Cyber incidents originating through suppliers, managed service providers (MSPs) and other technology partners are becoming a growing concern for Australian businesses, prompting insurance brokers to pay closer attention to third-party and vendor risk when arranging cyber cover.
The issue has gained prominence following cyber incidents affecting businesses in Tasmania. A ransomware group known as CMD Organization recently listed multi-technology and building services company Contact Group on its dark-web leak site, allegedly offering stolen information for 10 bitcoin. Contact Group had not confirmed the claimed incident when the report was published.
The same ransomware group was linked to a confirmed attack on Tasmanian hospitality operator Goodstone Group in April 2026. The company said it began responding to a cybersecurity incident on April 18 after hackers published material that reportedly included employee passport scans and financial documents.
Vendor Systems Can Become an Entry Point
Insurance broker Gallagher has highlighted the increasing exposure created when companies depend on external technology providers. In one case cited by the broker, a small Australian business suffered a ransomware incident that investigators traced to infrastructure managed by its MSP.
The attackers were linked to a major ransomware-as-a-service group and demanded approximately US$100,000, equivalent to about A$142,633 at the time. Because the affected company handled sensitive client information, the breach created potential financial consequences as well as concerns about customer trust, reputation and regulatory scrutiny.
Professional services businesses—including accounting, legal and consulting firms—can be particularly exposed because they often hold substantial volumes of confidential client and commercial information. Companies heavily dependent on cloud providers, MSPs and other technology vendors also face additional exposure when those service providers are compromised.
Businesses granting third parties remote access to their systems face another potential vulnerability, particularly where access permissions and privileges are not periodically reviewed.
48% of Breaches Involve Third Parties
The scale of vendor-related exposure is significant. According to figures cited from the Verizon 2026 Data Breach Investigations Report, third parties were involved in 48% of breaches analysed globally. This was the highest proportion recorded by the report and compared with 30% in the previous year—a 60% increase.
The Australian Signals Directorate has similarly identified supply chains as a potential weak point in organisational cybersecurity, with attackers able to exploit trusted relationships between businesses and their vendors to introduce malware or gain access to information.
Despite this exposure, the report notes that only around one in five Australian small and medium-sized businesses has standalone cyber insurance. This leaves a substantial protection gap among businesses that may lack the financial and technical resources required to respond independently to a serious cyber incident.
Cyber Cover Extends Beyond Claim Payments
The Gallagher case also demonstrates that the value of cyber insurance can extend beyond financial indemnification. After the affected business contacted its insurer’s emergency response hotline, specialist cyber incident-response teams were mobilised within hours to investigate the breach and contain the threat.
Legal advisers were also involved to help determine the organisation’s notification obligations. Gallagher said it had structured the client’s insurance programme around its specific exposures and subsequently assisted in coordinating access to specialist response services during the incident.
For brokers, this means evaluating not merely the cyber policy limit but also whether the insurance programme provides access to forensic investigators, breach-response specialists, legal advisers and other crisis-management capabilities when an incident occurs.
Brokers Urged to Review Vendor-Related Cover
The changing threat environment has important implications for cyber insurance placement. Brokers are being encouraged to establish whether a client’s policy responds when a cyber incident originates at a vendor or technology partner rather than directly within the insured organisation’s own network.
This becomes particularly relevant for organisations that outsource significant IT functions and for data-intensive sectors such as professional services and healthcare.
As businesses become increasingly interconnected with cloud platforms, technology vendors and outsourced service providers, cyber-risk assessment is consequently expanding beyond an organisation’s internal security controls. Vendor due diligence, access management, contractual risk allocation, incident-response planning and appropriate cyber insurance coverage are becoming integral elements of third-party risk management.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Insurancenews

