India recorded over 1.4 million cybercrime cases in 2024 — and businesses are the primary target. A single ransomware attack can shut down operations for days, a data breach can expose thousands of customer records, and a network failure can generate multi-crore liability claims from affected clients. Cyber Insurance for Business is the comprehensive business cyber insurance policy covering first-party losses, third-party liability, crisis management, and regulatory costs — for startups to large enterprises.
Cyber Insurance for Business · Data Breach · Ransomware · Network Security Failure · Third-Party Liability · Business Interruption
Cyber Insurance for Business — offered through the Cyber Insurance for Business policy — is a comprehensive specialist insurance programme that protects organisations against the financial consequences of cyber incidents. It covers two broad categories of loss: first-party losses (the company's own financial losses from a cyber incident — data restoration costs, ransomware payments, business interruption, crisis management, and forensic investigation) and third-party liability (legal liability to clients, customers, and other third parties whose data or systems are affected by the company's cyber failure — including defence costs, settlements, and regulatory fines). As India's digital economy grows and cyber threats escalate, business cyber insurance has moved from a niche product to a board-level risk management essential.
Covers investigation costs, forensic IT expenses, legal counsel, notification costs to affected individuals, credit monitoring services for breach victims, and public relations support — the full cost of managing a data breach from detection to resolution.
BREACHCovers ransom payments (where legally permissible), specialist cyber extortion negotiators, forensic costs to determine if decryption is possible without payment, and system restoration after a ransomware attack. Includes threat assessment and law enforcement liaison.
RANSOMWARECovers loss of revenue and additional operating expenses when the insured's digital systems are shut down or impaired by a cyber incident — network attacks, ransomware encryption, denial-of-service attacks, and IT infrastructure failures caused by a covered cyber event.
BICovers legal liability to clients and third parties for data privacy breaches, network security failures, transmission of malware, and denial of access to systems — including defence costs, settlements, and coverage for claims from clients whose data or systems were affected by the insured's cyber incident.
3RD PARTYCovers legal representation costs, regulatory investigation response costs, and fines or penalties imposed by regulators (including the Data Protection Board under the DPDP Act 2023, RBI, SEBI, and IRDAI cyber security directions) arising from a covered cyber incident.
REGULATORYCovers the cost of engaging specialist crisis management firms, public relations consultants, communication advisors, and brand reputation specialists to manage the reputational impact of a cyber incident — critical for consumer-facing businesses where trust is a core asset.
CRISISFirst-Party & Third-Party Coverage — Full Scope of Cyber Insurance for Business
Cyber Insurance for Business provides two-tier protection — first-party coverage for the insured's own losses, and third-party liability coverage for claims from clients and affected parties. Both tiers are essential for complete cyber risk management.
1. Data Breach Response Costs:
When a data breach occurs — whether from external hacking, insider threat, or accidental exposure — the policy covers:
• IT forensic investigation to identify the breach source, scope, and affected data
• Legal counsel to advise on regulatory obligations (DPDP Act notification requirements, RBI/SEBI mandatory reporting)
• Notification costs — notifying affected individuals, regulators, and business partners
• Credit and identity monitoring services for affected individuals for up to 12 months
• Public relations and crisis communications support
• Call centre costs to handle enquiries from affected individuals
2. Data Restoration and System Recovery:
• Costs of restoring, recreating, or replacing data that has been corrupted, destroyed, or encrypted
• IT expert costs for cleaning malware from systems and restoring to a clean state
• Hardware replacement if required due to the cyber incident
• Software restoration and reconfiguration costs
3. Ransomware and Cyber Extortion:
• Ransom payment (subject to legal advice and law enforcement guidance — certain jurisdictions restrict ransom payment)
• Specialist cyber extortion negotiator fees
• Forensic costs to determine if decryption is feasible without paying
• Costs of obtaining cryptocurrency for ransom payment (where applicable)
4. Business Interruption Loss:
• Loss of net revenue during the period when systems are down following a covered cyber incident
• Waiting period typically 8–12 hours before BI cover activates
• Indemnity period typically 3–12 months
• Additional expenditure to restore systems and resume operations faster
• Contingent business interruption — loss of revenue because a key technology supplier (cloud provider, payment gateway, SaaS vendor) suffers a cyber incident that affects the insured's operations
5. Network Security Liability:
Legal liability to third parties for:
• Failure to prevent unauthorised access to, or use of, third-party data or systems
• Transmission of malicious code (malware, virus) from the insured's network to a third party's system
• Denial of access to a third party's system or data (e.g., a DDoS attack originating from compromised insured systems)
• Failure of the insured's network security causing a third party's data loss
6. Privacy Liability:
Legal liability for breach of privacy obligations — including:
• Violation of the DPDP Act 2023's data protection principles
• Breach of contractual data security obligations to clients
• Unauthorised collection, use, or disclosure of personal data
• Claims from individuals affected by the insured's data breach
7. Media Liability:
Legal liability for defamation, breach of copyright, or privacy violations arising from the insured's online content — websites, social media, email communications, and digital publications
8. Regulatory Investigation and Fines:
• Costs of responding to regulatory investigations (Data Protection Board, RBI cyber security examination, SEBI direction, IRDAI)
• Regulatory fines and penalties where insurable under applicable Indian law
• Legal representation in regulatory proceedings
9. PCI DSS Fines:
Fines and penalties imposed by payment card networks (Visa, Mastercard, RuPay) for non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) following a payment card data breach — critical for e-commerce and retail businesses that process card payments
Crisis management (included):
• Specialist cyber crisis management consultants
• PR and brand reputation management
• Executive communications coaching for media interactions during a breach
• Stakeholder communication (customers, partners, investors, employees)
Optional add-ons available under Cyber Insurance for Business:
• Multimedia / Network Interruption cover: Additional cover for claims arising from the insured's multimedia content and extended network interruption scenarios
• Technology Errors & Omissions (Tech E&O): Covers claims from clients who suffer loss because the insured's technology product or service failed to perform as promised — distinct from a security failure, covering performance failure and professional negligence
• Social Engineering / Funds Transfer Fraud: Covers financial losses from fraudulent instruction attacks — BEC (Business Email Compromise), fake CEO instruction to transfer funds, vendor impersonation — where the company transfers funds based on fraudulent instructions that appear to come from a legitimate source
• Hardware Replacement: Covers the cost of replacing hardware physically damaged by a cyber incident (e.g., a wiper malware attack that destroys firmware, rendering hardware permanently unusable)
• Reputational Harm: Covers revenue loss directly attributable to the reputational impact of a publicised cyber incident — measured against pre-breach revenue trends
The Cyber Threat Landscape — What Attacks Indian Businesses Face in 2025–26
Understanding the specific cyber threats that trigger insurance coverage helps businesses assess their risk exposure and select the right policy configuration.
| Cyber Threat Type | How It Affects Business | Insurance Coverage Triggered |
|---|---|---|
| Ransomware Attack | Encrypts files/systems; demands payment; operations paralysed; data exfiltrated as additional leverage | Ransomware payment, forensics, system restoration, Business Interruption, crisis management |
| Data Breach (Hacking) | Attacker exfiltrates customer, employee, or business data; regulatory notification obligation; client claims | Forensics, legal, notification, credit monitoring, regulatory fines, third-party privacy liability |
| Business Email Compromise (BEC) | Attacker impersonates CEO/CFO/vendor via email; company transfers funds to fraudster's account | Social Engineering / Funds Transfer Fraud add-on covers financial loss from fraudulent wire transfer |
| DDoS Attack | Floods servers with traffic; website/app goes offline; e-commerce revenue lost; customer service disrupted | Business Interruption, additional IT costs to mitigate attack and restore service |
| Phishing / Credential Theft | Employee clicks malicious link; credentials stolen; attacker gains access to systems; data or funds stolen | Data breach response, forensics, data restoration, third-party liability if client data accessed |
| Insider Threat | Employee (current or former) steals or leaks data; sabotages systems; downloads customer database | Data breach response, forensics, third-party liability if client data exposed, crisis management |
| Supply Chain / Third-Party Attack | A software vendor, cloud provider, or IT supplier is compromised; attack spreads to insured's systems | Business Interruption (contingent), data breach response, third-party liability for downstream client impact |
| OT/SCADA Cyber Attack | Industrial control systems attacked; manufacturing line or utility disrupted; physical damage possible | Business Interruption, system restoration, third-party liability; note: physical property damage may need separate cover |
India's Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changes the corporate cyber liability landscape:
• Mandatory breach notification: Data Fiduciaries (companies processing personal data) must notify the Data Protection Board and affected Data Principals (individuals) of significant data breaches — with penalties for non-notification
• Penalties up to ₹250 crore: The DPDP Act empowers the Data Protection Board to impose penalties of up to ₹250 crore for significant data breaches where the company failed to implement adequate security measures
• No cap on civil claims: Affected individuals can claim compensation for harm suffered from a data breach — creating open-ended civil liability exposure for companies holding large personal data sets
• Children's data obligations: Special requirements for processing children's data create additional compliance obligations and increased penalty risk for companies serving younger demographics
Cyber insurance with regulatory coverage specifically addresses DPDP Act compliance costs, Data Protection Board investigation response costs, and penalties — making it directly relevant to every Indian business that processes personal data of Indian citizens.
