Skip to main content

Cyber claims examples: what small businesses can learn from real incidents

A cyber incident can feel like a technology problem at first.

Then the business impact starts to show. Staff cannot access systems. Payments are redirected. Customer information may be exposed. A website stops taking bookings.

For Australian small businesses, cyber claims examples can show where costs may come from and why planning matters.

The examples below show how different cyber incidents can affect day-to-day business operations, from payments and systems access to data recovery and response costs.

For a broader overview of cover, read Marsh’s cyber insurance for Australian businesses.

What you should know

Cyber risk is not only about large companies.

Many smaller businesses use digital systems every day. They may use email for invoices, cloud tools for client records, booking software, or accounting systems for cash flow.

The Australian Signals Directorate reported that ASD’s ACSC “Received over 84,700 cybercrime reports to ReportCyber” and that the average self-reported cost of cybercrime per report for businesses included “small business: $56,600 (up 14%)”.1

Those figures are not specific to any one industry. They show the wider cost pressure cybercrime can place on Australian businesses.

A cyber claim may involve investigation, system recovery, data recovery, lost income, legal support, privacy support or payment fraud.

A real estate office faced a large response cost

A real estate office in regional South Australia experienced a cyber attack.

The office did not have cyber insurance in place.

After the incident, external support was arranged so the business could understand its response options. The business then received a quote for investigation and legal services only. That quote was just under $200,000.

The lesson is not that every real estate business will face the same cost.

The lesson is that a smaller office can still face a cyber event that needs urgent external help. Real estate businesses may handle personal information and business records, depending on how they operate.

Ransomware can affect everyday operations

In a CFC case study, a small electrical contracting firm was hit by ransomware after an employee opened an attachment that looked like a résumé. The ransomware encrypted the business’s computer programs and demanded $5,000 to restore access.

The business did not rely only on computers to perform electrical work. But the office relied on systems for calls, work orders, invoices and financial accounts.

For four days, office staff worked manually while systems were restored. Later, one older program still did not work properly. Staff had to move data into a new system, which took 1,562 overtime hours and 521 temporary staff hours. The total claim cost came to $81,387.

Backups need to be checked

In another CFC case study, a small engineering firm was affected by WannaCry ransomware. The attack encrypted files on its server and on a local hard drive. The files included technical drawings, design specifications and project records.

The business expected to restore the files from a cloud backup.

When it tried to do that, it found the cloud backup had been failing since 2014. Several years of documents could not be recovered. The cost of data re-creation alone came to over $270,000.2

The Australian Signals Directorate says, “The best recovery method from a ransomware attack is to restore from an unaffected backup”, and “Backing up and checking that backups restore your files offers peace of mind.”4

Email fraud can look very normal

A CFC case study involving a construction firm showed how invoice fraud can start with one compromised email account. A fraudster gained access to an employee’s inbox through a phishing email, watched the account, and found an invoice from a subcontractor.

The fraudster then created a lookalike email address, used the same invoice template and changed only the bank details.

The business had a process to verify bank account changes by phone. In this case, that step was missed. The loss was $93,425.

This lines up with the Australian government guidance on business email compromise. The Australian Signals Directorate says business email compromise is when malicious actors “use email to abuse trust in business processes to scam organisations out of money or goods”.

Clubs and hospitality businesses can be exposed too

A semi-professional Australian rules football team had a virus spread to its point of sale server, taking tills offline. The total cost of dealing with the incident came to $36,911, with $31,814 payable under the club’s cyber policy with CFC.

A NSW golf club lost $198,274 after a finance manager received emails that appeared to come from the CEO. The CEO had been impersonated.

A cyber incident may affect payments, tills, bookings and supplier payments.

What could create claim costs?

A cyber claim may include investigation, legal support, system restoration, data recovery, lost income, privacy support and fraudulent payment loss.

Cyber insurance may help with some of these costs, depending on the cover arranged and the policy terms.

If a business handles personal information, privacy obligations may also need to be considered. Business.gov.au says, “If your business has an annual turnover of more than $3 million, you must comply with the Privacy Act”, and “Some businesses with smaller turnovers still need to comply with the Privacy Act.”5

The Office of the Australian Information Commissioner says, “The NDB scheme requires regulated entities to notify particular individuals and the Commissioner about ‘eligible data breaches’” and “A data breach is eligible if it is likely to result in serious harm to any of the individuals to whom the information relates.”6

What small businesses can take from these examples

The examples are different, but the practical lessons are similar.

