Back to RFS homepage
Home Products Cyber Insurance
Specialised Cover

Cyber Insurance

First-party and third-party cyber risk insurance covering ransomware response, data breach costs, business interruption from cyber events and legal liability for data privacy failures. With India's DPDPA enforcement underway, cyber insurance has moved from discretionary to essential for any data-intensive organisation.

Coverage at a Glance
First-Party Losses

Data recovery, ransomware, business interruption

Third-Party Data Liability

Legal liability for customer data breaches

Incident Response

24/7 breach response team on call from day one

Regulatory Defence

CERT-In and DPDPA investigation costs

First & Third Party Cover
24/7 Incident Hotline
DPDPA Aligned
45+ Insurer Network
Coverage

What Your Policy Covers

A structured placement designed to close every material gap in your risk exposure, not a standard policy sold off the shelf.

Data Breach Response
Covers forensic investigation, legal notification costs and credit monitoring services for affected individuals following a confirmed data breach.
Ransomware & Cyber Extortion
Covers ransom payments made under duress and the cost of professional crisis negotiators, subject to prior insurer notification and compliance with applicable law.
Business Interruption
Covers revenue loss and increased operating costs during the period systems are unavailable or degraded following a cyber attack, subject to a minimum waiting period.
Data Recovery & Restoration
Covers the cost of recreating or restoring data and systems that have been corrupted, deleted or encrypted by an attack, including specialist IT forensics.
Third-Party Data Liability
Covers legal liability to customers, employees or third parties whose personal data has been compromised, including defence costs and compensation awards.
Regulatory Response Costs
Covers the cost of responding to regulatory investigations by CERT-In, the Data Protection Board or sector regulators, and civil penalties where they are insurable under Indian law.
Cyber Risk Specialists Cyber Risk Specialists
Our Approach

The Threat Environment Has Changed, Your Insurance Programme Should Reflect That

Ransomware attacks targeting Indian businesses increased materially through 2024-2025. The DPDPA, once enforced, creates mandatory breach notification obligations and significant financial penalties for data fiduciaries. A cyber insurance programme is now both a financial and a compliance consideration.

We assess your digital infrastructure, data classifications, third-party vendor dependencies and incident response maturity before approaching the cyber insurance market, risk quality directly affects both terms and premium.
We match your risk profile to insurers with demonstrated claims-paying track records in the Indian market, not simply the broadest policy wording on paper.
Your insurer's breach response panel, forensic investigators, legal counsel and communications advisors, is agreed before an incident, so there is no delay in activation when it matters.
Who Needs This

Businesses That Carry This Risk

If your operations create the exposures described below, this cover belongs in your insurance programme.

01
IT & Technology Companies
Software firms, IT services providers and SaaS companies handling large client data volumes carry significant third-party data liability and business interruption exposure.
02
Healthcare & Hospitals
Patient health records are among the most sensitive and most frequently targeted data categories. Healthcare providers face both regulatory obligations and elevated ransomware risk.
03
BFSI Sector
Banks, NBFCs, fintech companies and insurers face sector-specific cyber regulation from RBI and IRDAI, alongside the reputational and financial consequences of a breach.
04
E-Commerce & Retail
Online retailers storing payment card data and personal customer records face PCI-DSS obligations and significant third-party liability following a breach.
05
Manufacturing with OT
Manufacturers with operational technology systems face ransomware attacks that target production line control systems and can cause physical damage and extended downtime.
06
Professional Services Firms
Law firms, accounting firms and management consultancies hold sensitive client data under confidentiality obligations, a breach carries both legal and reputational consequences.
How We Work

From Brief to Bound Cover

Three steps from your first conversation to a policy that is correctly structured and competitively priced.

01
Cyber Risk Assessment
We conduct a structured assessment covering your IT infrastructure, data assets, vendor dependencies, incident response plans and prior cyber incidents to characterise your risk accurately.
02
Policy Design & Market Placement
We specify the coverage, first-party, third-party, regulatory, dependent BI, and approach specialist cyber insurers to obtain competitive terms with a pre-agreed breach response panel.
03
Incident Response Activation
On a reported incident, we activate the response panel, notify the insurer formally and co-ordinate forensic, legal and communications support from the first hour onwards.
Comparing Quotations

Two cyber quotations, the same limit, very different settlements

Cyber wordings diverge more than any other commercial line. Two quotes can carry an identical headline limit and pay quite differently on the same incident, because what decides a cyber claim sits in the retroactive date, the waiting period mechanics and the sub-limits rather than in the limit on the front page. These are the six we put side by side before anyone looks at the premium.

