Products

Cyber Insurance

The money you lose online, and the cost of putting your name back together

Protection · Digital Risk

Cyber Insurance

Personal cyber insurance covers financial loss from online fraud, identity theft, phishing and cyber extortion, together with the legal costs of dealing with the aftermath.

As banking, shopping and identity moved onto phones, the loss moved with them. A cyber policy treats a compromised account or a stolen identity as an insurable event rather than as bad luck.

It sits alongside the Reserve Bank of India's framework on unauthorised electronic transactions rather than replacing it — and the gap it fills is largest where you were deceived into authorising the payment yourself.

Illustrative growth
Modular Sections Type
Type
Modular Sections
Scope
Personal, Worldwide
RBI Reporting
3 Working Days
Cover
Loss + Legal
Risk ProfileVery Low
The basics

What is personal cyber insurance?

Cover for financial loss caused by online fraud, identity theft, phishing and cyber extortion — together with the legal costs of dealing with the aftermath.

As banking, shopping and identity moved onto phones, the loss moved with them. A personal cyber policy is the response: it treats a compromised account or a stolen identity as an insurable event rather than as bad luck.

In plain terms: it covers the money you lose online, and the cost of putting your name back together afterwards.

What a cyber policy actually does

  • Reimburses money lost to unauthorised online transactions and fraud
  • Funds the legal costs of pursuing or defending a cyber incident
  • Pays to restore data and clean infected devices
  • Covers extortion demands and the specialist help to handle them
Your existing protection

What the banking rules already give you

Before buying cover it is worth knowing what protection already exists. The Reserve Bank of India’s framework on unauthorised electronic transactions is stronger than most customers realise — and it turns on how quickly you report.

Zero
Liability if reported in time
4–7 days
Limited liability window
10 days
Bank’s reversal timeline
Report fast
The variable you control

Liability if reported in time — Zero

Under the RBI circular of 6 July 2017, a customer bears zero liability for an unauthorised electronic transaction where the loss arises from the bank’s negligence, or from a third-party breach reported to the bank within three working days of receiving the bank’s communication about it.

Limited liability window — 4–7 days

Where a third-party breach is reported between four and seven working days, the customer’s liability is capped at an amount set by account type. Beyond that window, the bank’s own policy governs.

Bank’s reversal timeline — 10 days

The bank must credit the disputed amount to the account within ten working days of notification, without waiting for any insurance claim of its own to be settled.

The variable you control — Report fast

Every protection in the framework is triggered by prompt reporting. Bank alerts should be readable without unlocking the phone, and a suspected compromise should be reported the same day — not after investigating it yourself.

Source: RBI circular of 6 July 2017, “Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions”, applicable to scheduled commercial banks, small finance banks, payments banks and prepaid payment instrument issuers. Insurance sits alongside this framework; it does not replace it.

What is insured

The sections of a personal cyber policy

Cover is modular. Most products let you choose sections and set a limit for each rather than buying a single undifferentiated sum insured.

Identity theft

Financial loss where someone uses your personal information to open accounts, obtain credit or transact in your name — together with the cost of restoring your credit record and the legal work involved.

Restoring your name

Unauthorised online transactions

Loss from fraudulent transactions on your bank account, cards, net banking or digital wallets, over and above what the bank ultimately restores under the RBI framework.

Bank, card and wallet

Phishing and social engineering

Loss where you were induced by deception to transfer funds or disclose credentials — the category that has grown fastest, and the one where the customer’s own action makes recovery from the bank hardest.

Being deceived

Cyber extortion

A demand made against you following the compromise of your device or data, together with the cost of specialist help in responding. Payment is normally subject to the insurer’s prior consent.

Ransom and response

Malware and data restoration

The cost of cleaning infected devices and restoring or recreating lost personal data and software after an attack.

Devices and files

Cyber stalking and bullying

Legal costs of pursuing a person responsible for online harassment, stalking or bullying of you or a family member, and in many wordings the cost of counselling.

Harassment

Media liability

Your legal liability for defamation or infringement arising from something you posted online — a section people rarely look for and occasionally need.

What you publish

Legal and prosecution costs

The cost of defending a claim brought against you following an incident, and of prosecuting a claim yourself, subject to the insurer’s agreement.

