📞 022 4302 0000contact@takemyinsurance.com
Register|LoginJoin us as POSP
AboutWhat Is CoveredCyber ThreatsPolicy OptionsWho Needs ItClaim ProcessExclusionsFAQsGet Quote Page Progress  0%
🔒 Cyber Insurance · Data Breach · Ransomware · Network Security · Business Interruption · Third-Party Liability · All Business Sizes

Cyber Insurance for Business — Data Breach, Ransomware, Network Failure & Third-Party Cyber Liability —
Cyber Insurance for Business · First-Party & Third-Party · Crisis Management · Legal & Regulatory · Business Interruption

India recorded over 1.4 million cybercrime cases in 2024 — and businesses are the primary target. A single ransomware attack can shut down operations for days, a data breach can expose thousands of customer records, and a network failure can generate multi-crore liability claims from affected clients. Cyber Insurance for Business is the comprehensive business cyber insurance policy covering first-party losses, third-party liability, crisis management, and regulatory costs — for startups to large enterprises.

✓ Data Breach Response ✓ Ransomware & Extortion ✓ Network Security Failure ✓ Business Interruption ✓ Third-Party Cyber Liability ✓ Regulatory & Legal Costs
IT · BFSI · Healthcare · E-Commerce · Manufacturing · Retail · Hospitality · Professional Services · Startups · SMEs · Large Enterprises  |  IRDAI Licensed Broker — Lic. No. 528
CYBER
🏛IRDAI Licensed Broker · Lic. No. 528 · Cyber Insurance for Business
🔒Data Breach · Ransomware · Network Failure · Business Interruption · Third-Party Liability · Crisis Management
💻IT · BFSI · Healthcare · E-Commerce · Manufacturing · Retail · SMEs · Startups · Enterprises
📞Cyber Insurance Enquiry 022 4302 0000
An IRDAI Licensed Insurance Broker

Cyber Insurance for Business · Data Breach · Ransomware · Network Security Failure · Third-Party Liability · Business Interruption

What Is Cyber Insurance for Business?

Cyber Insurance for Business — offered through the Cyber Insurance for Business policy — is a comprehensive specialist insurance programme that protects organisations against the financial consequences of cyber incidents. It covers two broad categories of loss: first-party losses (the company's own financial losses from a cyber incident — data restoration costs, ransomware payments, business interruption, crisis management, and forensic investigation) and third-party liability (legal liability to clients, customers, and other third parties whose data or systems are affected by the company's cyber failure — including defence costs, settlements, and regulatory fines). As India's digital economy grows and cyber threats escalate, business cyber insurance has moved from a niche product to a board-level risk management essential.

🔒

Why Cyber Risk Is Now India's #1 Business Risk

  • Scale of the threat — India-specific data:The Telangana Cyber Threat Report 2025 recorded 62,52,023 malware detections (17,128 per day), 17,505 ransomware attacks (47 per day), and over 1,23,465 cybercrime cases in 2024 — in a single state. Nationally, CERT-In (India's Computer Emergency Response Team) reported over 15 lakh cyber incidents in 2024. Indian businesses — especially SMEs, BFSI companies, healthcare providers, and e-commerce operators — are increasingly primary targets for sophisticated global cybercriminals.
  • A single ransomware attack can cost crores and paralyse operations:Ransomware attacks encrypt business data and demand payment for the decryption key. The average ransomware demand targeting Indian mid-size businesses in 2024 ranged from ₹50 lakh to ₹5 crore. Beyond the ransom itself, the cost of operational downtime (often 5–15 days), IT forensic investigation, system restoration, and business recovery can multiply the total loss several times over. Without cyber insurance, many SMEs find this level of loss existential.
  • Data breach liability is expanding under India's DPDP Act 2023:The Digital Personal Data Protection Act 2023 (DPDP Act) creates significant new obligations and potential liabilities for companies handling personal data of Indian citizens. The Act empowers the Data Protection Board to impose penalties of up to ₹250 crore for significant data breaches. As enforcement begins, companies face regulatory fines in addition to the technical costs of managing a breach. Cyber insurance covers both the response costs and the regulatory penalty exposure.
  • Third-party cyber liability — your client holds you responsible:If your company's systems are compromised and that breach exposes your client's data or disrupts their operations, your client can hold you legally and contractually liable for their losses. For IT service providers, BPOs, cloud vendors, and any company with access to client data, third-party cyber liability is often the largest single cyber risk exposure — far exceeding their own first-party losses.
  • Cyber threats hit every sector — not just IT companies:Manufacturing plants are targeted for industrial espionage and operational disruption via OT/SCADA attacks. Hospitals face ransomware that locks patient records. Retailers suffer point-of-sale breaches. Hotels experience guest data theft. Law firms face client confidentiality breaches. Financial companies face wire transfer fraud. Every business that uses digital systems, processes customer data, or conducts online transactions has material cyber risk — regardless of sector.
Key Coverage Components of Cyber Insurance for Business
📋

Data Breach Response

Covers investigation costs, forensic IT expenses, legal counsel, notification costs to affected individuals, credit monitoring services for breach victims, and public relations support — the full cost of managing a data breach from detection to resolution.

