← Cyber insurance

Business insurance · Cyber

The Complete Guide to Cyber Insurance for Indian Businesses & Professionals

In a hyper-connected world, if you're not fully protected you're not just risking data — you're risking your future. Here's the full picture of cyber insurance, in plain terms.

Cyber threats don't discriminate. If your world intersects with data, transactions or digital infrastructure, this is for you.

🎯 A 10-second risk check

  • Do you store customer data?
  • Do you accept online payments?
  • Do you work on cloud platforms?
  • Do employees access systems remotely?
  • Do you handle sensitive client information?

If you answered “yes” to two or more, you're at real risk.

At Ethika we deal with the real-world problems that keep business owners up at night. The goal here isn't to sell you a product — it's to help you understand one of the most pervasive and financially serious risks of our time.

What is cyber insurance? Your essential digital shield

Cyber insurance — also called cyber liability insurance — is specialised coverage that protects you from the financial fallout and legal liabilities of cyberattacks and data breaches.

Just as you insure your car or home against physical damage, cyber insurance protects your digital assets and online presence. As your operations, customer records and reputation increasingly live in the digital realm, cyber threats become very real, very costly problems.

Who needs this protection?

Cyber threats don't discriminate. This isn't only for large technology firms — it's for anyone whose work intersects with data, transactions or digital infrastructure.

Digital-first businesses

SaaS providers, fintechs, D2C brands and agencies collect, process and store large amounts of data. A breach isn't just a hit — it threatens operations, customer trust and competitive edge.

Professional practices

CAs, architects, lawyers, doctors and consultants are built on trust and sensitive client information. A cyber incident doesn't just compromise data; it shakes the confidence clients place in you, with legal and reputational consequences.

Founders & leaders

Leaders with significant assets and visible digital footprints are prime targets for spear-phishing and identity theft. Personal digital security is tied to your professional legacy.

Why cyber insurance is a “now” priority

In a world running on data, the threats aren't just lurking — they're actively targeting, and the cost of inaction is higher than most owners assume.

#2
India's global rank for ransomware (2023)

Your data isn't safe by default; it's a constant target.

>60%
of SMEs close after a major breach

A serious attack is often a fatal blow for a small business within six months.

₹250 Cr
maximum DPDP Act penalty

The DPDP Act, 2023 reshaped accountability with severe penalties and mandatory breach notification.

How does cyber insurance work?

Cyber insurance transfers the financial risk of a cyber incident from your balance sheet to the insurer — covering the cascade of costs that standard policies typically don't.

Risk assessment & policy design

It starts with an assessment of your digital exposure; a tailored policy is then designed, specifying coverage limits and deductibles.

The incident (the “trigger”)

The policy activates on a security or privacy breach. You're required to notify the insurer as soon as possible.

First-party cost coverage

Covers IT forensics, data recovery, business-interruption losses, cyber-extortion costs and crisis management to repair your reputation.

Third-party liability coverage

If a customer or other third party sues, the policy covers legal defence, settlements and regulatory fines (for example, under the DPDP Act).

Claims process & support

Once reported, the insurer gives access to pre-vetted experts — forensics, legal, PR — to help you recover.

Real cyber incidents — could this be you?

Case: AIIMS cyberattack (December 2022)

AIIMS Delhi suffered a major cyberattack that disrupted online services and affected patient care; roughly 1.3 terabytes of data were encrypted.

Why cover matters here: immense business-interruption and data-restoration costs. A policy would have funded forensic experts, system rebuilds and downtime, while the PR component helped manage public concern.

Case: Cosmos Bank attack (August 2018)

Cosmos Co-operative Bank in Pune suffered a sophisticated attack resulting in a financial breach of nearly ₹94 crore, after malware compromised its ATM switch and SWIFT systems.

Why cover matters here: financial-fraud protection. A robust policy would have responded to the unauthorised transactions and losses, covered legal defence, supported regulatory compliance and helped mitigate reputational damage.

Case: Juspay data breach (August 2021)

Fintech firm Juspay suffered a breach compromising the personal information of over 100 million users, with the data later listed for sale on the dark web.

Why cover matters here: data-privacy liability. Insurance would help cover legal expenses from class actions, regulatory fines under the DPDP Act, and customer credit-monitoring to rebuild trust.

The dos and don'ts of cyber insurance

Do — maximise your protection

  • Run a cyber risk assessment — know your digital assets and exposure before choosing a policy.
  • Choose the right broker — work with a cyber-savvy broker to tailor coverage to your risk.
  • Maintain cyber hygiene — use MFA, patch systems and run anti-virus.
  • Back up data securely — keep immutable, offline backups against ransomware.
  • Train your employees — regular phishing and security training strengthens your human firewall.

Don't — avoid these pitfalls

  • Don't delay notification — report incidents promptly; delays can void a claim.
  • Don't pay a ransom without insurer consent — always inform your insurer first.
  • Don't misrepresent your cyber hygiene — false declarations can lead to claim denial.
  • Don't focus only on premium — the cheapest policy isn't the best; check coverage depth and exclusions.
  • Don't reveal you're insured — disclosing policy details to attackers can increase ransom demands.

Ready to secure your digital future?

Ethika isn't just arranging a cyber policy — we're helping protect your peace of mind. Talk to us and get an honest read on your exposure and your cover.

Book a risk conversation

Frequently asked questions

Is cyber insurance mandatory in India?

No — but for any company storing sensitive data it's strongly recommended, especially under the DPDP Act. See who needs cyber insurance, and who can wait.

Who is vulnerable to a cyber attack?

Everyone — individuals, small businesses and large corporations. If you have an online presence or store any sensitive information digitally, you're a potential target.

Does my general liability policy cover cyber risks?

Most standard general liability policies don't adequately cover cyber risks — they're designed for physical damage and bodily injury. You need a specialised cyber policy.

What's the difference between first-party and third-party coverage?

First-party covers your direct costs (data restoration, business interruption). Third-party protects you from liabilities to others (legal defence, settlements, regulatory fines). More in what cyber insurance covers.

Can a cyber insurance policy be customised?

Yes — many policies are flexible and can be tailored, letting you set coverage limits and add protection based on your exposure.

Will it cover a ransom demand involving cryptocurrency?

Coverage varies. Some policies cover ransom payments; others have limits or exclusions. Review the terms carefully.

Is cyber insurance a replacement for strong cyber security?

No — it's a complement. Security aims to prevent attacks; insurance helps you recover financially and operationally when one occurs.

How do I prepare my company for ransomware?

Implement MFA, run regular backups, train employees, keep software updated, and maintain an incident-response plan.

What should I do immediately after an attack?

Isolate affected systems, activate your incident-response plan, notify internal stakeholders, and contact your cyber insurer for next steps.

What happens when you talk to us

A 20-minute video call with a Growth Advisor — no obligation, and no quote pushed. It opens with a five-minute video from our founder on how the benefits stack works and why Ethika exists; the rest is your questions. You'll leave with an honest read on your current cover and claims experience, and a straight answer on whether we can genuinely help — even if you never become a client.

Talk to us

20 minutes with a Growth Advisor. No obligation.

Read next

A note on this page. Everything here is general information, not insurance, legal, financial or tax advice, and nothing is an offer. For advice about your situation, talk to us.