APRA has said the change reflects the market's rapid growth and a lack of usable data on how these products are performing, as reported by Insurance Business in July 2026.

Why it matters: cyber has been one of the few classes insurers could not price off published historical claims experience, a gap the Insurance Council of Australia has repeatedly linked to underinsurance. Standalone claims and policy data will not fix that overnight, but it makes the market measurable, and this page tracks what the measurements say as each release lands.

What do insurers require before they'll cover you?

Frontrow's separate guide to what Australian cyber insurers actually require in 2026 covers proposal forms, minimum controls and claim-denial traps in detail. The short version: insurers now expect evidence of multi-factor authentication on email and remote access, a working patching cadence, tested backups that an attacker cannot reach, and some form of endpoint detection, and the answers on a proposal form are verified when a claim is lodged, not when the policy is sold.

Try it

Insurers ask Essential Eight questions — score yourself first

The controls cyber insurance proposals ask about map closely to the Essential Eight, so scoring your Microsoft 365 environment against it shows how your answers will read before an underwriter or claims assessor does.

Score each of the 8 strategies

Where are you on the Essential Eight — honestly?

Eight strategies. Four levels each. Pick the statement closest to your reality today. We'll map it to the Microsoft 365 tooling that closes the gap.

What's your target Maturity Level?

Maturity Level 2 — most orgs' pragmatic target

  • 01

    Application control

    Only approved applications can execute on workstations and servers.

  • 02

    Patch applications

    Internet-facing apps, browsers, Office, PDF readers patched promptly.

  • 03

    Microsoft Office macros

    Macros disabled unless from trusted locations and signed by a trusted publisher.

  • 04

    User application hardening

    Web browsers and productivity apps hardened against the most common attacks.

  • 05

    Restrict administrative privileges

    Admin accounts limited, separated and reviewed — the crown jewels of the tenant.

  • 06

    Patch operating systems

    Operating system patches applied on a schedule that matches the risk.

  • 07

    Multi-factor authentication

    MFA everywhere that matters — privileged accounts, remote access, important data.

  • 08

    Regular backups

    Backups of important data, configuration and software — and restores you have actually tested.

Statistics checked July 2026 against the sources named above. APRA publishes its Quarterly General Insurance Performance Statistics roughly eight to nine weeks after each quarter closes; the March 2026 edition arrived on 29 May 2026, which puts the June 2026 quarter edition, the first quarterly release since cyber became a standalone published category, in late August or early September 2026. Frontrow will update this page when that release lands, and again when APRA publishes the NCPD's 2025 data later in 2026.

Common questions

Frequently asked

How big is the Australian cyber insurance market?
Small. Cyber gross written premium was AUD $32 million in the March 2026 quarter and has never exceeded AUD $73 million in any quarter of APRA's current dataset, which begins in September 2023. The class is under 0.2% of total industry premium in any quarter (Insurance Business analysis of APRA quarterly data, May 2026). APRA's figures exclude Lloyd's Australian operations, so the full market is somewhat larger.
Is cyber insurance profitable for Australian insurers?
Yes, recently and consistently. The cyber class posted a positive insurance service result of AUD $17 million in the September 2025 quarter, AUD $10 million in December 2025 and AUD $10 million in March 2026, after seven earlier quarters alternating between modest profits and losses (Insurance Business analysis of APRA quarterly data, May 2026).
What did APRA change on 1 July 2026?
APRA finalised a non-confidentiality determination on 1 July 2026 and published its redesigned National Claims and Policies Database statistics with cyber insurance and management liability as standalone product categories for the first time. Cyber claims and policy data was previously buried inside a broader public liability category (APRA, July 2026).
How many Australian businesses have cyber insurance?
There is no official count, and the uptake percentages often quoted in marketing have no traceable primary source. The measured signals: about 6,000 cyber risks were written in the March 2026 quarter versus 4.78 million domestic motor risks (Insurance Business analysis of APRA quarterly data, May 2026), and the share of AIC survey respondents holding cyber insurance fell from 4.6% in 2024 to 3.7% in 2025 (AIC, Cybercrime in Australia 2025).
What do cyber insurers require before offering cover?
Typical minimums in 2026 are multi-factor authentication on email and remote access, a demonstrated patching cadence, tested backups an attacker cannot reach, and endpoint detection and response. These overlap heavily with the Essential Eight, and proposal-form answers are verified at claim time, so the controls need to be real, not aspirational.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.