Expert SpeakYoung Voices
Published on Sep 07, 2026
India has built a strong cybersecurity architecture, but its insurance framework has lagged behind. Closing the gap will require better data, cyber-hygiene incentives, and public support for catastrophic risks.
On 31 August 2025, a single intrusion into Jaguar Land Rover’s (JLR) Information Technology (IT) systems halted production at Britain’s largest carmaker for five weeks. The United Kingdom’s (UK) Cyber Monitoring Centre modelled the financial impact at £1.9 billion, affecting more than 5,000 supply chain businesses, and judged it the most economically damaging cyberattack in British history. Weeks later, the Bank of England named the disruption as one reason UK growth slowed. Jaguar Land Rover’s India-based parent, Tata Motors, bore that cost directly: JLR booked £260 million in exceptional charges across two quarters after the attack, without any cyber insurance in place to absorb it. This is a reminder that cyber risk now crosses borders as easily as capital does.
As attacks grow more frequent and sophisticated, cybersecurity needs to be treated as an economic and national resilience challenge, not merely a technical one.
Much of the global conversation on cybersecurity still centres on prevention: firewalls, audits, patch cycles. Recovery receives less attention, even though it decides whether an attack stays contained or leaves lasting damage. As attacks grow more frequent and sophisticated, cybersecurity needs to be treated as an economic and national resilience challenge, not merely a technical one. Cyber insurance, still a niche product across much of the world, is becoming central to that resilience. India’s cybersecurity strategy has yet to catch up.
Cybersecurity Is Becoming an Economic Problem
Munich Re, a leading reinsurer, estimates global cyber insurance premiums totalled nearly US$15 billion in 2025 and could reach US$28 billion by 2030. The World Economic Forum (WEF) finds that 94 percent of leaders expect artificial intelligence (AI) to be this year’s biggest driver of change in cybersecurity, while fewer than 45 percent of private sector chief executive officers (CEOs) are confident their country could respond to a critical infrastructure attack. This gap between rising cyber risk and preparedness looks like a market failure, but government-backed insurance, not private cover alone, can close it.
Artificial intelligence is shifting cybercrime economics toward attackers, automating reconnaissance, phishing, and vulnerability discovery faster than any human team, while driving down attack costs and multiplying reach across thousands of targets.This makes cyber risk harder to price using claims history alone, so continuous pricing is becoming indispensable to resilience, not just a post-incident exercise.
Artificial intelligence is shifting cybercrime economics toward attackers, automating reconnaissance, phishing, and vulnerability discovery faster than any human team, while driving down attack costs and multiplying reach across thousands of targets.
Ransomware remains the costliest single driver of loss, which Munich Re ranks as the leading cause of cyber insurance losses. Business interruption and third-party dependence now determine how far damage spreads, as JLR showed — though whether this was ransomware at all remains disputed. Most of its loss came not from stolen data but from halted production and thousands of smaller suppliers left unpaid, creating a chain reaction that no single firm could contain. When one incident can dent a country’s growth figures, cyber risk becomes a matter of economic governance, requiring the attention of finance ministries, central banks, and regulators.
The Rise of Cyber Insurance
Cyber insurance covers an incident’s direct and indirect costs: business interruption, data recovery, extortion payments, and post-breach crisis management. The Organisation for Economic Co-operation and Development (OECD) argues that cyber insurance, while no substitute for cybersecurity investment, strengthens risk management by pricing exposure, sharing expertise and encouraging prevention.
Cyber risk also breaks conventional insurance’s core assumption: that risks are independent and can be priced against decades of stable data. Cyber losses are instead highly correlated. A single vulnerable software product or cloud platform can trigger simultaneous claims across thousands of policyholders. This correlated, hard-to-price risk is why cyber insurance behaves like an immature market, drawing governments in not to replace insurers but to underwrite what private capital cannot: reliable data and cover for catastrophic loss. Munich Re puts the industry’s accumulation exposure for a 1-in-200-year event at US$ 20–46 billion, showing how unsettled that pricing still is.
Within that narrower space, insurers are no longer passive payers of claims. Underwriting has become a lever for raising cybersecurity standards economy-wide: insurers assess multi-factor authentication, endpoint protection, patching, and backup practices before pricing a policy. Those meeting recognised standards pay less; those that don’t often go uncovered. This discipline functions as a private regulator, reaching firms regulators rarely visit, and shifts insurance from compensating loss to shaping prevention — giving insurers a strategic role beyond their commercial function.
Global Lessons
Several jurisdictions now treat cyber insurance as part of national cyber resilience, not merely as a private-sector product.
The first lesson is that governments can shape insurance markets, turning underwriting into a hygiene lever no regulator could match. In the UK, insurers discount premiums for firms certified under the National Cyber Security Centre’s Cyber Essentials scheme, and smaller certified firms automatically qualify for cover. Singapore’s Cyber Security Agency further negotiates discounted premiums for certified firms while co-funding up to 70 percent of small firms’ certification costs.
The second is that insurers can only price what they can measure, so mandated reporting matters as much as mandated defence. The European Union’s (EU) NIS2 Directive requires risk management and incident reporting across 18 critical sectors, creating auditable loss data that thin, fast-dating models otherwise lack.
