Programme Economics·~16 min read·3,614 words

Cyber insurance economics: what the policy actually covers, what it doesn't, and how the post-incident premium math worksPremium

Practitioner reference for CISOs, CFOs, risk managers, and the executive sitting opposite an insurance broker with a renewal quote that doubled · 2026-05-24 · Written from twelve years of being either the buyer, the underwriter-interview subject, or the consultant called after a claim got disputed


Why cyber insurance is the security investment that confuses everybody

The cyber insurance market is the one part of the security ecosystem where the pricing is fully visible and the value is genuinely unclear. Companies pay premiums that have tripled in three years for coverage that increasingly excludes the things they actually worry about, and the people who buy the policies often do not understand what they have bought until they try to claim against it.

I want to lay out the economics honestly. What the policy actually covers. What the exclusions mean in practice. How underwriting has shifted in the last five years. How premiums escalate after an incident. How the questionnaires that underpin pricing actually work. And what I tell CFOs when they ask whether the policy is worth the money.

This is not insurance advice. I am not a broker. I have just been on the buyer side of too many cyber insurance conversations and on the response side of too many incidents where the question “is this covered?” had a complicated answer.


The market, in brief

The global cyber insurance market crossed roughly $16 billion in gross written premium in 2024 and is on track to be near $20-25 billion by the end of 2026. Indian cyber insurance is a much smaller market — around ₹2,500-3,500 crore in 2025 — but is growing at 25-35% year on year, faster than any other line of business insurance in India.

Two waves shaped the current state of the market. The 2019-2021 ransomware wave drove a hard market — premium increases of 50-200%, capacity tightening, exclusions broadening. Then a brief soft cycle in 2023-2024 as new capacity came in. The 2025 ransomware resurgence and the rise of AI-related fraud and supply-chain compromise tightened the market again; premiums rose 15-30% in 2025-26 for clean accounts and much more for accounts with recent claims.

Six insurers carry most of the relevant capacity globally: Coalition, At-Bay, Beazley, Chubb, Munich Re, AIG. In India the carriers writing cyber are largely the major general insurers (HDFC ERGO, Bajaj Allianz, Tata AIG, ICICI Lombard, New India Assurance) with capacity reinsured globally. The questionnaires they use are converging on a common set of controls; the underwriting differences are mainly in pricing model and claims philosophy.


What a cyber policy actually covers

A typical cyber insurance policy is structured as a bundle of separate coverages, each with its own sub-limit, deductible, and conditions. The standard bundle:

First-party coverages — your losses:

  • Business interruption. Lost revenue and extra expense from a covered cyber event causing system downtime. Usually subject to a waiting period (8-12 hours typical) before coverage starts. Capped per incident and per period.

  • Data restoration. Cost to restore or recreate data lost or corrupted by a covered event. Often capped at much lower limits than the headline policy limit because insurers do not want to pay to rebuild your data warehouse from scratch.

  • Cyber extortion / ransomware. Ransom payments and associated negotiation and response costs. Increasingly capped or co-insured (you bear 25-50% of the loss); some policies are excluding ransomware entirely for accounts that cannot demonstrate strong backup and segmentation controls.

  • Forensics and incident response. Cost of external forensics, incident response firms, and IT remediation. Usually covered subject to using a panel firm pre-approved by the insurer.

  • Notification and credit monitoring. Cost of notifying affected individuals and providing credit monitoring or identity protection services. Particularly relevant for breaches involving personal data.

  • Public relations and crisis management. Cost of communications support during an incident.

Third-party coverages — claims against you:

  • Privacy liability. Defence and settlement costs for claims by individuals or regulators for breaches of personal data. This is the biggest single coverage line in most policies, and the one that DPDPA will materially expand demand for.

  • Network security liability. Defence and settlement for claims by other companies that suffered loss because of your security failure (you spread malware to them, your compromised systems were used to attack them).