BREACH
🔥

Ransomware & Cyber Extortion

Covers ransom payments (where legally permissible), specialist cyber extortion negotiators, forensic costs to determine if decryption is possible without payment, and system restoration after a ransomware attack. Includes threat assessment and law enforcement liaison.

RANSOMWARE
📈

Business Interruption

Covers loss of revenue and additional operating expenses when the insured's digital systems are shut down or impaired by a cyber incident — network attacks, ransomware encryption, denial-of-service attacks, and IT infrastructure failures caused by a covered cyber event.

BI
🌐

Third-Party Cyber Liability

Covers legal liability to clients and third parties for data privacy breaches, network security failures, transmission of malware, and denial of access to systems — including defence costs, settlements, and coverage for claims from clients whose data or systems were affected by the insured's cyber incident.

3RD PARTY
🔒

Regulatory & Legal Costs

Covers legal representation costs, regulatory investigation response costs, and fines or penalties imposed by regulators (including the Data Protection Board under the DPDP Act 2023, RBI, SEBI, and IRDAI cyber security directions) arising from a covered cyber incident.

REGULATORY
👥

Crisis Management

Covers the cost of engaging specialist crisis management firms, public relations consultants, communication advisors, and brand reputation specialists to manage the reputational impact of a cyber incident — critical for consumer-facing businesses where trust is a core asset.

CRISIS

First-Party & Third-Party Coverage — Full Scope of Cyber Insurance for Business

What Is Covered — First-Party & Third-Party in Detail

Cyber Insurance for Business provides two-tier protection — first-party coverage for the insured's own losses, and third-party liability coverage for claims from clients and affected parties. Both tiers are essential for complete cyber risk management.

💻

First-Party Coverage — The Insured's Own Losses

1. Data Breach Response Costs:
When a data breach occurs — whether from external hacking, insider threat, or accidental exposure — the policy covers:
• IT forensic investigation to identify the breach source, scope, and affected data
• Legal counsel to advise on regulatory obligations (DPDP Act notification requirements, RBI/SEBI mandatory reporting)
• Notification costs — notifying affected individuals, regulators, and business partners
• Credit and identity monitoring services for affected individuals for up to 12 months
• Public relations and crisis communications support
• Call centre costs to handle enquiries from affected individuals

2. Data Restoration and System Recovery:
• Costs of restoring, recreating, or replacing data that has been corrupted, destroyed, or encrypted
• IT expert costs for cleaning malware from systems and restoring to a clean state
• Hardware replacement if required due to the cyber incident
• Software restoration and reconfiguration costs

3. Ransomware and Cyber Extortion:
• Ransom payment (subject to legal advice and law enforcement guidance — certain jurisdictions restrict ransom payment)
• Specialist cyber extortion negotiator fees
• Forensic costs to determine if decryption is feasible without paying
• Costs of obtaining cryptocurrency for ransom payment (where applicable)

4. Business Interruption Loss:
• Loss of net revenue during the period when systems are down following a covered cyber incident
• Waiting period typically 8–12 hours before BI cover activates
• Indemnity period typically 3–12 months
• Additional expenditure to restore systems and resume operations faster
• Contingent business interruption — loss of revenue because a key technology supplier (cloud provider, payment gateway, SaaS vendor) suffers a cyber incident that affects the insured's operations

🌐

Third-Party Liability Coverage — Claims from Clients & Others

5. Network Security Liability:
Legal liability to third parties for:
• Failure to prevent unauthorised access to, or use of, third-party data or systems
• Transmission of malicious code (malware, virus) from the insured's network to a third party's system
• Denial of access to a third party's system or data (e.g., a DDoS attack originating from compromised insured systems)
• Failure of the insured's network security causing a third party's data loss

6. Privacy Liability:
Legal liability for breach of privacy obligations — including:
• Violation of the DPDP Act 2023's data protection principles
• Breach of contractual data security obligations to clients
• Unauthorised collection, use, or disclosure of personal data
• Claims from individuals affected by the insured's data breach

7. Media Liability:
Legal liability for defamation, breach of copyright, or privacy violations arising from the insured's online content — websites, social media, email communications, and digital publications

8. Regulatory Investigation and Fines:
• Costs of responding to regulatory investigations (Data Protection Board, RBI cyber security examination, SEBI direction, IRDAI)
• Regulatory fines and penalties where insurable under applicable Indian law
• Legal representation in regulatory proceedings

9. PCI DSS Fines:
Fines and penalties imposed by payment card networks (Visa, Mastercard, RuPay) for non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) following a payment card data breach — critical for e-commerce and retail businesses that process card payments

