Skip to main content

Cyber insurance solutions for jewellers: protecting POS, customer and payment data

Cyber insurance for jewellers is one part of managing the risks that can come with using point-of-sale (POS) systems, online accounts, email and digital customer records.

A scam email can lead to a fraudulent payment (social engineering / invoice fraud). It can also expose customer data or can have a reputational hit after a major public incident.

Cyber insurance may help with certain response, recovery and liability costs, depending on the policy, limits, exclusions and circumstances.

Why cyber risk matters for jewellery businesses

Cybercrime affects Australian businesses across different industries. 

For 2024–25, ASD's Australian Cyber Security Centre reported: “Received over 84,700 cybercrime reports to ReportCyber, down 3%. On average, a report every 6 minutes, consistent with last year.”

Australian Government guidance also puts the wider business risk simply: “Your money, information, technology and reputation are at risk from cyber-attacks.”

For a jewellery business, this is a reminder to think about digital systems and information as well as valuable physical stock.

How cyber incidents can affect a jewellery business

Cyber risk is not limited to a website. Problems can start through email, devices like POS, accounts or other systems used by the business.

Placeholder Image

Phishing and account compromise

Phishing can use fake emails or text messages to trick someone into providing private information or account details.

Australian Government cyber guidance also identifies malicious emails and messages, malware and access through employees or customers as ways cyber criminals may attack businesses.

Placeholder Image

Ransomware and system disruption

Ransomware can make a system or device unusable. ASD's ACSC says ransomware attacks can encrypt business data and shut down or severely limit operations/ sales.

For a jeweller, it is worth considering which systems would make it harder to trade if they became unavailable.

Placeholder Image

Customer data breaches

A data breach can happen when sensitive or personal information is accessed, disclosed or exposed to unauthorised people.

Cyber security is therefore about protecting information as well as keeping systems running.

What jewellers should know about customer and payment data

ASD's ACSC identifies information such as names, addresses, payment details, email addresses, passwords and phone numbers as examples of personal data.

A jewellery business may/may not hold all of these. The important step is knowing what information your business collects, where it is stored and who can access it.

Know what customer information you hold

ASD's ACSC recommends businesses keep track of customer personal data, limit what they collect and delete information that is no longer needed.

Knowing what you hold can also make it easier to work out what information may be affected after a cyber incident.

Payment information also needs protection

Payment details are among ASD's ACSC examples of personal data.

If your business handles payment information, it should form part of your wider approach to protecting customer data.

How can cyber risk affect a jeweller's POS system?

A POS system forms part of the technology a jewellery business may use to process sales.

If the system becomes unavailable, it may affect the way the business processes transactions. It is also worth understanding what information the system processes or stores and who can access it.

Know what information your POS system handles

Understanding what information your systems process or store can help identify where controls may be needed.

This should form part of the wider review of customer data, payment information and business technology.

Review access to payment-related systems

ASD's ACSC recommends controlling access to customer personal data and limiting employee access to the information needed for their work.

Access controls are also worth considering where payment-related systems provide access to customer personal data.

Why jewellers are a high-value target

  • High transaction values, fast-moving goods, time-critical deliveries
  • Frequent supplier/courier payments (good for invoice fraud)
  • Customer identity + payment information can be valuable
  • Often lean IT and shared logins in-store (creates easy entry points)

How jewellers can reduce cyber risk

Insurance is one part of managing cyber risk. Day-to-day security practices also matter.

ASD's ACSC recommends practical steps such as:

  • Know what customer information you hold and where it is stored.
  • Limit access and remove information that is no longer needed.
  • Back up important data and prepare for how you will respond to an incident.

The ASD’s guidance also discusses encryption, monitoring access and secure practices where staff use their own devices for work.

Prepare for a cyber incident

A response plan can help clarify who needs to act, what systems need attention and what reporting requirements may apply.

It can also help identify which insurer, broker or incident response service needs to be contacted if cyber insurance is in place.

How cyber insurance may help with system and data incidents

Marsh describes first-party cover this way: “First-party cyber cover helps businesses manage costs that arise directly from cyber incidents affecting their systems, data, or operations.”

Placeholder Image

First-party cyber cover

Depending on the policy, first-party cover can include investigation and response costs, system restoration, data recovery, business interruption, certain cybercrime losses and cyber extortion costs.

