Arch Insurance Australia has listed its Management Liability Plus product on Ebix Australia's Sunrise Exchange, joining a growing group of insurers offering financial lines products through the platform. The more significant aspect of the announcement for brokers is not the distribution channel but the coverage architecture: at a moment when much of the Australian management liability market has been excluding or limiting cyber-related exposures in standard wordings, Arch has taken the opposite position.
Sunrise Exchange processes more than 7.5 million transactions annually and is used by over 80% of Australian insurance brokers as their primary policy management and transaction processing system, according to Ebix. Delta Insurance Australia listed its Cyber and Management Liability products on the platform in June 2026. Hutch Underwriting launched its Management Liability product there in November 2025. Nearly half of all general insurance written in Australia - $35.6 billion in gross written premiums out of a total market of $77.9 billion in the year to June 30, 2025 - passed through the intermediated channel, per NIBA, making Sunrise Exchange a meaningful distribution target for any insurer pursuing SME broker business at scale.
Arch says its point of differentiation on the platform is real-time LiveChat access to underwriters directly within the system, which it describes as the first such capability offered by an insurer on Sunrise Exchange. Louise Lumley (pictured), head of executive assurance at Arch Insurance Australia, said: "Being the first insurer to offer real-time LiveChat functionality is something we're genuinely proud of and reflects our commitment to continually growing our relevance and delivering high-quality service and solutions for our brokers and clients."
The Australian management liability market has taken divergent approaches to cyber-related exposures - a tension often described as silent cyber, where cyber risk sits within a policy without being clearly covered or excluded. Many insurers have moved to exclude cyber-related exposure from management liability wordings, either to direct clients towards standalone cyber cover or to manage accumulation between separate cyber and management liability policies. Broker feedback has pointed to rising standalone cyber uptake among Australian SMEs as cyberattacks, regulatory requirements and contractual demands increase pressure on smaller businesses to address the risk independently.
Arch has taken the opposite approach in Management Liability Plus. The product includes personal liability cover for directors and officers in the event of a cyber incident, alongside social engineering cover - affirmative language that addresses the gap other wordings have left open rather than excluding it.
The practical significance of that coverage decision sits in a specific claim scenario. Social engineering fraud - in which a staff member is manipulated into authorising a payment or disclosing credentials - simultaneously generates a cyber event and a potential governance claim against a director for inadequate oversight or controls. A management liability policy with a cyber exclusion leaves the D&O dimension of that claim uncovered. Arch's affirmative position means both dimensions respond under the one policy.
The risk environment makes that coverage question material. According to the Australian Signals Directorate's Annual Cyber Threat Report 2024-25, phishing accounted for 60% of cyber security incidents reported to the Australian Cyber Security Centre in FY2024-25. ASD's ACSC responded to more than 1,200 cyber security incidents during the period, while the average self-reported cost of cybercrime to businesses rose 50% to $80,850.
The coverage architecture question has become more urgent since June 10, 2025, when the statutory tort for serious invasions of privacy created under the Privacy and Other Legislation Amendment Act 2024 commenced. The new cause of action allows individuals to seek remedies for serious privacy invasions and operates separately from the Australian Privacy Principles, which generally apply only to organisations with annual turnover of more than $3 million.
The $3 million small-business exemption from the broader Privacy Act does not apply to the statutory tort in the same way. A business currently outside the Act's general coverage may still face a cause of action under the tort, and a director of that business may face personal liability for a governance failure that enabled the privacy invasion. That exposure is live today, not contingent on further legislation.
For broader context: the government has agreed in principle to remove the Privacy Act's $3 million small-business exemption as part of further reforms. The exemption currently covers approximately 2.5 million SMEs. Its removal, when legislated, would substantially expand the number of businesses subject to the Act's full privacy obligations - and the personal exposure of their directors. Brokers placing management liability for SME clients should be reviewing whether existing ML wordings affirmatively cover cyber-originated director liability claims now, before that reform passes, rather than addressing the gap after the legislative position becomes clearer.