Introduction
A cyberattack can create several losses at the same time: stolen data, business interruption, ransom demands, regulatory exposure, investigation costs and reputational damage. Cyber insurance has emerged to address some of these risks, but a policy does not guarantee payment after every cyber incident.
One increasingly important question is whether the insured maintained the cybersecurity standards required by the policy.
When Security Becomes a Coverage Issue
A cyber policy may contain conditions concerning security controls, access management, authentication or incident reporting. If an insurer alleges that the policyholder failed to comply with such requirements, the dispute can move beyond the question of whether a cyberattack occurred.
The issue becomes whether the insured's conduct affected coverage under the contract.
India's Regulatory Environment
Cybersecurity is also becoming an increasingly important regulatory concern for insurers themselves. IRDAI has issued information and cybersecurity requirements for insurers and continues to update its cyber-incident preparedness framework.
Conclusion
Cyber insurance is not simply a financial product. It is increasingly becoming part of a company's wider cybersecurity strategy. Businesses should therefore understand both the coverage and the security obligations attached to the policy.