A small business can reduce cyber pressure by checking a few basics:

  • Confirm bank account changes by phone using a known number
  • Turn on multi-factor authentication for email and key systems
  • Keep systems and software updated
  • Back up important data and test that it can be restored

These steps cannot remove every risk. They can make some incidents less likely and may help the business respond faster.

It is also worth reviewing cyber insurance before an incident happens. Once a business is in the middle of a cyber event, it may need to make decisions quickly.

Need help?

If you have questions about cyber risk or cyber insurance for your business, speak with a Marsh advisor. 

You can also read about Marsh’s cyber insurance for Australian businesses.

Frequently asked questions

Common cyber claims can involve ransomware, business email compromise, invoice fraud, data recovery, privacy breach response and business interruption. The examples in this article show how those issues may affect real estate, construction, engineering, sport and hospitality businesses.

A cyber claim is a request made under a cyber insurance policy after a cyber event. It may involve costs linked to investigation, response, system restoration, data recovery, lost income, legal support or certain fraud losses, depending on the policy.

Some Australian small businesses may consider cyber insurance if they use email, store customer information, take online payments, rely on booking systems or use digital records. The right decision depends on the business’s risk, budget and insurance needs.

The Australian Signals Directorate reported that the average self-reported cost of cybercrime per report for businesses included “small business: $56,600 (up 14%)”.1 This is an average across reports and should not be treated as a forecast for any one business.

Cyber insurance may respond to ransomware-related costs, depending on the policy. This may include incident response, system restoration, data recovery, business interruption or ransom-related costs where legally insurable and covered by the policy.

Some cyber policies may include cybercrime cover for certain fraudulent transfers, including invoice manipulation. Cover depends on the policy wording, sub-limits, exclusions and the facts of the claim.

Business email compromise happens when criminals use email to abuse trust in business processes. It may involve similar-looking domains, fake logos or compromised accounts used to redirect payments or goods.

A business should contain the issue, contact its IT provider or incident response contact, preserve evidence, report the matter where needed, and notify its insurer or broker if it has cover. Cyber.gov.au provides ReportCyber for reporting cybercrime, incidents and vulnerabilities.

Some businesses do. If the Privacy Act covers the business and a data breach is likely to result in serious harm, the business may need to notify affected individuals and the OAIC under the Notifiable Data Breaches scheme.

Yes. A sole trader may rely on email, banking, customer records, accounting tools or online sales platforms. A cyber event affecting those systems may create costs, lost income or recovery issues.

Real estate agencies may handle personal information and business records. If those records or systems are affected, the business may need help with investigation, recovery and privacy response.

Professional indemnity and cyber insurance respond to different types of risks. Cyber insurance is focused on cyber events, such as hacking, data breaches, ransomware, business email compromise and system disruption. The exact difference depends on the policy wording.

References

  1. Australian Signals Directorate, “Annual Cyber Threat Report 2024-2025", https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025 accessed 7 July 2026.
  2. CFC, “Cyber claims case studies”, https://www.cfc.com/en-au/knowledge/resources/case-studies/cyber-claims-case-study-search-engine-setback, accessed 7 July 2026.
  3. Australian Signals Directorate, “Protect yourself from ransomware”, https://www.cyber.gov.au/report-and-recover/recover-from/ransomware/protect-yourself-from-ransomware, accessed 7 July 2026.
  4. Australian Signals Directorate, “Protecting against business email compromise”, https://www.cyber.gov.au/business-government/protecting-devices-systems/hardening-systems-applications/email-hardening/protecting-against-business-email-compromise, accessed 7 July 2026. 
  5. business.gov.au, “Protect your customers’ information”, https://business.gov.au/online-and-digital/cyber-security/protect-your-customers-information, accessed 7 July 2026.
  6. Office of the Australian Information Commissioner, “Part 4: Notifiable Data Breach (NDB) Scheme”, https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme, accessed 7 July 2026.

LCPA 26/32580