👥

Crisis Management & Optional Add-Ons

Crisis management (included):
• Specialist cyber crisis management consultants
• PR and brand reputation management
• Executive communications coaching for media interactions during a breach
• Stakeholder communication (customers, partners, investors, employees)

Optional add-ons available under Cyber Insurance for Business:
Multimedia / Network Interruption cover: Additional cover for claims arising from the insured's multimedia content and extended network interruption scenarios
Technology Errors & Omissions (Tech E&O): Covers claims from clients who suffer loss because the insured's technology product or service failed to perform as promised — distinct from a security failure, covering performance failure and professional negligence
Social Engineering / Funds Transfer Fraud: Covers financial losses from fraudulent instruction attacks — BEC (Business Email Compromise), fake CEO instruction to transfer funds, vendor impersonation — where the company transfers funds based on fraudulent instructions that appear to come from a legitimate source
Hardware Replacement: Covers the cost of replacing hardware physically damaged by a cyber incident (e.g., a wiper malware attack that destroys firmware, rendering hardware permanently unusable)
Reputational Harm: Covers revenue loss directly attributable to the reputational impact of a publicised cyber incident — measured against pre-breach revenue trends

The Cyber Threat Landscape — What Attacks Indian Businesses Face in 2025–26

Common Cyber Threats Covered by Business Cyber Insurance

Understanding the specific cyber threats that trigger insurance coverage helps businesses assess their risk exposure and select the right policy configuration.

🔒

Cyber Threat Coverage Map — Attack Type to Insurance Trigger

Cyber Threat TypeHow It Affects BusinessInsurance Coverage Triggered
Ransomware AttackEncrypts files/systems; demands payment; operations paralysed; data exfiltrated as additional leverageRansomware payment, forensics, system restoration, Business Interruption, crisis management
Data Breach (Hacking)Attacker exfiltrates customer, employee, or business data; regulatory notification obligation; client claimsForensics, legal, notification, credit monitoring, regulatory fines, third-party privacy liability
Business Email Compromise (BEC)Attacker impersonates CEO/CFO/vendor via email; company transfers funds to fraudster's accountSocial Engineering / Funds Transfer Fraud add-on covers financial loss from fraudulent wire transfer
DDoS AttackFloods servers with traffic; website/app goes offline; e-commerce revenue lost; customer service disruptedBusiness Interruption, additional IT costs to mitigate attack and restore service
Phishing / Credential TheftEmployee clicks malicious link; credentials stolen; attacker gains access to systems; data or funds stolenData breach response, forensics, data restoration, third-party liability if client data accessed
Insider ThreatEmployee (current or former) steals or leaks data; sabotages systems; downloads customer databaseData breach response, forensics, third-party liability if client data exposed, crisis management
Supply Chain / Third-Party AttackA software vendor, cloud provider, or IT supplier is compromised; attack spreads to insured's systemsBusiness Interruption (contingent), data breach response, third-party liability for downstream client impact
OT/SCADA Cyber AttackIndustrial control systems attacked; manufacturing line or utility disrupted; physical damage possibleBusiness Interruption, system restoration, third-party liability; note: physical property damage may need separate cover
📋

DPDP Act 2023 — The Regulatory Context Driving Cyber Insurance Adoption

India's Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changes the corporate cyber liability landscape:

Mandatory breach notification: Data Fiduciaries (companies processing personal data) must notify the Data Protection Board and affected Data Principals (individuals) of significant data breaches — with penalties for non-notification
Penalties up to ₹250 crore: The DPDP Act empowers the Data Protection Board to impose penalties of up to ₹250 crore for significant data breaches where the company failed to implement adequate security measures
No cap on civil claims: Affected individuals can claim compensation for harm suffered from a data breach — creating open-ended civil liability exposure for companies holding large personal data sets
Children's data obligations: Special requirements for processing children's data create additional compliance obligations and increased penalty risk for companies serving younger demographics

Cyber insurance with regulatory coverage specifically addresses DPDP Act compliance costs, Data Protection Board investigation response costs, and penalties — making it directly relevant to every Indian business that processes personal data of Indian citizens.

Policy Configuration, Coverage Limits & Premium Benchmarks for Indian Businesses

Policy Options & How to Structure Your Cyber Cover

Cyber Insurance for Business is structured to allow customisation — the core coverage can be combined with add-ons and the coverage limits calibrated to the organisation's specific risk profile, data sensitivity, and revenue exposure.

