Cyber Insurance
DPDP Act breach notification is now mandatory

Covers what happens after a breach: forensic investigation, data restoration, regulatory fines, ransom, business interruption, and claims from customers whose data you lost. Available for businesses and, increasingly, for individuals facing UPI fraud and identity theft.

₹94,000
from, ₹5 Cr limit for an SME
₹22 L
average Indian SME breach cost
72 hrs
DPDP notification deadline

Illustrative figures until sourced from the insurer of record.

What it covers

Breach response

Forensics and legal, first 72 hours

Business interruption

Lost profit while systems are down

Ransom and extortion

Including negotiation support

Third-party liability

Customer and regulator claims

Plans

SME, 60,000 records, card payments, ₹5 Cr limit

Premiums and claim-settlement ratios are illustrative until sourced from the insurer of record.

Cyber Sachet Business

98.5% settled
HDFC ERGO

Best incident-response panel in India and 24-hour forensic mobilisation. You are paying for the first eight hours.

₹1.06 L
a year
Quote this

Cyber Risk Protect

96.2% settled
ICICI Lombard

Broadest business-interruption wording, with a short 6-hour waiting period before loss starts accruing.

₹94,000
a year
Quote this

CyberEdge

96.8% settled
Tata AIG

Highest sub-limit for regulatory fines and the only one here that covers social-engineering fund transfer in full.

₹1.18 L
a year
Quote this
What it will not pay for

Read this before you buy.

  • Breaches that began before the policy started, even if discovered later
  • Unencrypted data on a lost laptop, where encryption was a policy condition
  • Failure to apply a patch that was available for more than 45 days
  • Loss of intellectual property value, and reputational harm itself
  • Fines that are uninsurable by law in the relevant jurisdiction
How a claim works

The first 72 hours decide both the loss and the claim. Every cyber policy includes an incident-response hotline — using it immediately is a policy condition, not a convenience.

  1. 01

    Call the incident hotline

    · hour 1

    Before you wipe anything. The insurer appoints forensics and legal counsel; acting alone first can void the cover.

  2. 02

    Contain and notify

    · hours 1–72

    Forensics isolate the breach. Under the DPDP Act you must notify the Data Protection Board and affected individuals within 72 hours.

  3. 03

    Restore and quantify

    · days 2–14

    Data restoration costs and business-interruption loss are measured against your pre-incident trading. Good books make this claim far larger.

  4. 04

    Third-party claims follow

    · months

    Customer claims and regulatory penalties arrive long after the systems are back. The policy defends these on a claims-made basis, so it must still be live.

The common mistake

Believing your size protects you. Attackers automate; they do not choose. The average Indian SME breach now costs ₹22 L, and the ones that close afterwards are the ones that had no response plan and no cover.