Best Cyber Insurance Providers in Australia |
5-Star Cyber  

 

Dark web monitoring and AI-aware underwriting define Australia’s best cyber insurance providers in 2026 

 

By Insurance Business Australia 

Introduction 


No business is too small to be a target, and none is too big to be safe. Identifying the best cyber insurance providers in Australia has never mattered more.  

The Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications across Australia in the 2025 calendar year – the highest total since mandatory reporting began in 2018, and an 8% rise from 2024 – with 716 of those attributed directly to malicious or criminal attacks.  

Layer in the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) Annual Cyber Threat Report for 2024–25, which logged more than 84,700 cybercrime reports – one every six minutes – and the picture is unambiguous.  

Attackers aren’t just chasing headline-grabbing breaches at major corporations; they’re working the middle and lower end of the market, too, where defences are thinner and the payoff is often just as easy. 

02
5-STAR CYBER 2026 DATA INSIGHT

Australian data breach notifications hit a record high in 2025

Notifiable Data Breaches (NDB) scheme — annual notifications and breach causes

Notifications, 2024 vs 2025
1,112
 
2024
1,205
 
2025
↑ 8% year-on-year — highest since the NDB scheme began in 2018
2025 notifications by cause
59% malicious / criminal
Malicious or criminal attack 716
Human error / system fault / other 489
Source: Office of the Australian Information Commissioner (OAIC), Notifiable Data Breaches scheme — 2025 calendar year statistics.

 

 

 

 

The cost of getting this wrong keeps climbing. IBM’s Cost of a Data Breach research puts the average cost of an Australian breach at $4.26 million, and Australians themselves have noticed: the OAIC’s 2026 Australian Community Attitudes to Privacy Survey found 82% of the public now rank data breaches as their top privacy concern, up from 74% in 2023.  

Artificial intelligence has poured fuel on the fire, and AI is fuelling a rise in cybercrime across Asia-Pacific at a pace that’s pushed AI to Australia’s number one ranked business risk in the Allianz Risk Barometer 2026 global risk rankings, ahead of cyber incidents at number two. 

For Australian brokers, that’s exactly why this year’s 5-Star Cyber Report matters. The insurers making this list aren’t just underwriting risk; they’re actively working to shrink it – for the sole trader and the enterprise listed on the Australian Securities Exchange (ASX) alike. It’s also why understanding how brokers actually choose a cyber insurer has become as important a conversation as the coverage itself. 

This year’s 5-Star Cyber Report names AXA XL, Emergence Insurance and Liberty among the best cyber insurance providers in Australia for 2026. They were selected via Insurance Business Australia’s broker and reader community voting process.

Each has built dark web monitoring, AI-aware risk assessment or global incident response directly into their offering – proof that the shift from reactive claims payment to proactive resilience partnership isn’t optional anymore, whatever size client sits across the table.  

These three cyber insurance providers are profiled in depth below as standout examples of that shift. The full 2026 5-Star Cyber list also includes other broker-recognised insurers across the Australian market. 

 
5-STAR CYBER 2026 AT A GLANCE

Key data behind this year's 5-Star Cyber Report

#1risk
AI is Australia's top-ranked business risk in 2026, up from #8
Allianz Risk Barometer 2026, Australia country ranking
1,205
Data breach notifications in Australia in 2025 — a record high
OAIC, +8% year-on-year
60%
Of large cyber claim value driven by ransomware
Allianz Commercial, H1 2025
6min
Average frequency of a reported cybercrime in Australia
ASD's ACSC, FY2024–25
Key takeaways
  • 1 Prevention is now built into the policy, not sold as an add-on — dark web monitoring, executive crisis simulations and complimentary risk consulting feature across this year's winners.
  • 2 No business is too small to be a target — winners are building dedicated products and services for SMEs, not just large enterprise clients.
  • 3 AI cuts both ways — it's accelerating attacker capability while also powering faster underwriting and risk assessment, with human underwriters still making the final call.
  • 4 Broker education is a growth strategy, not a support function, for insurers competing on relationships as much as on coverage.
AXA XL
Emergence Insurance
Liberty
Sources: Allianz Risk Barometer 2026 · OAIC Notifiable Data Breaches scheme · Allianz Commercial cyber claims analysis · ASD's ACSC Annual Cyber Threat Report 2024–25.