📈

How Coverage Limits Are Set — What Drives Cyber Insurance Premium

Unlike property insurance where the sum insured is a physical asset value, cyber insurance limits are set based on the organisation's digital risk exposure. The key factors the insurer assesses:

1. Annual revenue: Larger revenue means greater business interruption loss potential — a ₹100 crore annual revenue company losing 2 weeks of operations loses approximately ₹4 crore in revenue. The BI coverage limit must reflect this exposure.
2. Data volume and sensitivity: A company holding 5 million customer records (including PII, payment data, health records) has far higher breach notification and regulatory exposure than a company with 1,000 records. The data population drives per-record notification cost and aggregate regulatory penalty exposure.
3. Third-party data custody: IT service providers, BPOs, cloud vendors, and payroll processors that hold client data face substantial third-party liability if they suffer a breach — the value of data in their custody (not their own revenue) drives the liability limit requirement.
4. Industry sector: BFSI, healthcare, and government-adjacent sectors face higher regulatory scrutiny and higher breach notification costs. Technology companies face higher third-party liability exposure from service failures.
5. Cyber maturity: Companies with strong cyber security controls (ISO 27001 certification, SOC 2 compliance, regular penetration testing, zero-trust architecture, multi-factor authentication across all systems) attract lower premium rates than companies with weak security posture.

Indicative coverage limit ranges for Indian businesses:
• SME (revenue ₹10–50 crore): ₹1–5 crore cyber limit
• Mid-size (revenue ₹50–500 crore): ₹5–50 crore
• Large enterprise (revenue ₹500 crore+): ₹50–500 crore or higher
• IT/BFSI/Healthcare with large data sets: Limits may be set higher than revenue-based benchmarks due to data liability exposure

📋

Sub-Limits, Deductibles & Waiting Periods

Cyber Insurance for Business uses sub-limits for specific coverage categories within the overall policy limit:

Common sub-limit structure:
Data breach response costs: Often sub-limited at 25–50% of overall limit (forensics and notification typically less than full limit)
Ransomware/extortion payment: Sub-limited separately — often 25–50% of overall limit, subject to law enforcement guidance
Business interruption: May have separate sub-limit or use overall limit with specified indemnity period
Crisis management: Typically 5–15% of overall limit
Regulatory fines: Sub-limited (regulability of fines varies; sub-limit reflects insurable portion)

Deductibles (Excess):
Business cyber insurance typically carries a deductible (the amount the insured bears before insurance responds):
• SME policies: ₹50,000–₹5 lakh deductible
• Mid-market: ₹5–25 lakh
• Enterprise: ₹25 lakh–₹5 crore or higher (time-based deductible for BI — e.g., 8-hour waiting period)

Retroactive date: The retroactive date (retro date) is critical — the policy covers claims arising from incidents that occurred on or after the retro date. If a breach occurred before the retro date (even if discovered later), it is not covered. Setting the retro date as early as possible (ideally policy inception date of the first cyber policy taken) is important for coverage continuity.

💰

Premium Benchmarks & Cost-Benefit

Cyber insurance premium in India is calculated as a percentage of the coverage limit, adjusted for risk factors:

Indicative premium rates (market benchmarks 2025–26):
• Low-risk sector, strong cyber maturity (ISO 27001, MFA, regular pen testing): 0.5%–1.0% of limit per annum
• Standard risk (most SMEs and mid-size companies): 1.0%–2.0% of limit
• Higher risk (healthcare with patient data, BFSI, e-commerce with payment data): 1.5%–3.0%+
• Companies with poor cyber hygiene (no MFA, no patch management, legacy systems): rates can exceed 3% or coverage declined

Premium examples:
• SME manufacturing company, ₹2 crore limit, standard risk: ₹2–4 lakh/year
• IT services company, ₹25 crore limit, strong security controls: ₹12.5–25 lakh/year
• Healthcare provider, ₹10 crore limit, patient data exposure: ₹15–30 lakh/year

The cost-benefit is compelling: The average cost of a data breach in India in 2024 was USD 2.35 million (approximately ₹19.7 crore) according to IBM Cost of Data Breach Report 2024 — orders of magnitude more than typical cyber insurance premium. A single ransomware attack with 2 weeks of downtime on a ₹100 crore revenue company costs ₹4+ crore in lost revenue alone — well justifying a ₹10 crore policy at ₹10–20 lakh annual premium.

Which Businesses Need Cyber Insurance

Who Needs Business Cyber Insurance?

Cyber insurance is relevant to every business that uses digital systems, processes customer data, or conducts online transactions. Certain sectors face elevated exposure due to the sensitivity of data they hold or their dependence on digital operations.

