← Blog

Cyber insurance, and the word both systems turn on

Most of what a personal cyber policy pays on stolen money, the bank may already owe you back if you report fast enough. What is genuinely new is not theft at all — it is the legal and clean-up costs. And the one theft where the policy could have added something, the transfer you were talked into approving, is the one its exclusion names.

Two systems can put the money back

A personal cyber policy pays for a listed set of online losses: money taken from your account, the cost of undoing an identity theft, legal bills. A second system already covers part of that list — the RBI's limited-liability framework, under which your bank carries most of an unauthorised transaction you report quickly.

These two do not sit side by side. Insurance pays only what is left after every other recovery route has run, so the policy's job begins where the bank's obligation ends. If the bank reverses the transaction, the policy pays nothing on it, and correctly so.

That reorders the question. The useful question is not does cyber insurance cover online fraud, because the brochure will always say yes. It is what this policy pays for that the bank route does not.

The bank route, and the word it turns on

The RBI framework does not ask how clever the fraud was. It sorts the incident into one of three buckets and applies a different rule to each.

Two mechanical consequences matter more than the categories themselves. First, in every bucket the clock, not the story, is what you control — even in the negligence bucket, reporting stops the meter. Second, the bank must credit the disputed amount back while it investigates, so the money can return before fault is decided.

The windows, the liability ladder and the credit-back period are set by regulation and have been revised more than once, so the current circular is the only reliable source — not any summary of it, including this one. What has not changed across revisions is the direction: every version has priced delay.

Now notice the word the whole structure rests on: unauthorised. Hold on to it.

Where the bank route stops

Three edges, and they are quite different from one another.

Transactions you authenticated yourself. The bank's log shows a valid second factor, entered by you, on your registered device. Whether an instruction obtained by deception is still “unauthorised” is a genuinely contested question rather than a settled one, and it is decided case by case on evidence you usually do not have.

The size of that carve-out follows from its definition, not from a statistic. It catches every fraud that succeeds by persuading you rather than by bypassing you — getting a code out of you, getting you to approve a request in an app, getting you to install something. All three end in an instruction your bank's log shows you authenticated. What share of Indian fraud losses that pattern accounts for is a question for the data rather than for a brochure, but it is the pattern the bank and police advisories are written about.

Losses that never touch your bank account. A loan or a card taken in your name at an institution you have no relationship with. A wallet or an exchange that is not a bank. Money handed to a marketplace buyer by ordinary transfer. Your bank cannot reverse a transaction it did not process, and the framework does not reach an account you never opened.

Costs that are not the stolen money. The lawyer. The forensic clean-up of a compromised device. The weeks of correspondence to remove a fraudulent loan from your credit record.

The bank route reverses a transaction; it does not reimburse a cost.

What the policy schedule actually lists

Personal cyber policies in India are sold as one product but written as a stack of separate sections, each with its own limit. Reading them as a stack is the only way to see what is new.

Policy sectionWhat it pays forAlready covered elsewhere?
Unauthorised online transactionsMoney taken from your account, card or wallet by a third partyLargely — the RBI framework, plus the card route for asking an issuer to reverse a disputed payment (a chargeback), if reported fast
Identity theft resolutionCosts of undoing misuse of your identity: legal fees, documentation, disputing a loan opened in your nameNo comparable route
Legal defence costsDefending a claim brought against you after your device or account was used against someone elseNo
Prosecution costsPursuing the perpetrator, where that is worth doingNo
Cyber extortion and data restorationRansomware on your own devices, and rebuilding what it lockedNo
Online defamation and stalkingLegal costs of pursuing or defendingNo

The third column is the whole argument: every row that is genuinely new is a legal or restoration cost, not a stolen rupee. The row the marketing leads with — money taken from your account — is the one row that most nearly duplicates something you already have.

The authorisation gap

So what does the policy add on the fraud itself? Less than the overlap suggests, and for a reason that is structural rather than unlucky.

The bank route pays on unauthorised transactions. Cyber policies pay on unauthorised transactions too, and the Indian wordings commonly carry an exclusion for voluntary parting with money — transfers the insured themselves instructed. That is a claim about wordings in general and is worth confirming on the schedule in front of you; where it holds, both protections are keyed to the same word and read it much the same way.

Line that up against how fraud actually happens and the picture is uncomfortable:

Call it the authorisation gap. A second layer of protection is worth its price when it fires in the situations where the first one fails; that independence is the whole reason two layers beat one. Here the two are keyed to the same word, so they fire together and fail together. Buying the policy on top of the bank route therefore does not diversify the risk — it buys a second copy of a defence you already had, with the same hole in it.

That makes one question worth more than the rest of the sales conversation: does this policy pay when I was tricked into authorising the transfer myself, and what is the exact wording? Ask for the exclusion clause, not the brochure. A policy that answers yes in writing is covering something the bank route may not. A policy that answers no is, on this section, sold against a risk it has excluded.

There is a second-order version of this. A cyber claim typically requires a police or cybercrime-portal complaint filed promptly as a condition of cover — and prompt reporting is exactly what maximises the bank's own liability under the framework. Which means the discipline the policy demands of you is the discipline that makes it least necessary. Slow reporting weakens both at once. Fast reporting strengthens the one you did not pay for.

The exclusions that decide the claim

General insurance is decided in the exclusions and the limits, and cyber cover is more exclusion-dense than most. The ones that change outcomes:

The arithmetic is simple and almost nobody does it before buying. Suppose a schedule reads ₹5 lakh sum insured, an identity-theft sub-limit of ₹1 lakh, and a ₹10,000 deductible per claim. A ₹60,000 loss under that section settles at ₹50,000, and the ₹5 lakh was never available to it. Those figures are illustrative — the point is to run your own quote through the sub-limit for the section you would actually claim under, and price the premium against that number rather than the headline.

