Having Cyber Insurance Is Not the Same as Being Cyber Ready

Having Cyber Insurance Is Not the Same as Being Cyber Ready

Plenty of clients treat buying a cyber policy as the end of the job when it is really the start of it. You can see why the confidence is there. MinterEllison’s August 2026 Cyber Risk report found 94% of surveyed Australian organisations now hold cyber insurance, which shows how far the risk has travelled from an IT problem to a board-level one. The trouble is that the policy is where a lot of them stop, and a policy cannot make up for weak security controls, a wording that does not fit the business, or an incident response plan nobody has ever tested.

Four gaps usually hide behind “we have cyber insurance.” The coverage gap is the first, where limits and sub-limits do not match the real cost of a major outage, a forensic investigation or a funds-transfer loss. The control gap is next, where the business no longer meets the security conditions or the representations made on its proposal form. Then the operational gap, where key people do not know who to call, what to preserve or how to contain an incident in the first hour. Last is the supplier and AI gap, where new technology and third-party vendors shift a client’s exposure faster than the policy gets reviewed.

That final point is timely. MinterEllison’s 2026 report centres on the implications of AI for cyber risk, which is a clean prompt to get clients revisiting assumptions that may already be out of date.

A broker-led annual cyber review keeps all four gaps in view. Confirm which systems, customer data and payment processes actually run the business. Review MFA, patching, backup and recovery arrangements with the client’s IT provider rather than taking a form at face value. Ask directly whether the business has changed its use of cloud platforms, outsourced technology or AI-enabled tools since last year. Test the claims-response pathway end to end, so it is clear who notifies the insurer, broker, IT provider, lawyer and affected customers, and in what order. Then review the policy elements that decide a claim: business interruption, cybercrime and social engineering, incident-response vendors, exclusions and retentions.

The goal is not to turn every broker into an IT specialist. It is to make sure clients understand that insurance, controls and response planning only work when they work together.

More on this theme in the cyber patch trap, why cyber is now a condition of doing business, locking in better cover in 2026, and how staying educated prevents costly coverage gaps. On the AI angle, see what the ASIC 2026 outlook means for brokers.

Better Broker supports ARs with ongoing education, technology infrastructure and placement insight, so members can run practical cyber-risk conversations instead of simply selling a policy at renewal. If you want a review framework you can reuse, we can help you build one.