💻

High-Priority Sectors

  • IT & Technology companies (IT services, SaaS, BPO):IT service providers hold client data and have privileged access to client systems. A breach at an IT company can simultaneously affect dozens of its clients — creating massive third-party liability exposure. For technology companies, third-party cyber liability (not first-party BI) is the dominant risk. Tech E&O (Technology Errors & Omissions) as an add-on covers claims from clients whose business suffered from the IT company's technology performance failure — e.g., a software bug causing client financial loss, or downtime in a SaaS product causing client BI.
  • BFSI — Banks, NBFCs, Fintechs, Insurance companies:Financial sector companies face both large first-party risks (wire transfer fraud, trading system attacks, payment processing disruption) and extensive regulatory cyber obligations (RBI Cyber Security Framework, SEBI Cybersecurity Circular, IRDAI Information and Cyber Security Guidelines). Regulatory fines from RBI and SEBI for cyber failures are a specific and growing exposure. The 2024 Cosmos Bank and various NBFC cyber incidents demonstrate that financial sector cyber insurance is not optional — it is a risk management necessity.
  • Healthcare providers — Hospitals, diagnostic chains, telemedicine:Patient health data is among the most sensitive personal data categories — both under the DPDP Act and under medical ethics standards. Hospitals face ransomware attacks that can lock Electronic Health Record (EHR) systems, forcing a return to paper-based operations during the attack and creating patient safety risks. Diagnostic chains with large patient databases face regulatory breach notification and compensation exposure. Healthcare cyber insurance is one of the fastest-growing coverage categories in India.
  • E-Commerce and retail with payment card data:E-commerce businesses process payment card data and hold customer PII — creating both PCI DSS compliance obligations (and associated fine exposure) and DPDP Act obligations. A payment card data breach triggers PCI DSS fines from card networks (Visa, Mastercard, RuPay), forensic investigation costs, and customer notification obligations. For large e-commerce platforms, a single breach can affect millions of customers and generate thousands of crores in theoretical liability exposure.
🔒

Broader Business Coverage

  • Manufacturing companies with connected OT/IoT systems:Modern manufacturing increasingly uses internet-connected operational technology (OT) — SCADA systems, PLCs, IoT sensors, and industrial robots. Cyber attacks on manufacturing OT systems can shut down production lines, cause equipment damage, or create safety incidents. The Stuxnet precedent and numerous Indian manufacturing sector attacks demonstrate that OT cyber risk is real and growing. Manufacturing cyber insurance needs to address both IT (office systems) and OT (production systems) risk.
  • Professional services — Law firms, audit firms, consulting:Professional services firms hold highly sensitive client information — merger and acquisition plans, legal strategies, audit working papers, and confidential business information. Confidentiality obligations create significant liability if this information is breached. Law firms, in particular, are high-value targets for nation-state actors seeking M&A intelligence. Professional services cyber insurance addresses both breach response and client liability arising from confidentiality failures.
  • Hospitality — Hotels and restaurant chains:Hotels process guest payment data, hold passport and ID copies for compliance, and manage loyalty programme databases — all creating breach notification and liability exposure. Hotel property management systems (PMS) are a known target for cybercriminals seeking payment card data from high-volume guests. International hotel brands have suffered multiple major breaches (Marriott, Hilton) with losses running to hundreds of millions of dollars globally.
  • SMEs and startups — often the most vulnerable:Small and mid-size businesses are paradoxically both the most targeted (perceived as having weaker defences) and the least protected (fewest resources for cyber security investment). Studies consistently show that 60% of SMEs that suffer a significant cyber attack cease operations within 6 months — making cyber insurance potentially existential for smaller businesses. Even a ₹1–2 crore cyber policy at a modest premium provides meaningful protection against the most common attack types affecting SMEs.
  • Educational institutions — Universities and EdTech:Universities and educational institutions hold student PII, financial aid information, research data, and intellectual property. EdTech platforms hold millions of student records including payment data. The education sector has seen a significant increase in ransomware targeting in 2024–25, with several Indian universities reporting system encryption attacks requiring lengthy recovery periods.

How to Respond to a Cyber Incident & File a Claim

Claim Process — Cyber Insurance for Business

Cyber claims are time-critical — the first 72 hours after a cyber incident are the most important. Rapid notification activates the insurer's specialist cyber response team, which can significantly reduce the total impact of the incident.

🚨

Step 1 — Immediate Response (First 72 Hours)

When a cyber incident is detected:

Activate your Incident Response Plan (IRP): Contain the breach — isolate affected systems from the network to prevent further spread. Do not shut down systems before forensic imaging — this destroys evidence
Notify Probitas / the insurer immediately: Call 022 4302 0000. For theft of funds specifically, notify within 72 hours (policy condition). Early notification activates the insurer's 24/7 cyber incident response team — specialists in forensic investigation, legal guidance, and crisis management
Do NOT pay ransom without insurer guidance: Ransomware payment decisions must be made in consultation with the insurer, specialist cyber negotiators, and law enforcement (CERT-In, cyber crime cell). Paying without notification can affect coverage
Notify law enforcement: File a complaint with the local cyber crime cell and notify CERT-In (mandatory for significant incidents under CERT-In directions — within 6 hours of detecting certain incident types)
Preserve evidence: Take forensic images of affected systems before remediation. Preserve all logs, emails, and communications related to the incident. This evidence is critical for the insurance claim and any law enforcement action
Document the timeline: Record when the incident was discovered, by whom, what actions were taken, and when — this timeline is the foundation of the insurance claim

📋

Step 2 — Investigation & Documentation

The insurer's cyber incident response team coordinates:

