Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Home/ Insights/Claims
Claims

Anatomy of a ransomware claim: the 22 days that cost more than the ransom

Published 8 July 2026 · 9 min read · DPDP Insurance India

What follows is a composite. It is not one client's claim; it is the shape most mid-market Indian ransomware claims take, assembled so you can see where the money goes. If you have never sat through one, the surprising thing is how little of the loss is the ransom.

The nine quiet days

It starts in accounts payable. An invoice attachment, a macro, a credential harvested. Nothing visible happens. For the next nine days the intruder moves laterally, finds the domain admin account that still has no second factor, reads the backup configuration, and quietly deletes the retention policy on the cloud backup vault.

This period is where the loss is actually created. Every hour of undetected access widens the scope of the eventual forensic investigation, which is billed by the hour, and increases the volume of personal data that must be assumed compromised.

The morning everything stops

At 02:40 the encryption runs. By the time the first shift arrives, file servers are gone, the ERP will not start and there is a note demanding payment. Production halts. Dispatch halts. The finance team cannot raise invoices.

The first decision of the day is the most valuable one in the whole claim: someone calls the number on the policy rather than starting to rebuild. That call engages the insurer's incident response panel — forensics, privacy counsel, a negotiator — before the office has finished filling up. It also protects the claim, because unilateral action taken before the insurer is notified is the most common reason cyber claims get reduced.

If you take one thing from this piece: do not wipe machines, do not pay anyone, and do not tell the market before you have spoken to your insurer. Preserve logs. All three instincts are natural and all three cost money.

Two clocks start at once

The operational clock is obvious: every hour offline is revenue not booked. The regulatory clock is quieter and less forgiving. Once you become aware of a personal data breach you must inform the Data Protection Board without delay, and then notify every affected data principal — in plain language, describing the breach, the data involved, what they can do to protect themselves, and how to reach you — within 72 hours of the Board notification.

Meeting that clock requires knowing what was taken, which requires forensics, which takes days. This is the tension every incident lives inside, and it is why a rehearsed notification runbook is worth more than most security tooling on the day.

Where the money went

LineShare of the claimNote
Business interruptionLargest single lineEleven days of halted production and dispatch, claimed after a twelve-hour waiting period
Forensics and restorationSecondResponse firm, rebuild, overtime, temporary infrastructure
Legal, notification and PRThirdPrivacy counsel, Board notification, notices to data principals, customer questions
RansomFourthNegotiated down substantially; paid only with insurer consent after a lawfulness check
UninsuredOngoingInfrastructure the company chose to upgrade, and management time nobody bills for

That ordering is remarkably stable across claims. Businesses buy cyber insurance thinking about the ransom and end up claiming mostly for the fortnight they could not trade.

Four lessons from the loss run

  1. The waiting period is a real number. Twelve hours off an eleven-day outage is a rounding error; twelve hours off a fourteen-hour outage is almost the whole claim. Know yours.
  2. Immutable backups shorten everything. The single control that most reduces both the loss and the premium.
  3. Notification is an operation. Draft the templates and decide who signs before you need them.
  4. Call before you act. Wiping the first infected machine destroys the evidence that scopes the breach — and the scope is what determines who you have to notify.

None of this argues that insurance replaces security. It argues the opposite: the controls that make a claim survivable are the same ones that make it cheaper to insure. See what a cyber policy covers, or how the premium is calculated.

Questions people ask

Should we pay a ransom?

That decision belongs to the insurer, a negotiator and counsel together, and it depends on whether paying is lawful in the circumstances and whether decryption is even likely to work. Paying before notifying your insurer will usually cost you the claim.

How long does a cyber claim take to settle in India?

Response costs are typically funded as they are incurred. Business interruption takes longer because it needs a forensic accountant to establish lost gross profit, so a full settlement in the region of four to six months is common for a mid-market claim.

Want this applied to your business? Send us your record count and your largest customer contract. We will come back with a sized limit and a market quote. Call +91 63070 73633 or use the enquiry form.

Keep reading

More insights

WhatsApp us Call +91 63070 73633