 

 

 

Industry context: how Australia’s top cyber insurers are shifting to prevention 

 

The numbers behind the risk 


The data leaves little room for complacency. Cyber has topped the Allianz Risk Barometer as the world’s number one business risk for five consecutive years, and in 2026, it did so by its widest margin yet.  

Allianz Commercial’s cyber claims analysis for 2025 found ransomware accounted for 60% of the value of large cyber claims above €1 million in the first half of the year, while data theft featured in 40% of large claims by value, up from 25% across all of 2024.  

In Australia specifically, the OAIC’s 2025 figures show malicious or criminal attacks now driving the clear majority of reportable breaches, with health, finance and government the most exposed sectors – but, as this year’s 5-Star Cyber winners consistently point out, no sector or business size is exempt. 

01
5-STAR CYBER 2026 DATA INSIGHT

AI now outranks cyber as Australia's top business risk

Top business risks in Australia, ranked — Allianz Risk Barometer 2026

Country-specific ranking for Australia (not the global ranking)

1

Artificial intelligence (AI)

Implementation risk, liability exposure, misinformation

↑ Up from #8
2

Cyber incidents

Cybercrime, IT disruption, malware, data breaches

↓ Down from #1
3

Changes in legislation & regulation

Tariffs and regulatory divergence

↓ Down from #2
4

Climate change

Extreme weather, physical & financial impact

↑ Up two places
Source: Allianz Risk Barometer 2026 — Australia country-specific ranking, Allianz Commercial/Allianz Australia.

 

 

 

Why Australia’s cyber insurers are shifting to prevention 


That combination, with AI lowering the barrier to entry for attackers while simultaneously becoming a defensive tool for insurers, is reshaping what brokers expect from a cyber policy. As Vicky Sheridan, senior claims specialist – cyber at AXA XL in Australia, explains, artificial intelligence is accelerating existing cyber threats by reducing the expertise, time and resources required for threat actors to execute attacks.  

Meanwhile, David Gallagher, vice president and head of cyber and IT liability – Asia Pacific at Liberty, is careful to draw a line around how far insurers let AI go: “What AI cannot replace is our underwriter’s expertise and judgement. It’s always the underwriter who makes the decision about the risk; we never rely on AI for that.” 

Prevention has become the key differentiator brokers are voting for. Dark web monitoring – scanning for stolen credentials and compromised data before they’re weaponised – now sits alongside traditional cover as a core expectation, not an add-on, echoed in Katrina Hickson’s observation, as head of distribution at Emergence Insurance, that prevention has become just as important as the insurance policy itself. 

03
5-STAR CYBER 2026 DATA INSIGHT

Ransomware and data theft drive the biggest cyber payouts

Share of large cyber claim value (claims above €1 million), H1 2025

Ransomware60%
 

Share of the value of large cyber claims (>€1m) in H1 2025

Data theft40%
 
2024: 25%
 

Share of large claim value featuring data theft — up from 25% across all of 2024

Source: Allianz Commercial, cyber claims analysis, Allianz Risk Barometer 2026. Categories are not mutually exclusive — a single large claim can involve both ransomware and data theft.

 

 

 

Profiles of the best cyber insurance providers in Australia 

 

 AXA XL

 

 

A claims-led philosophy


Ask Vicky Sheridan what’s actually changed in the cyber threat landscape, and she doesn’t start with technology. She starts with people. “Business email compromise remains the leading cause of cyber incidents, with social engineering the largest root cause of incidents,” she says.  

It’s a distinction worth sitting with; the technology is almost incidental. The vulnerability is human, and increasingly, it’s being exploited at a scale that individual businesses can’t easily see coming.  


“We’re also seeing growing exposure to cyber risks arising from third-party technology providers,” Sheridan explains, pointing to the Instructure cyber incident, in which a compromise of the Canvas learning management system caused significant service disruption to over 9,000 educational institutions globally.  

The scale of the incident was independently corroborated: cybersecurity outlet Security Affairs and other outlets reported close to 9,000 schools and institutions worldwide were affected.  

