Facebook Pixel

CGIB Cyber Insurance

Please complete the following information and submit this form to obtain a Cyber insurance quotation for your business.

Click on the following link to learn more regarding Cyber Insurance.

Cyber Insurance

All information you provide must be correct, true, and accurate as incorrect or misleading information may alter our quote and jeopardise cover if you proceed with a policy.

Please refer to the CGIB Financial Services Guide, Privacy Statement, General Advice Warning and Duty of Disclosure before completing this form.

You have errors in your submission, they are highlighted in red below

Policy & Business Details

Client Security Officer Details

Please provide contact details for the client's Chief Information Security Officer or other staff member who is responsible for data and network security and/or responsible for the contract with a managed 3rd party vendor

Underwriting Questions

None of these
Accreditation Services
Adult Content
Credit Bureau
Cryptocurrency / Distributed Ledger Technology
Cybersecurity Product or Services
Data Aggregator / Data Brokerage / Data Warehousing
Gambling Industry
IT Managed Services
Local or Regional authority
Manufacturer of Life Safety Products or Services
Payment Processing or Trading Exchanges
Peer to Peer FileSharing
Social Media Platform Provider (excludes Named Insured own use of Social Media Platforms)
Digital Surveillance
Third Party Claims Administration
Yes   No
Yes   No
None of these
Immutable or write-once read-many protections
Access to backups is restricted via multi-factor authentication
Completely offline or air-gapped (tape or non-mounted disk) that is disconnected from the rest of your network
Access to backups is restricted via separate privileged accounts that are not connected to active directory or other domains
None of these
URL or web filtering
Application isolation and containment
Centralised Endpoint Protection Platform
Advanced antimalware and antivirus with heuristic capabilities
EDR (endpoint detection and response), XDR (extended detection and response), or MDR (managed detection and response)
None of these
Quarantine service for suspicious emails
Ability to detonate attachments and links in a sandbox
Sender Policy Framework (SPF) is enforced
Phishing simulations or training for employees
Microsoft Office macros are disabled on documents by default
Yes   No
Yes   No
Yes   No
Yes   No
Yes   No
  • derive any revenue from Russia, Belarus, or Ukraine (including Crimea and the Luhansk and Donetsk regions);
  • have any operations, products, subsidiaries, employees, property or facilities in Russia, Belarus, or Ukraine (including Crimea and the Luhansk and Donetsk regions); or
  • have any supply chain reliance on companies or resources located in Russia, Belarus, or Ukraine (including Crimea and the Luhansk and Donetsk regions)?
Yes   No
Yes   No
Yes   No
Yes   No

Limits and Coverage

State & Territories Details

Please provide a breakdown of each state. *  %

NSW
 %
VIC
 %
QLD
 %
SA
 %
WA
 %
TAS
 %
ACT
 %
NT
 %
Overseas
 %

NSW Exemption
that my client (policyholder) is/will be a CGT small business entity (within the meaning of section 152-10 (1AA) of the Income Tax Assessment Act 1997 of the Commonwealth) for the income year in which the insurance is effected or renewed and that I have obtained a declaration to that effect from my client which I am able to produce if requested to do so by the Chief Commissioner.

Coverage Required

Incident Response Expenses

Incident Response Expenses

Incident Response Expenses by reason of a Cyber Incident or a Business Interruption Incident discovered by any Control Group member during the Policy Period and reported to the insurer. Subject to the insurers policy wording.

Cyber Extortion

Cyber Extortion

Cyber Extortion Damages and Cyber Extortion Expenses by reason of a Cyber Extortion Event discovered by any Control Group member during the Policy Period. Subject to the insurers policy wording.

Emergency Incident Response

Emergency Incident Response

Emergency Incident Response Expenses incurred within the first 48 hours immediately following the discovery of a reasonably suspected or confirmed Cyber Incident or Business Interruption Incident by any Control Group member during the Policy Period and reported to Us pursuant to General Condition 5.10 Notification, which requires immediate attention in order to mitigate the damage from, effects of and costs related to such Cyber Incident or Business Interruption Incident. Subject to the insurers policy wording.

