
The Indian cyber-insurance market sits at approximately ₹1,000 crore in 2026, with cumulative premium estimates for the financial year approaching ₹60 billion. The Banking, Financial Services, and Insurance sector holds up to 35 percent of that market share. The growth is double-digit and accelerating.
The underwriting is also tightening.
The controls bar moved up.
Indian cyber-insurance underwriters in 2026 are demanding evidence of specific controls before binding coverage. The 2022 procurement memo described the policy. The 2026 procurement memo describes the controls the policy requires. The two memos look fundamentally different.
For the Indian BFSI buyer renewing cyber insurance in 2026-2027, the procurement question is no longer "what coverage is in the policy." The procurement question is "what controls does our environment have to demonstrate to bind the coverage at commercially viable pricing, and what is the timeline to close the gap between the current posture and the underwriter's required bar."
But first, some catch-up on infra this week.
🔍 The Controls Bar: EDR, 24x7 SOC, MFA, IR Plan, Backup Hygiene
The Indian cyber-insurance underwriters' 2026 controls list is consistent across the major carriers. The buyer that meets the list gets bound at commercially reasonable pricing. The buyer that does not meet the list either pays a substantial premium loading, accepts lower coverage limits, or gets declined.

Five tiers, one underwriting outcome.
EDR on every endpoint and every server. The bar is modern Endpoint Detection and Response running on every workstation, laptop, and server. The 2022 procurement allowed legacy antivirus as the baseline. The 2026 procurement does not. The underwriter wants to see vendor name, deployment coverage percentage, agent-status compliance, and the SOC's ability to triage EDR-generated alerts.
24x7 SOC monitoring. EDR alerts have to land in a Security Operations Centre with 24x7 human (or human-supervised agentic) coverage. The buyer running EDR with alerts that go to an empty SOC mailbox at night is the buyer that the underwriter declines. The MDR alternative satisfies this requirement if the MDR contract documents the operational handoff and response time.
Multi-factor authentication. MFA on every administrative account, every privileged-access workflow, every external-facing application. The April 2026 RBI authentication mandate aligns with this requirement for Indian BFSI specifically. The underwriter wants evidence of MFA enforcement, not just MFA availability.
Incident response plan, tested. A documented IR plan with annual tabletop exercises and quarterly drills for the critical scenarios (ransomware, BEC, data exfiltration). The 2022 paper IR plan that has never been tested is the IR plan the underwriter discounts. The 2026 IR plan has to demonstrate operational rehearsal.
Backup hygiene. Immutable backups, air-gapped tiers, verified restore testing. The 3-2-1-1-0 framework covered earlier this year is now the underwriting baseline rather than a forward-looking architectural goal.
For the Indian BFSI buyer working backward from the 2026-2027 renewal:
✔ Audit each of the five tiers against the carrier's questionnaire. The questionnaire is detailed and specific; the response has to be detailed and specific.
✔ Close the gaps before the renewal conversation, not during it. The underwriter who finds the gap on the questionnaire response is the underwriter who loads the premium.
✔ Document the operational evidence for each tier (deployment coverage percentages, SOC staffing rosters, MFA enforcement reports, IR drill logs, backup verification artefacts). The underwriter wants the evidence, not the assurance.
✔ Renegotiate the coverage limits in light of the actual exposure. Most Indian BFSI buyers are under-insured on the business-interruption side of cyber coverage; the 2026 renewal is the moment to fix it.
How we plug in: Our Cyberdefense practice runs the controls-bar assessment for Indian BFSI buyers preparing for cyber-insurance renewal. We map the existing posture against the five-tier underwriting questionnaire, identify the gaps that drive premium loading, and document the operational evidence the carrier needs. The carrier's broker is on the carrier's side. The buyer needs the procurement-side counsel.
🔐 The Indian Cyber-Insurance Carrier Landscape
The Indian cyber-insurance market in 2026 is structured across four categories of carrier, each with a different posture toward the BFSI segment.

Capacity is the procurement question.
Domestic insurers (ICICI Lombard, Bajaj Allianz, HDFC ERGO, Tata AIG, New India Assurance) provide most of the Indian cyber-insurance capacity in the primary layer. The strength is the operational relationship with the BFSI buyer and the Indian jurisdiction for claims. The procurement caveat is capacity: a primary policy with an Indian carrier rarely exceeds ₹50-100 crore for a single buyer; large Indian BFSI buyers need additional excess layers.
Global reinsurance (Munich Re, Swiss Re, AIG, Chubb) provides the excess layers and structured placements above the domestic primary. The capacity is the strength. The trade-off is the underwriter's distance from Indian operational reality; the reinsurer's questionnaire is sometimes more rigorous than the domestic carrier's, and the buyer's evidence package has to satisfy both.
Specialised cyber underwriters (Beazley, CFC, Coalition, Resilience) provide pure-play cyber coverage with deeper technical engagement during binding. Coalition is the most active in the Indian market through broker partnerships. The strength is the carrier's understanding of cyber risk specifically; the trade-off is the smaller available capacity and the higher procurement-process intensity.