The retroactive date
Cyber cover is written on a claims-made basis, and the retroactive date is the cut-off before which the breach must not have begun. An attacker who was already inside the network before that date is outside the policy, however recently you discovered them. Full prior-acts cover is worth asking for by name.
How the business interruption waiting period is applied
Most policies state a waiting period of roughly eight to twelve hours before interruption cover starts. The question almost nobody asks is what happens once you exceed it: some policies deduct that period from the claim, others pay back to hour zero. Identical stated waiting periods, materially different settlements.
Contingent business interruption
Loss caused by an outage at somebody you depend on rather than at your own premises - the cloud provider, the payment gateway, the outsourced IT desk. For most businesses that is the likelier failure, and it is frequently excluded.
Social engineering and funds transfer fraud
Somebody in accounts is deceived into paying an attacker. It is the loss a small business is most likely actually to suffer, and it is usually carried at a small sub-limit or excluded outright rather than sitting inside the headline limit.
Whether the response is fast enough for CERT-In
CERT-In directions require certain incidents, including ransomware and unauthorised access, to be reported within six hours of being noticed - among the tightest windows anywhere. A business without a round-the-clock security desk cannot meet that without a pre-agreed playbook and named contacts, so what the insurer's response desk does in hour one is a coverage question, not a service one.
Support for DPDP notification
The Digital Personal Data Protection Act, 2023, with its rules notified in November 2025, places a notification duty on a data fiduciary running from the moment it becomes aware of a breach. Ask whether the policy funds that work, and whether the panel has done it in India rather than elsewhere.

None of this is exotic. It is the ordinary content of an Indian cyber wording, and it is the part that is almost never compared because the proposal forms make the policies look alike.

Key Benefits

Why Clients Place This Cover Through Us

Pre-Agreed Response Panel
Your forensic investigators, legal counsel and crisis communications advisors are named in the policy before an attack, no time lost sourcing vendors under pressure.
DPDPA Alignment
We brief you on mandatory notification timelines under the Data Protection Board framework and ensure your policy covers the regulatory response costs associated with compliance.
Business Interruption Sizing
We model your revenue exposure during a realistic outage scenario to set the BI sum insured and waiting period correctly, most cyber BI limits are inadequate relative to actual revenue at risk.
Annual Threat Briefing
At each renewal, we provide a sector-specific briefing on current attack techniques and threat actors targeting your industry, informing both your security posture and your coverage requirements.
FAQ

Common Questions

Most cyber policies include ransomware and cyber extortion cover, which pays the ransom amount and professional negotiator costs. Conditions typically require prior insurer notification before payment and compliance with applicable law. Payments to sanctioned entities are excluded across all policies.
The Digital Personal Data Protection Act, 2023 requires data fiduciaries to notify the Data Protection Board and affected individuals of a data breach within prescribed timelines. It also creates civil penalty exposure for processing failures. Cyber insurance covers the notification costs, regulatory response expenses and, where insurable, penalty exposure.
First-party cover pays for losses your business suffers directly, data recovery, ransom payments, business interruption and forensic costs. Third-party cover pays your legal liability to individuals or organisations whose data was compromised. Most cyber programmes combine both.
Social engineering fraud, where an employee is deceived into transferring funds, is typically a crime or fidelity cover rather than a cyber cover. Some cyber policies offer a social engineering extension. We ensure your programme addresses both, either within the cyber policy or through a complementary crime policy.
Cyber policies typically include dependent business interruption cover for outages at cloud providers such as AWS, Azure or Google Cloud, subject to a waiting period, usually eight to twelve hours. This extension is increasingly important as businesses migrate critical workloads to cloud infrastructure.

Cyber risk insurance matched to how your business actually operates.

Generic cyber policies are not written for your industry or your data profile. We structure cover that is.

Request a Proposal →