Back to RFS homepage
Home Risks Cyber & Data Breach
Digital peril

Cyber & Data Breach

Ransomware, data breach and BI from cyber events, plus DPDP Act penalties.

The risk

The breach is not if. It is when, and how ready you are.

Cyber cover responds to first-party loss (ransomware, system restoration, business interruption, cyber extortion) and third-party liability (data-breach claims and regulatory penalties under the Digital Personal Data Protection Act, 2023). Every business holding customer or employee data is now a data fiduciary with statutory obligations and real financial exposure.

Exposure profile

Where this risk lands on your balance sheet.

The exposures we evaluate first when scoping a programme against this risk.

01
Ransomware & system restoration
Encryption, extortion demands and the cost of rebuilding systems and data.
02
Data-breach liability & DPDPA penalties
Third-party claims and statutory penalties for mishandled personal data.
03
Business interruption from outage
Lost revenue while systems are down, increasingly the largest single cost.
04
Funds-transfer fraud & social engineering
Authorised-push-payment and invoice-redirection fraud targeting finance teams.

Want a risk-specific programme review?

Speak with an advisor who has structured cover against this risk for clients in your sector.

Request an Assessment →
FAQ

Common Questions

The attacks that reach Indian SMEs are not targeted, they are automatic, and a smaller business is more exposed rather than less because the recovery capacity is thinner. The question is not whether anybody is interested in your data, it is how many days you could operate with your billing system encrypted.
Rarely the ransom. It is the days of stopped operations, the specialist work to establish what was taken, notifying the people affected, and answering the regulator afterwards. The technical restoration is usually the smallest line in the total.
It attaches consequences to holding personal data badly, so a breach now creates a regulatory exposure alongside the operational one. Any business holding customer or employee records is inside its scope, which is very nearly all of them.
Not the part that matters. Their contract limits their liability, usually to fees paid, and the obligation to notify and to answer for the data stays with you. Outsourcing the systems does not outsource the accountability.
Often late. The typical pattern is not a dramatic announcement but a system behaving oddly for a while, then a demand or a customer telling you their data is somewhere it should not be. The gap between the intrusion and its discovery is where most of the eventual cost is created.