cuttleflow
Commons
Meridian Commons · Cyber

Cyber Insurance

First- and third-party cover for cyber events and data breaches.

About This Policy

This policy protects your business from the financial consequences of cyber incidents. It covers both the direct costs you incur (first-party cover) and the claims others make against you (third-party cover).

Cyber incidents can move fast. If you experience one, contact our incident response team immediately — their details are in your schedule. Do not wait to file a formal claim. Early response often determines the outcome.

This policy, together with your schedule and any endorsements, forms your contract of insurance with us. Words shown in bold have special meanings — you will find their definitions in Section 01.

A note on “reasonable”. Where this policy uses “reasonable” or “reasonably”, it means reasonable having regard to the circumstances known at the time, including the nature and scale of the cyber event, privacy breach, or claim, and current market practice at that time.

Schedule

(Completed separately for each policy — contains your specific details.)

The schedule shows:

01 Definitions

When the following words appear in bold in this policy, they have the meanings set out below.

Claim Any written demand for compensation, any writ, summons, or legal proceeding, or any formal regulatory investigation or proceeding, made or commenced against you during the policy period arising from a cyber event or privacy breach. Two or more claims arising from the same cyber event or privacy breach, or from a series of related events or breaches, are treated as a single claim first made when the earliest was first made.
Company The entity named as the named insured in the schedule, and any subsidiary.
Computer system Any computer, server, network, hardware, software, firmware, data storage system, cloud service, hosted platform, website, application, or communications system that is: (a) owned or leased by you; or (b) operated by you or on your behalf. A system operated by a service provider under a written contract with you is not your computer system. Loss or interruption caused by an event affecting a service provider’s systems is not a cyber event for the purposes of Section 2.2 (Business Interruption), Section 2.3 (Data and System Restoration), or Section 3.2 (Network Security Liability), and is covered only under Section 2.8.2 (Dependent Business Interruption), or another extension of this policy that expressly says so — see the definition of dependent event below.
Cyber event (a) any unauthorised access to, or unauthorised use of, your computer system; (b) any malware, ransomware, virus, trojan, worm, or other malicious code that affects your computer system; (c) any denial-of-service attack directed at your computer system; (d) any system failure of your computer system; or (e) any theft, loss, or unauthorised disclosure of data. A cyber event does not include the planned shutdown, maintenance, or upgrade of your computer system.
Cyber extortion threat A credible threat made against you during the policy period to: (a) introduce malware into, or disrupt the operation of, your computer system; (b) corrupt, damage, destroy, or restrict access to your data; (c) publish, release, or misuse your data or your clients’ data; or (d) cause any other damage to your business using electronic means, unless you pay a ransom or meet other demands.
Data Any information stored electronically on a computer system (including a computer system operated by a service provider) or held in your physical possession, including personal information, confidential business information, financial records, intellectual property, and any other digital records.
Defence costs The reasonable legal costs and expenses incurred with our prior written consent in investigating, defending, or settling a claim. We will not unreasonably withhold or delay our consent.
Dependent event Unauthorised access to, or unauthorised use of, a service provider’s systems; malware, ransomware, virus, trojan, worm, or other malicious code affecting a service provider’s systems; a denial-of-service attack directed at a service provider’s systems; or an unplanned outage or failure of a service provider’s systems caused by human error, accidental misconfiguration, power surge, or unintentional software defect, that is not caused by a malicious external act. A dependent event does not include the planned shutdown, maintenance, or upgrade of a service provider’s systems.
Digital media content Content you publish electronically, including on your website, social media accounts, email communications, newsletters, blogs, podcasts, or online advertising — but only content published in connection with your business.
Employee Any natural person who works for you under a contract of employment, including permanent, fixed-term, and casual employees. It includes volunteers and interns. It does not include independent contractors.
Endorsement A document attached to this policy that changes its terms.
Excess The amount shown in the schedule that you must pay as the first part of each claim or insured loss. The excess may differ by section.
Extra expense The reasonable and necessary costs you incur, beyond your normal operating expenses, to continue your business operations during a business interruption caused by a cyber event or a dependent event.
