That's all fine and dandy if the attacker/zombie is under the jurisdiction of the Australia government, but what if it is not? Is the insurance company really going to step into your shoes and chase someone halfway across the world to get a judgment and enforce it? What if you don't have a cause of action against the attacker/zombie in the foreign jurisdiction?
Ironically, the effect of your proposed law would be to protect foreign victims of Australian attackers.
I guess what you are proposing is some sort of multi-national treaty whereby all signatories of the treaty would enact similar legislation to force internet users to take liability for the actions of their computers.
Good luck!