Defence and pursuit
Typically included

Costs a policy will usually meet

  • The financial loss itself. Funds taken through unauthorised transactions or obtained by deception, within the section limit and after any recovery from the bank.
  • Legal expenses. Advocate’s fees and court costs for pursuing or defending a claim connected to the incident, with the insurer’s prior agreement.
  • Identity restoration costs. The administrative and legal work of correcting records, notifying credit bureaus and re-establishing your identity.
  • Data and system restoration. Recovering or recreating personal data, and cleaning or reinstating software on affected devices.
  • Extortion payment and response. A demand met with the insurer’s consent, plus the cost of specialist negotiation or forensic assistance.
  • Counselling. Psychological counselling following stalking, bullying or a serious identity compromise, where the wording provides for it.
  • Transportation and documentation. Reasonable costs of attending proceedings and obtaining the records a claim requires.

What is not covered

Loss already recovered

Anything the bank, card issuer or another party has made good. The policy covers your net loss, not a second recovery of the same money.

Incidents known before inception

A compromise that had already occurred, or that you were aware of, when the policy started.

Deliberate or dishonest acts

Loss arising from your own dishonesty, or that of a family member or anyone acting with your consent.

Business losses

Loss connected with a trade, business or profession. That belongs to a commercial cyber policy, not a personal one.

Trading and speculative losses

Losses on investments, cryptocurrency or trading platforms arising from market movement or from your own decisions.

Unsupported or unprotected systems

Many wordings require reasonable precautions — supported software, security updates, no sharing of credentials. Failing them can cost the claim.

Disclosure of credentials to a third party

Sharing a password, PIN or one-time password, other than where the wording specifically covers social engineering.

Bodily injury and property damage

Physical loss is the province of other policies.

Unreported incidents

Loss not reported to the bank and to the police, or to the national cybercrime reporting portal, within the stated time.

Practical steps

What to do the moment something goes wrong

Speed is the single largest determinant of how much you recover — both from the bank under the RBI framework and from the insurer.

Report to the bank the same day

Do not investigate first. Reporting an unauthorised transaction within three working days of the bank’s communication is what triggers the zero-liability position.

Block cards and freeze the account

Through the bank’s official app or its published helpline. Never through a number found in a search result or sent to you in a message.

File a cybercrime complaint

On the national cybercrime reporting portal or at a police station. A complaint reference is required for the insurance claim and helps the bank’s own investigation.

Preserve the evidence

Screenshots of messages, transaction alerts, email headers and call records. Do not delete anything, including the message that deceived you.

Change credentials from a clean device

If a device may be compromised, reset passwords from a different one and enable two-factor authentication on email first, because email is the recovery route for everything else.

Notify the insurer

Within the period stated in the policy, with the bank reference and the cybercrime complaint reference.

Check your credit report

After any suspected identity compromise, and again a few months later. Accounts opened in your name usually surface there before they surface anywhere else.

Selection

How to choose a policy

The checks that change the outcome, in the order they matter.

Cover is modular. A household that banks and shops online needs the transaction, phishing and identity sections. A family with teenagers may value the stalking and bullying section more highly. Paying for sections that do not describe your risk is the commonest waste in this class.
Look at what could realistically move in a single day — account balances, card limits, transfer limits, credit available in your name. That, rather than a round number, is the sensible basis for the sum insured.
This is the section that matters most and the one wordings differ on most. Some policies cover loss where you were deceived into transferring money; others exclude anything you did yourself. Establish which you are buying.
Most wordings require reasonable precautions — supported operating systems, security updates applied, credentials not shared. These are conditions of cover, not suggestions.
Some policies cover the named insured only; others extend to a spouse, children and dependent parents on the same limit. Given who in a household is usually targeted, this matters.
The policy covers your net loss after any recovery under the RBI framework. It does not duplicate that recovery, and it does not remove your obligation to report promptly — late reporting can prejudice both.
Personal cyber policies typically carry a per-claim deductible, which can be a meaningful fraction of a small loss.
Loss connected to a trade or profession is excluded. If you run a business, the exposure — customer data, systems, liability to third parties — needs a commercial cyber policy instead.
At claim time

How a claim actually works

Most rejected claims fail on process rather than on cover. These five steps are the process.

1

Report to the bank and block access

Immediately, and through official channels only. Note the complaint reference and the time of the report; both are central to the file.

2

File a cybercrime complaint

On the national cybercrime reporting portal or with the police. The acknowledgement is required documentation for the insurance claim.

3

Notify the insurer

Within the period stated in the policy. Provide the bank reference, the complaint reference and a plain account of what happened and when.

4

Preserve and submit evidence

Transaction statements, alert messages, email headers, screenshots, call records and any correspondence with the bank. Forensic examination of a device may be required for a malware or extortion claim.

5

Assessment and settlement

The insurer establishes the net loss after any recovery from the bank or card issuer, applies the deductible and the section limit, and settles. Legal and restoration costs are usually reimbursed against invoices with the insurer’s prior agreement.