Indemnity period The period shown in the schedule, starting from the date of the cyber event or dependent event, during which we will measure your net income loss and extra expense.
Insured loss A loss, cost, or expense payable to you under Section 2 (First Party). Two or more insured losses arising from the same cyber event, dependent event, cyber extortion threat, or privacy breach, or from a series of the same, similar, or related cyber events, dependent events, cyber extortion threats, or privacy breaches — including those exploiting the same vulnerability or attributable to the same threat actor or campaign — are treated as a single insured loss first discovered when the earliest of them was first discovered.
Insured person Any past, present, or future partner, principal, director, officer, company secretary, or employee of the company.
Limit of liability The amount shown in the schedule, which is the most we will pay for all losses, costs, and claims combined during the policy period.
Named insured The entity shown as the named insured in the schedule.
Net income loss The reduction in your net revenue, after deducting costs and expenses that do not continue during the interruption, directly caused by a cyber event or a dependent event. We calculate this by comparing your actual revenue during the interruption against what you would reasonably have earned had the cyber event or dependent event not occurred.
Personal information Information about an identified or identifiable individual, as defined in the Privacy Act 1988 (Cth) and any equivalent state, territory, or foreign law.
Policy period The period shown in the schedule.
Privacy breach (a) the actual or suspected unauthorised access to, collection, use, disclosure, or loss of personal information or confidential corporate information in your care, custody, or control; (b) your actual or suspected failure to comply with any privacy or data protection law; or (c) a civil claim against you for damages arising from a serious invasion of privacy, to the extent the claim is made under the statutory tort for serious invasions of privacy inserted into the Privacy Act 1988 (Cth) by the Privacy and Other Legislation Amendment Act 2024.
Retroactive date means the date shown in the schedule. See Section 7.11 (Retroactive Date) for how this date operates.
Schedule The document titled “Schedule” issued with this policy, as amended by any endorsement.
Service provider A third party that provides information technology services to you under a written contract, including cloud computing, hosting, managed security, data storage, and payment processing — but not including telecommunication or utility providers for general internet connectivity or power supply.
Subsidiary Any entity in which the named insured holds more than 50% of the voting rights, or over which the named insured has effective management control, at the time of the relevant cyber event.
System failure An unplanned outage or failure of your computer system, caused by human error, accidental misconfiguration, power surge, or unintentional software defect, that is not caused by a malicious external act.
Unauthorised In relation to access to, or use of, a computer system, a service provider’s systems, or data: access or use that is not permitted, and includes access or use by a person who holds a valid credential, authority, or right of access for some purposes but who accesses or uses the computer system, the service provider’s systems, or the data beyond the scope of, or for a purpose not permitted by, that credential, authority, or right.
Waiting period The number of consecutive hours shown in the schedule. A business interruption must last longer than the waiting period before any net income loss or extra expense is payable. Once the interruption exceeds the waiting period, we measure your loss from the start of the interruption.
We / us / our The insurer named in the schedule.
Widespread event A cyber event, dependent event, or privacy breach that arises from, or is attributable to, the same vulnerability, exploit, malicious code, or campaign that also affects one or more other parties insured under this wording (whether insured by us or by any other insurer), where the number of affected parties, or the aggregate loss across those parties, reaches the threshold shown in the schedule. See Section 5.7 (Widespread Events).
You / your (a) the company; and (b) any insured person, but only while acting within the scope of their duties for the company.

02 What Is Covered — Your Own Losses (First Party)

These insuring clauses cover the costs and losses you incur directly. They are not about claims by third parties — those are covered in Section 3. All cover under this section is subject to Section 7.11 (Retroactive Date).

2.1 Incident Response Costs

If you discover a cyber event or privacy breach during the policy period, we will pay the reasonable costs you incur, with our prior consent, for:

You should use the incident response team named in your schedule. If you use a different provider, you need our prior written consent. We will not unreasonably withhold consent, but using our panel helps ensure a fast, coordinated response.

