Cyber Insurance for Startups in India: A Guide

Cyber Insurance for Startups in India
HomeInsightsInsurance › Cyber Insurance for Startups in India
Business Insurance
AS
Ankit Sarawagi|Founder, CFOmatrix·August 2026·9 min readBusiness Insurance

One phishing email, one leaked database, one ransomware note on a Monday morning, and a startup that thought of security as an engineering line item is suddenly facing forensics bills, angry enterprise customers and a regulator asking questions. Cyber insurance is what turns that into a claim instead of a crisis.

Cyber insurance pays for the cost of a data breach or cyber attack: the response, the recovery, and the claims that follow. For a SaaS, fintech or healthtech startup sitting on customer data, it is one of the covers that most directly matches the risk you actually run, and yet it is one founders most often skip. This guide covers what cyber insurance covers, first-party versus third-party cover, common exclusions, indicative cost, and why the DPDP Act has pushed it up every founder’s list.

Cyber insurance at a glance
What it is
Cover for the cost of a data breach or cyber attack, both your own losses and claims from others.
Who needs it most
SaaS, fintech and healthtech and anyone holding sensitive or regulated customer data.
What it covers
Breach response, data restoration, business interruption, third-party liability, often ransomware and regulatory add-ons.
Indicative cover
₹1 crore to ₹5 crore, scaled to data volume and customer contracts (indicative, not a quote).
Why it is rising
Enterprise contracts increasingly require it, and the DPDP Act raises the cost of a breach.
₹1-5 crIndicative sum insured, scaled to data
2 sidesFirst-party (your loss) + third-party (claims)
DPDPBreach duties and penalties raise the stakes

1 What is cyber insurance?

Cyber insurance is a policy that responds when your business suffers a cyber incident: a data breach, a hack, ransomware, a business-email compromise, or the accidental leak of customer information. It covers two very different kinds of cost. The first is your own cost of dealing with the incident. The second is the cost of other people making claims against you because their data or systems were affected.

That is a different risk from the physical world. Fire insurance pays when the office burns; cyber insurance pays when the thing that burns is your data and your customers’ trust. For a modern startup, where the whole business runs on software and the balance sheet is mostly other people’s data, that is often the larger exposure.

A typical cyber policy brings several building blocks together:

  • Breach response costs: forensic investigation, legal advice, customer notification and public relations.
  • Data and system restoration: rebuilding or recovering data and systems corrupted or locked in an attack.
  • Business interruption: lost income while systems are down because of a covered incident.
  • Third-party liability: claims from customers, partners or regulators whose data was exposed.
  • Cyber extortion / ransomware and regulatory response, often as add-ons rather than automatic inclusions.
NoteCyber insurance sits alongside, not inside, your other covers. It is separate from professional indemnity (errors & omissions), which responds when your service or software causes a client a financial loss, and from D&O, which protects directors. Many startups need more than one.

2 First-party vs third-party cover

The single most useful distinction in a cyber policy is first-party versus third-party cover. Founders who understand it read quotes far more clearly, because most of the important limits and sub-limits sit on one side or the other.

SideWhat it pays for
First-party (your own loss)Forensic investigation, breach notification and PR, restoring lost or corrupted data and systems, business interruption income loss, and cyber extortion / ransom costs where covered. This is the money you spend to recover.
Third-party (claims against you)Legal defence and settlements when customers, partners or regulators bring claims because their personal data was exposed or a service failed after an attack, including regulatory investigation costs and penalties where insurable.

A seed-stage company obsessing only over the ransom headline often under-insures the third-party side, which is exactly where a DPDP penalty or an enterprise customer’s claim would land. A good policy carries meaningful limits on both.

TipRead the sub-limits, not just the headline sum insured. A policy can advertise ₹5 crore but cap business interruption or regulatory-response cover at a much smaller figure. Match the sub-limits to your real exposure, not the biggest number on page one.

3 Who needs it, and why customers now demand it

Cyber insurance is not equally urgent for every business, but the startups it matters most to are exactly the ones building on the internet. As a rough order of priority:

  • SaaS: you hold customer data and your product IS the uptime. A breach or outage hits both liability and business interruption.
  • Fintech: financial data, payment flows and heavy regulatory scrutiny make both first-party and third-party exposure large.
  • Healthtech: health information is among the most sensitive data there is, and a leak carries both reputational and regulatory weight.
  • Any startup holding meaningful volumes of personal data, running e-commerce, or dependent on always-on systems.