  • Regulatory defence and penalties. Defence costs for regulatory inquiries and, where insurable, the fines themselves. DPDPA penalties may or may not be insurable depending on Indian law and policy wording; GDPR penalties are explicitly not insurable in many EU jurisdictions; US state breach fines vary.

  • Media liability. Defence for claims arising from content you publish that infringes IP, defames, or violates privacy.

  • Payment Card Industry (PCI) costs. Card brand assessments, fines, forensic audits, and reissuance costs if your environment is the source of a card data breach.

Some policies also include cyber crime cover — usually a separate sub-limit, often as low as ₹1-5 crore, covering social engineering fraud and funds transfer fraud. The sub-limit is small precisely because this is the coverage most often claimed against; insurers protect themselves by capping it.

The total policy limit (the aggregate cap) is the upper bound across all of this. Sub-limits within the policy mean that the ransomware sub-limit might be only 25-50% of the aggregate, the cyber crime sub-limit might be 5-10%, and the data restoration sub-limit might be 10-20%. The headline number is not the number you can actually claim for any single type of loss.


What is excluded

This is where most disputes happen. The headline policy lists exclusions; the policy language defines what they actually mean; the claims handling tests them in practice. The exclusions you need to read carefully:

1. Acts of war and state-sponsored attacks. This is the most contested exclusion in modern cyber insurance. After the NotPetya incident in 2017 (which Merck eventually litigated and won against its insurer, but the litigation took six years), insurers have tightened war exclusions to cover state-sponsored cyber operations. The trouble is that attribution is uncertain in cyber, and many ransomware groups have loose state affiliations. If your incident gets attributed to a state actor — even speculatively — the insurer may invoke the war exclusion. Some policies now define attribution standards explicitly; read them carefully.

2. Failure to maintain stated security controls. Most policies require you to maintain the security controls you declared on the questionnaire. If you said “we have MFA on all email accounts” and the breach happened because the CFO did not have MFA on email, the insurer will dispute coverage. The questionnaire is not paperwork — it is the foundation of the contract. Misrepresentations are the most common reason claims get denied.

3. Prior known vulnerabilities or incidents. If you knew about a vulnerability and did not patch it, or had a prior breach you did not disclose, the insurer will exclude losses arising from it. The “knew about” test is harsher than you might think — if the vulnerability was on your scanner output for six months, you knew about it.

4. Bodily injury and property damage. Standard cyber policies exclude these; they belong on general liability and property policies. This matters as IoT and OT cyber incidents increasingly cause physical consequences.

5. Contractual liability. Defence and indemnity for contractual obligations you assumed (e.g. master services agreements requiring you to indemnify customers for breaches) are often excluded or sub-limited. This is a critical exclusion for B2B SaaS companies whose customer contracts include unlimited indemnity clauses.

6. Insider acts (rogue employee). Some policies exclude losses arising from intentional acts by your employees. Others cover them but exclude the acts of executives. Read the definition carefully.

7. Patent and trade secret. IP litigation is usually excluded; intellectual property claims belong on IP-specific policies.

8. Reputational harm. Loss of customers, market value, future revenue arising from reputational harm is usually excluded as too speculative. Some policies provide narrow “reputational recovery” sub-limits for PR and brand-rebuilding costs, but the consequential business loss from a damaged reputation is uninsurable.

9. Specific named events. Some policies exclude losses from specific publicly known incidents (e.g. SolarWinds, Log4Shell) for a defined exclusion period. These named exclusions can dramatically narrow coverage at renewal.

10. Failure to comply with applicable law. A loose exclusion that can be invoked surprisingly often. If your incident involved violation of any law — privacy, sectoral regulation, IT Act — the insurer may exclude coverage. This is more common in policies written by Indian carriers; international carriers have tightened the language but it varies.

If you are buying or renewing, get a coverage comparison from your broker that itemises exclusions across the alternatives. Two policies with identical aggregate limits can have radically different effective coverage depending on the exclusion suite.