Policy Configuration, Coverage Limits & Premium Benchmarks for Indian Businesses
Cyber Insurance for Business is structured to allow customisation — the core coverage can be combined with add-ons and the coverage limits calibrated to the organisation's specific risk profile, data sensitivity, and revenue exposure.
Unlike property insurance where the sum insured is a physical asset value, cyber insurance limits are set based on the organisation's digital risk exposure. The key factors the insurer assesses:
1. Annual revenue: Larger revenue means greater business interruption loss potential — a ₹100 crore annual revenue company losing 2 weeks of operations loses approximately ₹4 crore in revenue. The BI coverage limit must reflect this exposure.
2. Data volume and sensitivity: A company holding 5 million customer records (including PII, payment data, health records) has far higher breach notification and regulatory exposure than a company with 1,000 records. The data population drives per-record notification cost and aggregate regulatory penalty exposure.
3. Third-party data custody: IT service providers, BPOs, cloud vendors, and payroll processors that hold client data face substantial third-party liability if they suffer a breach — the value of data in their custody (not their own revenue) drives the liability limit requirement.
4. Industry sector: BFSI, healthcare, and government-adjacent sectors face higher regulatory scrutiny and higher breach notification costs. Technology companies face higher third-party liability exposure from service failures.
5. Cyber maturity: Companies with strong cyber security controls (ISO 27001 certification, SOC 2 compliance, regular penetration testing, zero-trust architecture, multi-factor authentication across all systems) attract lower premium rates than companies with weak security posture.
Indicative coverage limit ranges for Indian businesses:
• SME (revenue ₹10–50 crore): ₹1–5 crore cyber limit
• Mid-size (revenue ₹50–500 crore): ₹5–50 crore
• Large enterprise (revenue ₹500 crore+): ₹50–500 crore or higher
• IT/BFSI/Healthcare with large data sets: Limits may be set higher than revenue-based benchmarks due to data liability exposure
Cyber Insurance for Business uses sub-limits for specific coverage categories within the overall policy limit:
Common sub-limit structure:
• Data breach response costs: Often sub-limited at 25–50% of overall limit (forensics and notification typically less than full limit)
• Ransomware/extortion payment: Sub-limited separately — often 25–50% of overall limit, subject to law enforcement guidance
• Business interruption: May have separate sub-limit or use overall limit with specified indemnity period
• Crisis management: Typically 5–15% of overall limit
• Regulatory fines: Sub-limited (regulability of fines varies; sub-limit reflects insurable portion)
Deductibles (Excess):
Business cyber insurance typically carries a deductible (the amount the insured bears before insurance responds):
• SME policies: ₹50,000–₹5 lakh deductible
• Mid-market: ₹5–25 lakh
• Enterprise: ₹25 lakh–₹5 crore or higher (time-based deductible for BI — e.g., 8-hour waiting period)
Retroactive date: The retroactive date (retro date) is critical — the policy covers claims arising from incidents that occurred on or after the retro date. If a breach occurred before the retro date (even if discovered later), it is not covered. Setting the retro date as early as possible (ideally policy inception date of the first cyber policy taken) is important for coverage continuity.
