Lesson 5 of 5 · Cyber Insurance

Cyber Insurance Case Studies

Three illustrative scenarios, an insider taking data, an attack through a trusted vendor and a claim larger than the policy limit, used to show what a cyber policy responds to and where it stops.

Fact-checked 8 October 20264 practice questions in the game

How to read these scenarios

The scenarios in this lesson are examples for learning, not accounts of particular companies. Each one is used to ask the same three questions: what triggers the cover, where an exclusion or a limit bites, and who ends up bearing which part of the loss.

The insider who takes data

Suppose an employee of an edtech company copies its user database and takes it to a competitor. The company faces several kinds of loss at once. It must investigate what was taken, notify the users, defend claims from them and answer any regulatory proceedings.

Cyber policies respond to these direct costs of a breach: forensics, notification, legal defence and regulatory proceedings, subject to the policy terms and exclusions, including any on dishonest acts by employees. The loss a cyber policy is least likely to cover is the revenue lost as students move to the competitor. That is a commercial loss, not a standard cyber cover. The company may suffer it because of the breach, but the policy is not built to make good a loss of market share.

The attack that arrives through a vendor

A supply chain attack exploits a trusted relationship. Malware delivered through a legitimate vendor update or data link bypasses normal security, because the victim has authorised the vendor's access. The danger lies in that trust: the malware spreads through legitimate channels and is not treated as a threat.

For insurance purposes the victim's own costs and liabilities are looked at under its own cyber policy. If the vendor's negligence caused the breach, the insurer, after paying the claim, may pursue recovery from the vendor by subrogation, and the insured must cooperate.

When the claim is larger than the limit

A policy limit is the most the insurer will pay. If a company with a ₹5 crore cyber policy faces ₹10 crore in third-party claims, the insurer pays up to ₹5 crore and the company bears the remaining ₹5 crore. The insurer's liability is capped at the limit, whatever the size of the loss.

This is why the adequacy of the limit matters, and why excess or umbrella cyber liability cover exists as a further layer above the primary policy.

A breach also has a public side. PR crisis management is a first-party cover under cyber insurance: the insurer provides access to professional crisis communication firms to manage media, customer communication and public statements after a breach.

Rules at a glance

Policy limitThe insurer pays up to the limit; the excess is borne by the insuredCyber policy wording
Revenue lost to a competitorCommercial loss; not a standard cyber coverCyber policy scope
PR crisis managementFirst-party coverCyber policy wording
Illustration

A payroll vendor's update

Illustration: a garment exporter in Bengaluru uses an outside payroll software vendor. One month the vendor's routine update carries malware, and because the update comes through the vendor's authorised connection the exporter's security tools let it through. Employee records are copied. The exporter's forensic, notification and crisis-communication costs are first-party costs under its cyber policy, and employees' claims are looked at under the third-party covers, all subject to the policy terms and limit. If the investigation shows the vendor was negligent, the insurer may later seek recovery from the vendor.

Worked example

Who pays what when claims exceed the limit

  1. Assumptions, for arithmetic only: policy limit ₹5,00,00,000; third-party claims totalling ₹10,00,00,000, all within the scope of the policy; no other cover in place.
  2. Insurer pays the lower of the claims and the limit = ₹5,00,00,000.
  3. Amount borne by the company = ₹10,00,00,000 − ₹5,00,00,000 = ₹5,00,00,000.
  4. If the company had also held an assumed excess layer of ₹3,00,00,000 above the primary policy, the two policies together would pay ₹5,00,00,000 + ₹3,00,00,000 = ₹8,00,00,000, and the company would bear ₹10,00,00,000 − ₹8,00,00,000 = ₹2,00,00,000.

Result. With only the ₹5,00,00,000 policy, the company bears ₹5,00,00,000 of the ₹10,00,00,000 claims. With the assumed ₹3,00,00,000 excess layer it would bear ₹2,00,00,000.

Key points

  • Cyber policies respond to the direct costs of a breach: forensics, notification, legal defence and regulatory proceedings.
  • Revenue lost because customers move to a competitor is a commercial loss and not a standard cyber cover.
  • Supply chain attacks are dangerous because malware arrives through a trusted vendor's authorised access.
  • The insurer's liability is capped at the policy limit; the insured bears any amount above it.
  • PR crisis management after a breach is a first-party cover.

Common misunderstandings

  • A cyber policy does not make good every consequence of a breach: lost customers and market share are commercial losses outside standard cover.
  • The policy limit is not a guide to the likely loss: it is a cap, and anything above it stays with the insured.
  • A trusted vendor is not a safe channel by definition: supply chain attacks work because the vendor's access is authorised.
  • Crisis communication is not a liability cover: it is a first-party cover for the insured's own response.

Questions people ask

Are these scenarios real cases?

No. They are illustrative examples for learning and do not describe particular companies.

In the insider scenario, which costs does a cyber policy respond to?

The direct costs of the breach: forensics, notification, legal defence and regulatory proceedings, subject to the policy terms.

What is excess or umbrella cyber liability cover?

A further layer of cover above the primary policy's limit, relevant where claims could exceed that limit.

What this lesson relies on

  • Cyber insurance policy wording — first-party and third-party covers, limit of liability, crisis management cover, subrogation condition

This lesson was reviewed independently against these sources on 8 October 2026. Rules change: check the current regulation, scheme document or policy wording before relying on any figure. This is education, not advice.

Free learning from the Trustner Group. Trustner Academy is an education initiative of the Trustner Group, whose companies work across insurance broking and investment services, with offices in Bangalore, Guwahati, Kolkata, Hyderabad and Mumbai. Everything here is for learning only — it is not advice, a recommendation or an offer of any product. Scenarios are illustrative. Rules and figures change; check the current regulation, scheme document or policy wording before acting on anything.