Cyber & digital risk

When a breach hits: what cyber insurance actually does, and the two clocks that start

A terabyte of a major Indian bank’s data turned up on the dark web this month, and the companies building frontier AI admitted their own models had broken into other businesses. The threat is speeding up — and in India, a breach now starts two reporting clocks the moment you find it.

You find out at the worst possible time: a systems alert in the small hours, a customer asking why their details are for sale, a payment that left for an account no one recognises. And somewhere in the scramble, a clock you did not know about has already started running.

In the last few days, a major Indian public-sector bank has been investigating a breach after roughly a terabyte of data, reportedly including customer account and loan records, surfaced on the dark web. In the same week, the companies building the most advanced AI disclosed that their own models had broken into outside organisations’ systems during testing. Read together, they point at one thing: attacks that once took weeks can now move at machine speed, and no organisation is quietly too small or too dull to be a target.

India has already recognised this. Cybersecurity is now ranked the country’s top national risk, and the law has caught up with it. The uncomfortable truth for a business owner is that the day of a breach is not only a technical emergency. It is a legal one, with deadlines measured in hours, and cyber insurance is what is built to carry the cost and the response.

In short

  • Cyber insurance does not stop an attack. It helps you carry the cost and the response when one gets through.
  • In India a breach can start two clocks: a report to CERT-In within 6 hours, and one to the Data Protection Board within 72 hours under DPDP, plus telling affected people without delay.
  • A policy has two halves: first-party cover for your own costs, and third-party cover for claims others bring against you.
  • The claim is decided in the grey areas — the fake-invoice fraud conditions, the ransomware terms, vendor breaches, and whether a statutory penalty is even insurable, which is often not.

Put simply: cyber insurance is a business policy that helps you respond to and recover from a cyber incident — a data breach, ransomware, online fraud, or an attack-driven outage — by helping meet response costs and certain claims from others, subject to the policy wording. It does not prevent attacks; your controls do that. It is what responds when one gets through.

What cyber insurance is, and what it is not

Think of the difference between locks on your doors and the cover that pays to put things right after a break-in. Firewalls, multi-factor login, backups and staff training are the locks; they reduce the chance of an incident. Cyber insurance is the cover that responds when something gets past them anyway, so a single event does not put the business on the floor. It does not replace the security work, and it will not pay for security you told an insurer you had and then let lapse. One reduces the odds; the other limits the damage.

The two clocks a breach starts

This is the part most people meet for the first time on the worst day, and it is worth knowing in the calm. Under the CERT-In Directions of April 2022, made under the Information Technology Act, 2000, certain cyber incidents must be reported to CERT-In within six hours of being noticed. Separately, under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, a business that suffers a personal-data breach must give the Data Protection Board of India a detailed report within 72 hours of becoming aware, and must notify each affected individual without delay. These duties sit alongside each other, not instead of one another.

A careful line on what insurance does here, because it matters: whether cyber insurance can pay a statutory fine or penalty is an unsettled legal question that turns on Indian law, the nature of the penalty and the policy wording, so no honest page should tell you it pays government fines. What cyber cover is more reliably built to help with is the cost of responding — the forensic, legal and notification work the law effectively forces you to do well, and fast.

What a policy actually responds to

Most business cyber policies have two halves. First-party cover pays for what the incident costs your own business: forensic investigation, breach response and customer notification, restoring lost data, income lost during downtime, and ransomware response. Third-party cover responds when someone else brings a claim against you afterwards, from customers whose data was exposed to vendors and partners affected downstream. Which halves you hold, and the limits and conditions on each, are set by the wording, which is exactly where the real differences hide.

The grey areas that decide a claim

The fake-invoice scam, where a finance team is tricked into paying a convincing but fraudulent request, is not treated like a data breach. Many policies cover it only under a specific social-engineering extension, often with a sub-limit and conditions such as a call-back to verify a change of bank details. Ransomware carries its own conditions and sanctions rules; vendor and supply-chain compromises depend heavily on the wording; and war and state-backed attacks are a fast-moving exclusion. Being told you have cyber cover and having the right cyber cover are not the same thing.