The underwriting questionnaire — how it actually works

The questionnaire is the foundation of both pricing and claims handling. The major insurers’ questionnaires converge on roughly 40-80 questions covering:

  • Identity and access (MFA coverage, privileged access management, joiner-leaver process, periodic access reviews)
  • Endpoint and email security (EDR/AV coverage, email security gateway, phishing training cadence)
  • Network and infrastructure (segmentation, remote access, RDP exposure, firewalls)
  • Vulnerability management (scanning cadence, patch SLA, last penetration test)
  • Backup and recovery (backup frequency, offline/immutable backups, restoration testing)
  • Incident response (plan exists, tested, retainer in place, breach notification procedure)
  • Third-party risk (vendor inventory, due diligence process, critical vendor security)
  • Data and privacy (data classification, encryption at rest and in transit, customer data inventory)
  • Compliance and certifications (SOC 2, ISO 27001, sectoral regulatory compliance)
  • Claims history (any cyber incidents in the last 3-5 years)

The questionnaire has hardened materially over the last three years. Five years ago “we have antivirus” was a sufficient answer; today the insurer wants EDR deployment percentages, mean time to patch metrics, and evidence of phishing simulation results. Many accounts get effectively non-renewable not because they have had claims but because they cannot answer the questionnaire honestly to meet the current bar.

The MFA question is the most consequential. Almost every major carrier now requires MFA on all privileged access, all remote access, and all email access as a condition of coverage. Accounts that cannot certify this are either declined or written with severe sub-limits. If you are buying cyber insurance and have any holdout systems without MFA, fix that before the application; the cost of fixing MFA is dramatically lower than the cost of being uninsurable.

The honest filling-in of the questionnaire is the single most important risk-management decision. Companies that mis-state controls — sometimes innocently, often through optimistic interpretation — set up coverage disputes that surface during the worst possible moment. I have seen claims of ₹15-30 crore denied because of MFA mis-statement on the application.


The premium math — what drives the number

Premiums are quoted as an annual amount for a defined limit and deductible. The pricing model is roughly:

Base rate × revenue × industry factor × control adjustment × claims history × limit factor × deductible factor

The base rate for a clean account with good controls in 2026 is roughly:

Revenue band (₹) Aggregate limit Typical annual premium (₹) Premium per crore of revenue (₹)
Up to 100 crore 5 crore 6-15 lakh 6,000-15,000
100-500 crore 10 crore 15-35 lakh 3,000-7,000
500-1,500 crore 25 crore 40-90 lakh 2,500-6,000
1,500-5,000 crore 50 crore 1.2-2.5 crore 2,400-5,000
5,000+ crore 100+ crore 2.5-7 crore+ varies

These are rough order of magnitude for an Indian buyer with reasonable controls and no recent claims. Real pricing varies significantly with industry (financial services and healthcare are higher; manufacturing and traditional retail are lower), control posture (a fully mature programme can be 30-50% under these numbers; a programme with known gaps can be 50-150% over them), and prior claims.

The factors that move the number most:

  • MFA completeness. A clean MFA story can take 20-30% off the premium versus an uncertain one.
  • Backup and immutability. Immutable, segregated backup capability is now a major price differentiator post-ransomware-wave.
  • Vendor risk maturity. Insurers increasingly underwrite supply chain risk; a strong third-party risk programme reduces premium.
  • Industry. Healthcare, financial services, technology, and government carry higher rates. Manufacturing and traditional retail carry lower rates.
  • Geography. US business carries higher rates; pure-Indian-market business carries lower rates. International exposure increases premium.
  • Revenue concentration. Higher concentration in big customers (more concentrated revenue, more contractual indemnity exposure) increases premium.

The deductible is the amount you bear before the policy responds. Deductibles have risen materially — typical 2026 deductibles are ₹50 lakh to ₹2 crore for mid-market and 5-25 crore for large enterprise. Higher deductibles reduce premium significantly; this is the largest dial you control.


Post-incident premium escalation — the math nobody wants to do

This is the part of cyber insurance economics that most CFOs do not fully appreciate until they are living through it.