Reward Expenses

Reward Expenses

Reward Expenses solely to the extent used in direct connection with a Cyber Extortion Event. Subject to the insurers policy wording.

Payment Card Loss

Payment Card Loss

Contractual liabilities owed to payment card industry firms because of a cyber incident. Subject to the insurers policy wording.

Social Engineering Fraud

Social Engineering Fraud

Direct Financial Loss solely as a result of Theft of Your Money or Securities due to Social Engineering Fraud by a Third Party and Discovered during the Policy Period. Subject to the insurers policy wording.

Business Interruption

Business Interruption

Loss of net profits and continuing operating expenses from interruptions of insured's systems; and with contingent business interruption, adds losses due to interruption of outsourced technology provider's systems. Subject to the insurers policy wording.

Privacy and Network Liability

Privacy and Network Liability

Damages and Privacy and Network Security Claims Expenses by reason of a Privacy and Network Security Claim first made during the Policy Period resulting from any Privacy and Network Security Wrongful Act taking place after the Retroactive Date and prior to the end of the Policy Period. Subject to the insurers policy wording.

Betterment costs

Betterment costs

Betterment Costs arising from a Business Interruption Incident. Subject to the insurers policy wording.

Telecommunications Fraud

Telecommunications Fraud

Telecommunications Expenses due to a Computer Malicious Act or Malicious Use or Access of a Covered Telecom System by a Third Party, discovered by any Control Group member during the Policy Period. Subject to the insurers policy wording.

Regulatory Fines

Regulatory Fines

Defense for regulatory actions and coverage for fines and penalties, where insurable by law. Subject to the insurers policy wording.

Data and System Recovery

Data and System Recovery

Data and System Recovery Costs during the Period of Indemnity, arising from a Business Interruption Incident discovered by any Control Group member during the Policy Period. Subject to the insurers policy wording.

Media

Media

Liability following defamation or copyright and trademark infringement online costs. Subject to the insurers policy wording.

Cyber Crime

Cyber Crime

Direct Financial Loss solely as a result of Theft of Your Money or Securities due to Malicious Use or Access of a Covered Computer System by a Third Party and Discovered during the Policy Period. Subject to the insurers policy wording.

Consumer Redress Fund

Consumer Redress Fund

Sum of money that You are legally obligated to deposit in a fund as equitable relief for the payment of consumer Privacy and Network Security Claims or Media Claims due to an adverse judgment or settlement of a Regulatory Proceeding. Subject to the insurers policy wording.

Ransomware

Ransomware

A type of malicious software designed to block access to a computer system until a sum of money is paid

All coverage options are pre-selected as we strongly recommend comprehensive protection. However, if you wish to exclude any coverage, you may do so by unticking the respective option. Please note that removing coverage may leave you uninsured and exposed to financial loss

Previous Insurance

Yes   No  
Yes   No  
Yes   No  
Yes   No  

Contact Details

Declaration

I/We hereby declare that:

My/Our attention has been drawn to the Important Notice accompanying this insurer proposal for insurance and further I/we have read these notices carefully and acknowledge my/our understanding of their content by my/our signature/s below.

The answers completed on my/our behalf to the insurer proposal questions are true and complete, and I/we have not suppressed or mis-stated any facts and should any information given by me/us alter between the date of this form and the inception date of the insurance to which this form relates I/we shall give immediately notice thereof.

I/We authorise CGIB and CGU Professional Risks, Insurance Australia Limited, to collect or disclose any personal information relating to this insurance to/from any other insurers or insurance reference service. Where I/we have provided information about another individual (for example, an employee, or client), I/we declare that the individual has been or will be made aware of that fact and the section in the policy on "The way we handle your personal information".

