1. INTRODUCTION
India’s rapid shift towards a digitally-driven economy has brought tremendous growth but also an unprecedented rise in cyber risks. Ransomware attacks, large-scale data breaches,business interruptions and AI driven cyber operations aimed at essential infrastructure are no longer mere hypothetical as they constitute a daily threats. As organizations face increasing regulatory scrutiny under the Information Technology Act,2000 and Digital Personal Data Protection Act,2023 (DPDP), cybersecurity insurance has emerged as an important weapon to manage risk and financial exposure, also known as “cyber liability insurance”, which is a specialized type of coverage that provides protection to businesses and individuals from financial losses and legal liabilities which occurs due to cyber incidents or attacks like data breaches, malware attacks and cyber extortion.1 It acts as a comprehensive strategy for risk management as a precaution but is not a replacement or a cover for strong cyber security law because the legal and regulatory framework surrounding the cyber insurance in India still remains largely underdeveloped.As of now, the Indian cyber Insurance is operating within a patchwork of legal framework, which involves the IT Act,2000 particularly section 43A and section 79, the DPDP Act,2023 involving strict penalties, IRDAI’s cyber security guidelines and general principles of insurance and contract law shaped by various precedents by Supreme Court and High Court.2 But, at present India has no dedicated statute or IRDAI product standard for cyber insurance and hardly any judicial precedent particularly to cyber insurance disputes and to allocate the liability.
This article argues that India needs an urgent regulatory approach which is coherent for cyber insurance that resolves major unresolved disputes pertaining to -absence of a dedicated regulatory framework, unclear principles of liability allocation and treatment of risks related to AI.
2. UNDERSTANDING CYBER INSURANCE AND CURRENT MARKET PRACTICE
Cyber Insurance is a preventive tool which is designed to guard and mitigate the businesses and private enterprises from potential effects of cyber-attacks. This type of insurance helps to mitigate risk exposure by offsetting costs which happens after a cyber-attacks or data breach after an organization gets hacked or from theft or loss of confidential information.3 It basically includes a combination of first-part cover and third-party cover which includes data restoration, recovery of system, ransom payments and legal costs, damages liability arising out of privacy breaches. In India, such policies are mainly bought by big companies and financial entities, although the market for (Small and Medium enterprises) SME’s and private individuals is still expanding. Even with the increase in cyber incidents , market penetration is low because of the factors like due to limited awareness, inconsistent policy wording and high premiums and lack of standardization as compared to the other establishes insurance line such as marine, fire and life insurance.
With the rapid digital transformation and introduction of enhanced network access and government initiatives like “DIGITAL INDIA”, which considerably expanded the cyber threat surface and this increased digital adoption has resulted in the surge of cyber-attacks which mostly targets sectors like banking, financial services and Insurance (BFSI) to even micro and small businesses.4
3. THE CURRENT LEGAL LANDSCAPE IN INDIA
3.1 Information Technology Act,2000
The Section 43A of the IT Act creates a liability for organization who are handling sensitive personal data if they fail to maintain “reasonable security practices”.5 the accompanying 2011 Rules framed under this section to set minimum technical and organizational measures, which indirectly shapes the cyber law. In practice, these rules influence as to how insurers evaluate the risk.If the company has not followed the expected security standards, insurers may decline coverage or reduce payouts, thereby encouraging stronger cybersecurity norms in the industry.
Similarly, Section 79, grants conditional “safe harbour” protection to intermediaries, subject to due-diligence and compliance with government directions, failure to do so can expose them to significant legal and financial consequences which directly influences underwriting decisions, policy exclusion and premium calculation for cyber insurance products.6
3.2 Digital Personal Data protection Act,2023
The DPDP Act,2023 serves as a major shift in India’s data governance landscape. It has introduced a new regulatory structure which classifies organization as “data fiduciaries” handling personal data information and bounds them under strict duties in order to ensure lawful processing, robust security safeguards and prompt breach notification to both Data Protection Board of India (DPB) and the individuals whose data has been compromised.7This type of regulatory framework significantly raises expectations of the perception of responsible data management and to ensure transparency in the situations of cyber incidents. A specific important provision is chapter 10, which authorizes substantial administrative penalties for violations, The act allows for imposition of fines in cases involving failure to prevent a breach or to notify affected persons and works alongside with customer distrust,damage of reputation leading to litigation This collectively forms a significant layer of regulatory and financial risk for companies functioning in the digital sphere and leads to consideration of cyber insurance as a means to transfer risk.A recent major data breach incident particularly the one involving Star health and Allied Insurance Companies Breach case, wherein the personal information of allegedly ten millions of policyholder is reported to have been compromised and given the potential for severe penalties under the DPDP Act and close examination of security practices, the breach has prompted challenging inquiries regarding accountability, compliance and financial exposure.9 This case basically illustrated the negligence on the side of company under Section 43A of the IT Act and breach notification under the DPDP Act and the potential role of the Data Protection Board. However there remains an ambiguity on the perspective of how cyber-insurance coverage would respond in such a scenario and whether insurers could legally assume liability for regulatory penalties of this large scale.10This gap between the statutory regulation and insurance response is likely to shape the next major gap in India’s cyber -risk landscape, which raises a question on such clarification.