When you have a claim, your renewal pricing changes. Insurers price prospectively on expected losses, and a claim is signal that expected losses are higher. The typical pattern:

  • Year 0: Incident. Claim filed.
  • Year 1 renewal: Premium up 50-150% if the claim was material. Deductible may also increase. Some carriers may decline to renew.
  • Year 2 renewal: If no further incidents, premium decreases but typically remains 25-50% above pre-incident baseline.
  • Year 3 renewal: Continued normalisation; many accounts return close to pre-incident pricing in year 3-4.
  • Year 4-5: The incident largely drops out of the underwriting consideration (most questionnaires ask about the last 3-5 years).

A material incident also typically triggers a re-underwriting deep dive. The next renewal involves a more thorough questionnaire, often a third-party validation of the controls (security ratings from a service like BitSight or SecurityScorecard, or an actual external security review), and may include policy conditions you did not have before — for example, mandatory adoption of specific controls within defined timelines.

If you have a second incident within the same 3-5 year window, the dynamics get harder. You may find yourself in the secondary market — markets that take risks the primary carriers will not. Pricing in the secondary market is 2-4x primary market pricing for equivalent coverage, and exclusions tend to be broader.

The implication for capital planning: if you carry a serious cyber programme, the cost of a single major incident is materially larger than the loss itself. The loss is what the insurer pays minus the deductible. The cost is the loss plus 3-5 years of elevated premiums plus the discount in any future M&A transaction where the disclosed incident factors into diligence.

For an Indian mid-market company, a major ransomware incident with ₹15 crore in direct losses might generate ₹8-12 crore in insurance recovery, leave you with ₹3-7 crore of bearing-cost, and add ₹15-40 crore in cumulative premium over five years versus a clean track record. The true cost of the incident, capitalised, can easily exceed ₹50 crore. The insurance pays for part of it; the company pays the rest of it through the future premium curve.


Where the policy actually pays

Insurance economics is fundamentally about the variance, not the mean. The honest accounting on whether cyber insurance is worth it depends on what you are trying to insure against.

Where the policy clearly pays:

  1. Catastrophic incidents. A ₹50 crore ransomware recovery, a ₹100 crore privacy class action, a ₹40 crore regulatory penalty. These are the events that the policy is best designed for.

  2. Forensics and incident response. The first 30-90 days of incident response can cost ₹2-10 crore in external services. The policy panels are pre-negotiated; the cost goes to the insurer with a manageable deductible.

  3. Notification at scale. Notifying 500,000 individuals after a breach costs real money. The policy covers it.

  4. Regulatory defence. Defending against DPBI, state AGs (US), DPAs (EU), CFPB, FTC, or sectoral regulators carries large legal fees regardless of outcome. The policy covers defence costs.

Where the policy pays less than you would hope:

  1. Small incidents under the deductible. Phishing leading to ₹50-200 lakh in wire fraud often falls entirely within the deductible. You bear it.

  2. Business interruption from cloud provider outages. Most policies exclude failures of cloud providers themselves (because you have no contractual leverage). If AWS goes down for two days and your service is unavailable, the policy will often dispute coverage.

  3. Reputational and customer-loss consequences. Speculative future losses are uninsurable.

  4. Litigation that drags on. Insurers prefer fast settlements; if your case requires multi-year defence the conditions may pressure you to settle on terms you might otherwise reject.

  5. Cross-border incidents. A breach involving EU data subjects from an Indian-domiciled policy may face coverage disputes around governing law, regulatory cooperation, and notification procedures.

The honest CFO conversation:

Cyber insurance is not a substitute for security investment. It is a tail-risk hedge for the catastrophic scenario you cannot fully prevent. The economics work for most mid-market and large companies; for very small companies the premium-to-coverage ratio is often unfavourable and the deductible swallows realistic claims.

The right framing is: assume the policy will pay 50-80% of a catastrophic incident’s direct costs, assume future-year premium escalation will recover 30-50% of that benefit, and ask whether the net protection against the catastrophic scenario is worth the cumulative premium. For most regulated, customer-facing, or data-intensive Indian companies the answer is yes; for low-data manufacturers and traditional businesses it is closer.


