Free ebook · 11 min read

Cyber Liability Insurance for Indian Businesses

  • Cyber
  • Liability
  • CFOs
  • Comparing Options

Quick answer: Cyber liability insurance covers the financial fallout of a data breach or cyberattack — forensic investigation, data recovery, business interruption, breach notification, ransomware response, and third-party claims. Under the Digital Personal Data Protection Act, 2023 that exposure applies to nearly any business holding personal data, not just tech companies.

All ebooks

Key facts

  • The DPDP Act, 2023 creates obligations around consent, data security safeguards and breach notification, with significant penalties for non-compliance.
  • Coverage splits into first-party costs (your own losses) and third-party liability (claims from others).
  • Any company storing customer, employee or partner data carries breach exposure — this is not a tech-only product.
  • Most modern policies cover ransomware response, though ransom payment terms vary significantly by insurer.
  • Companies with stronger security postures receive more favourable pricing, so underwriting doubles as a security audit.
  • Acts of war and state-sponsored attacks are a closely scrutinised and evolving exclusion area.

What cyber liability insurance covers

India’s data protection landscape shifted meaningfully with the Digital Personal Data Protection Act, 2023 coming into force, alongside tightening sector-specific cybersecurity requirements from the RBI and IRDAI. For businesses of every size, data breach exposure is no longer a theoretical IT concern — it is a financial and legal risk sitting squarely in the CFO and founder’s remit.

First-party coverage — costs your own company incurs directly after an incident: forensic investigation to determine scope and cause; data recovery and system restoration; business interruption losses from downtime; customer and regulator notification costs, which can be substantial given DPDP notification obligations; ransomware-related costs including incident response; and crisis PR support.

Third-party liability coverage — claims made against you: legal defence and settlement costs from customers, partners or vendors whose data was compromised; regulatory investigation defence costs; and PCI compliance failure costs where relevant.

Why this matters beyond “tech companies”

A common misconception is that cyber insurance is only relevant for software or tech-first businesses. In reality, almost any company holding customer, employee or partner data — a manufacturer’s ERP system, a healthcare provider’s patient records, a retail chain’s loyalty database, an HR system full of employee PII — carries meaningful breach exposure.

The DPDP Act’s obligations around consent, data handling and breach notification apply broadly across sectors that process personal data, not narrowly to IT companies. While cyber insurance does not eliminate compliance obligations, it provides a financial backstop for the costs that follow an actual breach — costs that can otherwise be severe enough to threaten a smaller company’s continuity entirely.

Common cyber risks facing Indian businesses

  • Ransomware — increasingly common across sectors, encrypting business-critical systems and demanding payment for restoration.
  • Phishing and social engineering fraud — employees tricked into transferring funds or credentials.
  • Third-party and vendor breaches — a breach at a SaaS provider you use can expose your data without any direct attack on your systems.
  • Insider threats — data misuse or theft by current or former employees.
  • Cloud misconfiguration — increasingly common as companies scale infrastructure faster than security practices mature.

What cyber insurance typically does NOT cover

  • Losses from known, pre-existing vulnerabilities not disclosed at policy purchase.
  • Intentional acts by the insured company’s leadership.
  • Reputational harm not tied to a quantifiable financial loss, though crisis PR support is often included as a service.
  • Betterment costs — upgrading security infrastructure beyond restoring the pre-incident state.
  • Acts of war or state-sponsored attacks in many policies — an evolving and closely scrutinised exclusion given rising nation-state activity.

How insurers assess risk — what you will be asked

  • What types and volumes of personal or sensitive data you handle.
  • Security controls in place: encryption at rest and in transit, multi-factor authentication, access controls, patch management.
  • Backup and disaster recovery practices, including how frequently backups are tested.
  • Incident response plan maturity — do you have a documented plan, and has it been tested?
  • Prior incident history and third-party vendor risk management practices.

Companies with stronger security postures generally receive more favourable pricing, which makes a cyber insurance evaluation a useful forcing function to actually document and improve security practices.

Choosing the right policy

  • Coverage scope — does it include both first-party and third-party coverage, and does it explicitly address ransomware?
  • Sub-limits — some policies cap specific costs like notification expenses or forensic investigation well below the headline limit.
  • Panel providers — many insurers require using their approved panel of forensic investigators, legal counsel and PR firms. Check whether that panel is genuinely strong or a limiting factor.
  • Retroactive date — ensures coverage applies to breaches discovered during the policy period even if the underlying vulnerability existed earlier.
  • Business interruption trigger and waiting period — how quickly does interruption coverage begin after discovery?

Cyber sits alongside, not inside, D&O and professional indemnity cover — the three address different risks and are frequently confused.

Frequently asked questions

Do Indian companies legally need cyber insurance?+

It’s not currently mandated by a single law, but the Digital Personal Data Protection (DPDP) Act, 2023 and sector regulations (RBI, IRDAI, SEBI cybersecurity frameworks) create financial and legal exposure from data breaches that cyber insurance is designed to address.

What does a typical cyber liability policy cover?+

First-party costs (breach investigation, data recovery, business interruption, ransom negotiation/payment where legal, customer notification costs) and third-party liability (claims from affected customers/partners, regulatory fines where insurable, legal defense).

How much does cyber insurance cost for a small Indian business?+

Costs vary by data volume handled, industry, and revenue, but small businesses can often access meaningful coverage at a modest premium relative to breach costs, which routinely run into lakhs or crores for a serious incident.

Does cyber insurance cover ransomware attacks?+

Most modern policies cover ransomware-related costs including incident response, data recovery, and business interruption, though ransom payment coverage and terms vary significantly by insurer and jurisdiction.

Is cyber insurance relevant for companies that don’t sell software?+

Yes — any company storing customer data (HR records, customer databases, payment information) carries breach exposure, regardless of whether the core business is technology.

What information do insurers need to underwrite a cyber policy?+

Typically details on data types handled, security controls in place (encryption, access controls, backup practices), past incident history, and vendor/third-party data-sharing arrangements.

Take this guide with you

Download the full PDF, or talk to an IRDAI-registered broker about your team.

Premium ranges, cost benchmarks and regulatory references in this guide are indicative and current as of February 2026. They are not a quotation and not legal or tax advice. Actual premiums depend on your group profile, claims history and insurer underwriting. Verify statutory obligations for your specific state, sector and headcount before acting. ClearCover (formerly MDH Insurance) is an IRDAI-registered Direct Broker, Reg. No. 596, Code DB 652/16.