Cyber & D&O liability insurance
Rytvae Consulting · Insurance placed through IRDAI-regulated partners · Banashankari, Bengaluru
Two exposures that leave no physical trace and are now routinely demanded by investors and clients. Why the wording matters more than the limit, and what claims-made cover means when you switch insurer or wind up.
Two liabilities that did not exist a generation ago
Traditional insurance covers things you can see: a building burning, a machine failing, a worker injured. Two significant modern exposures leave no physical trace at all.
Cyber liability responds when systems are attacked or data is lost. The driver is not only that ransomware has become an industrialised business, but that India now has a statutory data protection framework with real consequences attached to mishandling personal data.
Directors and officers liability responds when someone alleges that a management decision was wrongful. The Companies Act, 2013 substantially expanded directors’ duties and personal exposure, including for independent directors in defined circumstances, and claims can come from shareholders, regulators, employees, creditors or customers.
What links them is that both are claims-made covers, and both are now routinely demanded by counterparties rather than chosen voluntarily.
Incident response
Forensic investigation, containment and specialist support in the hours after a breach is discovered.
Business interruption
Lost income while systems are down, subject to a waiting period before cover begins.
Data restoration
The cost of rebuilding or recovering data and systems, as distinct from upgrading them.
Privacy liability
Third party claims and regulatory investigation costs arising from a breach of personal data.
D&O Side A
Cover for directors personally where the company cannot or will not indemnify them — including in insolvency.
D&O Sides B & C
Reimbursement to the company for indemnifying directors, and cover for entity securities claims.
Cyber: the wording matters far more than the limit
Cyber policies vary more than almost any other class, and a headline sum insured tells you very little. The things that determine whether a policy actually responds:
- The business interruption waiting period. If cover begins only after a stated number of hours, and most incidents are resolved within that window, the section may rarely pay.
- Social engineering and funds transfer fraud. Where an employee is deceived into authorising a payment, many policies exclude this entirely or sub-limit it sharply. Given how common the attack is in Indian businesses, this is worth asking about specifically.
- Dependent business interruption. If your operations stop because a cloud provider or key supplier is attacked rather than you, is that covered?
- Betterment. Policies pay to restore systems, not to improve them. Where recovery inevitably involves an upgrade, the split can be contentious.
- Extortion. Whether ransom payments are covered depends on the wording and on the legal position at the time, which is not static.
- Prior known circumstances. Anything you were aware of before inception is excluded, which is why the proposal form is answered carefully.
Underwriting has also tightened considerably. Insurers now assess controls seriously — multi-factor authentication, backup regime and recovery testing, patching discipline, endpoint protection and privileged access management. A business that cannot answer these questions may find cover expensive or unavailable, and improving the controls often costs less than the premium loading for not having them.
On the regulatory side, two obligations sit alongside any policy. CERT-In directions require reporting of specified cyber incidents within a short window and retention of logs for a defined period. The Digital Personal Data Protection Act, 2023 creates obligations for entities handling personal data, with financial consequences for failures, and implementation has been phased. Neither is discharged by holding insurance — but a good policy funds the response that compliance requires.
D&O: what it covers and why it is now routine
D&O responds to claims alleging a wrongful act in the management of the company — mismanagement, misstatement, breach of duty, failure of oversight. It pays defence costs, settlements and awards.
The structure has three parts. Side A protects directors personally where the company cannot indemnify them, which is exactly the position in insolvency — the point at which directors are most exposed and the company least able to help. Side B reimburses the company when it does indemnify. Side C covers the entity itself for securities claims.
It has stopped being a large-company product. Institutional investors and venture funds now commonly require D&O as a condition of investment, and experienced independent directors increasingly decline board seats at companies that do not carry it. What it does not cover is equally worth knowing: bodily injury and property damage sit under liability and property policies, and deliberate dishonesty or personal profit is excluded once established, though defence costs are typically advanced until then.
Employment practices liability — claims of wrongful dismissal, discrimination or harassment — is sometimes bundled and sometimes separate. Check which, because it is a frequent source of claims.