“Such incidents underscore the extent to which localised disruptions can trigger cascading effects across interdependent organisations, with the potential to generate material operational, financial and reputational impacts,” she says. 

That systemic view of risk shapes almost everything AXA XL has built over the past 12 months. Artificial intelligence, in Sheridan’s telling, isn’t a future risk to plan for – it’s already here and already changing the maths for insurers. “Artificial intelligence is further accelerating existing cyber threats by reducing the expertise, time and resources required for threat actors to execute attacks,” she says. 
 

Claire Hunter
“One of AXA XL’s key differentiators is our local Cyber Risk Consulting capability, which enables us to provide a comprehensive suite of complimentary pre-loss services to all primary cyber policyholders” Vicky SheridanAXA XL 


AXA XL has been working directly with its incident response partners to track the shift. “Their feedback points to a growing trend of more frequent, indiscriminate attacks leveraging compromised credentials at scale and exploiting software vulnerabilities across multiple targets simultaneously,” Sheridan says.  

Sheridan is careful not to overstate the certainty here. “It’s still too early to draw definitive conclusions,” she says.  

But the direction of travel is clear enough that AXA XL has acted on it, developing a cyber catastrophe management framework in partnership with its Incident Response Manager (IRM). “It’s being built specifically to ensure we’re prepared not only for increases in claim volumes but also for systemic cyber events capable of impacting large parts of the digital ecosystem simultaneously,” she says. 
 

Pre-loss services built for real scenarios 


Raymond Loh, product leader – cyber at AXA XL, describes the philosophy underpinning the policy itself in almost defiant terms. “This is a policy that has been designed by claims experience and learnings rather than theoretical cases,” he says. That’s not a small distinction in an industry that can default to templated wordings.  


“The product’s edge comes from deep technical underwriting expertise where speed, clarity and accessibility are prioritised for both clients and brokers,” Loh says. It is backed by a 24/7 incident response service with a comprehensive panel led by Australia's leading incident response firm – a panel he says has been “tested on hundreds of claims”, not assembled on paper and left untested.  

He is equally direct about what’s included at no extra cost to clients. “Our comprehensive pre-incident services, of which many are provided complimentary to our insureds, include complimentary tabletop exercises, dark web monitoring, etc.,” he says. 

That prevention layer runs deep. Every primary cyber policyholder gets access to Onboarding and Incident Readiness Sessions at policy inception – not a sales formality, but a working session covering cyber threat trends, market developments, policy insights and the incident response process. “It’s designed so clients understand how a claim would be managed in practice well before they ever need to make one,” he says.  

From there, clients can step into Executive Crisis Exercises: interactive simulations for executive leadership and crisis management teams, led by experienced cyber incident specialists, that force participants to navigate critical decisions relating to escalation processes, communications, stakeholder management and business continuity.  

The goal, Sheridan says, is “to strengthen organisational readiness, improve decision-making under pressure and develop the practical reflexes required during a major cyber event” – reflexes that, in her experience, are usually the difference between a contained incident and a chaotic one.
 

Closing the dark web gap 


Dark web exposure is addressed head-on through DarkWebIQ, which gives all cyber insureds – both primary and excess policyholders – 12 months of complimentary monitoring for data theft, ransomware activity and compromised credentials.  


“The service specialises in identifying access-brokers selling stolen login credentials and system access information on criminal marketplaces,” Sheridan explains. “Where a client’s information turns up, an alert is issued immediately, creating an opportunity for proactive intervention before a threat actor can exploit the compromised access data.”  

Enrolment, by design, is almost frictionless. “Clients need only provide a nominated contact and company domain to be automatically onboarded,” she says. 

A
5-STAR CYBER 2026 WINNER

What AXA XL offers

Vicky Sheridan, Senior Claims Specialist – Cyber, AXA XL

DarkWebIQ monitoring

12 months of complimentary dark web monitoring for all primary and excess policyholders

24/7/365 incident response

A cyber first responder available around the clock, every day of the year

Executive Crisis Exercises

Simulations covering deepfake impersonation, supply chain compromise, ransomware and insider events

Cyber Maturity Assessments

Independent evaluation of a client's security landscape to identify capability gaps

Ransomware backup assessment

A 4–5 week resiliency review delivered with global recovery specialist Fenix24

Threat Intelligence Reports

Published twice a year, roughly 20 pages, with no minimum premium threshold to access

Source: Insurance Business Australia interview and 5-Star Cyber 2026 submission, AXA XL Australia.

