Also known as: Cyber Liability Policy
Cover for financial loss, liability and response costs following a data breach or cyber attack.
Cyber Liability covers the financial consequences of a data breach, ransomware attack or system failure. It responds across two dimensions — first-party costs, which are what the incident costs you directly, and third-party liability, which is what you owe others as a result. With the Digital Personal Data Protection Act now shaping obligations around personal data in India, the regulatory dimension has become as significant as the operational one.
Any business that holds customer data, processes payments, or depends on systems to operate. That now includes most organisations. Sectors with elevated exposure include technology, healthcare, financial services, e-commerce, education and professional services. Businesses handling personal data at scale face the sharpest regulatory exposure.
Limits typically range from one crore to fifty crore depending on data volume, sector and regulatory exposure. The most common sizing error is anchoring the limit to the value of IT assets rather than to the cost of a breach — which is driven by the number of records held, notification obligations and business interruption duration, not hardware value.
The difference between a policy that responds and one that disappoints usually sits in details that are easy to overlook at purchase.
Not sure which combination fits your business?
Speak to an AdviserSmaller businesses are frequently targeted precisely because their defences are weaker. The financial impact of an incident is often proportionally more severe for them than for a large enterprise.
Many policies do, subject to conditions and regulatory constraints. Terms vary considerably between insurers, and this is one of the areas most worth comparing carefully.
Most policies cover accidental breaches caused by employees. Deliberate acts by employees usually require a fidelity or crime extension.
Defence costs are generally covered. Whether fines themselves are insurable depends on the regulation and jurisdiction. This should be checked against your specific exposure.
Primarily by data volume, sector, revenue, security controls in place and prior incident history. Demonstrable security practices materially improve terms.
The date from which incidents are covered. Since breaches often go undetected for months, an inappropriate retroactive date can leave a significant gap.