Claims-made: the feature that catches people out
Both covers respond to claims first made against you during the policy period, not to acts committed during it. Three consequences follow:
The retroactive date determines how far back prior acts are covered. A policy with a retroactive date equal to inception covers nothing that happened before you bought it. A gap in cover can therefore leave years of past work unprotected, and changing insurer without preserving the retroactive date quietly discards that history.
Run-off cover matters when you stop trading, sell the business, or a director retires. Claims can surface years later, and without run-off there is no policy to respond.
Notification discipline. Circumstances that might give rise to a claim must be notified within the policy period, even before a formal claim exists. Late notification is a common and avoidable reason for declinature.
How Rytvae helps
We compare these covers on wording rather than premium, flag the exclusions that matter for your particular exposure, and place cover through our IRDAI-regulated partners. See the full corporate and group insurance guide, and marine and contractors all risk for transit and project exposures.
Frequently asked questions
What does cyber insurance cover?
First party costs — incident response and forensics, business interruption while systems are down, data and system restoration, notification and reputational management — and third party liability arising from a data breach, including regulatory investigation costs and penalties where insurable.
Does cyber insurance cover ransomware?
A properly structured policy typically covers incident response, business interruption, data restoration and breach liability. Whether ransom payments themselves are covered depends on the wording and on the legal position at the time, which is not static.
Is social engineering fraud covered?
Often not, or only with a sharp sub-limit. Where an employee is deceived into authorising a payment, many policies exclude it entirely. Given how common this attack is in Indian businesses, ask about it specifically rather than assuming.
What is dependent business interruption?
Cover for losses when your operations stop because a cloud provider or key supplier is attacked rather than you. It is not always included, and for businesses heavily dependent on external platforms it is one of the more important extensions.
Why is my insurer asking about multi-factor authentication?
Because underwriting has tightened considerably. Insurers assess MFA, backup and recovery testing, patching discipline, endpoint protection and privileged access management. Improving these controls often costs less than the premium loading for not having them.
Does insurance discharge my obligations under CERT-In or the DPDP Act?
No. CERT-In directions require reporting of specified incidents within a short window and retention of logs for a defined period, and the Digital Personal Data Protection Act, 2023 creates obligations with financial consequences for failures. A policy funds the response; it does not replace compliance.
What does D&O insurance cover?
Claims alleging a wrongful act in the management of the company — mismanagement, misstatement, breach of duty or failure of oversight — covering defence costs, settlements and awards. Claims can come from shareholders, regulators, employees, creditors or customers.
What are Sides A, B and C in a D&O policy?
Side A protects directors personally where the company cannot indemnify them, which is the position in insolvency. Side B reimburses the company when it does indemnify. Side C covers the entity itself for securities claims.
Does a small private company need D&O?
It has stopped being a large-company product. Institutional investors and venture funds commonly require it as a condition of investment, and experienced independent directors increasingly decline board seats at companies without it.
What does D&O not cover?
Bodily injury and property damage, which sit under liability and property policies, and deliberate dishonesty or personal profit once established — though defence costs are typically advanced until that point. Employment practices claims may be bundled or separate, so check which.
What does claims-made mean?
The policy responds to claims first made against you during the policy period, not to acts committed during it. So a gap in cover can leave years of past work unprotected, and the retroactive date determines how far back prior acts are covered.
What is run-off cover and when do I need it?
Cover that continues to respond after you stop trading, sell the business, or a director retires. Claims can surface years later, and without run-off there is no policy to answer them. It is arranged at the point of exit, not afterwards.
Compare these covers on wording, not premium
Waiting periods, social engineering and retroactive dates decide whether the policy responds at all.
Rytvae Consulting — AMFI Registered Mutual Fund Distributor (ARN-265474), EUIN E091320. Rytvae Consulting is a distributor of mutual fund and insurance products and is not a SEBI-registered Investment Adviser. Any assistance offered is incidental to distribution.
Insurance is the subject matter of solicitation. Cover, exclusions, limits and conditions differ between insurers and are governed entirely by the policy wording issued to you — read it before you rely on it. This page is general information, not advice on any specific policy or business, and not legal advice. Rytvae Consulting distributes insurance through IRDAI-regulated partners.
See our full disclosures and disclaimers.