 

 

 

In AXA XL’s own words 


Q: How has AXA XL expanded its pre-loss services over the past 12 months? 

A: Sheridan says the focus has been on expanding and enhancing our pre-loss services to align more closely with AXA XL’s global cyber offering to deliver greater value beyond the insurance policy itself. Every primary policyholder is now offered a two-hour Executive Crisis Exercise covering scenarios including deepfake impersonation, supply chain compromise, ransomware attacks and malicious insider events.  

Each session is tailored to the client’s organisational structure, cyber readiness and risk profile to ensure a highly realistic and relevant experience. A post-event report follows, providing feedback to the client to elevate their security resilience. 

Q: What does the ransomware backup and resiliency assessment actually involve? 

A: Delivered with global cyber recovery specialist Fenix24, the assessment runs over four to five weeks: information gathering in week one (roughly two hours); interviews with key stakeholders – typically the Chief Information Security Officer (CISO) and Chief Information Officer (CIO) – in week two; technical review sessions with subject matter experts in week three; and analysis, reporting and executive briefings across weeks four and five.  

“The assessment is non-invasive and focuses on survivability and recoverability rather than theoretical controls,” Sheridan says, with clients receiving practical recommendations to strengthen the security, reliability and recoverability of their backup environments. 

Q: Does AXA XL charge extra for its risk consulting services? 

A: No – and Sheridan frames this as a point of principle rather than a marketing line. AXA XL publishes Threat Intelligence Reports twice a year, each around 20 pages, examining emerging cyber threats, evolving attack vectors and our outlook for the year ahead, supplemented by webinars and executive briefings.  

“There is no minimum premium threshold for any of these services,” she says. “AXA XL funds them directly because we believe proactive risk management benefits both our clients and the broader cyber ecosystem.” 

Q: How does AXA XL use its own claims data to sharpen the product? 

A: Sheridan points to the insurer’s inaugural Large Claims Analysis Report, published in 2025, drawing on claims data from across AXA XL’s global portfolio to examine claim trends, emerging threats and evolving risk patterns. “Those insights help clients make better-informed decisions while also allowing us to continuously refine our underwriting and claims practices,” she says. 

Q: Can you describe a case where AXA XL’s response made a material difference? 

A: Sheridan recounts an incident in which an ASX-listed insured was told by external parties that a threat actor had posted its name on a dark web leak site, alleging the theft of 85GB of data. A specialist threat actor negotiator was engaged to test the claim’s legitimacy. “And within a few days, we had sufficient information to determine the incident was a ‘phantom breach,’ and there had been no compromise of the insured’s system or data,” she says.  

AXA XL still moved to review the client’s regulatory, legal and contractual obligations and to manage external and media enquiries, delivering a preliminary coverage assessment within 10 days of becoming aware of the incident. As Sheridan puts it, “while not the most technically complex cyber event, it demonstrates the fast-paced and constantly evolving nature of cyber incidents.”

Emergence Insurance 

 

A philosophy, not just a policy 


Katrina Hickson, head of distribution at Emergence Insurance, doesn’t talk about her firm’s cyber offering as a product line. She talks about it as a philosophy.  

“Success for us isn’t simply measured by premium growth or policy count,” she says. “It’s about helping more Australian businesses become resilient to cyber threats, supporting brokers to confidently have cyber conversations with their clients and delivering exceptional outcomes when something goes wrong.”  

It’s an unusually candid framing for an award submission, and it sets the tone for everything else Hickson describes. “Over the past 12 months, Emergence has continued to focus on making cyber insurance more accessible without compromising on the quality of cover, expanding its underwriting appetite, enhancing policy wording and – pointedly – launching a dedicated Micro SME solution recognising that cyber risk isn’t reserved for large organisations,” she says. 

That last point isn’t incidental. It reflects a shift Hickson has watched unfold in real time: attackers moving down-market, targeting businesses too small to have dedicated security teams but large enough to be worth the effort.  

