• Capability statement
  • Contact sheet
  • API Docs
  • Customer Log in
  • Partner Log in
  • Broker Log in
1300 705 031 hello@withagile.com
with Agile with Agile
  • Home
  • Products
    • Aviation
      • Aircraft Hull & Liability
      • Aviation Hangar Keepers Liability
      • Renters Liability
      • ACRE
      • GliderCover
      • Pilot Personal Accident Cover
      • LAME
      • RAAus Level 2 Maintainers Insurance
      • Meet the Aviation team
    • Financial Lines
      • Professional Indemnity Insurance
      • Architects & Engineers
      • Accountants
      • Information Technology
      • Meet the Financial Lines team
    • Cyber Insurance
      • CyberCare
      • CyberSelect
      • Incident Response Plan Guide
      • Office 365 Cyber Health Check Guide
      • IT Security Awareness Training and Simulated Phishing Platform
      • White Paper: top tips for increasing cyber risk resilience
    • Accident & Health
      • Group Personal Accident Insurance
      • Individual Personal Accident Insurance
      • Voluntary Workers Personal Accident Insurance
      • Journey Personal Accident Insurance
      • Directors Personal Accident Insurance
      • Sports Personal Accident Insurance
      • Group Loss of Licence Insurance
      • Individual Loss of Licence Insurance
      • Corporate Travel Insurance
      • Make an Accident & Health Claim
    • Casualty
    • Construction
    • Travel
      • Leisure travel
    • Online
    • Wholesale
      • Wholesale at AGILE: appetite guide
  • Syndicate Services
  • New Zealand
    • Agile Group contact sheet – NZ
    • Agile capability statement – NZ
  • About
  • Articles
  • Make a Claim
    • Declarations
      • Medical Declaration
      • Employment Declaration
      • No claims declaration
    • Guide to making a claim
    • Aviation
    • Accident & Health
    • Drone DataCare
    • Consultants Professional Indemnity
    • Liability
    • Couriers Liability
    • Locums Liability
    • Allied Health Liability
    • Professional Indemnity
    • Real Estate Professional Indemnity
    • Audit Cover
    • IT Contractors Professional Indemnity
  • Help
    • Complaints procedure for Lloyd’s policies
    • Financial Services Guide
    • Duty of disclosure
    • Privacy policy
    • Refund notice
    • Terms and conditions
    • Translation and Teletype (TTY)
    • Family Violence Policy
    • Vulnerability Policy
    • Financial Hardship
    • Retail Insurance Product Design and Distribution Policy
    • Target Market Determinations
  • Contact
    • Contact sheet
    • Capability statement
    • Agile Group contact sheet – NZ
    • Agile capability statement – NZ
with Agile > Cyber Insurance > Incident Response Plan Guide

Incident Response Plan Guide

As your Cyber Risks insurer (Agile Underwriting Services Pty Ltd), we have collated some information to improve your company’s security readiness.

Introduction

As your Cyber Risks insurer (Agile Underwriting Services Pty Ltd), we have collated some information to improve your company’s security readiness. Incidents do occur and there is only so much that can be done to prevent them. Improvement in readiness will help you to recover more quickly and minimise the cost to your business.

Cyber security management is a complex topic and investment into protection (e.g. firewalls, anti-malware, and other intrusion detection systems) can be expensive. The level of investment should be commensurate with the level of potential exposure to your business. This document is NOT a “how to” cyber security guide. This is a common sense guide on what basic business steps can be taken to be better prepared.


Notifiable Data Breach (NDB)

The Office of the Australian Information Commissioner – OAIC has mandated reporting of data breach on personal privacy data under the Notifiable Data Breach (NDB) scheme since February 2018. They have published a guide on preparation and response to data breach here. We encourage all our policyholders to take advantage of the guidance and share with us your incident response plan. The information in the response plan will greatly assist our panel of claims experts assigned to assist with the handling of your claim and accelerating your recovery process. It will inform our experts in:

  1. Determining the extent and materiality of the data breach
  2. The effectiveness of the containment effort against the cyber attack
  3. Perform targeted forensic analysis to identify and eradicate attackers from your systems
  4. Facilitate rapid recovery of your system to return your business operation to normality

Incident Response Plan (IRP)

The incident response plan should contain the following minimum elements:

  1. An inventory of current asset (information, data, equipment, network, facilities etc) covered by the IRP
  2. Process for detection and confirmation of data breach
  3. Process for notifying Cyber Insurers, see policy notification requirements
  4. Implementation process (as per the OAIC guide)
    1. Contain the data breach
    2. Assess the data breach
    3. Notify impacted parties and/or appropriate authorities
    4. Review the incident and initiate preventative measures

If your business uses cloud based services such as Gmail, Saleforce.com, MYOB Cloud, Xero etc, the incident response plan should address these services with all the current contract information so that our panel of experts can engage these cloud service providers effectively on your behalf to contain and repair any damage associated with these cyber-attacks.