Cyber insurance premium in India is calculated as a percentage of the coverage limit, adjusted for risk factors:
Indicative premium rates (market benchmarks 2025–26):
• Low-risk sector, strong cyber maturity (ISO 27001, MFA, regular pen testing): 0.5%–1.0% of limit per annum
• Standard risk (most SMEs and mid-size companies): 1.0%–2.0% of limit
• Higher risk (healthcare with patient data, BFSI, e-commerce with payment data): 1.5%–3.0%+
• Companies with poor cyber hygiene (no MFA, no patch management, legacy systems): rates can exceed 3% or coverage declined
Premium examples:
• SME manufacturing company, ₹2 crore limit, standard risk: ₹2–4 lakh/year
• IT services company, ₹25 crore limit, strong security controls: ₹12.5–25 lakh/year
• Healthcare provider, ₹10 crore limit, patient data exposure: ₹15–30 lakh/year
The cost-benefit is compelling: The average cost of a data breach in India in 2024 was USD 2.35 million (approximately ₹19.7 crore) according to IBM Cost of Data Breach Report 2024 — orders of magnitude more than typical cyber insurance premium. A single ransomware attack with 2 weeks of downtime on a ₹100 crore revenue company costs ₹4+ crore in lost revenue alone — well justifying a ₹10 crore policy at ₹10–20 lakh annual premium.
Which Businesses Need Cyber Insurance
Cyber insurance is relevant to every business that uses digital systems, processes customer data, or conducts online transactions. Certain sectors face elevated exposure due to the sensitivity of data they hold or their dependence on digital operations.
How to Respond to a Cyber Incident & File a Claim
Cyber claims are time-critical — the first 72 hours after a cyber incident are the most important. Rapid notification activates the insurer's specialist cyber response team, which can significantly reduce the total impact of the incident.
When a cyber incident is detected:
• Activate your Incident Response Plan (IRP): Contain the breach — isolate affected systems from the network to prevent further spread. Do not shut down systems before forensic imaging — this destroys evidence
• Notify Probitas / the insurer immediately: Call 022 4302 0000. For theft of funds specifically, notify within 72 hours (policy condition). Early notification activates the insurer's 24/7 cyber incident response team — specialists in forensic investigation, legal guidance, and crisis management
• Do NOT pay ransom without insurer guidance: Ransomware payment decisions must be made in consultation with the insurer, specialist cyber negotiators, and law enforcement (CERT-In, cyber crime cell). Paying without notification can affect coverage
• Notify law enforcement: File a complaint with the local cyber crime cell and notify CERT-In (mandatory for significant incidents under CERT-In directions — within 6 hours of detecting certain incident types)
• Preserve evidence: Take forensic images of affected systems before remediation. Preserve all logs, emails, and communications related to the incident. This evidence is critical for the insurance claim and any law enforcement action
• Document the timeline: Record when the incident was discovered, by whom, what actions were taken, and when — this timeline is the foundation of the insurance claim
The insurer's cyber incident response team coordinates:
Forensic investigation:
• Specialist cyber forensic investigators (typically from global firms — Mandiant, CrowdStrike, IBM X-Force, Palo Alto Unit 42 or their Indian partners) are engaged to identify the attack vector, attacker, scope of compromise, and data affected
• The forensic report is the foundation of the insurance claim — it determines what data was accessed, what systems were compromised, and whether specific coverage triggers (data breach, ransomware, network failure) are met
Legal assessment:
• Legal counsel assesses regulatory notification obligations under DPDP Act, RBI/SEBI/IRDAI directions, and contractual notification obligations to clients
• Claims from affected third parties are registered and managed through the insurer's legal team
Documentation for claim:
• Copy of FIR (cyber crime complaint)
• Forensic investigation report
• Bank statements and transaction records (for funds theft)
• Proof of affected data and systems
• All invoices for IT forensics, legal, notification, and crisis management costs
• Business interruption loss documentation (revenue records before and during the incident)
• Regulatory correspondence (CERT-In, Data Protection Board)
• Third-party claim notices received
The insurer appoints a specialist cyber loss adjuster to assess the claim:
• Reviews forensic report to verify coverage trigger (confirms data breach, ransomware, network failure, etc.)