“Business email compromise and ransomware continue to account for a significant proportion of our claims,” she says. “However, we’re also seeing a noticeable increase in incidents stemming from human error, including phishing, credential theft and social engineering. Attackers are becoming more sophisticated and are increasingly targeting people rather than technology.”  

The financial consequences of that shift are getting harder to ignore. She says, “While ransomware remains a major concern, the financial impact of socially engineered fund theft and business email compromise continues to grow, particularly where strong payment verification processes aren’t in place.”
 

Claire Hunter
“Because cyber is all we do, we’re able to continually evolve alongside one of the fastest-moving risk landscapes in the world” Katrina Hickson Emergence Insurance 

 

Prevention built into every policy 


Emergence’s answer has been to make prevention non-negotiable rather than optional. “Every business cyber policy includes Smarter Cyber Services at no additional cost – reflecting our belief that cyber insurance should extend well beyond financial protection,” Hickson says.  


The service supports organisations before, during and after a cyber event, bundling expert cyber resilience consultations, vulnerability and threat monitoring, dark web and credential theft reporting, signs-of-compromise detection and a comprehensive library of practical cyber risk resources. The objective, as Hickson describes it, is straightforward: to help businesses build stronger cyber resilience, reduce the likelihood of an incident and be better prepared to respond if one does occur. 

The current Cyber Event Protection 5.1 (CEP-005.1) policy is built around “each-incident” limits – the full policy limit automatically resets for every separate, unrelated incident during the policy period, at no extra cost to the policyholder – alongside optional Non-IT Contingent Business Interruption, Criminal Financial Loss and Tangible Property covers, full-limit system failure cover and affirmative AI cover.  

Hickson is direct about what sets the product apart operationally. “Unlike many insurers who outsource key parts of the response process, Emergence manages claims handling and incident coordination internally, creating a single, accountable point of control during a cyber event, where decisions are made quickly and communication is clear,” she says.  

She argues that this in-house model isn’t just about speed – it’s a feedback loop where insights from claims are fed directly back into underwriting and risk services, strengthening the product and helping clients better prepare for future events.
 

A cyber partner, not just an insurer 


Hickson is equally candid about where Emergence sits in the market relative to competitors who position themselves purely as underwriters. “Our biggest differentiator is that we don’t see ourselves as simply an insurer; we see ourselves as a cyber partner,” she says. “Every decision we make is focused on helping brokers grow their cyber business and helping insureds become more resilient.”  


That extends deliberately into broker education, which Hickson calls one of the biggest levers available to the business. “Helping brokers confidently identify cyber opportunities remains one of the biggest drivers of better client outcomes,” she says. It’s a theme she returns to unprompted more than once – growth, for Emergence, runs through the broker relationship rather than around it. 

E
5-STAR CYBER 2026 WINNER

What Emergence Insurance offers

Katrina Hickson, Head of Distribution, Emergence Insurance

Smarter Cyber Services

Included at no extra cost on every business cyber policy, covering prevention through to response

Dark web & credential monitoring

Ongoing threat notification and signs-of-compromise detection built into the core service

Free vCISO consultation

A complimentary one-hour session with an in-house virtual Chief Information Security Officer

Micro SME solution

A dedicated policy for businesses with under $1 million turnover, closing a common coverage gap

Each-incident limit reset

Under CEP-005.1, the full policy limit resets for every separate, unrelated incident

CyberBind broker portal

A purpose-built platform to quote, bind, renew and manage cyber business, launching soon

Source: Insurance Business Australia interview and 5-Star Cyber 2026 submission, Emergence Insurance.

 

 

 

In Emergence’s own words 


Q: How is AI shaping Emergence’s cyber operations, both defensively and offensively? 

A: “Like many organisations, we’re exploring AI across several areas of the business to improve efficiency and enhance the experience for both brokers and insureds,” Hickson says, citing internal process streamlining and improved access to information.  

But she’s equally focused on AI as a live underwriting risk. “AI has become a consideration from an underwriting perspective, as cybercriminals are also leveraging AI to make phishing, impersonation and social engineering attacks more convincing than ever,” she says. 