What increasingly forces the decision is not risk in the abstract, it is the contract on the table. Enterprise customers, especially banks, insurers and large corporates, now routinely require their vendors to carry cyber insurance (and often professional indemnity) at a stated sum insured, and to name it in the master services agreement. The security questionnaire in an enterprise procurement cycle frequently asks for the policy certificate. No cover, no deal.

Watch outFounders systematically under-buy cyber insurance. It is one of the covers most startups get wrong by simply not taking it, alongside proper medical and general liability cover. The gap usually surfaces at the worst possible time: mid-breach, or mid-negotiation with an enterprise customer who wants the certificate before signing.

4 Common exclusions

Cyber insurance is broad, but it is not a blanket. The exclusions are where claims get denied, so read them before you buy, not after an incident. Watch for these in particular:

Typical exclusionWhat it means
Poor security hygieneClaims can be reduced or denied if you failed to apply patches, lacked basic controls, or misrepresented your security posture in the proposal form.
Prior / known incidentsBreaches that began, or were known, before the policy started (this is what the retroactive date governs).
Insider / fraudulent actsDeliberate criminal acts by the insured, and often certain insider-caused losses, are excluded or narrowly covered.
Fines that are uninsurableSome penalties cannot legally be insured. Regulatory cover applies only where a fine is insurable under law.
Infrastructure & warLarge-scale failures of external infrastructure and war / state-sponsored acts are commonly excluded or limited.

The practical takeaway is that the policy assumes you are doing the basics. Good security hygiene is not just risk management; it is what keeps your cover valid when you need it.

5 How much cover, and what it costs

There is no single right number. The sum insured should scale with how much data you hold, how sensitive it is, and what your customer contracts require. As an indicative guide only, cyber cover for Indian startups tends to sit in the ₹1 crore to ₹5 crore range, with data-heavy fintech and healthtech companies, or those with large enterprise contracts, needing the higher end or beyond.

Three inputs move the number most:

  • Data volume and sensitivity: more records, and more regulated records, mean higher exposure and higher cover.
  • Customer contracts: if a master services agreement stipulates a minimum sum insured, that becomes your floor.
  • Regulatory exposure: the DPDP regime raises the potential cost of a breach, which feeds into the cover you carry.

Most startups buy cyber cover through an IRDAI-registered broker, including insurtech platforms that bundle cyber alongside D&O and group health and help handle claims. Keep the policy document, schedule and endorsements filed; they get asked for in both enterprise procurement and investor due diligence. Treat every figure here as indicative, not a quote: your actual premium and sum insured depend on your data, controls and contracts.

Example

Brewly starts as a small SaaS ordering platform for cafes, holding a few thousand customer records. At that stage a cyber policy with an indicative sum insured of around ₹1 crore broadly matches its exposure. Brewly signs on a large hotel chain as an enterprise customer, and the master services agreement requires cyber cover of ₹5 crore plus professional indemnity, with the certificate attached before go-live. The contract, not the abstract risk, is what sets Brewly’s real sum insured.

Example

Eighteen months later a misconfigured storage bucket exposes Brewly’s customer database. First-party cover pays the forensics firm and the notification and PR costs; the business-interruption section covers a few days of lost subscription revenue while access is locked down. Then the third-party side does the heavy lifting: two enterprise customers claim under their contracts and, because personal data was exposed, Brewly has DPDP breach-notification duties and a regulatory query. Without cyber insurance, Brewly would have absorbed all of that from cash reserves.

CFO lensCyber insurance is one of the covers I most often see founders skip, and it is usually a false economy. The trigger to buy is rarely fear; it is the first serious enterprise contract, which will demand it in writing. Buy it through an IRDAI-registered broker, size it to your data and your biggest contract, and keep the certificate handy, because enterprise procurement and diligence both ask for it. This is business-driven cover, set by your customers and your data, not by your investors.
Founders insure the office long before they insure the data, and the data is the business. Cyber cover is the one policy that matches how a modern startup actually loses money.

6 The DPDP breach angle

The Digital Personal Data Protection Act, 2023 (DPDP) changes the arithmetic of a breach for Indian startups. It creates duties around protecting personal data and notifying breaches, and it backs those duties with significant financial penalties for failure. In other words, a data breach is no longer only a technical and reputational event; it is a potential regulatory liability with a real number attached.