Broker-arranged Lloyd's placements route through Indian brokers (Marsh, WTW, Aon, JLT) into Lloyd's of London syndicates for highly-customised coverage. Useful for buyers with non-standard exposure (large multinational, complex supply chain, regulated entity with unique requirements). The procurement intensity is the highest of the four categories.
The four-category read-out:
👉 Domestic carriers: operational relationship, Indian jurisdiction, primary-layer capacity.
👉 Global reinsurers: excess capacity, structured placements, rigorous underwriting.
👉 Specialised cyber: deep technical engagement, smaller capacity, higher process intensity.
👉 Lloyd's placements: customised coverage, broker-mediated, highest process intensity.
For most Indian BFSI buyers in 2026, the realistic structure is layered: domestic primary for the first ₹100 crore, global reinsurer excess for the next ₹500 crore, specialised cyber or Lloyd's placement for the tail beyond that. The procurement memo coordinates across all four categories.
The broker's role in this multi-layer placement is operationally important and often misunderstood. The broker is paid by the carrier (usually a commission on premium) but is contractually obligated to the buyer. The procurement memo should treat the broker as a partner in the placement process, not as a vendor selling a product. The right broker for an Indian BFSI cyber-insurance placement is the broker with deep technical staff who can translate the underwriter's questionnaire into the buyer's operational language, and translate the buyer's controls evidence back into the carrier's risk-assessment process. Marsh, WTW, Aon, and Howden have the most BFSI cyber-placement experience in the Indian market; the smaller specialist brokers can be competitive for specific use cases but the buyer should validate the team's actual technical depth before signing.
How we plug in: Our Complete IT Infrastructure Solution practice sits on the buyer side of the cyber-insurance procurement, alongside the broker. We have built the controls-evidence packages that satisfy multi-carrier structured placements for Indian BFSI clients. The broker arranges the placement. The buyer needs the technical evidence and the procurement counsel to negotiate the binding terms.
📌 Ransomware, Supply Chain, AI-Phishing: The Three 2026 Claim Drivers
The Indian cyber-insurance claims data for 2025-2026 shows three dominant drivers, each shaping the underwriting bar.

Three drivers shape the premium.
Ransomware remains the most visible and most expensive claim driver. Indian BFSI buyers experiencing ransomware in 2025 paid average ransoms exceeding ₹10 crore, with business-interruption losses several multiples higher. The insurance claim covers some of this; the deductible and sub-limit structures usually leave the buyer carrying significant residual exposure. The underwriter's premium loading for ransomware exposure is the dominant component of the 2026 quote.
Supply chain attacks are the second driver. Compromised SaaS vendor → customer breach. Compromised software dependency → customer compromise. Compromised managed-service-provider → multiple customer breaches simultaneously. The Indian BFSI buyer's vendor-stack inventory is the underwriter's risk assessment; the buyer that cannot document the vendor inventory cannot demonstrate the supply-chain risk control.
AI-powered phishing is the third driver and the fastest-growing. Voice-cloned executive impersonation. Deepfake video instructions for wire transfers. AI-generated business-email-compromise that adapts to the recipient's writing patterns. The 2024 BEC threat model is being replaced by a 2026 BEC threat model that requires fundamentally different defensive controls. The underwriter's questionnaire in 2026 asks about deepfake-detection tooling, out-of-band verification procedures for financial transactions, and AI-content-moderation policies; the 2022 questionnaire did not.
For the Indian BFSI buyer drafting the 2026-2027 cyber-insurance renewal:
✔ Document the ransomware-recovery-time-objective. The faster the documented recovery, the lower the business-interruption premium.
✔ Document the third-party-vendor risk-management programme. The underwriter wants to see the vendor inventory, the risk-tiering, and the contractual liability allocation.
✔ Document the AI-phishing defensive posture. Out-of-band verification, deepfake-detection, and the executive-impersonation incident-response playbook.
✔ Negotiate the war-and-state-actor exclusion specifically. Most 2026 policies have tightened the state-actor exclusion language; the buyer needs to understand what coverage is preserved.
How we plug in: Our Cyberdefense practice maps the ransomware, supply-chain, and AI-phishing risk posture against the cyber-insurance underwriting questionnaire for Indian BFSI buyers. We have built the documentation discipline that satisfies the carrier's risk-assessment process without overloading the buyer's procurement timeline.
📋 RBI, DPDP, IRDAI: The Compliance Layer Above the Insurance
The Indian regulatory framework intersects the cyber-insurance procurement in 2026-2027 in ways that the 2022 procurement memo did not anticipate.

Three regulators, one policy.
RBI Master Directions on Cyber Resilience apply to the bank's cybersecurity posture. The directions require specific controls (geographically distributed DCs, quarterly DR drills, RPO/RTO documentation, AES-256 encryption). The cyber-insurance underwriter's questionnaire mirrors many of these requirements, but the regulator's view is more granular. The bank that satisfies RBI generally satisfies the underwriter; the reverse is not always true.