Q: What makes Emergence’s Cyber Event Protection product deserving of recognition, in the company’s own words? 

A: Hickson describes it as a “Smarter Cyber approach” – a connected model that goes beyond traditional insurance to help organisations actively manage cyber risk.  

It is built on three pillars: comprehensive coverage for financial, commercial and reputational impacts; embedded services that reduce risk and improve preparedness; and coordinated incident response when it matters most.  

She adds that simplicity is deliberate. “Designed using plain language and streamlined wording, it is easy to understand, explain and rely on,” she says. 

Q: Can you share an example of Emergence’s incident response in practice? 

A: There was a case in which a manufacturing client’s ransomware attack encrypted critical financial and operational platforms, with more than 80% of its systems lacking viable backups. Emergence assembled digital forensics experts, lawyers and specialist ransom negotiators, who reduced an initial ransom demand of close to USD$1 million to under USD$200,000 over several weeks of negotiation.  

Within three weeks, the client’s core platforms were restored and operations resumed. The insured later said that “the efforts of all parties involved genuinely minimised the damage done to our business, acknowledging Emergence’s key role in helping us achieve a favourable outcome.” 

Q: What’s next for Emergence’s cyber program? 

A: The insurer is preparing to launch CyberBind, a purpose-built broker portal designed to transform how brokers quote, bind, renew and manage cyber business, with instant access to policy information, cyber resources and other value-added services.  

Alongside it, Emergence is rolling out a far more focused and data-driven engagement strategy, allowing it to deliver deeper support to brokers with the greatest growth opportunities.  

As Hickson puts it, “We want cyber insurance to become one of the easiest classes of business for brokers to transact, supported by technology, specialist expertise and a cyber insurance specialist that is continually evolving alongside the threat landscape.”
 

Liberty

 

A global product, delivered locally 

 

Where AXA XL and Emergence Insurance lean into prevention services tailored to the Australian market, Liberty makes its case on a different strength entirely: global consistency for clients and brokers operating across borders.  

For David Gallagher, the case for Liberty’s cyber offering starts with a blunt observation about the nature of the risk itself. “Cyber is a global risk where traditional country boundaries are irrelevant,” Gallagher says. It’s a line he returns to throughout because it explains almost every strategic decision Liberty has made over the past year.  

Rather than build a regional product and hope it scales, Liberty rolled out its flagship global offering, Liberty Cyber Resolution™, into Australia, Singapore, Hong Kong and India, followed by successful launches across North America and Europe.  

“Liberty Cyber Resolution™ is a global product,” Gallagher explains, “which means our brokers and clients benefit from a strong, consistent global offering coupled with consistent and clear coverage.” 
 

Claire Hunter
“We pride ourselves on having all the necessary infrastructure in place to support our position as a leading provider of cyber risk solutions in the region, and globally” David Gallagher Liberty 


Global consistency, in Gallagher’s telling, doesn’t mean centralised and remote. “Quite the opposite: the Cyber Resolution rollout has been accompanied by a significant uplift in technical capability across our Asia Pacific team,” he says. Liberty is hiring additional cyber resources in both risk engineering and underwriting, while continuing to evolve our proprietary risk assessment tools, pre- and post-breach services and dedicated cyber claims expertise.  

It’s the combination that Gallagher believes makes the difference: “With our mix of on-the-ground local risk engineers and underwriting experts, together with Liberty’s international network, our tight-knit global cyber practice is a perfect fit to serve brokers and policyholders with multinational needs,” he says.

Prevention without a one-size-fits-all package 


On prevention, Liberty resists the instinct to bundle everything into a single branded service. “Prevention is always central to how we support our policyholders,” Gallagher says. “And, when it comes to the complex world of cyber risk, we have a very wide, varied and curated network of technology and cybersecurity service firms that provide support across a range of key capabilities.”  


That network spans tabletop simulations, endpoint detection, awareness training, payment fraud prevention, specialised cybersecurity advisory and cyber-risk monitoring – but crucially, it’s modular.  

“Rather than a one-size-fits-all package, our policyholders have the flexibility to select the mix that best suits their size, sector and risk profile,” Gallagher says. “Whether our clients are looking to improve their technical security posture or better understand their risks, all the prevention measures we offer are aimed at helping to reduce the cyber risk that companies face.”

