Cyber cover is more accessible than brokers assume

Emergence says the technical knowledge required is far less than most brokerages expect and real claims examples do the heavy lifting

Cyber cover is more accessible than brokers assume

Cyber

By Daniel Wood

There is a version of the cyber insurance conversation that goes well and according to one of New Zealand's specialist cyber underwriters, it starts by throwing out most of what brokers think they need to know first.

"If we make cyber easy to understand, if we demystify the jargon and the myths around IT terminologies and things like that, and say, here's what we actually want to know, it's not that much, brokers can quickly come along for the journey and realise this is a really accessible type of insurance," said Fraser Walker (pictured), country head for Emergence Insurance in New Zealand. He was talking with Insurance Business at the recent the NZUAC Expo in Auckland.

That is a more encouraging read of the situation than the market usually gets. Cyber has a reputation as the line that requires a technical education before a broker can place it and Walker's argument is that the reputation is largely unearned. The underwriting information required is modest. What has been missing is a way in.

Brokerages are candid with him about that. "Most brokerages and brokers within will admit to us very quickly, we're not confident talking about cyber, we're not confident having the conversation with our clients, our customers," he said - an admission he treats as a useful starting point rather than a failing, because it identifies exactly what needs fixing.

The commercial case for fixing it is strong. Direct financial losses reported to New Zealand's National Cyber Security Centre (NCSC) reached $26.9 million in the 2024/25 year, up from $21.6 million a year earlier, across 5,995 incident reports. The NCSC consistently notes the real figure is higher because most incidents go unreported. At the same time, capacity has widened as more insurers concentrate on the line and pricing has softened accordingly. For brokers, that combination is unusually favourable: rising client need, more choice and cover that is cheaper to recommend than it has been in years.

Claims examples do the heavy lifting

The most effective tool, in Walker's experience, is not a product briefing. It is a claim.

Claims examples give a broker something concrete to put in front of a client - this is what happened to a panel beater, this is what happened to a single-practitioner GP. Walker described brokers effectively using claims as a postbox, forwarding real examples to clients to demonstrate that this is happening constantly rather than theoretically. It converts an abstract risk into a recognisable one.

The NCSC data supplies plenty of material. Scams and fraud have been the most-reported incident category every quarter since late 2024. Business email compromise - where a business is duped into paying a doctored invoice - drove reported losses to $12.4 million in the third quarter of 2025 alone, which the NCSC attributed to a small number of high-value reports involving falsified transfers of money. Social engineering theft of that kind is not an exotic attack on a large corporate. It is invoice fraud against ordinary businesses, and it is the exposure most SME clients assume does not apply to them.

Walker's other point is that the approach matters as much as the material. Walking into a brokerage, telling them they should be selling more cyber and delivering an hour-long presentation produces no uptake. The confidence comes from making the class accessible, not from being told to sell it and, he adds, from brokers giving themselves credit for what they already do well.

"So brokers have got to want to back themselves as well," he said.

Answering the one objection that matters

There is a single client rebuttal that brokers need a ready answer to, and it is not about wordings or limits. It is the client who says they have already spent money on IT, or that their information is in the cloud, so why would anyone attack them?

Walker's answer is that attackers are not selecting targets the way clients imagine. Threat groups operate from Eastern Europe, Russia, Ukraine, parts of Asia and Latin America, and they are not seeking out New Zealand businesses specifically. They are looking for weak defences. They work out what a business is worth to them only once they are already inside – which means obscurity is not protection, and adequate IT security is often enough to make an attacker move on to an easier target.

That reframing is the whole conversation. A client who understands that basic security makes them slightly too hard and that the alternative is being selected by an algorithm rather than a person, is a client who can be advised properly.

For brokers, the practical sequence is short. Establish that IT spend and cloud storage are not a defence against invoice fraud or credential theft. Keep two or three claims examples ready from occupations the client will recognise. And accept that the underwriting detail required is far less than the reputation of the class suggests.

The soft market has removed the price objection. What is left is a conversation that, on the evidence of the underwriters selling into it, is considerably more winnable than most brokerages currently believe.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!