Forensic investigation:
• Specialist cyber forensic investigators (typically from global firms — Mandiant, CrowdStrike, IBM X-Force, Palo Alto Unit 42 or their Indian partners) are engaged to identify the attack vector, attacker, scope of compromise, and data affected
• The forensic report is the foundation of the insurance claim — it determines what data was accessed, what systems were compromised, and whether specific coverage triggers (data breach, ransomware, network failure) are met

Legal assessment:
• Legal counsel assesses regulatory notification obligations under DPDP Act, RBI/SEBI/IRDAI directions, and contractual notification obligations to clients
• Claims from affected third parties are registered and managed through the insurer's legal team

Documentation for claim:
• Copy of FIR (cyber crime complaint)
• Forensic investigation report
• Bank statements and transaction records (for funds theft)
• Proof of affected data and systems
• All invoices for IT forensics, legal, notification, and crisis management costs
• Business interruption loss documentation (revenue records before and during the incident)
• Regulatory correspondence (CERT-In, Data Protection Board)
• Third-party claim notices received

Step 3 — Claim Assessment & Settlement

The insurer appoints a specialist cyber loss adjuster to assess the claim:

• Reviews forensic report to verify coverage trigger (confirms data breach, ransomware, network failure, etc.)
• Validates all first-party costs against the "reasonable and necessary" standard
• Calculates business interruption loss based on revenue records and the verified period of interruption
• Manages all third-party claims from affected clients and individuals
• Coordinates regulatory response and defence

Settlement structure:
First-party costs (forensics, notification, crisis management) are paid as incurred. Business interruption loss is paid at the end of the indemnity period. Ransomware payments are typically made quickly (subject to law enforcement clearance). Third-party liability claims are settled progressively as individual claims are resolved.

Important — notification timing:
Costs incurred BEFORE notifying the insurer are generally NOT covered. This is the most common reason cyber claim amounts are reduced. Notify the insurer immediately — even before the full scope of the incident is known.

Call Probitas on 022 4302 0000 at the first indication of any cyber incident — even suspected incidents that may turn out to be nothing. Early engagement costs nothing and protects your claim position.

What Cyber Insurance Does NOT Cover

Key Exclusions

Understanding cyber exclusions is critical — several common business losses that people assume are covered are actually excluded from standard cyber policies.

❌ Retroactive Date — Pre-Inception Incidents

Any loss from a cyber incident that occurred before the policy's retroactive date is not covered — even if discovered during the policy period. Setting the retro date as early as possible when purchasing cyber insurance is important. Breaches that began before the policy was taken are not covered.

❌ Dishonest or Criminal Conduct by Insured

Any cyber loss arising from the insured's own dishonest, criminal, or deliberate conduct is excluded. The policy covers external attacks and accidental internal errors — not the insured's own fraudulent or illegal acts.

❌ Bodily Injury & Physical Property Damage

Physical injury or property damage caused by a cyber incident is excluded from standard cyber insurance. A cyber attack on a manufacturing plant that physically damages equipment or injures workers may create property damage claims — these require property/engineering insurance. Physical consequences of OT cyber attacks may need specialist OT cyber or property cover.

❌ Business or Professional Activities (CyberShield)

For the individual CyberShield policy, business or professional activities are excluded — the individual policy covers personal cyber risks only. Business cyber risks require the Cyber Insurance for Business business policy.

❌ Non-Fiat Currency / Cryptocurrency Losses

Losses from theft or loss of cryptocurrency, NFTs, or other non-government-issued digital assets are not covered under standard cyber policies. If cryptocurrency holdings are a material business asset, specialist digital asset insurance may be required.

❌ Third-Party Infrastructure Outage

Failure, degradation, or outage of third-party infrastructure (telecommunications, electricity, internet providers, cloud platforms) that is NOT caused by a cyber attack is excluded. Only failures caused by a cyber security event are covered — general infrastructure outages are not covered.

❌ Expenses Before Claim Notification

Costs incurred by the insured before notifying the insurer of the cyber incident are generally not covered. This is a common and significant exclusion — companies that manage a cyber incident and only notify the insurer after incurring significant remediation costs may find those pre-notification costs excluded.

❌ War & Nation-State Attacks

Losses from cyber warfare, state-sponsored attacks, and acts of war are excluded. Nation-state cyber attacks — increasingly common in geopolitical tensions — may trigger this exclusion. The scope of this exclusion and how it interacts with commercially-motivated ransomware (often attributed to state-proxies) is a key area of ongoing policy development globally.

📋

Important Disclaimer

Cyber Insurance for Business is a specialist insurance product with individual underwriting based on the organisation's digital risk profile. Coverage terms, sub-limits, deductibles, retroactive dates, and premium rates vary by company size, sector, data sensitivity, security controls, and claims history. The DPDP Act 2023 regulatory framework referenced is evolving and organisations should seek legal advice on current obligations. Probitas Insurance Brokers Pvt. Ltd. · IRDAI Lic. No. 528.