The OAIC guidance has made it clear the importance of defining the escalation and notification process. This information would be very useful to our team in assessing and processing your claim request. Page 18 (see expert below) in the OAIC guide provides a quick checklist for other elements in the response plan.

Information to be included in the IRP Yes No
What a data breach is and how staff can identify one Yes No
Clear escalation procedures and reporting lines for suspected data breaches Yes No
Members of the data breach response team, including roles, reporting lines and responsibilities Yes No
Details of any external expertise that should be engaged in particular circumstances Yes No
How the plan will apply to various types of data breaches and varying risk profiles with consideration of possible remedial actions Yes No
An approach for conducting assessments Yes No
Processes that outline when and how individuals are notified Yes No
Circumstances in which law enforcement, regulators (such as the OAIC), or other entities may need to be contacted Yes No
Processes for responding to incidents that involve another entity Yes No
A record-keeping policy to ensure that breaches are documented Yes No
Requirements under agreements with third parties such as insurance policies or service agreements Yes No
A strategy identifying and addressing any weaknesses in data handling that contributed to the breach Yes No
Regular reviewing and testing of the plan Yes No
A system for a post-breach review and assessment of the data breach Yes No
A system for a post-breach review and assessment of the data breach response and the effectiveness of the data breach response plan Yes No

Once you have completed the checklist

Once you have completed your own IRP, ask Agile or your broker about our Dynamic Excess Endorsement to get up to 50% of your Policy excess back if you make a claim.

Download the IRP checklist as a PDF

Documents

  • CyberCare PDS
  • CyberSelect PDS
  • CyberSelect Proposal Form
  • Download the IRP checklist as a PDF
  • Multi-factor Authentication Guide
  • Office 365 Cyber Health Guide
  • IT Security Awareness Training and Simulated Phishing Platform
  • White paper – Top tips for increasing cyber risk resilience

Making a claim

Read our guide to claiming to ensure a smooth process and you can make a claim online here.

Latest news
  • Challenging the Status Quo: The future of Underwriting in New Zealand by Liz Geden
  • Kunal Monga – Insurance Broker at Arcuri & Associates Insurance Professionals
  • Harnessing AI: How brokers can leverage Artificial Intelligence for business growth
  • Agile promotes Jamie Connor to lead Aviation operations in Australia and New Zealand
  • Agile recognised as 2024 5-Star Insurance Innovator by Insurance Business ANZ
Connect with us on socials
Products
  • Aviation
  • Financial Lines
  • Cyber Insurance
  • Accident & Health
  • Casualty
  • Travel
  • Online
Claims & help
  • Complaints procedure for Lloyd’s policies
  • Complaints and Dispute Resolution Procedure for Non-Lloyd’s Policies
  • Financial Services Guide
  • Duty of disclosure
  • Refund notice
  • Privacy policy
  • Terms and conditions
  • Translation and Teletype (TTY)
  • Family Violence Policy
  • Vulnerability Policy
  • Financial Hardship
  • Retail Insurance Product Design and Distribution Policy
  • Target Market Determination (TMDs)
Partner with us
  • Insurance Brokers
  • Retailers and distributors
  • Make a payment
  • API Documenation
We are a member of UAC
Agile Underwriting Services Pty Ltd (ABN 48 607 908 243 — AFS Licence No. 483374) is located at Level 5, 63 York Street, Sydney, NSW 2000. Agile is a trading name of Agile Insurance Group NZ Limited (NZBN: 9429052286766), a Lloyd’s coverholder authorised to underwrite insurance on behalf of Lloyd’s Syndicates. Agile operates on behalf of the insurer when providing these services. Agile’s registered office address is Agile Insurance Group NZ Limited, Ground Floor, 48 Broadway, Newmarket, Auckland, New Zealand, 1023. This site only contains general guidance on insurance products that are available to you. Before buying a policy, you should consider if the product suits your needs by reading the Policy Wording, a Product Disclosure Statement (PDS) in light of your circumstances.

Let's get in touch

Give us a call or drop by anytime, we endeavour to answer all enquiries within 24 hours on business days.

1300 705 031

hello@withagile.com