2.2 Business Interruption

If a cyber event that occurs during the policy period causes a total or partial interruption to your business (whether the interruption occurs during the policy period or afterwards), we will pay:

(a) your net income loss; and

(b) your extra expense,

for the duration of the interruption, up to the indemnity period shown in the schedule.

Waiting period — threshold basis. The waiting period operates as a qualifying threshold, not a deduction. If the interruption lasts longer than the waiting period, we pay your net income loss and extra expense measured from the start of the interruption. If the interruption does not exceed the waiting period, no payment is made under this section. The waiting period applies in addition to, not instead of, the excess shown in the schedule (Section 5.4).

We measure your net income loss by comparing your actual revenue during the interruption against what you would reasonably have earned. We will take into account trends, seasonal variations, and any growth or decline in your business.

2.3 Data and System Restoration

If a cyber event that occurs during the policy period corrupts, damages, destroys, or encrypts your data or computer system, we will pay the reasonable costs to:

(a) restore, recreate, or recollect your data from backups or other sources;

(b) repair or replace the affected components of your computer system; and

(c) verify that your computer system is functioning correctly and free of malware.

We will not pay for improvements or upgrades beyond the specification of your computer system immediately before the cyber event, except as provided under the betterment extension (Section 2.8.1).

2.4 Cyber Extortion

If you receive a cyber extortion threat during the policy period, we will pay:

(a) the reasonable costs of investigating and responding to the threat; and

(b) any ransom payment, but only with our prior written consent.

We will only consent to a ransom payment after we have confirmed (so far as reasonably possible) that the payment does not breach any law, including sanctions laws. We may engage a specialist negotiator on your behalf.

We will not reimburse any ransom payment made without our prior written consent, unless you can demonstrate that the delay in obtaining consent would have caused you materially greater loss.

2.5 Funds Transfer Fraud

If during the policy period a third party gains unauthorised access to your computer system and fraudulently transfers your funds from your account, we will pay your direct financial loss.

You must discover the fraudulent transfer during the policy period and notify us within 30 days of discovery.

We will not pay if the transfer was authorised by you or any insured person, even if that authorisation was obtained by deception. Social engineering fraud (where you are deceived into making the transfer yourself) is covered separately under Section 2.6.

2.6 Social Engineering Fraud

If during the policy period you transfer funds as a result of a fraudulent communication that impersonates a genuine person or entity — for example, a fake invoice, a spoofed email from a senior executive, or a fraudulent change of bank details — we will pay your direct financial loss.

You must discover the loss during the policy period and notify us within 30 days of discovery.

We will not pay if you did not follow your own documented verification procedures (if any) before making the transfer. If you do not have documented verification procedures, we will assess whether you took reasonable steps to verify the instruction.

SUB-LIMIT The amount shown in the schedule (or $250,000 per claim if not stated)

2.7 Regulatory Fines and Penalties

If a regulator (including the OAIC, ASIC, ACMA, or any state, territory, or foreign equivalent) imposes a fine or penalty on you arising from a cyber event or privacy breach that occurs during the policy period, we will pay the fine or penalty — but only to the extent that it is insurable at law.

We will also pay your defence costs in responding to the regulatory proceeding.

Not all fines and penalties are insurable. Australian law generally allows the insurance of civil penalties but not criminal penalties. We will not pay any amount that is not legally insurable.

2.8 Extensions — Your Own Losses

2.8.1 Betterment

When restoring your computer system after a cyber event, we will pay up to 120% of the cost of restoring to the pre-event specification, to allow for reasonable security improvements that would not have been needed but for the event.

2.8.2 Dependent Business Interruption

If a dependent event during the policy period directly causes a total or partial interruption to your business, we will pay your net income loss and extra expense as if the event had occurred at your own computer system.

This is the only cover under this policy for business interruption caused by a dependent event. Section 2.2 does not respond to interruption caused by a dependent event, and a dependent event is not a cyber event for the purposes of Section 2.2.