Cyber Insurance for Business Questions

Frequently Asked Questions

Standard Commercial General Liability (CGL) policies have extensive cyber exclusions — they were designed before cyber risk existed and are not equipped to cover modern cyber losses. Specifically, CGL policies typically exclude: first-party cyber losses entirely (data breach response costs, ransomware, business interruption from cyber events are all first-party losses that CGL simply doesn't cover); third-party cyber liability arising from data breach or network security failure — most CGL policies either exclude cyber liability explicitly or have narrow coverage that is routinely disputed by insurers; regulatory fines from data protection authorities — CGL doesn't address DPDP Act, RBI, or SEBI cyber enforcement; and crisis management costs specific to cyber incidents. Some CGL policies have very limited "personal and advertising injury" coverage that might apply narrowly to media liability claims — but this is a far cry from comprehensive cyber liability coverage. Cyber insurance was designed specifically for this risk class, with policy language that precisely addresses the coverage triggers, costs, and exclusions relevant to cyber incidents. It is not duplicative of CGL — it fills the major cyber-specific gap that CGL leaves open.
Paying ransom is a complex decision involving legal, law enforcement, ethical, and practical considerations — and must never be made unilaterally without insurer guidance. As soon as ransomware is detected: notify Probitas and the insurer immediately (022 4302 0000); engage the insurer's specialist cyber extortion negotiator (the insurer maintains relationships with specialist firms who deal with ransomware operators daily); notify CERT-In and the local cyber crime cell (CERT-In directions may require reporting within 6 hours); engage your own cyber forensic firm to assess whether decryption is possible without paying. On coverage: ransomware payments are covered under Cyber Insurance for Business, subject to: the payment being authorised by the insurer's specialists before payment is made; law enforcement clearance where applicable; and verification that the payment is genuinely demanded (not a scam). The insurer's goal is to minimise total loss — sometimes paying a negotiated ransom (often reduced by 30–60% from the initial demand by specialist negotiators) is cheaper than the BI loss from extended downtime. Other times, restoration from clean backups is faster and cheaper. The specialist team makes this assessment. Costs incurred before notifying the insurer — including any unilateral ransom payment — may not be covered.
The Digital Personal Data Protection Act 2023 materially increases cyber insurance relevance for every Indian business that processes personal data. Key implications: (1) Mandatory breach notification — DPDP Act requires Data Fiduciaries to notify the Data Protection Board and affected individuals of significant breaches. The cost of identifying who was affected, preparing regulatory notifications, and communicating with affected individuals is covered under data breach response. (2) Penalties up to ₹250 crore — the Data Protection Board can impose substantial penalties for breaches that result from inadequate security measures. Cyber insurance with regulatory fine coverage addresses this penalty exposure (subject to insurability under Indian law). (3) Civil liability to affected individuals — individuals who suffer harm from a data breach can claim compensation. With large customer databases, aggregate civil liability from many individual claims can be substantial. (4) Board-level accountability — the DPDP Act's accountability framework means that senior management cyber oversight decisions are under regulatory scrutiny, increasing the value of robust cyber risk management including insurance. The DPDP Act's enforcement framework is still developing as of 2025–26, but companies should structure their cyber insurance to explicitly address DPDP Act-related regulatory investigation response costs, notification costs, and penalty exposure. Probitas can advise on policy wording to ensure DPDP Act relevance.
IT service companies face one of the highest cyber risk profiles of any sector — but the primary risk is not their own first-party BI; it is third-party liability to their clients. When an IT company is compromised (through their own systems or via their privileged access to client systems), the resulting client losses can dwarf the IT company's own recovery costs. Key exposures for IT service companies: (1) Supply chain attack — attackers use the IT vendor as a vector to reach the vendor's clients (as in the global SolarWinds and Kaseya attacks). The IT company faces liability to all affected clients. (2) Negligent security failure — a client claims the IT company's inadequate security allowed the client's system to be breached. (3) Technology failure causing client loss — a software bug, deployment error, or outage in the IT company's service causes client business interruption. (4) Confidentiality breach — client data accessed via the IT company's systems is exposed. For IT companies, the right cyber insurance structure combines Cyber Insurance for Business (for first-party BI and data breach) with Technology Errors & Omissions (Tech E&O) add-on (for client claims arising from technology performance failure). The combined programme addresses the full spectrum of IT company cyber and technology liability. Limits should be calibrated to the value of data in the IT company's custody across all client engagements simultaneously.