Success measured in stability, not just growth 


That flexibility extends to how Gallagher defines success for the business. It isn’t framed around growth metrics or market share, but around reliability.  
 

Success for us means meeting all our broker and policyholder cyber needs across coverage, loss control services and claims,” he says. “We’re also well known for being a long-term, stable insurer for our brokers and policyholders across the region – a deliberate positioning against insurers who move in and out of the cyber market depending on the pricing cycle.” 

L
5-STAR CYBER 2026 WINNER

What Liberty offers

David Gallagher, VP, Head of Cyber and IT Liability, Asia Pacific, Liberty

Liberty Cyber Resolution™

One global product rolled out consistently across Australia, Singapore, Hong Kong and India

24/7 coordinated response

A defined first-48-hours protocol, from triage meetings to privilege-protective communications

Curated prevention network

Tabletop simulations, endpoint detection, awareness training and payment fraud prevention

Dedicated provider panel

Vetted incident response vendors selected by local claims handlers based on breach type

Prompt grant of indemnity

Incident response vendor costs covered promptly under the policy from day one of a breach

Liberty Tech Resolution™

Combined cyber, technology liability and general liability cover, expanding into Asia soon

Note: Dark web monitoring was not confirmed in Liberty's interview and is not included above.
Source: Insurance Business Australia interview, 5-Star Cyber 2026, Liberty Specialty Markets.

 

 

 

In Liberty’s own words 


Q: What’s driving the majority of claims Liberty sees, and is that changing? 

A: “Reflecting on our claims experience from prior years, most of our cyber claims are caused by business email compromise and ransomware incidents,” Gallagher says. While there is a myriad of primary causes, most claims tend to stem from phishing attempts that result in a user’s credentials being compromised – a pattern he says has remained broadly consistent even as attack sophistication has increased. 

Q: How is AI used inside Liberty’s cyber operations, and where does Liberty draw the line? 

A: “AI plays a growing role in Liberty’s cyber risk assessment, particularly... analysing large amounts of unstructured data,” Gallagher says. This speeds up assessment processes and improves internal administrative efficiency, while also helping gather and process underwriting information from a wide range of sources.  

But he’s unambiguous about where human judgement takes over. “What AI cannot replace is our underwriters’ expertise and judgement. It’s always the underwriter who makes the decision about the risk; we never rely on AI for that,” he says. 

Q: What single thing separates Liberty from its competitors? 

A: Beyond the global product itself, Gallagher points to Liberty’s fast, 24/7 coordinated incident response process, wherever a breach occurs, alongside specialist underwriting, regional scale and mutual ownership, which he says allow Liberty to underwrite complex risks that many others simply can’t or won’t.  

He adds a point that’s easy to overlook in a hard market: Liberty’s ability to stick with clients through market cycles, meaning continuity of coverage rather than retreating when conditions tighten. “From our experience, that continuity and stability of coverage really matters to brokers and clients,” he says. 

Q: Walk us through what actually happens in the first hours after a breach is reported. 

A: Gallagher doesn’t soften the stakes. “The first 24–48 hours of a cyber breach are critical,” he says. Within that window, Liberty’s claims team acknowledges receipt of the incident, participates in relevant incident response triage meetings, and works to establish communication protocols to enhance the prospect of legal professional privilege.  

From there, Liberty engages incident response vendors from its dedicated provider panel, with local expertise from regional claims handlers described as paramount in ensuring relevant and appropriate vendor selection depending on the nature of the breach.  

Liberty also provides a prompt grant of indemnity for incident response vendor costs under the cyber policy – a detail Gallagher frames as removing one source of client anxiety at an already stressful moment. “Our experience and locked-down process are critical to effectively managing and minimising the impact of a cyber breach,” he says. 

Q: What’s next for Liberty’s cyber program in the region? 

A: Building on the Cyber Resolution rollout, Liberty is extending Liberty Tech Resolution™ – a trademarked product bringing together cyber, technology liability and combined general liability into one streamlined policy – into Asia in the coming months, following its North American launch.  