DPDP applies to the bank's customer-data handling, including the data fragments that may surface during a cyber incident. The cyber-insurance policy's data-breach response coverage has to align with the DPDP notification timeline (72 hours for serious incidents) and the consent-management framework. The policy that does not align introduces residual compliance risk that the carrier is not contractually responsible for.
IRDAI applies to the carrier providing the cyber insurance, and to the bank's own insurance-licensed subsidiaries if applicable. The IRDAI direction on cyber-insurance policy wording has tightened progressively from 2022 through 2026, with specific requirements for policy schedules, exclusion language, and claim-process documentation.
For the Indian BFSI buyer drafting the 2026-2027 cyber-insurance procurement:
👉 Map the policy's coverage language against the RBI Master Directions to identify uncovered exposure.
👉 Map the policy's data-breach response against the DPDP notification timeline to identify timing mismatches.
👉 Verify the carrier's IRDAI compliance with the 2026 cyber-policy-wording direction.
The compliance overlay is the procurement frame. The policy is the implementation.
How we plug in: Our Complete IT Infrastructure Solution practice reads the RBI + DPDP + IRDAI overlay against the cyber-insurance policy for Indian BFSI buyers. We have done this work alongside the broker and the buyer's legal counsel. The compliance gaps that the broker does not flag are the gaps that the next regulator review surfaces.
🔍 Links We Liked This Week
Cyber Insurance in India: From Breach Recovery to Business Resilience
EY India.
The strategic-side read on the Indian cyber-insurance market evolution.
Cyber Insurance in India: Premiums, Ransomware, and AI
Asia Insurance Post.
The market-sizing primary source with the ₹60bn premium pool figure and BFSI 35 percent share data.
Cyber Insurance Requirements 2026: What Insurers Now Demand
BASG.
The controls-bar primary source. Essential for the procurement-side preparation.
Cyber Insurance Risks and Trends 2026
Munich Re.
The reinsurance-side view of the 2026 risk landscape and the underwriting evolution.
Cybersecurity Insurance Requirements in 2026
Medhacloud.
The technical-controls explainer. Useful for the IT side of the procurement preparation.
💡 My Take
For most of the last decade, cyber insurance in Indian BFSI was a financial-risk-transfer product purchased once a year by the procurement-and-finance team.
The board read the policy summary. The risk committee approved the coverage. The infrastructure team was rarely consulted. The renewal was a price negotiation, not a controls assessment.
That arrangement is finishing.
Insurance is a controls programme.
The 2026 cyber-insurance procurement is fundamentally a controls programme dressed up as a financial-risk-transfer product. The buyer that recognises this reframe and structures the procurement accordingly receives commercially viable pricing and adequate coverage. The buyer that treats the procurement as a financial transaction without the controls work pays for the gap in premium loading or in coverage exclusions, sometimes both. The underwriter binds the coverage when the controls evidence satisfies the questionnaire. The coverage is conditional on the controls. The premium is priced against the controls. The claim is paid against the controls. Every layer of the conversation circles back to whether the buyer has the controls in place and can prove it.
For the Indian BFSI CIO drafting the 2026-2027 cyber-insurance renewal, the procurement question is not "what coverage do we want."
The procurement question is "what is the controls posture we can demonstrate, what is the gap between our current posture and the underwriter's required bar, what is the timeline and budget to close the gap, and what is the procurement coordination across infrastructure, security, risk, finance, and legal that produces the binding artefact the carrier needs."
Once that question has an answer, the carrier shortlist follows. The premium negotiation follows. The coverage-limit and exclusion negotiation follows. The audit-committee narrative follows.
The buyer that treats cyber insurance as a financial product to be bought once a year is the buyer that pays the highest premium for the lowest coverage with the largest exclusions. The buyer that treats cyber insurance as the procurement frame for the broader controls programme is the buyer that pays a reasonable premium for adequate coverage with the exclusions negotiated explicitly.
VEMIO™ exists because the operational reality of running a controls programme that satisfies the cyber-insurance underwriter, the RBI sector-regulator, the DPDP framework, and the IRDAI policy-wording direction needs an observability layer that no single tool provides. The platform tells you which control is operational. The CIO needs to see across the EDR coverage percentages, the 24x7 SOC response time, the MFA enforcement evidence, the IR drill documentation, the backup verification artefacts, the supply-chain risk register, and the regulatory-compliance posture. All in one operator view, with the evidence package the underwriter's questionnaire requires.
The buyer that internalises this reframe transforms the cyber-insurance procurement from a once-a-year cost-management exercise into a continuous controls-maturity programme. The premium becomes a leading indicator of the bank's actual cyber-risk posture, not a lagging indicator of the carrier's appetite. The 18-24 month window between renewals is the operational programme that drives the next year's premium negotiation, with documented evidence rather than negotiated assertions.
Premium pricing is a controls assessment in disguise.
Reply to this email with the one cyber-insurance control gap you cannot currently close before the next renewal, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.
Until next time,
Ajay Salvi & the Vinay Enterprises team.
