AS | Ankit Sarawagi|Founder, CFOmatrix·August 2026·9 min read | Business Insurance |
One phishing email, one leaked database, one ransomware note on a Monday morning, and a startup that thought of security as an engineering line item is suddenly facing forensics bills, angry enterprise customers and a regulator asking questions. Cyber insurance is what turns that into a claim instead of a crisis.
Cyber insurance pays for the cost of a data breach or cyber attack: the response, the recovery, and the claims that follow. For a SaaS, fintech or healthtech startup sitting on customer data, it is one of the covers that most directly matches the risk you actually run, and yet it is one founders most often skip. This guide covers what cyber insurance covers, first-party versus third-party cover, common exclusions, indicative cost, and why the DPDP Act has pushed it up every founder’s list.
- What it is
- Cover for the cost of a data breach or cyber attack, both your own losses and claims from others.
- Who needs it most
- SaaS, fintech and healthtech and anyone holding sensitive or regulated customer data.
- What it covers
- Breach response, data restoration, business interruption, third-party liability, often ransomware and regulatory add-ons.
- Indicative cover
- ₹1 crore to ₹5 crore, scaled to data volume and customer contracts (indicative, not a quote).
- Why it is rising
- Enterprise contracts increasingly require it, and the DPDP Act raises the cost of a breach.
1 What is cyber insurance?
Cyber insurance is a policy that responds when your business suffers a cyber incident: a data breach, a hack, ransomware, a business-email compromise, or the accidental leak of customer information. It covers two very different kinds of cost. The first is your own cost of dealing with the incident. The second is the cost of other people making claims against you because their data or systems were affected.
That is a different risk from the physical world. Fire insurance pays when the office burns; cyber insurance pays when the thing that burns is your data and your customers’ trust. For a modern startup, where the whole business runs on software and the balance sheet is mostly other people’s data, that is often the larger exposure.
A typical cyber policy brings several building blocks together:
- Breach response costs: forensic investigation, legal advice, customer notification and public relations.
- Data and system restoration: rebuilding or recovering data and systems corrupted or locked in an attack.
- Business interruption: lost income while systems are down because of a covered incident.
- Third-party liability: claims from customers, partners or regulators whose data was exposed.
- Cyber extortion / ransomware and regulatory response, often as add-ons rather than automatic inclusions.
2 First-party vs third-party cover
The single most useful distinction in a cyber policy is first-party versus third-party cover. Founders who understand it read quotes far more clearly, because most of the important limits and sub-limits sit on one side or the other.
| Side | What it pays for |
|---|---|
| First-party (your own loss) | Forensic investigation, breach notification and PR, restoring lost or corrupted data and systems, business interruption income loss, and cyber extortion / ransom costs where covered. This is the money you spend to recover. |
| Third-party (claims against you) | Legal defence and settlements when customers, partners or regulators bring claims because their personal data was exposed or a service failed after an attack, including regulatory investigation costs and penalties where insurable. |
A seed-stage company obsessing only over the ransom headline often under-insures the third-party side, which is exactly where a DPDP penalty or an enterprise customer’s claim would land. A good policy carries meaningful limits on both.
3 Who needs it, and why customers now demand it
Cyber insurance is not equally urgent for every business, but the startups it matters most to are exactly the ones building on the internet. As a rough order of priority:
- SaaS: you hold customer data and your product IS the uptime. A breach or outage hits both liability and business interruption.
- Fintech: financial data, payment flows and heavy regulatory scrutiny make both first-party and third-party exposure large.
- Healthtech: health information is among the most sensitive data there is, and a leak carries both reputational and regulatory weight.
- Any startup holding meaningful volumes of personal data, running e-commerce, or dependent on always-on systems.
What increasingly forces the decision is not risk in the abstract, it is the contract on the table. Enterprise customers, especially banks, insurers and large corporates, now routinely require their vendors to carry cyber insurance (and often professional indemnity) at a stated sum insured, and to name it in the master services agreement. The security questionnaire in an enterprise procurement cycle frequently asks for the policy certificate. No cover, no deal.
4 Common exclusions
Cyber insurance is broad, but it is not a blanket. The exclusions are where claims get denied, so read them before you buy, not after an incident. Watch for these in particular:
| Typical exclusion | What it means |
|---|---|
| Poor security hygiene | Claims can be reduced or denied if you failed to apply patches, lacked basic controls, or misrepresented your security posture in the proposal form. |
| Prior / known incidents | Breaches that began, or were known, before the policy started (this is what the retroactive date governs). |
| Insider / fraudulent acts | Deliberate criminal acts by the insured, and often certain insider-caused losses, are excluded or narrowly covered. |
| Fines that are uninsurable | Some penalties cannot legally be insured. Regulatory cover applies only where a fine is insurable under law. |
| Infrastructure & war | Large-scale failures of external infrastructure and war / state-sponsored acts are commonly excluded or limited. |
The practical takeaway is that the policy assumes you are doing the basics. Good security hygiene is not just risk management; it is what keeps your cover valid when you need it.
