Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Home/ Insights/Buying guide
Buying guide

What cyber insurance costs in India, and the six things that move the price

Published 29 July 2026 · 8 min read · DPDP Insurance India

The honest answer to "what does cyber insurance cost in India" is that it is a function of six variables, four of which you control. The unhelpful answer, which is what most websites give, is a single number. Here is the working version.

The ranges we see in the market

As a planning figure, Indian small and mid-market businesses pay roughly 0.4% to 0.9% of the sum insured per year. Larger limits price at a lower rate because the top layers are less likely to be reached.

Sum insuredIndicative annual premiumTypical buyer
₹1 crore₹75,000 – ₹1.2 lakhEarly-stage SaaS meeting a customer contract requirement
₹5 crore₹2.5 – 4.5 lakhGrowth-stage D2C, edtech, IT services
₹10 crore₹4.5 – 8 lakhMid-market with meaningful record volumes
₹25 crore₹11 – 18 lakhFintech, healthcare, large processors

Treat these as the middle of a wide distribution. A fintech holding ten lakh KYC records with a prior incident will sit above the top of its band. A services business with strong controls and no personal data at scale can sit below the bottom.

How underwriters get to a number

Pricing starts from an exposure base — your revenue and the volume and sensitivity of the personal data you hold — and is then modified by controls, sector, claims history and the structure you buy. The exposure base sets the ballpark. Controls decide where in the ballpark you land, and they can move the premium by 30% or more in either direction.

This is why the proposal form matters more than the negotiation. Every question on it is a rating factor, and vague answers get priced as though the answer were no.

Six things that move your premium

1. Multi-factor authentication, enforced without exception

The single highest-weighted control in the Indian market right now. Not "available", not "for admins". Enforced on email, VPN, remote desktop and every administrative account. Insurers ask what percentage of accounts are covered; anything short of effectively all of them is treated as a gap.

2. Backups an attacker cannot delete

Offline or immutable, tested by an actual restore in the last twelve months. Modern ransomware crews hunt backups before they encrypt anything, which is why "we have backups" and "we have backups they cannot reach" are priced very differently.

3. Endpoint detection and response

EDR or MDR with someone actually watching the alerts. A tool nobody monitors is a licence, not a control.

4. Data volume and sensitivity

Financial, health and children's data are rated harder than a mailing list. Reducing what you retain is the only lever here — and it is also a DPDP obligation, so it pays twice.

5. Claims and incident history

Five years is the usual look-back. A prior incident is not disqualifying; an unremediated one is.

6. Structure: retention, sub-limits and waiting period

A higher retention lowers premium. So does accepting a longer business interruption waiting period — but if your outages typically run twelve hours, a twelve-hour waiting period buys you a discount on cover you will never collect.

Why the cheapest quote is usually the worst one

Two quotes for ₹5 crore can differ by 40% in price and by far more in what they pay. The gap usually hides in four places: the funds-transfer fraud sub-limit, the business interruption waiting period, whether the regulatory section responds to a Data Protection Board inquiry, and whether cover follows personal data held by your processors.

Compare policies on sub-limits and triggers first, price second. A cheap policy with a ₹25 lakh sub-limit where you needed ₹2 crore is not cheap.

How to run the process well

  1. Fix the free wins first — MFA coverage gaps and backup immutability — then go to market. Quoting before you fix them prices the gap in for a year.
  2. Write a real risk narrative. Underwriters price uncertainty; specifics reduce it.
  3. Go to several insurers at once with the same submission, so terms are genuinely comparable.
  4. Negotiate the structure, not just the number: sub-limits, waiting period, processor extension, regulatory trigger.
  5. Start eight weeks before renewal. Rushed submissions get rushed pricing.

Questions people ask

Is cyber insurance expensive in India compared to other cover?

It is priced on a similar order to professional indemnity for most businesses, roughly 0.4% to 0.9% of the sum insured, and considerably cheaper than the exposure it funds. The premium is usually smaller than a single week of business interruption.

Can we reduce the premium without reducing cover?

Yes, in two ways: improve the controls insurers rate — enforced MFA, immutable and tested backups, monitored EDR — and take a higher retention. Both lower price without touching the limit or the sub-limits that matter.

Want this applied to your business? Send us your record count and your largest customer contract. We will come back with a sized limit and a market quote. Call +91 63070 73633 or use the enquiry form.

Keep reading

More insights

WhatsApp us Call +91 63070 73633