The waiting period applies separately to dependent business interruption losses, on the same threshold basis as Section 2.2.

Interruption arising at a non-IT supplier, or at a named customer, can be added by endorsement E13 or E14.

SUB-LIMIT The amount shown in the schedule (or $500,000 in the aggregate if not stated)

2.8.3 Bricking

If a cyber event renders any of your hardware permanently and irreparably unusable (sometimes called “bricking”), we will pay the reasonable cost of replacing the affected hardware with equipment of equivalent specification.

SUB-LIMIT The amount shown in the schedule (or $250,000 in the aggregate if not stated)

2.8.4 Reputational Harm — Income Loss

If a cyber event or privacy breach covered by this policy results in negative media coverage or public reporting that causes a measurable loss of customers or revenue, we will pay your resulting net income loss for up to 12 months from the date of the first public report.

You must demonstrate a direct causal link between the cyber event or privacy breach, the public reporting, and the loss of revenue.

SUB-LIMIT The amount shown in the schedule (or $250,000 in the aggregate if not stated)

2.8.5 Telecommunications Fraud

If a third party gains unauthorised access to your telephone or communications system during the policy period and makes calls or uses services at your expense, we will pay the charges you incur as a direct result.

SUB-LIMIT The amount shown in the schedule (or $100,000 in the aggregate if not stated)

2.8.6 Voluntary Notification

If a privacy breach occurs and you are not legally required to notify affected individuals, but we agree that notification would be prudent, we will pay the reasonable costs of voluntary notification.

SUB-LIMIT $100,000 in the aggregate

2.8.7 PCI-DSS Assessment

If a payment card industry body (such as Visa, Mastercard, or their acquiring bank) imposes a fine, penalty, or assessment on you arising from a privacy breach that involves payment card data, we will pay the amount assessed — including any contractual penalties under your merchant services agreement.

SUB-LIMIT The amount shown in the schedule (or $250,000 in the aggregate if not stated)

2.8.8 Reward

We will pay the cost of a reward offered with our prior consent for information leading to the arrest and conviction of any person responsible for a cyber event covered by this policy.

SUB-LIMIT $25,000 per event

03 What Is Covered — Claims by Others (Third Party)

These insuring clauses cover claims that other people or organisations make against you. All cover under this section is subject to Section 7.11 (Retroactive Date).

3.1 Privacy and Data Breach Liability

If a claim is first made against you during the policy period for a privacy breach that first occurs on or after the retroactive date, we will pay:

(a) any amount you become legally liable to pay as compensation (including the claimant’s costs); and

(b) your defence costs.

This covers claims alleging:

(i) your failure to protect personal information or confidential corporate information;

(ii) your failure to comply with the Privacy Act 1988 (Cth) or any other privacy or data protection law;

(iii) your failure to notify a data breach as required by law;

(iv) your failure to comply with your own published privacy policy; and

(v) a serious invasion of privacy under the statutory tort described in paragraph (c) of the definition of privacy breach.

3.2 Network Security Liability

If a claim is first made against you during the policy period for a cyber event that first occurs on or after the retroactive date, we will pay any amount you become legally liable to pay as compensation, and your defence costs, for your failure to prevent:

(i) unauthorised access to or use of your computer system;

(ii) a denial-of-service attack originating from or directed at your computer system;

(iii) the transmission of malware from your computer system to a third party’s system; or

(iv) the use of your computer system to attack a third party (where you are an unwitting intermediary).

3.3 Media Liability

If a claim is first made against you during the policy period arising from your digital media content, we will pay any amount you become legally liable to pay as compensation, and your defence costs, for:

(i) defamation (including libel and slander);

(ii) breach of privacy or intrusion upon seclusion;

(iii) infringement of copyright, trademark, or domain name; or

(iv) plagiarism.

This section does not cover claims arising from advertising of products or services other than your own, or any content published by third parties on platforms you operate (unless you were aware of the content and failed to remove it after being notified).