Placeholder Image

Third-party cyber cover

Third-party cyber cover can help manage certain claims made by customers, regulators or other parties following a cyber incident involving sensitive information.

This can include areas such as privacy breach liability, legal defence costs, unauthorised disclosure claims, regulatory investigations and penalties where insurable, and payment card industry compliance costs.

Placeholder Image

Incident response and recovery support

Some cyber insurance solutions may also provide incident response support.

Cover varies, so check the relevant policy wording, limits, conditions and exclusions before relying on a particular feature.

How is cyber insurance different from Jewellers Block insurance?

Jewellers Block insurance addresses a range of jewellery-related property risks.

The Jewellers Block includes stock and merchandise, goods in trust, cash and negotiable documents, subject to the policy's terms, conditions, limits and exclusions.

Jewellers Block addresses jewellery-related property risks

Jewellers Block insurance can address risks involving stock, merchandise, goods in transit and entrusted goods, subject to the relevant policy terms, conditions, limits and exclusions.

Cyber insurance addresses a different area of risk

Cyber insurance is presented separately from Jewellers Block insurance, so check the relevant policy wording to understand which risks and events are covered.

What should a jeweller do after a cyber incident?

The right response depends on what has happened and which systems or information are affected.

1

Report the incident

ASD's ACSC advises businesses to report cyber security incidents through ReportCyber or the Australian Cyber Security Hotline.

2

Check whether privacy reporting obligations apply

ASD's ACSC states: “Businesses that are covered by the Privacy Act must report eligible data breaches to the OAIC.”

Whether the Privacy Act applies to your business, and whether an incident is an eligible data breach, depends on the circumstances.

3

Follow your cyber insurance notification process

If you have cyber insurance, check and follow the notification requirements in your policy and contact the relevant insurer or incident response service.

Need help?

Protecting jewellery stock and protecting digital systems involve different risk considerations.

If you would like to review cyber insurance alongside your jewellery business cover, speak with a Marsh broker.

Frequently asked questions

Cyber insurance may help a jewellery business manage certain financial losses, response costs and liabilities after an insured cyber incident. Cover depends on the policy, limits, conditions and exclusions.

There is no single answer for every business. It may be worth considering if your business relies on digital systems, processes payments or stores sensitive information.

A cyber policy may help with certain costs if an insured cyber incident affects business systems or operations. Whether an incident involving a POS system is covered depends on the policy wording and circumstances.

ASD's ACSC includes payment details among its examples of personal data, along with information such as names, addresses, email addresses and phone numbers.

This depends on what your business collects. ASD's ACSC recommends understanding what customer personal data you hold, where it is stored and who can access it.

Jewellers Block insurance addresses a range of jewellery-related property risks. Marsh identifies cyber protection separately as an additional insurance solution. Check the relevant policy wording to understand what is and is not covered.

Marsh's Australian cyber insurance information includes cyber extortion costs related to ransomware or extortion demands within its first-party cover information. Whether cover applies depends on the individual policy.

First-party cyber cover may include business interruption resulting from a cyber incident. The circumstances and amount of cover depend on the policy.

Third-party cyber cover may include privacy breach liability, unauthorised disclosure claims and legal defence costs. Policy terms, limits and exclusions apply.

Follow your incident response process and take steps to contain the issue. ASD's ACSC advises businesses to report cyber security incidents through ReportCyber or the Australian Cyber Security Hotline.

Not necessarily. ASD's ACSC says the Privacy Act applies to organisations with annual turnover of more than $3 million and some small business operators. Check OAIC guidance to understand how the Privacy Act may apply to your business.

Start by understanding what customer data you hold. ASD's ACSC also recommends limiting unnecessary data, controlling access, using encryption, keeping secure backups and monitoring access to personal data.

References

  1. Australian Signals Directorate, "Annual Cyber Threat Report 2024–25", https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025, accessed on 10 September 2026.
  2. Australian Signals Directorate, "Securing customer personal data", https://www.cyber.gov.au/business-government/small-business-cyber-security/securing-customer-personal-data, accessed on 10 September 2026.
  3. Australian Government, "Cyber security and your business", https://business.gov.au/online-and-digital/cyber-security/cyber-security-and-your-business, accessed on 10 September 2026.

LCPA 26/3522