Cyber insurance

Cyber protection for connected engineering practices.

Cover designed to help engineering businesses respond to selected cyber incidents, privacy events, data loss, interruption and digital extortion.

Not sure what cyber cover should include?Ask for information before completing a full quote form.

Call now ↗

Engineering data risk

Project delivery now depends on digital systems.

Engineering firms hold valuable client information, project files, calculations, models and commercial data. Email, remote access and cloud platforms also create pathways for fraud and disruption.

  • CAD, BIM, modelling and project-management files
  • Client, employee and supplier information
  • Email instructions and electronic payments
  • Cloud storage and third-party software platforms
  • Remote access for employees and contractors
  • Connections with client and project systems

Common events

Cyber incidents are not only data breaches.

A single compromised account or unavailable project platform can create operational, financial and reputational consequences.

01Phishing and business email compromise

02Ransomware and digital extortion

03Loss or disclosure of personal and client data

04Corrupted, encrypted or unavailable project files

05Business interruption following a cyber event

06Fraudulent payment or funds-transfer instructions

07Third-party software and cloud-service incidents

08Regulatory, notification and contractual obligations

How cover may respond

Support before, during and after a cyber incident.

01 / Response

Incident response

Selected forensic, legal, notification, public-relations and crisis-management costs.

02 / Recovery

Data and system restoration

Selected costs to restore data, systems and normal operations following a covered event.

03 / Interruption

Business interruption

Selected loss of income and additional costs caused by a covered network interruption.

04 / Liability

Privacy and network liability

Selected defence and compensation costs arising from covered privacy or security allegations.

Cyber policies vary materially. Extortion, cybercrime, social engineering, system failure and dependent-business interruption may have separate limits, conditions or exclusions.

Risk controls

Insurance works alongside practical cyber security.

Insurers increasingly ask how the business protects accounts, devices, backups and payment processes.

  • Multi-factor authentication for email, remote access and cloud services
  • Offline, segregated or otherwise resilient backups
  • Regular patching and supported operating systems
  • Endpoint protection and managed monitoring
  • Payment-verification procedures independent of email
  • Employee awareness training and incident-response planning

Preparing a request

Information that helps shape the terms.

01 / Business

Practice profile

Turnover, staff numbers, disciplines, locations and the types of clients supported.

02 / Systems

Technology environment

Cloud platforms, remote access, outsourced IT and any connections to client systems.

03 / Controls

Security controls

Multi-factor authentication, backups, endpoint protection, training and payment verification.

04 / History

Incidents and claims

Previous cyber events, suspected compromises and corrective work already completed.

Useful guides

Practical reading for connected engineering practices.

01

Cyber risks particularly relevant to engineering firms

Read guide ↗

03

When an engineering consultancy may need Public Liability

Read guide ↗

Common questions

Cyber insurance, explained clearly.

View all FAQs ↗

Engineering businesses depend on digital project files, email and cloud platforms. A cyber policy can provide specialist incident-response and recovery support that is not normally the focus of Professional Indemnity or standard property insurance.

PI may respond to some allegations arising from professional services, but it is not a substitute for dedicated cyber cover addressing response costs, privacy, data restoration, cybercrime and interruption.

Some policies provide selected extortion and response cover, subject to the law, policy terms, insurer consent, security controls and sub-limits. Cover should never be assumed without checking the wording.

Cybercrime and social-engineering cover varies substantially. It may be optional, sub-limited or subject to strict verification conditions, so the payment process should be disclosed and reviewed carefully.

Insurers commonly ask about revenue, staff, data held, technology dependencies, multi-factor authentication, backups, endpoint security, payment controls, incident history and the limits required.

Next step

Request cyber terms for your engineering business.

Tell us about the practice, its systems, security controls and the cover you want to explore.

Request a written quote ↗

A simpler first step

Not ready for a quote? Start a conversation.

Call 1300 215 566 ↗