3.4 Regulatory Defence Costs

We will pay your defence costs in responding to a formal investigation, inquiry, or proceeding by a regulator (including the OAIC, ASIC, ACMA, or any state, territory, or foreign equivalent) arising from a cyber event or privacy breach covered by this policy.

3.5 Extension — Court Attendance

If any insured person attends court, a tribunal, or an arbitration as a witness in connection with a claim covered by this policy, we will pay $500 per day or part-day of attendance required by us.

SUB-LIMIT $10,000 in the aggregate

04 What Is Not Covered

We do not cover any loss, cost, expense, claim, or liability:

4.1 War and State-Backed Cyber Operations

arising from:

(a) war (whether or not declared), invasion, hostilities, rebellion, revolution, insurrection, civil unrest, or the use or usurpation of military power, or any similar belligerent act;

(b) the use of a computer system, by or on behalf of a state, to cause harm in the course of war;

(c) the use of a computer system, by or on behalf of a state, that has a major disabling effect on the essential functions of another state; or

(d) action taken between states in response to any of the above.

Definitions for this exclusion.

In this exclusion, a reference to the use of a computer system by or on behalf of a state includes using it to damage, disrupt, or interfere with information, systems, or networks, whether the target is in another state or elsewhere.

A major disabling effect on the essential functions of a state means significantly impairing an essential service (such as energy, water, financial services, telecommunications, transport, or health) or the state's security or defence.

Attribution.

Whether an act is carried out by or on behalf of a state is determined by reference to any attribution made by the government of the state where the affected computer system is located. If that government does not make an attribution, we may rely on a reasonable and informed assessment of the available evidence. If attribution is disputed, the burden of proving it rests with us.

This exclusion does not apply to a cyber event that is not carried out by or on behalf of a state, even if it occurs during a period of war.

For the avoidance of doubt, a cyber event carried out by a non-state actor for ideological, political, or terrorist purposes is not excluded by this Section 4.1. Cover for such an event is determined by the other terms, conditions, and exclusions of this policy.

4.2 Infrastructure Failure

arising from the failure, interruption, or outage of:

(a) the public internet or a national telecommunications network;

(b) the electricity grid or other utility supply; or

(c) satellite or GPS systems,

that is not caused by a cyber event or dependent event specifically targeting your computer system or your service provider’s systems.

4.3 Bodily Injury and Property Damage

arising from the death, bodily injury, illness, or disease of any person, or from physical loss of or damage to tangible property. Data is not tangible property for the purposes of this exclusion.

4.4 Professional Services

for any errors or omissions in professional advice or services you provide to third parties.

This exposure is designed to be covered under a professional indemnity policy. However, if the advice or service relates to IT security and the resulting claim involves a cyber event, you should check whether your PI policy’s cyber carve-back responds.

4.5 Contractual Liability

for any liability you assume under a contract that is greater than the liability you would have at law without the contract — except for:

(a) liability under a confidentiality or non-disclosure agreement; and

(b) PCI-DSS assessments under your merchant services agreement (covered under Section 2.8.7).

4.6 Deliberate and Dishonest Acts

arising from any cyber event or privacy breach that you deliberately cause, condone, or direct. However: we will still cover any insured person who did not personally participate in, direct, or know about the conduct. This protection applies separately to each insured person.

4.7 Prior Known Events

arising from any cyber event or privacy breach that:

(a) you knew about before the start of this policy period; or

(b) first occurred before the retroactive date (see also Section 7.11).

4.8 Unsupported Software

arising from a cyber event that exploits a known vulnerability in software or an operating system that has reached end-of-life and is no longer supported by the vendor with security patches — unless you have purchased the end-of-life software buy-back endorsement (E03), or you can demonstrate that you had implemented reasonable compensating controls (such as network segmentation, application whitelisting, or virtual patching).

4.9 Patent and Trade Secrets

for the infringement of a patent or the misappropriation of a trade secret. Copyright and trademark infringement arising from your digital media content is covered under Section 3.3.

4.10 Nuclear

arising from nuclear reaction, radiation, or radioactive contamination.