The Insurance Regulatory and Development Authority of India (IRDAI) has also taken significant steps as in 2017 they issued Information and Cyber Security Guidelines (Letter No. IRDA/IT/GDL/MISC/082/-4/2017), which requires the insurers and intermediaries to adopt boards-approved information-security policies and appointment of Chief Information Security officers (CISO) and conduct for regular risk assessments and to report for cyber incidents without delay.11 The detailed requirement was later consolidated and updated through the IRDAI Information and Cyber Security Guidelines,2023 by placing an emphasis on timely incident reporting and strong encryption standards and strict alignment with CERT-In directions.12 Although these guidelines mark a significant advancement in the regulation of insurer’s cyber security, it is crucial to recognize that these are just institution facing measures, they only concentrate on how insurers safeguard their own systems and data, rather than establishing definitions or standards for the structure, content or minimum parameters of the cyber-insurance policies they offer to clients.13 No guidance exists on uniform policy definitions,necessary coverage elements or grow to incorporate DPDP compliance obligations into cyber-insurance wordings. Consequently, insurers have significant flexibility in formulating the terms, exclusions and coverage of these contracts.14This has resulted in considerable inconsistency, uncertainty in cyber-insurance agreement throughout the market and even though IRDAI seeks to secure the insurer themselves but there is an absence of standardized product norms means businesses who are adopting for cyber-insurance may face uncertainty about what their policy actually covers during breaches and attacks.
4. UNRESOLVED ISSUES AND RESEARCH GAPS IN INDIA’S CYBER INSURANCE FRAMEWORK.
4.1 Absence of a Dedicated Cyber -Insurance Regulatory Framework : Despite the fact that cyber risk has emerged as one of the most serious threats to contemporary businesses, India lacks a dedicated statutory or IRDAI-level framework for cyber-insurance as a distinct product category-contrasting with the comprehensive regulatory frameworks in place for other traditional insurance products. The existing IRDAI regulations mainly target general domains like solvency criteria , corporate governance and information security standards. However, these regulations do not provide direct guidance on the drafting of cyber- insurance policies, the minimum coverage they should include or their relationship with statutory liabilities established by the Information Technology Act,2000 and Digital Data Protection Act,2023.15 The absence of regulation has led to a market characterized by fragmentation and inconsistency in practices. Insurers have significantly differing definitions of key terms like “cyber incident”, “data breach”, “system failure” are defined differently in various policies. Also, the approach to regulatory penalties in the DPDP Act and the IT Act is inconsistent: Certain policies exclude all fines, others include “insurable penalties to the extent permitted by law”, and some do not specifying anything, resulting in interpretation during disputes.
4.2 Liability Allocation and Cumulative Liability in Cyber Incidents :Cyber incidents rarely involves only one party who’s responsible. A single data breach may involve the insured organization, its cloud-service provider, software vendors, outsourced IT processors, intermediaries, employees, and even state-linked cyber threat actors. In situations like these, statutory duties listed under Section 43A of the IT Act, contractual indemnity provisions in IT and outsourcing agreements, and DPDP obligations , may all be activated simultaneously.This complex ecosystem raises several unresolved gaps and practical questions that are central to allocating responsibility for losses arising from a cyber incident to the insured organization or corporation..Potential gaps include as to how should the liability be apportioned. Indian courts have consistently tried to establish jurisprudence regarding doctrines related to negligence, contributory negligence, joint and several liability, these doctrines have rarely been applied in cases which involves data breaches or cyber-risk. The legal action taken in the case of Star health data breach, underscores the potential for the concept of concurrent liability wherein, the insurer could be statutorily liable as a data fiduciary, individual officers might incur personal liability like the CISO.However, there is a lack of judicial discourse with regards to how a cyber-insurance policy would react in scenario including multiple actors ,like this, or if insurers could actually engage in recovery of amount by way of subrogation. This gap shows a pressing need for having for clear laws. Also, examinations of principles such as proximate cause, composite negligence, contribution and subrogation should be reinterpreted or adapted in context of cyber insurance products. In order to ensure accountability without diluting the deterrence function of cyber security law.
4.3 AI Driven and Algorithmic Risk: Cyber risk have placed growing importance on the idea that AI systems can serve not just as targets for cyberattacks but also acts as a transmitter that facilitates or increases such attacks. Conventional insurance principles like intention, foreseeability, proximate cause, and the definition of an “occurrence” were formulated with human behavior as their focus.1.1 Cyber-insurance policies typically contain exclusions for intentional wrongdoing by the insured, as well as for acts of war, terrorism, or state-sponsored attacks. Also, can we regard an autonomous AI assault as something which is deliberate, and who has the responsibility to demonstrate whether or not there is state backing? There are no rules on liabilities, specifically for AI in Indian law, either under the IT Act or the DPDPA, and the IRDAI’s guidelines do not address how to manage AI-driven insurance risks. With the growing use of AI systems by organizations and the reliance of attackers on tools powered by AI, there exists a considerable and pressing research gap due to the lack of clear rules.