That matters for cyber insurance in two ways. First, it increases the third-party and regulatory-response exposure the policy is meant to cushion, which pushes sensible sums insured upward. Second, cyber policies increasingly offer regulatory-response cover, helping with the cost of responding to an investigation and, where the penalty is insurable, some of the financial hit. As the DPDP rules bed in, expect enterprise customers and brokers alike to treat cyber cover as standard rather than optional.

NoteInsurance does not replace compliance. Cyber cover helps you respond to and recover from a breach; it does not discharge your DPDP obligations to secure data and notify breaches. Do both: get the controls right and carry cover for when they are tested. For where cyber fits among your other policies, see the business insurance for startups pillar guide.

7 Your cyber insurance checklist

  1. Map what personal and sensitive data you hold, and where it lives, so you can size the exposure honestly.
  2. Check your customer contracts for any required sum insured or named cover, and treat that as your floor.
  3. Decide the split you need across first-party (breach response, restoration, business interruption) and third-party (liability, regulatory).
  4. Confirm ransomware and regulatory-response cover are included or added, and read the sub-limits on each section.
  5. Read the exclusions, especially security-hygiene conditions and the retroactive date, and make sure you can meet them.
  6. Buy through an IRDAI-registered broker or insurtech platform, and align cyber with your D&O, group health and PI cover.
  7. Keep the policy schedule, endorsements and certificate filed for enterprise procurement and investor diligence.
  8. Review the sum insured each year as your data volume, customers and DPDP exposure grow.

Not sure how much cyber cover you actually need?

Use our free Startup Insurance Need Checker: tell it your sector, data and contract situation, and see which covers, including cyber, D&O, group health and professional indemnity, fit your stage.

Check my insurance needs

8 FAQs

What does cyber insurance cover for a startup?

Cyber insurance covers the cost of a data breach or cyber attack. On the first-party side it pays for breach response (forensics, legal, notification, PR), data restoration, and business interruption when systems are down. On the third-party side it pays claims and defence costs when customers, partners or regulators come after you because their data was exposed. Many policies also offer ransomware and regulatory cover as add-ons.

Which startups need cyber insurance in India?

Any startup that holds customer data or runs its business on software should consider it, but it matters most for SaaS, fintech and healthtech companies because they store large volumes of sensitive or regulated data. Enterprise customers increasingly make cyber cover a contractual requirement, so a signed enterprise deal is often what forces the purchase.

What is the difference between first-party and third-party cyber cover?

First-party cover pays for your own losses after an incident: forensic investigation, restoring data and systems, business interruption, extortion and breach-notification costs. Third-party cover pays claims made against you by others, such as customers whose data leaked, partners, or regulators, including legal defence and settlements or penalties where insurable.

How much cyber insurance cover does a startup need?

There is no fixed number. Indicative sums insured run from around ₹1 crore to ₹5 crore, scaled to how much data you hold and what your customer contracts require. A seed-stage SaaS with a few thousand users sits at the lower end; a fintech or healthtech with regulated data and enterprise contracts often needs the higher end or more. These are indicative ranges, not quotes.

Does the DPDP Act make cyber insurance more important?

Yes. The Digital Personal Data Protection Act, 2023 introduces breach-notification duties and significant financial penalties for failing to protect personal data. That raises the cost of a breach for Indian startups, and cyber policies increasingly offer regulatory-response cover, so the DPDP regime is a big reason founders are moving cyber insurance from nice-to-have to needed.
Sources: Digital Personal Data Protection Act, 2023; IRDAI framework for insurers and insurance brokers; standard market wordings for cyber / data-protection insurance (first-party, third-party, business interruption and regulatory-response sections). Covers, sub-limits and exclusions vary by insurer and policy; indicative sums insured and cost ranges are general guidance as of August 2026 and are not quotes. Confirm terms with an IRDAI-registered broker before buying.
AS
Founder, CFOmatrix  |  Finance Strategy & Compliance

CFOmatrix helps Indian startups build finance, tax and compliance functions that stand up to investor due diligence, from process and controls to the filings and the numbers behind them.

Disclaimer: This article is general information as of August 2026 and is not insurance, legal or professional advice. It does not recommend any specific insurer or policy and does not promise that any loss will be covered. Cover, exclusions, sums insured and costs vary and are indicative only. Consult an IRDAI-registered insurance broker before making any decision.

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

Insights

More Related Articles

D&O Insurance for Startups in India: A Guide

Employees’ Compensation Insurance in India (WC)

Group Health Insurance for Startups in India