I/We also confirm that the undersigned is/are authorised to act for and on behalf of all persons who may be entitled to indemnity under any policy which may be issued pursuant to this insurance renewal, and I/we completed this insurer proposal for insurance on their behalf.

To be signed by the Chairman/President/Managing Partner/Managing Director/Principal of the association/Partnership/Company/Practice/Business.

* Mandatory Fields

Thank you for completing our online form.
We will endevour to contact you with your insurance details soon.

Important Information

An Important Notice From the Insurer to the Applicant for ‘Claims Made’ Contracts of Insurance

Please read and retain in your file

The proposed insurance is issued on a ’claims made’ basis.

This means that the policy responds to:

1.Claims first made against the insured during the policy period and notified to CGU Professional Risks during that policy period, providing that the insured was not aware, at any time prior to the policy inception, of circumstances which would have alerted a reasonable person in the insured’s position that a claim may be made against the insured; and

claims circumstances’ notified pursuant to Section 40 (3) of the Insurance Contracts Act which states: ’where the insured gave notice in writing to the insurer of facts that might give rise to a claim against the insured as soon
as was reasonably practicable after the insured became aware of those facts but before the insurance cover provided by the contract expired, the insurer is not relieved of liability under the contract in respect of the claim, when made, by reason only that it was made after the expiration of the period of insurance cover provided by the contract’.

After policy expiry, no new claims can be made on the expired policy, even though the event giving rise to the claim may have occurred during the policy period.

If during the policy period you become aware of circumstances which a reasonable person in your position would consider may give rise to a claim, and which you fail to notify to us during the policy period, we may not cover you under a subsequent policy for any claim which arises from these circumstances.

When completing the Insurer Proposal you are obliged to report and provide full details of all circumstances of which you are aware and which a reasonable person in your position would consider may give rise to a claim.

It is important that you make proper disclosure (see Duty of Disclosure, below) so that your cover under any new policy with us is not compromised.

Pursuant to the Insurance Contracts Act your duty to disclose all relevant information is set out below

Duty of Disclosure

Before entering into a contract of general insurance, you have a duty, under the Insurance Contracts Act, to disclose to us every matter that you are aware of, or could reasonably be expected to be aware of, that is relevant to our decision about insuring you and if so, on what terms. You have the same duty to disclose these matters to us before you renew, extend, vary or reinstate a contract of general insurance.

Your duty however does not require disclosure of matter -

  • that diminishes the risk to be undertaken by us;
  • that is of common knowledge;
  • that we know or, in the ordinary course of our business, ought to know;
  • as to which compliance with your duty is waived by us.

You should note that your duty continues after the Insurer Proposal has been completed until the policy is entered into.

Non-disclosure
If you fail to comply with your duty of disclosure, we may be entitled to reduce our liability under the policy in respect of a claim or may cancel the policy. If your non-disclosure is fraudulent, we may also have the option of avoiding the contract from its beginning. It is therefore vital that you enquire of all entities comprising the insured, including senior staff, before completing the Insurer Proposal and before you sign any declaration confirming no change in the information disclosed.

Retroactive Liability
The proposed insurance may be limited by a retroactive date either stated in the schedule or endorsed onto the policy. Where the retroactive cover provided by the proposed policy is subject to such a date, then the policy does not cover any claim arising from actual or alleged act, error, omission or conduct occurring prior to such retroactive date.
    
Average Provision
One of the insuring provisions of the proposed insurance may provide that where the amount required to dispose of a claim exceeds the limit of the sum insured in the policy then CGU Professional Risks shall be liable only for a proportion of the total costs and expenses. This shall be the same proportion of the total expenses as the policy limit bears to the total amount required to dispose of the claim.

Surrender or Waiver of any Right of Contribution or Indemnity
If another person or company is liable to compensate you or hold you harmless for part or all of any loss or damage otherwise covered by our policy, but you agree with that person or company (either before or after the inception of our policy) that you would not seek to recover any loss or damage from them, we will not cover you for this loss or damage.