5. WAY FORWARD AND SUGGESTIONS
To establish a more predictable, transparent, and practical framework for cyber-insurance in India, it is necessary to implement several reforms—policy-based on the research gaps identified. With the rise in prevalence and intricacies of cyber risks, it is essential for the insurance sector, regulatory bodies, and judiciary to collaborate in order to clarify coverage, liability, and claims resolution. The states that these potential actions can lead to a more effective and responsive legal-insurance ecosystem by including cyber context.
5.1 Dedicated cyber insurance guidelines.
The IRDAI needs to adopt dedicated guidelines which are focused towards cyber-insurance products. Nowadays, insurers use a variety of words or terminologies like “data breach”, “network”, “security failure”, “cyber-terrorism”, and “business interruption”, this inconsistency generates a lot of uncertainty during processing of claims. Its better that policyholders have knowledge about what they are actually purchasing.These guidelines can help to put mandatory imposition on insurers to provide clear and proper disclosures on various excluded things, mainly those related to war risks, terrorism, or state-sponsored attacks, as these are frequently the focus of disputes. There needs to be an alignment of the regulatory framework for cyber-insurance with the obligations which are outlined in the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. When the language of policies clearly lays down the legal obligations, therefore ,it removes any uncertainty which might be caused by varied interpretations and upholds culture of compliance, while offering insurers a more proper foundation for evaluation of risk and liability.
5.2 Liability Allocation and Subrogation Based on Clear Principles.
Cyber incidents generally includes in its spectrum various stakeholders which includes cloud service providers, outsourced IT companies, business partners, and customers. In such situations, it becomes difficult to ascertain who bears the actual legal responsibility and how an insurance claim should be allocated properly in order to know the liability. To tackle this challenge, IRDAI can provide for model clauses and regulatory guidance that clarifies the relationship between the provisions of cyber-insurance and contractual indemnity.Also, the regulators shall take into account by establishing rules for contribution, priority of payments to be paid, and subrogation rights of insurers. Moreover, the judicial system can help by giving aid in this field by creating specialized training programs or appointment of judges who can adjust traditional doctrines like proximate cause, ascertaining negligence, and contribution to fit modern cyber contexts with respect to cyber insurance This would assist in and speedier resolution of disputes.
6. CONCLUSION
Cyber-insurance in India is still growing, and at present, it is functions within a fragmented legal framework. Instead of a single regulatory structure, the industry is dependant on a of traditional insurance principles, selective provisions of the IT Act,2000 ,duties established under the DPDP Act ,2023, and wide cyber security guidelines which are provided by the IRDAI. Thus, there is an absence of a dedicated and product-specific framework then it leaves behind several critical gaps.These type of uncertainties present practical issues for both, insurers and policyholders. As India is developing nations and inclining toward a highly digital economy, it creates a requirement for an independent and accessible cyber-risk transfer methods which is vital for enterprises and companies of all kinds, financial institutions, and even people. A proper structured bye-laws for cyber insurance products can increase the prevalence of cyber insurance and promote a responsible way of data governance and promote responsible data governance, and enhance endurance against cyber threats in the nation.
REFERENCES
- Information Technology Act, 2000, No. 21 of 2000 (India).
- Digital Personal Data Protection Act, 2023, No. 22 of 2023 (India).
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India).
- IRDAI, Information and Cyber Security Guidelines, 2017 (Letter No. IRDA/IT/GDL/MISC/082/-4/2017).
- IRDAI, Information and Cyber Security Guidelines, 2023.
- EY, “Cyber insurance in India: From breach recovery to business resilience.”
- Invest India, “Cyber insurance sector fortifying India’s digital economy.”
- Fortinet, “Cyber Insurance” page / cyber glossary entry.
- WTW, “Digital Data Protection Bill: Key provisions, implications and recommendations for India Inc.”
- Cyril Amarchand Mangaldas, “Primer on IRDAI Information and Cyber Security Guidelines, 2023.”
- Himani Doshi, “Cyber Insurance Coverage for Data Protection Fines,” Bimakavach.
- Sanjana Mahesh, “Analytical Study of Insurance Law Regulations in India,” IJLLR (2025).
- Mohd. Salim, “Cyber Insurance and Liability Distribution in India: The Next Frontier,” IJIRL Vol. 5, Iss. 5 (2025).
- K.P. Hemanth Kumar, “Legal Ramifications of Data Breach in light of Star Health and Allied Insurance Breach,” SCC Times (2025).
- Ajoy Roy & Aishani Das, “Insurance, Cross Border Data Breach Disputes: India,” ABLJ (2025).