• Validates all first-party costs against the "reasonable and necessary" standard
• Calculates business interruption loss based on revenue records and the verified period of interruption
• Manages all third-party claims from affected clients and individuals
• Coordinates regulatory response and defence
Settlement structure:
First-party costs (forensics, notification, crisis management) are paid as incurred. Business interruption loss is paid at the end of the indemnity period. Ransomware payments are typically made quickly (subject to law enforcement clearance). Third-party liability claims are settled progressively as individual claims are resolved.
Important — notification timing:
Costs incurred BEFORE notifying the insurer are generally NOT covered. This is the most common reason cyber claim amounts are reduced. Notify the insurer immediately — even before the full scope of the incident is known.
Call Probitas on 022 4302 0000 at the first indication of any cyber incident — even suspected incidents that may turn out to be nothing. Early engagement costs nothing and protects your claim position.
What Cyber Insurance Does NOT Cover
Understanding cyber exclusions is critical — several common business losses that people assume are covered are actually excluded from standard cyber policies.
Any loss from a cyber incident that occurred before the policy's retroactive date is not covered — even if discovered during the policy period. Setting the retro date as early as possible when purchasing cyber insurance is important. Breaches that began before the policy was taken are not covered.
Any cyber loss arising from the insured's own dishonest, criminal, or deliberate conduct is excluded. The policy covers external attacks and accidental internal errors — not the insured's own fraudulent or illegal acts.
Physical injury or property damage caused by a cyber incident is excluded from standard cyber insurance. A cyber attack on a manufacturing plant that physically damages equipment or injures workers may create property damage claims — these require property/engineering insurance. Physical consequences of OT cyber attacks may need specialist OT cyber or property cover.
For the individual CyberShield policy, business or professional activities are excluded — the individual policy covers personal cyber risks only. Business cyber risks require the Cyber Insurance for Business business policy.
Losses from theft or loss of cryptocurrency, NFTs, or other non-government-issued digital assets are not covered under standard cyber policies. If cryptocurrency holdings are a material business asset, specialist digital asset insurance may be required.
Failure, degradation, or outage of third-party infrastructure (telecommunications, electricity, internet providers, cloud platforms) that is NOT caused by a cyber attack is excluded. Only failures caused by a cyber security event are covered — general infrastructure outages are not covered.
Costs incurred by the insured before notifying the insurer of the cyber incident are generally not covered. This is a common and significant exclusion — companies that manage a cyber incident and only notify the insurer after incurring significant remediation costs may find those pre-notification costs excluded.
Losses from cyber warfare, state-sponsored attacks, and acts of war are excluded. Nation-state cyber attacks — increasingly common in geopolitical tensions — may trigger this exclusion. The scope of this exclusion and how it interacts with commercially-motivated ransomware (often attributed to state-proxies) is a key area of ongoing policy development globally.
Cyber Insurance for Business is a specialist insurance product with individual underwriting based on the organisation's digital risk profile. Coverage terms, sub-limits, deductibles, retroactive dates, and premium rates vary by company size, sector, data sensitivity, security controls, and claims history. The DPDP Act 2023 regulatory framework referenced is evolving and organisations should seek legal advice on current obligations. Probitas Insurance Brokers Pvt. Ltd. · IRDAI Lic. No. 528.
Cyber Insurance for Business Questions
Get Your Business Cyber Insurance Quote
Cyber insurance is individually underwritten based on your company's digital risk profile. Share your details and Probitas will arrange a Cyber Insurance for Business quotation within 48 hours.
By submitting you agree to our Privacy Policy and Terms & Conditions. Cyber Insurance for Business is subject to individual underwriting assessment. Coverage terms, sub-limits, deductibles, retroactive dates, and premium are agreed following review of the company’s digital risk profile and security posture. Probitas Insurance Brokers Pvt. Ltd. · IRDAI Lic. No. 528.