The DPDPA-specific considerations

DPDPA materially changes the underwriting picture for Indian companies. A few specifics:

1. Coverage of DPDPA penalties. Whether DPDPA penalties are insurable in India is not fully settled. Penalties for criminal acts or for gross negligence are generally uninsurable as a matter of public policy. Regulatory civil penalties are sometimes insurable; it depends on the wording. Most policies marketed in India explicitly exclude criminal penalties and may exclude civil penalties unless specifically extended. Read the policy language; do not assume DPDPA penalties are covered.

2. The independent Data Audit cost. Rule 13 of the DPDP Rules 2025 requires SDFs to engage an independent Data Auditor. This is an annual cost (₹25 lakh - 2 crore depending on size). Some policies are starting to offer “compliance audit cost coverage” as a sub-limit; useful but small relative to the operational cost.

3. The DPBI inquiry cost. Defending against a DPBI inquiry requires legal representation, evidence production, and potentially expert testimony. Costs can run ₹50 lakh - 5 crore for a serious inquiry. Cyber policy regulatory defence cover typically responds; verify the trigger language includes Indian privacy regulator inquiries explicitly.

4. The Data Principal class action exposure. DPDPA does not create a statutory class action right, but the DPBI’s mediation function may aggregate claims, and Indian consumer protection litigation may layer on top. The privacy liability sub-limit is the relevant coverage; ensure it is sized for the potential aggregation scenario.

5. The pre-loss compliance scrutiny. Insurers underwriting Indian risks now ask explicitly about DPDPA readiness — DPO appointment (for SDFs or likely SDFs), consent mechanism, breach notification procedure, Data Principal rights workflows. Accounts that cannot demonstrate readiness will face premium loading and possible exclusions.

The Indian cyber insurance market is still adjusting to DPDPA enforcement. Expect pricing volatility through 2027 as carriers see the first wave of DPBI claims and recalibrate.


What I tell CFOs when they ask “is it worth it”

Three sentences:

Yes, if the catastrophic scenario would damage the business materially and you cannot fully prevent it. For most mid-market and large companies that handle customer data, run regulated activities, or have significant digital revenue, this is the case.

Buy the right policy with eyes open about what it covers. Read the exclusions. Validate the questionnaire responses. Size the sub-limits to the realistic loss profile, not the headline aggregate. Understand the deductible. Negotiate the carrier-panel forensics and IR firms.

Treat the policy as a hedge, not a strategy. The security programme is what prevents the incident. The policy is what funds the response. A weak security programme cannot be replaced by an expensive policy; underwriters know this and price accordingly.


What this guide does not cover

Three areas worth their own treatment:

  1. Specific carrier comparisons. I have deliberately not ranked individual insurers because pricing, claims philosophy, and panel quality vary engagement to engagement and change over time. Get current quotes from at least three carriers and compare apples to apples on coverage, exclusions, sub-limits, and deductibles.

  2. The captive insurance discussion. Large companies sometimes establish captive insurance structures to retain cyber risk economically. The economics work for very specific profiles; for most companies the regulatory and capital overhead makes it impractical.

  3. The growing tension between cyber insurance and sanctions. As governments restrict ransomware payments and impose sanctions on payment routes, the legal structure of cyber extortion coverage is shifting. This is moving fast and warrants its own treatment.


This is a practitioner reference, not insurance advice. It reflects the cyber insurance market as of May 2026 and the DPDP Rules 2025 as notified 13 November 2025. Specific coverage decisions should be made with a qualified broker and counsel review of policy language. Indian buyers should also validate Indian-law insurability of regulatory penalties with counsel before relying on those coverage lines.

ControlForge maps the security controls underwriters test for during cyber insurance underwriting against ISO 27001, SOC 2, NIST CSF, RBI CSF, SEBI CSCRF, and DPDPA — surfacing the strictest-clause synthesis that satisfies both audit and insurance questionnaires from a single control programme.