The third is that catastrophic risk exceeds what private capital can carry alone. A 2022 study by the United States’ Government Accountability Office found that losses from one catastrophic attack on US infrastructure could range from US$2.8 billion to US$1 trillion, and recommended the Cybersecurity and Infrastructure Security Agency and Treasury Department jointly assess a federal backstop. The US has not built one but now treats catastrophic cyber risk as public finance.
None of these governments treat cyber insurance as separate from cybersecurity policy. All three approaches reinforce one another.
India’s Missing Piece
India illustrates the paradox this creates. Its cybersecurity architecture is broadly aligned with these approaches, yet almost none of the mechanisms that make insurance work elsewhere, such as certification-linked pricing, mandated data and catastrophic risk planning, have been built into the system.
The capability side is real. The Indian Computer Emergency Response Team (CERT-In) handled more than 2.9 million cyber incidents in 2025, has empanelled 231 audit organisations, runs sectoral response teams, and publishes cyber defence controls for micro, small and medium enterprises (MSMEs). The National Critical Information Infrastructure Protection Centre safeguards critical systems, and the Reserve Bank of India (RBI) requires banks and non-bank finance companies to have Board-approved IT and cybersecurity policies.
The Insurance Regulatory and Development Authority of India (IRDAI) has studied cyber liability insurance since 2020, recommending simpler wording, but without a UK- or Singapore-style link between certification and pricing, adoption stays concentrated among large banks and technology firms, leaving MSMEs largely uninsured. Nor is there a pooled incident dataset like NIS2 provides in Europe, so underwriters price against foreign, not domestic, loss experience.
The insurance side has not kept pace. The Insurance Regulatory and Development Authority of India (IRDAI) has studied cyber liability insurance since 2020, recommending simpler wording, but without a UK- or Singapore-style link between certification and pricing, adoption stays concentrated among large banks and technology firms, leaving MSMEs largely uninsured. Nor is there a pooled incident dataset like NIS2 provides in Europe, so underwriters price against foreign, not domestic, loss experience. The Digital Personal Data Protection Rules add penalties of up to INR 200 crore for mishandled breaches, a gap insurance could bridge before 2027.
Coordination has improved on paper. The National Security Council Secretariat (NSCS) was designated in 2024 as the nodal agency for overall coordination and strategic direction on cybersecurity, with the National Cyber Security Coordinator (NCSC) serving as the nodal point of contact, but India has yet to publish a strategy naming insurance as part of resilience planning, as the UK, Singapore and the US now do through certification-linked pricing and catastrophic-risk planning.
The Way Forward
Closing this gap means building on what already exists, not starting anew.
- Building a Domestic Data Backbone: Indian insurers price cyber risk against foreign loss experience, since domestic loss experience is limited, and against threat data that goes stale within months. Two fixes address both gaps: a national cyber risk database pooling anonymised loss data from the Indian Computer Emergency Response Team (CERT-In), sectoral computer security incident response teams (CSIRTs) and insurers; and structured intelligence-sharing among the same three actors, so underwriting adjusts as fast as threats evolve.
- Premiums Tied to Cyber Hygiene: Insurers should discount premiums for firms meeting recognised security standards, as UK insurers do for Cyber Essentials-certified firms. Indian firms have little reason to invest in stronger defences while certification and pricing remain unlinked.
- Extending Cover to MSMEs: Certification and insurance remain two separate costs few MSMEs can bear, so adoption stays concentrated among large firms. Singapore’s co-funded certification model helps, but subsidising certification alone may not be enough: MSMEs are the high-risk, low-margin segment an undercapitalised market has least incentive to underwrite. Public risk-sharing or reinsurance support will likely be needed as well.
- A National Strategy That Names Insurance: The National Security Council Secretariat (NSCS) has had no strategy to execute its 2024 mandate. India needs one that names insurance as a resilience tool, assigns responsibility to the NSCS and Insurance Regulatory and Development Authority of India (IRDAI), and directs the catastrophic-risk assessment the United States Government Accountability Office (GAO) recommended, since JLR shows India is exposed too.
None of these steps requires new institutions — just the ones India already has, working together.
Conclusion
Cyber resilience has always demanded technical defence. It now demands economic preparedness too: absorbing a shock, keeping suppliers paid, and restoring operations before an incident turns macroeconomic.Britain learned that lesson at a cost approaching £2 billion. India, with its fast-digitising small-enterprise base, cannot afford to learn it the same way.
Cyber resilience has always demanded technical defence. It now demands economic preparedness too: absorbing a shock, keeping suppliers paid, and restoring operations before an incident turns macroeconomic.
Cyber insurance won’t stop the next attack. But priced on domestic data, extended to the MSMEs CERT-In advises, and backed once losses turn catastrophic, it stops being a compliance afterthought. It becomes what its economics always pointed toward: strategic infrastructure for national resilience, deserving the same attention as the power grid it protects.
Sairah Zahooris a Research Intern at the Observer Research Foundation.
The views expressed above belong to the author(s). ORF research and analyses now available on Telegram! Click here to access our curated content — blogs, longforms and interviews.