“This is all about ensuring our customers are aware of our multiline capabilities so they can utilise the full benefits of our offerings,” Gallagher says.
 

Industry outlook: what’s next for cyber insurance providers in Australia 


With AI now ranked Australia’s number one business risk and the OAIC recording its highest-ever volume of reportable data breaches in 2025, brokers can expect this year’s 5-Star Cyber winners to keep investing on two fronts: sharper AI-assisted underwriting and risk assessment, and continued expansion of complimentary prevention services such as dark web monitoring and executive crisis simulation.  

Liberty’s planned Asian rollout of Liberty Tech Resolution™ and Emergence’s CyberBind portal both point to a market consolidating cyber, technology and broker-servicing capability into fewer, more integrated products. Brokers can browse the latest cyber insurance news for Australian brokers to track how these products evolve over the coming year – a trend likely to accelerate as broker education becomes a competitive differentiator rather than a support function, and as the cost of a single breach in Australia continues to climb past the $4 million mark. 
 

What Australia’s best cyber insurance providers have in common 


What unites Australia’s best cyber insurance providers is not the size of their capacity, but their refusal to treat the policy as the end of the relationship. The strongest providers embed dark web monitoring, AI-aware assessment or global incident response directly into their offering, while investing heavily in broker education to help brokers spot and explain cyber risk earlier.  

In a threat environment where AI is arming attackers as fast as it’s arming underwriters, that shift from reactive cover to proactive resilience looks set to define the cyber insurance market well beyond 2026. 
 

Best Cyber Insurance Providers in Australia |
5-Star Cyber

  • Allianz
  • CFC
  • Chubb
  • Coalition
  • Dual
  • HDI Global
  • IAG/CGU (Cylo)
  • Liberty
  • QBE

 

 

Insights

As part of our editorial process, Insurance Business Australia’s researchers interviewed the subject matter expert below for an independent analysis of this report and its findings.   

 

Frequently asked questions

 

Q: How were the 5-Star Cyber 2026 winners selected? 

A: Insurance Business Australia identified the best cyber insurance providers in Australia by surveying its broker and reader community across multiple channels, inviting brokers to vote on the cyber insurers they believe deliver the strongest value. Insurers with strong broker support were then invited to submit detailed entries on their products, claims support and underwriting expertise. 

Q: Why is dark web monitoring becoming standard in cyber policies? 

A: Dark web monitoring alerts insureds when their credentials or data appear on criminal marketplaces, allowing intervention before a threat actor can exploit the access, shifting the value of a policy from post-incident payout to pre-incident prevention. 

Q: How is AI changing cyber risk in Australia? 

A: AI is lowering the technical barrier for attackers to run convincing phishing and social engineering campaigns, while insurers increasingly use AI to process large volumes of underwriting data. However, several 5-Star winners stress that final risk decisions remain with human underwriters. 

Q: What causes the majority of cyber claims? 

A: Business email compromise and ransomware remain the leading causes of cyber claims among this year’s winners, though social engineering and credential theft driven by human error are growing contributors. 

Q: What should brokers look for in a 5-Star cyber policy? 

A: Beyond core coverage, brokers should look for embedded prevention services such as dark web monitoring, incident response speed commitments and insurer investment in broker education and training. 

Q: How is the cyber insurance market expected to change over the next 12–24 months? 

A: Insurers are moving towards more integrated products that combine cyber, technology liability and general liability into a single policy, alongside deeper investment in AI-assisted underwriting and complimentary prevention services such as dark web monitoring and executive crisis simulation – a trend likely to accelerate as AI-driven threats continue to grow.
 

Methodology

To identify the best cyber insurers for 2026, Insurance Business Australia drew on its broker and reader community through multiple survey channels, inviting brokers nationwide to vote on the cyber insurers they believe deliver the strongest value.  

Insurers with notable broker support were invited to submit a detailed entry outlining their policy strengths, including coverage features, claims support, underwriting expertise and risk management capability.  

Winners were selected by combining broker feedback with insurer-submitted information, with primary weight given to overall broker support and additional consideration given to demonstrated excellence in product quality, claims handling and broker relationships.

Keep up with the latest news and events

Join our mailing list, it’s free!