Published 07 September 2026
Cyber insurance for trades in Australia: what to know
You quote a job over text, invoice from an app on your phone, and the money lands in the business account before you've packed up the ute. None of that used to look like a "cyber risk" to a tradie. It was just doing the job. Insurers see it differently now, and so, more and more, do criminals. A plumber's invoicing app or an electrician's shared email account is as attractive a target as a big company's server room, and often far less protected.
This isn't insurance advice. Every insurer sets its own underwriting criteria and policy terms, and a broker who knows trade businesses is the right person to interpret them for yours. What follows describes patterns commonly seen in the Australian market.
Why trade businesses are being asked about this now
A trade business runs on the same digital plumbing as any office. Client names, addresses and job notes in an app. Quotes and invoices sent and paid online. A shared login or two for the business email or the accounting software. The difference is that most trade businesses never set any of that up with security in mind. It was simply the fastest way to get quotes out and money in.
Insurers have noticed. Several Australian insurers now offer cyber products built specifically for trades (electricians, plumbers, builders, carpenters, HVAC) as their own category. That tells you two things. Trade businesses hold enough digital risk to be worth underwriting, and insurers have enough claims data from the trades to price it. Whether you're on a trade-specific policy or a general small-business one, the questions about your setup aren't a formality any more.
What a trade-specific cyber policy typically covers
Cover varies by insurer and by policy. The elements that commonly show up in trade-focused cyber products include:
- Data breach response. The cost of working out what happened and notifying affected clients if their details are exposed.
- Cyber extortion. Support if the business is hit with ransomware and data or systems are held hostage.
- Business interruption. Income lost while an outage stops you quoting, invoicing or getting into job files.
- Regulatory costs. Some policies extend to the cost of responding to a regulator inquiry after a breach, to the extent insurable by law.
There's no guarantee of a payout for every incident. Exact inclusions, sub-limits and exclusions differ between insurers, and your broker can walk you through what a specific policy actually promises. What's consistent across providers is the underwriting side. The questions you're asked before cover is issued or renewed increasingly come back to the same handful of security basics.
What insurers commonly ask, mapped to a trade business's actual setup
You don't need a server room for any of this to apply. It's about the phone, the app and the login you already use every day.
Multi-factor authentication on email and your job-management app
This is the most commonly asked question, and the one insurers treat as close to a baseline. If your business email or your quoting and invoicing app only needs a password to get in, that's the answer most likely to cause trouble on an application. Multi-factor authentication is a second step on top of the password, like a code from an app. It's usually a free setting in whatever platform you already use. Minutes per person to switch on.
Backups of quotes, invoices and client records
Say your only copy of client jobs and payment history lives inside one app on one phone. Losing that phone to theft, damage or a ransomware-style lockout is then a real business risk, not just a nuisance. Insurers ask whether backups exist, whether they're kept somewhere a compromised login couldn't also wipe, and whether you've ever actually tried restoring from one.
Patched phones, tablets and laptops
Updates matter on every device you use for work: the phone in your pocket, the tablet mounted in the ute, the laptop that does the books. Unpatched software is one of the easier ways in for an attacker. Insurers care less about brand names than about whether updates actually get installed when a fix ships, and how fast.
Who can access the shared logins
Plenty of trade businesses share one email or accounting login between a couple of people because it's easier day to day. Insurers ask about it because a shared, unmanaged login is harder to secure and harder to lock down quickly if something goes wrong. Restricting administrative access to the people who actually need it, each with their own account, is the kind of answer that holds up on a questionnaire.
Preparing without hiring a consultant
You don't need a security firm to answer these questions honestly. Work through it in this order:
- Check where you actually stand. Our free Essential Eight self-assessment runs through plain-English questions on MFA, backups, patching and admin access, and gives an indicative Level 0–3 for each. About 20 minutes, no jargon, no account needed to see the result.
- Fix the cheap, high-impact gaps first. Turning on MFA and setting up a proper backup are usually the quickest wins, and they're what insurers ask about first.
- Answer the application accurately. An optimistic answer isn't a shortcut. If a claim is ever investigated and a control you attested to wasn't actually in place, that can affect the claim itself.
- Talk to a broker who knows trades. They can match cover to what your business actually holds and does, and explain what a specific policy will and won't pay out for.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of what any insurer will offer. See what Australian cyber insurers commonly ask across all business types for the bigger picture beyond trades, or start with the Essential Eight explained for small business if you'd like all eight controls laid out first.
Know your answers before the application or renewal form arrives: take the free Essential Eight self-assessment. 20 minutes, plain English, built for businesses that don't have an IT department.
FAQ
Do sole traders need cyber insurance? There's no legal requirement to hold it. But a one-person trade business faces the same risks as a bigger one: client details, quotes and invoices on a phone or laptop, and payments processed digitally. Whether it's worth taking out is a decision for you and a broker, based on what you hold and what a day of downtime would cost you. The security questions an insurer asks are the same regardless of business size.
Does a mobile or ute-based setup count as a cyber risk? Yes. A cyber policy and an insurer's questionnaire don't care whether your "office" is a fixed premises or a phone and a tablet in the ute. What matters is where client data, quotes and invoices are stored and accessed, and how well those devices and accounts are secured. A phone with no lock screen and shared logins to a job-management app is a real gap, not a technicality.
What's the cheapest first fix for a trade business? Turning on multi-factor authentication for email and your job-management or invoicing app. It's usually a free setting and takes minutes per person. It's also commonly the first thing an insurer's questionnaire asks about, and the answer most likely to cause problems if it's no.
Will cyber insurance cover a hacked invoice or payment redirection scam? Many cyber policies include cover for this kind of incident (often called business email compromise or invoice fraud) alongside data breach response and cyber extortion, but exact terms, sub-limits and exclusions vary by insurer and policy. Confirm what's included with your broker before you assume it's covered. This article describes patterns commonly seen in the Australian market, not the terms of any specific policy.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).