How a breach maps to cover

It helps to separate the incident into the losses it creates, because each is answered by a different part of a policy. This is category-level — it describes how cover generally works, not any one insurer’s product.

How a cyber incident maps to the cover that responds (general categories, subject to policy wording)
The lossThe cover that typically responds
Customer or employee data exposed in a breachData breach response, and privacy liability for claims
Systems locked and operations stopped by ransomwareRansomware and cyber extortion, with business interruption
A fraudulent or “CEO” payment (business email compromise)Cyber fraud / social engineering, subject to verification conditions
A vendor or software provider compromise flowing to youThird-party and supply-chain wording
Claims from customers or partners after an incidentThird-party liability

A five-minute check before you need it

You don’t need a full review to find the biggest gaps. Five questions usually surface them:

  1. Do you have MFA and backups you have actually tested restoring?This is prevention, not insurance, but insurers check it closely and it shapes both your terms and your recovery. Untested backups are the gap found at the worst moment.
  2. Does your wording cover the fake-invoice fraud?Check whether social-engineering loss is covered, at what sub-limit, and what verification steps the policy requires you to have followed for a claim to stand.
  3. What are the ransomware terms and conditions?Look at sub-limits, waiting periods and sanctions conditions. This is where a policy either answers on a bad day or quietly does not.
  4. Does the cover reach a vendor or supply-chain compromise?More incidents now arrive through a trusted third party. Ask whether your wording follows the risk downstream, or stops at your own systems.
  5. If a breach were found this hour, who do you call, and are the clocks mapped?Know in advance who to notify first and how the six-hour CERT-In and 72-hour DPDP duties would be met, because speed early on helps both recovery and the claim.

Frequently asked questions

Is cyber insurance mandatory in India?

No single law currently requires a business to buy cyber insurance. But the breach-reporting and data-protection duties under CERT-In and the DPDP regime are mandatory when an incident happens, and many customer, investor and enterprise contracts now require cyber cover even though the law does not.

What reporting timelines does a breach start in India?

Under CERT-In rules, certain cyber incidents must be reported within six hours of being noticed. Under the DPDP regime, a personal-data breach must be reported to the Data Protection Board of India within 72 hours of becoming aware, and affected individuals must be notified without delay. These are the current positions and should be confirmed with counsel.

Does cyber insurance pay a DPDP fine or penalty?

Be very careful here. Whether a statutory fine or penalty is insurable depends on Indian law, the nature of the penalty and the policy wording, so a business should take legal advice before assuming such penalties are covered. What cyber cover more reliably helps with is the cost of responding to a breach.

Does cyber insurance cover ransomware?

It can. Many policies include ransomware and cyber-extortion cover, with conditions, sub-limits and applicable sanctions rules. The exact terms decide what you actually get, so they are worth reading closely.

Does it cover the fake-invoice fraud (business email compromise)?

Some social-engineering loss may be covered, often only under a specific extension and often only if the business followed its own payment-verification steps, such as a call-back to confirm a change of bank details. It is one of the first things worth checking in any wording.

What happens when you talk to us

A 20-minute video call with a Growth Advisor — no obligation, and no quote pushed. It opens with a five-minute video from our founder on how the benefits stack works and why Ethika exists; the rest is your questions. You’ll leave with an honest read on your current cover and claims experience, and a straight answer on whether we can genuinely help — even if you never become a client.

Talk to us

20 minutes with a Growth Advisor. No obligation.

A note on this page. Everything here is general information about cyber insurance, not insurance, legal, financial or tax advice, and nothing is an offer of cover. Cover depends on your own policy wording. For advice about your situation, talk to us. Statutory references — the DPDP Act 2023 and DPDP Rules 2025, the CERT-In Directions of April 2022, and the Information Technology Act 2000 — are the current position and should be confirmed with counsel before you rely on them.