Cyber Insurance Coverage
What a cyber insurance policy covers: the split between first-party and third-party covers, the claims-made basis, how fines and penalties are treated, and why the kind of data involved matters.
What cyber insurance is for
A cyber incident rarely damages anything that can be seen. The loss arrives as bills for investigators, lost income while systems are down, and claims from the people whose data was exposed. Cyber insurance protects businesses and individuals against financial loss from such incidents: data breaches, ransomware attacks and business interruption caused by a cyber event.
First-party and third-party covers
A policy usually has two families of cover. First-party covers pay the insured's own costs. These include data breach response and forensic investigation, data restoration, breach notification and lost income during the interruption.
Third-party covers deal with what the insured owes to others. They include privacy liability and network security liability to customers and other parties, and the cost of defending regulatory proceedings. The test is simple: a cost the business itself incurs is first-party; a claim or proceeding brought against the business is third-party.
Regulatory fines and penalties sit on the third-party side, but with a qualification. They are covered only where the law allows them to be insured and the policy wording provides for it. Neither condition can be assumed.
The basis of cover
The liability covers in a cyber policy are written on a claims-made basis, as in professional indemnity insurance. The claim must be first made against the insured during the policy period and notified as the policy requires; any retroactive date or prior-knowledge terms in the policy can also limit cover for earlier breaches.
The first-party covers work differently. They are triggered when the incident is discovered during the policy period.
Insurers also expect basic cyber hygiene to be maintained. Forensics, ransomware response and business interruption are core covers, but loss flowing from known critical vulnerabilities left unpatched is treated differently: some policies exclude it and others restrict it through conditions or sub-limits. Which applies depends on the policy.
Why the type of data matters
Not all data is equal. Health records are sensitive personal data or information under the 2011 rules made under the Information Technology Act, 2000, and a breach of medical data is treated as especially serious because of the harm it can do to the people concerned.
The Digital Personal Data Protection Act, 2023 (DPDP Act) does not create a separate sensitive category. Under it, however, the type of data involved is one of the factors in fixing a penalty. The DPDP Act's main duties and penalties are not yet in force; until they are, section 43A of the IT Act and the 2011 rules remain the operative regime.
Rules at a glance
Sorting the bills after a breach
Illustration: a diagnostic laboratory in Kochi finds that patient reports have been copied from its server. It hires forensic investigators, restores its data from back-ups and writes to the affected patients; these are its own costs and fall under the first-party covers. Some patients then claim compensation, and a regulator opens proceedings; the liability and the cost of defending the proceedings fall under the third-party covers. If a penalty is finally imposed, whether the policy pays it depends on whether the law allows it to be insured and on the wording.
Key points
- Cyber insurance covers financial loss from data breaches, ransomware and business interruption caused by a cyber event.
- First-party covers pay the insured's own costs, such as forensics, data restoration, notification and lost income.
- Third-party covers respond to liability to others and the cost of defending regulatory proceedings.
- Fines and penalties are covered only where the law allows them to be insured and the wording provides for it.
- Liability covers are claims-made; first-party covers are triggered by discovery of the incident in the policy period.
- Health records are sensitive personal data under the 2011 rules, and the type of data is a factor in fixing a DPDP Act penalty.
Common misunderstandings
- A cyber policy is not only a liability policy: it also pays the insured's own costs through the first-party covers.
- Claims-made turns mainly on when the claim is first made and notified, which for the liability covers must be in the policy period; any retroactive date and prior-knowledge terms in the policy still matter.
- Fines are not automatically covered: both the law and the wording must allow it.
- The DPDP Act has not created a sensitive-data category: that label comes from the 2011 rules, though the type of data still counts when a DPDP penalty is fixed.
Questions people ask
Is forensic investigation a first-party or third-party cover?
First-party. It is a direct cost incurred by the insured business in responding to the breach.
What triggers the business interruption cover?
It is a first-party cover, so it is triggered when the incident is discovered during the policy period, subject to the policy's own terms.
Will the policy respond if a known critical vulnerability was left unpatched?
It depends on the policy. Some exclude such loss and others restrict it through conditions or sub-limits, because insurers expect basic cyber hygiene to be maintained.
What this lesson relies on
- Cyber insurance policy wording — first-party and third-party insuring clauses, claims-made and discovery triggers
- Information Technology Act, 2000 — section 43A, and the 2011 rules on sensitive personal data or information
- Digital Personal Data Protection Act, 2023
This lesson was reviewed independently against these sources on 8 October 2026. Rules change: check the current regulation, scheme document or policy wording before relying on any figure. This is education, not advice.