The questions that decide whether it adds anything

None of this makes the product pointless. It makes the value conditional, and the conditions are checkable before you buy.

  1. Does the wording cover induced-but-authorised transfers? In writing, in the policy, not in an email from a salesperson.
  2. What is the sub-limit on the section you would realistically claim under, and what is the deductible against it?
  3. Do the legal-cost sections apply to you at all? Defence costs, prosecution costs and defamation cover are the rows with no substitute — and also the rows most people will never touch.
  4. How much is actually reachable? This is the one you control. If the bulk of your money sits one step away from the account attached to your card and UPI, the maximum a compromised credential can take is a number you chose.
  5. Do you carry exposure the bank channel cannot reach? Business money in a personal account, a public profile that invites a defamation claim, a household running its whole financial life through one device.

Question four usually settles it, because it converts an unbounded fear into a bounded number. The principle from why insurance exists at all applies unchanged: insurance is for the loss that cannot be absorbed, not for the one that would merely annoy. A loss capped at an operating balance kept deliberately small is an annoyance already designed in. A long legal defence is not.

The cover is also not the first line. The habits that stop these frauds cost nothing and are set out in how banking fraud actually works. A policy bought instead of them is expensive; a policy bought alongside them is a decision about residual risk, which is what insurance is for.

The cover you may already hold

Before adding a policy, check three places, because duplicate cover is one of the standard and most expensive insurance errors — two policies covering the same loss do not pay twice.

If two of those already cover the money section, what you are considering buying is the legal-cost sections. That is a much smaller purchase, and a much clearer one to price.

The alternative use of the premium

Every insurance decision has a version of the same trade-off. A premium transfers a tail you could not absorb. It does not help with a bounded loss you could — and for a bounded loss, a buffer does the same work and keeps the money.

Which one a cyber premium is depends on the answers above. Compare the annual premium, over the years you expect to hold the policy, against the sub-limit net of deductible on the section you would claim under. If those two numbers are close, you are pre-paying a loss rather than transferring one — and the same money in an emergency fund covers every other emergency too.

FNOTrader's Mutual Funds app runs on the full AMFI NAV history — around 34 million NAV rows — and will run a monthly contribution against any scheme and period, reporting invested versus value, maximum drawdown, and the internal rate of return for cashflows that land on irregular dates — XIRR. That produces the buffer-side number to set against the premium.

FNOTrader does not sell insurance, is not affiliated with any insurer, and is not a SEBI-registered investment adviser. This is an explanation of how the two systems work, not advice on whether to buy a policy. Policy wordings differ between insurers and are revised; the RBI framework is set by regulation and has been amended — read your own schedule and the current circular before deciding anything.

Common questions

Is cyber insurance worth it for an individual in India?

It depends on which section you would claim under. The money-theft section largely duplicates the RBI limited-liability framework, under which your bank carries most of the loss on an unauthorised transaction reported quickly. The legal defence, prosecution, identity-restoration and defamation sections have no equivalent elsewhere, and those are where the cover is genuinely additive.

Does cyber insurance cover money lost to a phishing or UPI scam?

Often not, and this is the question to ask before buying. These wordings commonly exclude voluntary parting with money — transfers the insured authorised themselves. Any fraud that works by inducing you to enter a code or approve a request produces exactly that: a transfer your bank's log shows you authenticated. Ask for the exclusion clause in writing rather than relying on the brochure.

What is the RBI limited-liability framework?

A rule that decides how much of an unauthorised electronic transaction the customer bears. It sorts incidents into bank deficiency, third-party breach with no fault on either side, and customer negligence, and applies a different liability rule to each, with reporting speed the main variable the customer controls. The windows and amounts are set by regulation and have been revised — check the current circular.

If my bank refunds the money, will the insurer still pay?

No. Cyber cover is written excess of other recovery, so the policy pays only the shortfall after the bank route has run. That is how indemnity works, and it is why the sum insured on the schedule overstates what a claim actually returns.

What does a cyber policy cover that a bank cannot refund?

Costs rather than transactions. Legal defence if a claim is brought against you after your account or device was used, prosecution costs, the expense of undoing an identity misuse such as a loan opened in your name, ransomware and data restoration on your own devices, and legal costs in online defamation or stalking matters.

Do I need to file a police complaint to claim on cyber insurance?

Typically yes — a police or cybercrime-portal complaint filed promptly is usually a condition of cover. Note that the same prompt reporting is what maximises the bank's liability under the RBI framework, so the discipline the policy requires is also the discipline that reduces how much you need it.

Why does the sum insured not match what a claim pays?

Three reasons that stack: the headline sum insured is a ceiling across the whole policy while each section carries its own smaller sub-limit; a deductible is taken off every claim; and the cover pays only what remains after any bank or card recovery. Price the premium against the sub-limit net of deductible, not the headline.

Might I already have cyber cover without knowing?

Possibly. Some credit cards carry fraud-liability or purchase-protection benefits, some householder packages include an identity or cyber rider, and some employer group covers now add one. Because indemnity insurance restores a loss rather than pays for it twice, two policies over the same loss do not double the recovery — which makes those three worth checking before a third is bought.

Continue reading

More in Insurance · App: Mutual Funds · Definitions: glossary · Free tools: calculators · All: every article