5 How much cover, and what it costs
There is no single right number. The sum insured should scale with how much data you hold, how sensitive it is, and what your customer contracts require. As an indicative guide only, cyber cover for Indian startups tends to sit in the ₹1 crore to ₹5 crore range, with data-heavy fintech and healthtech companies, or those with large enterprise contracts, needing the higher end or beyond.
Three inputs move the number most:
- Data volume and sensitivity: more records, and more regulated records, mean higher exposure and higher cover.
- Customer contracts: if a master services agreement stipulates a minimum sum insured, that becomes your floor.
- Regulatory exposure: the DPDP regime raises the potential cost of a breach, which feeds into the cover you carry.
Most startups buy cyber cover through an IRDAI-registered broker, including insurtech platforms that bundle cyber alongside D&O and group health and help handle claims. Keep the policy document, schedule and endorsements filed; they get asked for in both enterprise procurement and investor due diligence. Treat every figure here as indicative, not a quote: your actual premium and sum insured depend on your data, controls and contracts.
Brewly starts as a small SaaS ordering platform for cafes, holding a few thousand customer records. At that stage a cyber policy with an indicative sum insured of around ₹1 crore broadly matches its exposure. Brewly signs on a large hotel chain as an enterprise customer, and the master services agreement requires cyber cover of ₹5 crore plus professional indemnity, with the certificate attached before go-live. The contract, not the abstract risk, is what sets Brewly’s real sum insured.
Eighteen months later a misconfigured storage bucket exposes Brewly’s customer database. First-party cover pays the forensics firm and the notification and PR costs; the business-interruption section covers a few days of lost subscription revenue while access is locked down. Then the third-party side does the heavy lifting: two enterprise customers claim under their contracts and, because personal data was exposed, Brewly has DPDP breach-notification duties and a regulatory query. Without cyber insurance, Brewly would have absorbed all of that from cash reserves.
6 The DPDP breach angle
The Digital Personal Data Protection Act, 2023 (DPDP) changes the arithmetic of a breach for Indian startups. It creates duties around protecting personal data and notifying breaches, and it backs those duties with significant financial penalties for failure. In other words, a data breach is no longer only a technical and reputational event; it is a potential regulatory liability with a real number attached.
That matters for cyber insurance in two ways. First, it increases the third-party and regulatory-response exposure the policy is meant to cushion, which pushes sensible sums insured upward. Second, cyber policies increasingly offer regulatory-response cover, helping with the cost of responding to an investigation and, where the penalty is insurable, some of the financial hit. As the DPDP rules bed in, expect enterprise customers and brokers alike to treat cyber cover as standard rather than optional.
7 Your cyber insurance checklist
- Map what personal and sensitive data you hold, and where it lives, so you can size the exposure honestly.
- Check your customer contracts for any required sum insured or named cover, and treat that as your floor.
- Decide the split you need across first-party (breach response, restoration, business interruption) and third-party (liability, regulatory).
- Confirm ransomware and regulatory-response cover are included or added, and read the sub-limits on each section.
- Read the exclusions, especially security-hygiene conditions and the retroactive date, and make sure you can meet them.
- Buy through an IRDAI-registered broker or insurtech platform, and align cyber with your D&O, group health and PI cover.
- Keep the policy schedule, endorsements and certificate filed for enterprise procurement and investor diligence.
- Review the sum insured each year as your data volume, customers and DPDP exposure grow.
Not sure how much cyber cover you actually need?
Use our free Startup Insurance Need Checker: tell it your sector, data and contract situation, and see which covers, including cyber, D&O, group health and professional indemnity, fit your stage.
Check my insurance needs8 FAQs
What does cyber insurance cover for a startup?
Which startups need cyber insurance in India?
What is the difference between first-party and third-party cyber cover?
How much cyber insurance cover does a startup need?
Does the DPDP Act make cyber insurance more important?
Related guides & tools
Business insurance for startups (pillar guide) →
Professional indemnity (E&O) insurance →
Directors & officers (D&O) insurance →
Startup Insurance Need Checker (free tool) →
AS | Founder, CFOmatrix | Finance Strategy & Compliance CFOmatrix helps Indian startups build finance, tax and compliance functions that stand up to investor due diligence, from process and controls to the filings and the numbers behind them. |
Disclaimer: This article is general information as of August 2026 and is not insurance, legal or professional advice. It does not recommend any specific insurer or policy and does not promise that any loss will be covered. Cover, exclusions, sums insured and costs vary and are indicative only. Consult an IRDAI-registered insurance broker before making any decision.