4.11 Sanctions

We will not make any payment that would breach any trade or economic sanctions, embargo, or restriction imposed under the Autonomous Sanctions Act 2011 (Cth), the Charter of the United Nations Act 1945 (Cth), or equivalent sanctions measures of the European Union, the United Kingdom, or the United States.

4.12 Unfair Collection Practices

arising from your collection, use, or disclosure of personal information in a manner that is deliberately deceptive, deliberately unfair, or that you know to be in violation of law — as distinct from a negligent or accidental failure to comply.

4.13 Trading Losses

for your lost profit or revenue other than net income loss covered under Sections 2.2, 2.8.2, and 2.8.4, or for the loss of any client, contract, or business opportunity (other than as measured under Section 2.8.4).

4.14 Improvement and Upgrade Costs

for the costs of improving, upgrading, or redesigning your computer system beyond its pre-event specification — except as provided under the betterment extension (Section 2.8.1) and to the extent necessary to restore functionality.

05 How Much We Will Pay

5.1 Limit of Liability

The most we will pay for all losses, costs, expenses, and claims combined during the policy period is the limit of liability shown in your schedule. This is an aggregate limit.

5.2 Sub-Limits

Where a sub-limit is stated (either in this wording or in the schedule), that sub-limit is included within — not in addition to — the limit of liability, unless the schedule states otherwise.

5.3 Defence Costs

Defence costs are included within the limit of liability. We will advance defence costs as they are incurred, before the outcome of a claim is determined. If it is later established that a claim is not covered, you must repay any defence costs we advanced for the uncovered portion.

5.4 Excess

You must pay the excess shown in the schedule as the first part of each claim or insured loss. The excess may differ between sections.

Aggregation. Claims arising from the same or related events are aggregated under the definition of claim; first-party losses arising from the same or related events are aggregated under the definition of insured loss. Only one excess applies to a single claim or a single insured loss (as aggregated).

Multiple sections or endorsements. Where a single cyber event, dependent event, privacy breach, or cyber extortion threat gives rise to insured loss or a claim under more than one section or endorsement of this policy, only the highest applicable excess for those sections or endorsements applies, and the related losses and claims are treated as a single insured loss or single claim for the purposes of the excess.

The excess does not apply to incident response costs under Section 2.1 unless the schedule specifically states otherwise. We want you to respond quickly — not hesitate because of the excess.

5.5 Other Insurance

If you have other insurance that covers the same loss, this policy will pay only the amount that exceeds what is payable under the other insurance — unless the other insurance states that it is excess over this policy.

5.6 Paying Out the Limit

At any time, we may pay you the limit of liability (or whatever remains of it) and our obligation to pay any further amount will end. We will not do this without giving you reasonable notice.

5.7 Widespread Events

If the schedule shows this section as operative, our total liability for all losses, costs, expenses, and claims arising from a widespread event is limited to the widespread event sub-limit shown in the schedule, applied in place of — and not in addition to — the limit of liability in Section 5.1.

If this section is not shown as operative in the schedule, it does not apply, and the limit of liability in Section 5.1 applies without modification.

06 Your Obligations

6.1 When a Cyber Incident Occurs — Act Fast

Step 1: Contact our incident response team immediately using the details in your schedule. Do this before contacting any other service provider, if possible. Speed matters.

Step 2: Do not attempt to negotiate with any attacker or pay any ransom without our prior written consent.

Step 3: Preserve all evidence. Do not wipe, rebuild, or reformat affected systems until a forensic investigation has been conducted or we have agreed you may do so.

Step 4: Follow the incident response team’s advice on containment, investigation, notification, and recovery.

6.2 Notify Us of Claims

Tell us in writing as soon as reasonably practicable after a claim is made against you. Provide:

(a) the identity of the claimant and the nature of the allegations;

(b) details of the cyber event or privacy breach involved;

(c) when you first became aware of the claim; and

(d) your estimate of the potential value (if you can).

