India's Biggest Cyber Attacks (2022–2024): What ₹22 Crore Looks Like in Practice
The IBM figure of ₹22 crore as an "average" breach cost is an abstraction. These are the real incidents that shaped it — and each one is a case study in what cyber insurance would have partially mitigated.
31 million customer records — personal details, medical records, policy data leaked on dark web.
278 GB of sensitive user data exfiltrated. Three separate incidents in a single year.
$230 million stolen in a single hack — one of the largest crypto heists globally.
7.5 million users' PII (2 GB) found on dark web. Customer names, addresses, phone numbers.
40 million patient records compromised. Ransomware shut down hospital operations for weeks.
DPDP Act 2023: India's Penalty Schedule
India's Digital Personal Data Protection Act 2023 is now the primary regulatory framework for data breach liability. Unlike older IT Act provisions, DPDP Act penalties are imposed per violation and can stack — a single incident exposing multiple failures can attract multiple penalty categories simultaneously.
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable security safeguards (leading to a data breach) | ₹250 Crore |
| Failure to notify Data Protection Board + affected individuals of a breach | ₹200 Crore |
| Breach of children's data obligations | ₹200 Crore |
| Significant Data Fiduciary (SDF) non-compliance | ₹150 Crore |
| Other Act/Rules violations | ₹50 Crore |
Source: DPDP Act 2023 Schedule. Penalties are per violation, per inquiry. Enforcement by Data Protection Board of India (DPB).
What Cyber Insurance Covers (and What It Doesn't)
Typically Covered
- Breach investigation & digital forensics
- Mandatory notification costs (CERT-In, DPB, affected individuals)
- Ransomware / cyber extortion payments
- Business interruption & revenue loss
- Data recovery and system restoration
- Legal defence and regulatory fine coverage
- DPDP Act & CERT-In compliance support
- Reputational management & PR costs
Common Exclusions
- Unpatched software / default passwords at breach time
- Social engineering / BEC (usually sub-limited)
- Acts of war or state-sponsored attacks
- Insider fraud by responsible employees
- Pre-existing incidents discovered post-inception
- Pure IT failures unrelated to a cyber attack
- Unencrypted data loss (claim may be denied)
- Non-cyber-related regulatory fines
India Cyber Insurance Costs: What SMBs Are Paying
| Business Profile | Recommended Cover | Annual Premium (India) |
|---|---|---|
| Freelancer / Solo consultant | ₹25 lakh | ₹15,000–₹30,000 |
| Small business (≤50 employees) | ₹1 crore | ₹80,000–₹1,00,000 |
| Mid-size tech / SaaS company | ₹2–5 crore | ₹1,50,000–₹3,00,000 |
| Fintech / Healthcare SMB | ₹5–10 crore | ₹3,00,000–₹8,00,000 |
| Large enterprise / data processor | ₹25 crore+ | Custom underwriting |
Premium ranges are indicative for 2025–26. Actual premiums depend on industry, turnover, security posture, and claims history. Source: Mitigata / insurer data.