Setting it straight

Myths and facts

Commonly believed
What is actually true
My bank will always refund fraud, so I do not need cover.
The RBI framework gives you a strong position for unauthorised transactions reported promptly. It is a much weaker position where you were deceived into authorising the payment yourself — which is now the largest category of loss.
Cyber insurance stops me being hacked.
It does nothing of the kind. It meets the financial consequences afterwards. Two-factor authentication, updated software and scepticism about unexpected messages remain the actual defence.
Only careless people get caught.
Current fraud is well-researched, well-timed and often uses information the target genuinely recognises. Being careful reduces the risk; it does not remove it.
My home insurance covers this.
Home policies cover physical loss to property. Money taken from an account and identity used fraudulently are neither.
It covers my business too.
A personal cyber policy expressly excludes loss connected with a trade, business or profession. Business exposure needs a commercial policy.
Cryptocurrency losses are covered.
Generally not. Losses on trading platforms and speculative assets are typically excluded, though theft from a wallet through a covered event may be treated differently. Check the specific wording.
Plain English

Terms you should know

Phishing
Deception by message, email or call designed to obtain credentials or induce a payment.
Social engineering
Manipulating a person into acting against their own interest, rather than defeating a technical control.
Identity theft
Use of your personal information to transact, borrow or open accounts in your name.
Cyber extortion
A demand for payment following the compromise of your data or devices.
Zero liability
The RBI position under which a customer bears no loss for an unauthorised transaction reported within three working days.
Deductible
The first portion of each claim borne by you.
Section limit
The maximum payable under one part of the policy, as distinct from the overall sum insured.
Two-factor authentication
A second proof of identity beyond a password — the single most effective control available to a household.
Common questions

Frequently asked questions

It depends on the wording, and this is the most important question to ask. Some personal cyber policies cover loss arising from phishing and social engineering, including transfers you made under deception. Others exclude anything you authorised. Since deception now accounts for the largest share of losses, establish this before you buy.
No. Card protection schemes are limited to specific card transactions and are operated by the issuer. A cyber policy is broader — identity theft, extortion, data restoration, legal costs and harassment — and responds to your net loss across accounts and platforms.
Report it to the bank the same day through its official app or published helpline, and block the cards. Under the RBI framework, reporting within three working days of the bank’s communication is what secures the zero-liability position. Investigate afterwards, not first.
On some products, yes — family cover extending to a spouse, children and dependent parents is available, and the stalking and bullying section is usually what matters there. Confirm who is a named insured before assuming it.
Some wordings cover extortion payments, almost always subject to the insurer’s prior consent and to specialist involvement. Never respond to a demand independently if you intend to claim.
Usually not. Speculative and trading losses are typically excluded, and cryptocurrency is generally treated as outside the scope. A small number of wordings address theft from a wallet through a covered event, so read the specific policy.
Prompt reporting protects you well for unauthorised transactions on regulated accounts. It does not help with identity theft, extortion, data loss, harassment, legal costs, or with a payment you were deceived into authorising. Those gaps are what the policy is for.
Not for the business. Personal cyber policies exclude loss connected with a trade or profession. If your business handles customer data or takes payments, that exposure needs a commercial cyber policy — which we can arrange separately.
Important. Insurance is the subject matter of solicitation. This page is general information about how personal cyber insurance works in India, not a recommendation of any insurer or product. Sections, limits, deductibles, security conditions and, in particular, the treatment of social engineering losses vary materially by product and insurer — read the policy document and the sales brochure before concluding a sale. The summary of the Reserve Bank of India’s framework on unauthorised electronic banking transactions is provided for general information; your position depends on the facts and on the rules in force. Nothing here is legal advice. ILNB Group distributes insurance products and is paid a commission by the insurer, disclosed to you for anything we recommend.
Free consultation

Not sure if this fits your plan?

Tell us your goal and timeline. We will tell you honestly whether Cyber Insurance belongs in your portfolio — or whether something simpler would serve you better.

  • A senior advisor calls you, not a call centre
  • Recommendation matched to your goal and risk profile
  • Written summary after the call
  • No cost and no obligation
+91 99308 07175 Mon–Sat, 10:00 AM – 7:00 PM IST

Book your free consultation

Takes 30 seconds. No obligation, no sales pressure.

Please enter your name.
Please enter a valid number.
Please enter a valid email address.
Prefer to chat? WhatsApp us
Thank you — we’ve received your details and will call you within one business day.

We use your details only to respond to this enquiry. No spam, no selling your data — see our privacy policy.

Take the first step

Is Cyber Insurance right for you?

Every product suits a particular goal, horizon and temperament. A short conversation is the fastest way to find out where this fits in your plan — or whether something else serves you better.