6.3 Notify Us of Circumstances

Tell us in writing during the policy period if you become aware of any cyber event or privacy breach that might reasonably be expected to give rise to a claim. Any claim that later arises from notified circumstances will be treated as if made during this policy period, consistent with s 40(3) of the Insurance Contracts Act 1984 (Cth).

Examples of things you should tell us about:

6.4 Do Not Admit Liability

Do not admit liability, make any offer to settle, or agree to pay any amount without our written consent. We will not unreasonably withhold or delay our consent.

6.5 Cooperate With Us

Give us all information, documents, and assistance we reasonably need. Cooperate with our incident response team, forensic investigators, and legal advisors.

6.6 Mitigate Your Loss

Take all reasonable steps to prevent or reduce any loss, including following your own security policies and procedures and the recommendations of our incident response team.

6.7 Preserve Our Recovery Rights

Do not do anything after a cyber event or claim that might prejudice our right to recover from any third party. If we pay a loss, we may take action in your name to recover what we have paid.

6.8 Your Security Obligations

You must maintain reasonable cybersecurity practices throughout the policy period, consistent with the information you provided when applying for this policy. This does not mean you must achieve perfect security. It means you must take the steps a reasonable business of your size and type would take.

Note about this obligation: Under s 54 of the Insurance Contracts Act 1984 (Cth), we cannot refuse your claim solely because you failed to maintain a particular security standard, unless that failure caused or contributed to the cyber event or prejudiced our interests. If your failure prejudiced our interests, we may reduce what we pay by a fair amount.

07 General Conditions

7.1 Your Duty of Disclosure

Before you enter into this policy, and before you renew, extend, or vary it, you have a duty to tell us anything you know (or could reasonably be expected to know) that would be relevant to our decision to insure you and on what terms.

You do not need to tell us about matters that reduce the risk, that are common knowledge, that we know or should know as an insurer, or that we have told you we do not need to know.

If you do not tell us something you should have told us, we may reduce or refuse your claim, cancel this policy, or both. The Insurance Contracts Act 1984 (Cth) sets out the rules.

7.2 Cancellation and Extended Reporting

By you: You can cancel this policy at any time by telling us in writing. We will refund the premium for the unexpired portion of the policy period, less any amount we have paid or reserved.

By us: We can cancel this policy by giving you 30 days’ written notice. We will refund the premium for the unexpired portion proportionally.

Automatic extended reporting period: If we cancel this policy, or decline to offer renewal, for any reason other than non-payment of premium or fraud, you have an automatic 30-day period after the end of the policy period in which to notify us of any claim first made against you during that 30-day period, arising from a cyber event or privacy breach that first occurred before the end of the policy period. There is no additional premium for this. This automatic period does not apply if this policy is replaced by other insurance covering the same exposure. A longer extended reporting period is available under endorsement E01.

7.3 Governing Law

This policy is governed by the laws of the state or territory of Australia shown in the schedule as the governing law state. That state is fixed at the start of the policy period and does not change if your principal place of business later changes.

7.4 Jurisdiction and Service of Suit

Claims under this policy may be brought only in the courts of the state or territory identified under Section 7.3, and each party submits to the jurisdiction of those courts and any courts of appeal from them.

This policy does not cover, and we will not pay in respect of, any claim brought within, or judgment entered or enforced from, a court of the United States of America or Canada or their territories, except to the extent that endorsement E11 (United States/Canada Jurisdiction Extension) is shown as operative in the schedule.

7.5 GST

When we pay a claim or loss, we will reduce our payment by the amount of any input tax credit you are entitled to claim under A New Tax System (Goods and Services Tax) Act 1999 (Cth). Tell us the extent of your entitlement. If you do not, we will assume full entitlement.

7.6 Several Liability

If more than one insurer is shown in the schedule, each is responsible only for its own share.

7.7 Assignment

You cannot transfer this policy without our prior written consent.

7.8 Entire Agreement

This policy, the schedule, and any endorsements form the entire agreement between you and us.

