Incident response and forensics
The specialist firm that works out what happened, what left, and how to close the door. Triggered by a phone call, billed by the hour, and the first cost you will face.
When ransomware lands, the ransom is rarely the biggest number. The forensics, the rebuild and the weeks of lost output are. Cyber insurance funds all of it, and puts a response team on your side within the hour.
A cyber policy is not one cover, it is a bundle. These are the sections worth arguing over at placement, because each carries its own limit and its own conditions.
The specialist firm that works out what happened, what left, and how to close the door. Triggered by a phone call, billed by the hour, and the first cost you will face.
Rebuilding servers, restoring from backups, re-creating data that cannot be restored. Covers the overtime and the vendors, not the hardware upgrade you were already planning.
Lost gross profit while you are down, plus the extra expense of working around it. Subject to a waiting period, usually 8 to 12 hours. Frequently the largest single line in the claim.
Negotiators, cryptocurrency handling and the ransom itself where it is lawful to pay and the insurer consents. The value is in the negotiation team, who routinely take demands down substantially.
The invoice that was not really from your vendor. Almost always sub-limited well below the policy limit, so read this number rather than the headline one.
Defending a Data Protection Board inquiry, drafting notifications, and the privacy claims that follow. This is where the cyber section hands over to the DPDP and privacy sections.
A composite built from the pattern Indian mid-market claims follow. Illustrative, not a specific client — but the shape is depressingly consistent.
A finance laptop opens an invoice attachment. Nothing appears to happen.
Backups are quietly deleted. The attacker has had nine days inside the network.
File servers encrypt. ERP is gone. Production stops. A note demands payment in bitcoin.
You call the number on your policy. The insurer's response panel is engaged before the office opens.
Forensics scopes the breach. Legal assesses whether personal data was taken. You are still not shipping.
Board notification is filed. Within 72 hours, notices go to every affected data principal.
Systems restored from an offline backup. Business interruption is claimed from hour 12 onward.
Claim settles. Downtime, not the ransom, was the biggest line on the loss run.
The lesson underwriters keep repeating. The nine quiet days are where the loss is made. Immutable backups and enforced MFA would have shortened this claim by two weeks — and they are also the two controls that most move your premium.
Same incident, three separate bills. Most businesses end up with all three sections on one policy; the useful thing is knowing which section is doing the paying.
| DPDP | Cyber (this page) | Data privacy | |
|---|---|---|---|
| Answers to | The regulator | Your own losses | Other people's claims |
| Typical trigger | A Data Protection Board notice or inquiry | Systems encrypted, hacked or down | A customer, employee or client alleges their data was mishandled |
| Pays for | Legal defence, representation, insurable penalties | Forensics, restoration, downtime, extortion | Damages, settlements, notification, credit monitoring |
| Biggest number | Penalty exposure up to ₹250 crore | Business interruption | Class-style claims and enterprise contract liability |
| You need it if | You are a data fiduciary — which is almost everyone | A day offline hurts | You hold personal data belonging to people who can sue you |
| Business profile | Records held | Common sum insured | What usually drives it |
|---|---|---|---|
| Early-stage SaaS, 10–50 staff | Under 1 lakh | ₹1–2 crore | Enterprise customer contracts specifying a minimum limit |
| Growth-stage D2C or edtech | 1–10 lakh | ₹5 crore | Notification cost at scale plus downtime on peak trading days |
| Fintech or lending platform | 10 lakh–1 crore | ₹10–25 crore | Regulated data, higher per-record cost, DPDP penalty exposure |
| Mid-market manufacturer | Low, but OT-dependent | ₹5–15 crore | Business interruption on a plant that stops when the network does |
| Listed or large enterprise | Over 1 crore | ₹25 crore and above, often layered | Aggregate exposure, board expectation, contractual indemnities |
Bands reflect what we see requested in the Indian market. Yours will move with your contracts, sector and claims history — treat this as a starting conversation, not a recommendation.
An Indian cyber policy typically pays for incident response and forensics, restoration of data and systems, business interruption while you are down, cyber extortion including ransom handling where lawful, funds-transfer fraud on a sub-limit, breach notification costs, crisis PR, third-party privacy liability and the legal costs of a regulatory inquiry. What varies wildly between insurers is the sub-limits, the business interruption waiting period and how the regulatory section is worded.
As a rough planning figure, small and mid-market Indian businesses pay in the region of 0.4% to 0.9% of the sum insured each year, so ₹5 crore of cover often lands somewhere between ₹2.5 lakh and ₹4.5 lakh. Strong controls — enforced MFA, immutable backups, EDR, tested recovery — move you toward the bottom of the range. A prior claim or a regulated sector moves you up.
The number of hours your systems must be down before cover starts counting, usually 8 to 12. It matters more than most buyers realise: a 12-hour waiting period on an outage that lasts 14 hours means you are claiming for two hours. We negotiate this line specifically.
Most Indian wordings cover extortion costs including the ransom, but only where paying is lawful and only with the insurer's prior consent. Pay first and you will usually have no claim. In practice the money that matters is the negotiation, forensics and restoration around the payment, not the payment itself.
Good wordings extend to personal data you are responsible for even when it sits with a processor. Weak ones do not. If you run on third-party cloud, payroll or CRM providers, this extension is worth more than an extra crore of limit.
MFA on email and remote access, backup frequency and whether backups are offline or immutable, endpoint detection, patching cadence, logging retention, employee phishing training, incident response plan, past incidents in the last five years, and your data volumes. Answer them accurately — the proposal form is the document a claims team reads first.
Send your data volumes, control stack and any enterprise contract that specifies a limit. We take it to the Indian cyber market and come back with comparable terms, sub-limits marked.