Australian cyber insurance is small, newly measured and, for the first time, consistently profitable. Cyber gross written premium was AUD $32 million in the March 2026 quarter, under 0.2% of industry premium, with about 6,000 risks written. From 1 July 2026 APRA publishes cyber as a standalone product category, and survey-measured uptake is still falling.
This page exists because the primary source is hard to link to. APRA publishes its cyber figures as spreadsheet downloads, and only carved cyber insurance out as a standalone category in its claims database in July 2026, so most of what circulates online is second-hand and undated. Frontrow maintains this page as a plain-English, sourced summary of the official numbers. Every figure names its source and reporting period, and widely quoted uptake percentages with no traceable primary source have been deliberately left out.
Key statistics at a glance
- Australian cyber insurance gross written premium was AUD $32 million in the March 2026 quarter, and has never exceeded AUD $73 million in any quarter of APRA's current dataset, which begins in September 2023 (Insurance Business analysis of APRA Quarterly General Insurance Performance Statistics, released 29 May 2026).
- Cyber accounts for less than 0.2% of total Australian general insurance gross written premium in any quarter (Insurance Business analysis of APRA quarterly data, May 2026).
- About 6,000 cyber risks were written in the March 2026 quarter, against 4.78 million domestic motor risks and 3.16 million householders risks in the same quarter (Insurance Business analysis of APRA quarterly data, May 2026).
- The cyber class posted a positive insurance service result in three consecutive quarters: AUD $17 million in September 2025, AUD $10 million in December 2025 and AUD $10 million in March 2026 (Insurance Business analysis of APRA quarterly data, May 2026).
- From July 2026, APRA publishes cyber insurance and management liability as standalone product categories in the National Claims and Policies Database for the first time, after finalising its response to consultation on 1 July 2026 (APRA, National Claims and Policies Database statistics, July 2026).
- The share of respondents to the AIC's Australian Cybercrime Survey who said they purchased or continued to have cyber insurance fell from 4.6% in 2024 to 3.7% in 2025 (AIC, Cybercrime in Australia 2025, published June 2026).
How many Australian businesses actually have cyber insurance?
No official statistic answers this directly. The uptake percentages that circulate in vendor marketing have no traceable primary source, so this page omits them. The closest measured signals are APRA's policy volumes and the Australian Institute of Criminology's annual survey, and both point the same way: uptake is very low and not growing.
On volumes, the cyber class recorded about 6,000 risks written in the March 2026 quarter, a rough proxy for policies sold. In the same quarter insurers wrote 4.78 million domestic motor risks and 3.16 million householders risks (Insurance Business analysis of APRA Quarterly General Insurance Performance Statistics, released 29 May 2026). Against the population of Australian businesses carrying digital risk, standalone cyber cover is reaching a very small fraction of the potential market.
On the survey side, the AIC's Cybercrime in Australia 2025 report, published June 2026, surveyed 10,593 online Australians recruited from online panels between May and July 2025. The share of respondents who said they had purchased or continued to have cyber insurance in the previous 12 months fell from 4.6% in 2024 to 3.7% in 2025, a statistically significant decline. That survey measures individual online Australians, including sole traders and SME owner-operators among them, not a census of businesses, so it is a trend indicator rather than a business uptake rate. The direction is consistent with the flat APRA volume figures.
Is cyber insurance profitable in Australia?
Recently, yes, and for the first time consistently. The cyber class posted a positive insurance service result in each of the three most recent reported quarters: AUD $17 million in September 2025, AUD $10 million in December 2025 and AUD $10 million in March 2026 (Insurance Business analysis of APRA quarterly data released 29 May 2026). Across the seven quarters before that run, the result alternated between modest profits and modest losses. Net claims incurred have rarely exceeded AUD $20 million in any quarter of the dataset.
Insurers still price the class as an uncertain one. APRA's risk margin benchmarking shows cyber carrying a weighted average outstanding claims risk margin of 14.7%, roughly double domestic motor's 7.4% (Insurance Business analysis of APRA risk margin data, June 2026). In plain terms, the market is making money on cyber but still reserves for it as one of the harder classes to predict.
That combination is the striking part of the 2026 data: a product line that is consistently profitable, covering a risk that is demonstrably growing, would normally attract premium growth. The APRA volume figures do not yet show it. The constraint is not underwriting economics, it is that most Australian businesses are not buying.
What changed on 1 July 2026?
On 1 July 2026 APRA finalised its response to consultation on a non-confidentiality determination, and days later published its redesigned National Claims and Policies Database statistics with cyber insurance and management liability as standalone product categories for the first time (APRA, 3 July 2026). Until this release, cyber policies were reported inside a broader public liability category and management liability sat within professional indemnity, so neither line was separately visible in published claims data (Insurance Business, July 2026).
- The NCPD publication is now a set of downloadable files with cyber insurance and management liability broken out as their own product categories (APRA, July 2026).
- Published figures carry privacy masking, with a process for requesting access to unmasked data (APRA, July 2026).
- The first refreshed publication covers data reported up to 31 December 2024, with 2025 figures to follow later in 2026 after validation (Insurance Business, July 2026).
- APRA has said the change reflects the market's rapid growth and a lack of usable data on how these products are performing, as reported by Insurance Business in July 2026.
Why it matters: cyber has been one of the few classes insurers could not price off published historical claims experience, a gap the Insurance Council of Australia has repeatedly linked to underinsurance. Standalone claims and policy data will not fix that overnight, but it makes the market measurable, and this page tracks what the measurements say as each release lands.
What do insurers require before they'll cover you?
Frontrow's separate guide to what Australian cyber insurers actually require in 2026 covers proposal forms, minimum controls and claim-denial traps in detail. The short version: insurers now expect evidence of multi-factor authentication on email and remote access, a working patching cadence, tested backups that an attacker cannot reach, and some form of endpoint detection, and the answers on a proposal form are verified when a claim is lodged, not when the policy is sold.
Try it
Insurers ask Essential Eight questions — score yourself first
The controls cyber insurance proposals ask about map closely to the Essential Eight, so scoring your Microsoft 365 environment against it shows how your answers will read before an underwriter or claims assessor does.
Score each of the 8 strategies
Where are you on the Essential Eight — honestly?
Eight strategies. Four levels each. Pick the statement closest to your reality today. We'll map it to the Microsoft 365 tooling that closes the gap.
What's your target Maturity Level?
Maturity Level 2 — most orgs' pragmatic target
- 01
Application control
Only approved applications can execute on workstations and servers.
- 02
Patch applications
Internet-facing apps, browsers, Office, PDF readers patched promptly.
- 03
Microsoft Office macros
Macros disabled unless from trusted locations and signed by a trusted publisher.
- 04
User application hardening
Web browsers and productivity apps hardened against the most common attacks.
- 05
Restrict administrative privileges
Admin accounts limited, separated and reviewed — the crown jewels of the tenant.
- 06
Patch operating systems
Operating system patches applied on a schedule that matches the risk.
- 07
Multi-factor authentication
MFA everywhere that matters — privileged accounts, remote access, important data.
- 08
Regular backups
Backups of important data, configuration and software — and restores you have actually tested.
Statistics checked July 2026 against the sources named above. APRA publishes its Quarterly General Insurance Performance Statistics roughly eight to nine weeks after each quarter closes; the March 2026 edition arrived on 29 May 2026, which puts the June 2026 quarter edition, the first quarterly release since cyber became a standalone published category, in late August or early September 2026. Frontrow will update this page when that release lands, and again when APRA publishes the NCPD's 2025 data later in 2026.