7.9 Disputes and Complaints

If you are not happy with a decision we have made, contact us first. We will follow our internal dispute resolution process.

If you are not satisfied with the outcome, you can refer the matter to the Australian Financial Complaints Authority (AFCA): www.afca.org.au | info@afca.org.au | 1800 931 678. AFCA provides a free and independent service. Time limits may apply.

7.10 Privacy

We handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Our Privacy Policy is available on our website and on request.

7.11 Retroactive Date

This policy does not cover any cyber event or privacy breach that first occurred before the retroactive date, under any section of this policy, whether or not the relevant insuring clause expressly refers to the retroactive date.

Sections 3.1 and 3.2 refer to the retroactive date for clarity; this Section 7.11 is the authoritative source of the restriction and applies to every section of this policy, including Section 2 (First Party).

Appendix A — How to Respond to a Cyber Incident

Guidance only. This appendix is practical guidance. It does not form part of the operative terms of this policy and does not vary, add to, or override Sections 1 to 7, including your obligations in Section 6.

Immediately (within hours)

Within 24 hours

Within 72 hours

Ongoing

Endorsement Library

The following endorsements are available and may be attached as shown in the schedule.

E01 Extended reporting period (additional run-off)
E02 Defence costs in addition to the limit of liability
E03 End-of-life software buy-back (subject to co-insurance)
E04 Increased social engineering fraud sub-limit
E05 Increased dependent BI sub-limit
E06 Cryptocurrency coverage (digital asset theft)
E07 Technology errors and omissions (combined PI + Cyber wording)
E08 Invoice manipulation fraud
E09 Contingent bodily injury (BI arising from a cyber event affecting operational technology)
E10 Excess layer
E11 United States / Canada jurisdiction extension
E12 Aggregate limit reinstatement
E13 Non-IT dependent business interruption (named suppliers)
E14 Customer business interruption (named customers)
E15 Generative AI cover (data poisoning and AI system risks)

Endorsements E01–E15 are set out in full in the companion Endorsement Library document (2026/CY/0003). This version of the base wording (v1.3.0-DRAFT) requires conforming edits to that library before both documents can be published together — the specific edits required are listed in the change register, to be published under wordings/changes/. The endorsement library is not rebuilt as part of this document.

Changes From v1.2.0

Provenance remediation (PROV-CMN-002); drafting-only, legal effect preserved. The War and State-Backed Cyber Operations exclusion (4.1) was reworded from the LMA5564–5567-derived formulation (the state cyber-operation and state-impact coinages and the attribution mechanic) into house wording, preserving the existing cover position — including the insurer-borne attribution burden — with a Wording Partner review tag added on reinsurance-treaty conformity. The endorsement companion document is not remediated here.

Changes From v1.1.0

Recorded in accordance with the Cuttleflow open wording library versioning requirements. Every entry below has been checked against the operative text of this draft.

See the companion Change Register (to be published) for the full finding-by-finding remediation record, including the endorsement-library edits required (not made in this document) and the repository-hygiene release-blocker actions.

Cuttleflow Systems — Open Source Insurance Wording · Licence: CC BY 4.0

2026/CY/0002 · v1.3.0-DRAFT · July 2026 · © 2026 Cuttleflow Pty Ltd t/a Cuttleflow Systems

DRAFT — SUBJECT TO LEGAL REVIEW — NOT FOR USE

This wording is a working draft and is not yet freely available for adoption, adaptation, or redistribution. Once Wording Partner sign-off is obtained it will be released under the terms of the CC BY 4.0 licence, which applies to the wording text only — it does not extend to the Meridian name, the bearing mark, or other Cuttleflow brand assets. It is designed for the Australian market and assumes the application of the Insurance Contracts Act 1984 (Cth). Users are responsible for their own legal review, regulatory compliance, and reinsurance alignment.

33°53′S · 151°16′E · SYDNEY · CUTTLEFLOW PTY LTD T/A CUTTLEFLOW SYSTEMS

Comments on this wording

The rest of the libraryComment where it’s quiet