For most of its short history, the growth problem cyber insurance has suffered is largely blamed on one thing: business owners not understanding what the policy does. Andrew Brett (pictured), director of Adelaide-based cyber insurance brokerage Infosure Insurance, built his early sales approach around fixing exactly that. He walked clients through sub-limits, first-party and third-party coverages and cited research that businesses are now more likely to suffer a cyber incident than a fire. It worked, up to a point. Then feedback from a room of 160 business leaders changed his thinking entirely. "It's a critical inflection point in cyber insurance's journey," Brett said. The shift he's describing could be subtle enough that most of the broking market hasn't caught up to it yet.
The problem, it turns out, was probably never entirely comprehension. It was inertia. And when Infosure changed how it questioned prospective clients, three distinct types of reluctant buyer emerged, each requiring a different conversation and none of them asking for a better explanation of the policy.
Three types of reluctant buyers
The first type simply doesn't believe an incident will happen to them – a psychological barrier no amount of technical detail moves. The second accepts the risk but won't prioritise the spend, deferring the decision indefinitely. Brett's clearest illustration cuts straight to the pain point: "The same person who spends $17,000 on building insurance won't spend $3,500 on a cyber policy." Unlike most commercial lines, cyber insurance carries no contractual trigger - no bank, landlord or council mandates it - so it remains what Brett calls a grudge purchase.
The third type is the one that reshaped Infosure's entire strategy. This group isn't interested in policy detail at all; what moves them is a real claims story, stripped of jargon. A single case now anchors Brett's client presentations: a business that lost $30,000 to a funds transfer fraud via keylogger, only to face a further $100,000 in digital forensics, Privacy Act reporting and third-party litigation exposure - a $130,000 cleanup for what looked, at first, like a $30,000 problem. In this case, the business was covered and the insurer paid the lot. Cyber insurance likely saved the business.
What the market data confirms
Brett's read on the market itself lines up with what the numbers already show. Despite the payouts, cyber insurance has quietly become one of the most consistently profitable lines in the country - Australian Prudential Regulation Authority (APRA) data shows the class posting a positive insurance service result for three straight quarters - yet growth remains flat, with premiums falling roughly 10% through 2025 without a corresponding lift in uptake. If price were the obstacle, cheaper cover should be moving the needle. It isn't.
Uptake estimates vary but tell a consistent story: the Insurance Council of Australia (ICA) still puts cyber insurance penetration at around one in five SMEs, while cyber underwriter Cowbell estimates a broader range of 5% to 20%. Both are in line with Brett's own figure. Meanwhile the exposure keeps climbing. Recent research shows 84% of Australian small businesses experienced a cyber incident in the past year, and the Australian Signals Directorate (ASD) puts the average self-reported cost of an incident to a small business at $56,600.
"We can no longer say people don't understand the policies and that's why they're not buying them," Brett said. What's changed, in his view, is that clients broadly grasp the concept now; they simply haven't been shown, in specific and granular terms, what a claim looks like for a business like theirs. For brokers, the implication is actionable: A client who nods through a sub-limit explanation hasn't necessarily been convinced of anything. The conversation that is more likely to convert is the one built around a real claim, told in detail. That shift, more than any change in price or product, is what Brett believes is now more likely to close a broker's cyber sale.