Business Email Compromise (BEC) is one of the most costly and fastest-growing cybercrime types in India — and is covered under cyber insurance as an optional Social Engineering / Funds Transfer Fraud add-on. In a BEC attack: a criminal either hacks a legitimate business email account or creates a convincing fake email account; they then send fraudulent payment instructions to a finance team member, typically impersonating the CEO, CFO, a vendor, or a lawyer handling a transaction; the victim transfers funds to the criminal's account believing it is a legitimate instruction. The RBI has reported thousands of BEC-style fraud cases involving Indian companies, with individual losses ranging from a few lakhs to tens of crores. A ₹3 crore wire transfer made based on a fake CEO email is a BEC loss. Under Cyber Insurance for Business's optional Social Engineering add-on, this specific loss type is covered — subject to the company having followed reasonable verification procedures (which typically means: a dual-authorisation process for large transfers, and a call-back verification to a pre-registered number before executing any large payment instruction received by email). Without the add-on, BEC losses are typically not covered under standard cyber or crime policies. Given how prevalent BEC is in India, we strongly recommend this add-on for any company that makes significant payments by wire transfer.
This is the "contingent business interruption" (CBI) or "dependent system failure" scenario — one of the most actively discussed areas in cyber insurance. The answer depends on the specific policy wording and what caused the cloud provider's outage. If the cloud provider's outage was caused by a cyber attack on their systems (ransomware, DDoS, hacking) — contingent BI coverage under your Cyber Insurance for Business policy would typically respond, as the trigger is a covered cyber event affecting a dependent system. If the cloud provider's outage was caused by a technical failure, power outage, or human error (NOT a cyber attack) — the standard CBI extension typically does NOT cover this. Non-cyber infrastructure failures are generally excluded. The scope of contingent BI coverage — which cloud providers are covered, what types of failures qualify, and the maximum indemnity period — should be reviewed carefully at policy placement. Given India's rapidly growing cloud adoption (AWS, Azure, Google Cloud, domestic cloud providers), the contingent BI cyber risk for cloud-dependent businesses is a material and growing exposure. Probitas recommends explicitly reviewing the policy wording for contingent BI scope and ensuring critical cloud provider dependencies are captured. Call 022 4302 0000 for a detailed review.
Cyber underwriters assess risk through a combination of questionnaire-based information gathering and increasingly, external scanning of the company's digital footprint. Key factors that drive premium up or down: (1) Multi-Factor Authentication (MFA) — companies without MFA on email, VPN, and administrative accounts face significantly higher rates or coverage restrictions. MFA is the single highest-impact control for reducing cyber risk. (2) Endpoint Detection and Response (EDR) — companies without EDR tools (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) on all endpoints face higher rates. (3) Regular patching — companies that patch critical vulnerabilities promptly within 30 days of release face lower rates than those with aged unpatched systems. (4) Backup integrity — companies with tested offline or immutable backups (that cannot be encrypted by ransomware) have materially better ransomware loss profiles. (5) Security certifications — ISO 27001 certification or SOC 2 Type II report demonstrates security maturity and typically attracts a 10–20% premium discount. (6) Incident response plan — companies with documented, tested IRP face lower rates. (7) 5-year loss history — prior cyber claims, especially frequent small claims, increase premium. The best premium improvement strategy: implement MFA everywhere, deploy EDR, test your backups monthly, and document your incident response plan. These investments typically cost far less than the premium reduction they generate.
Absolutely — small businesses are disproportionately targeted precisely because they are perceived as having weaker defences, and they suffer disproportionately from cyber attacks because they have less financial resilience to absorb the losses. Consider what a small business actually risks: a ransomware attack on a 20-person accounting firm could encrypt all client records and practice management software, creating a 2–4 week operational shutdown and loss of client trust. A business email compromise on a small trading company could result in a ₹50 lakh fraudulent wire transfer. A data breach at a small healthcare clinic could expose patient records, triggering DPDP Act notification obligations and compensation claims the clinic cannot afford. Studies consistently show that 60% of SMEs that suffer a significant cyber attack are unable to recover and cease trading within 6 months. Cyber insurance for a small business does not require a large premium — a ₹1–2 crore policy with appropriate deductible for a 20-person business might cost ₹1–3 lakh per year, covering precisely the existential financial losses that would otherwise close the business. At Probitas, we can structure small business cyber insurance that matches the risk profile and budget — call 022 4302 0000 for a quick indication.

Get Your Business Cyber Insurance Quote

Cyber Insurance for Business — Business Enquiry Form

Cyber insurance is individually underwritten based on your company's digital risk profile. Share your details and Probitas will arrange a Cyber Insurance for Business quotation within 48 hours.

💻 Company Details

🔒 Business & Risk Profile

By submitting you agree to our Privacy Policy and Terms & Conditions. Cyber Insurance for Business is subject to individual underwriting assessment. Coverage terms, sub-limits, deductibles, retroactive dates, and premium are agreed following review of the company’s digital risk profile and security posture. Probitas Insurance Brokers Pvt. Ltd. · IRDAI Lic. No. 528.

🔒 Cyber Insurance for Business — Defend Your Data, Revenue & Reputation

Data Breach Response · Ransomware & Extortion · Business Interruption · Third-Party Cyber Liability · DPDP Act Regulatory Cover · Crisis Management · BEC / Funds Transfer Fraud · Tech E&O — Cyber Insurance for Business for all business sizes. Call 022 4302 0000.