HomeInsurance Types › Cyber Insurance

Cyber Insurance

Ransomware, invoice fraud and data breaches now hit small Singapore firms far more often than fires do — and unlike a fire, the damage keeps compounding while you work out what happened. Cyber insurance is the response plan with money attached.

Cyber insurance covers the costs of dealing with a cyber incident — the forensic and legal response, the ransom negotiation, the downtime, the customer notifications — and your liability to others whose data or systems were compromised through you. It has moved from a big-company nicety to a practical SME cover for a simple reason: attackers automate, and automation doesn't care that you only have eight staff.

The PDPA raises the stakes. Under Singapore's Personal Data Protection Act, organisations can face significant financial penalties for data breaches — for larger firms, penalties can reach up to S$1 million or up to 10% of annual Singapore turnover. Add mandatory breach handling, forensic costs and customer fallout, and even a small incident gets expensive fast. Confirm current requirements with the PDPC.
Two-column diagram. cyber cover typically responds to: Ransomware response and getting systems back up; Investigating and notifying after a data breach; Income lost while your systems are down; Claims from customers whose data was exposed. Outside it: A regulatory penalty under the PDPA, which depends on the law and the wording; Money transferred out by invoice fraud, which a crime or funds-transfer extension; Replacing damaged laptops and servers, which commercial property cover; Bad professional advice you gave, which professional indemnity; Upgrading systems you knew were weak, which your own IT budget, not a policy.
Where this policy stops. Items on the right are not gaps in your protection — they are a different policy's job. Free to reuse with a link to this page.

First-party vs third-party cover: the two halves of a cyber policy

Cyber policies bundle two distinct types of protection, and understanding the split is the fastest way to read any quote:

  • First-party cover pays your own costs after an incident: IT forensics and system restoration, legal advice on notification duties, ransom payments and negotiation where insurable, data recovery, crisis communications, and often loss of income while systems are down.
  • Third-party cover pays your liability to others: claims from customers or partners whose data was exposed, regulatory investigation defence costs and — where insurable — financial penalties, and claims arising from malware spreading from your systems to someone else's.

For most SMEs, first-party costs arrive first and hit hardest — the incident-response bill lands within days, long before any lawsuit. A policy's real value often lies in its incident response service: a hotline that puts vetted forensic, legal and PR specialists on your problem immediately, at negotiated rates, when you have no idea whom to call.

CostFirst-party or third-partyTypically covered?
Incident response and IT forensicsFirst-partyUsually a core part of the cover, often via a 24-hour response panel
Data restoration and system rebuildFirst-partyTypically covered
Lost income while systems are downFirst-partyCommonly covered, often after a waiting period — check how the outage is defined
Ransom payment and negotiationFirst-partyContentious and varies widely by policy — may be sub-limited, excluded, or restricted by law
Breach notification costsFirst-partyTypically covered
Claims from customers whose data was exposedThird-partyTypically covered
Regulatory investigation costsThird-partyDefence costs are commonly covered; whether any penalty itself is insurable depends on the law and the policy

The incidents that actually hit Singapore SMEs

  • Ransomware. Attackers encrypt your systems and increasingly also steal data first, threatening to publish it — so backups alone no longer make the problem go away. Costs include forensics, restoration, downtime and, sometimes, a negotiated payment. A cyber policy typically covers the response and the business interruption; cover for ransom payments themselves varies by policy and circumstances.
  • Business email compromise (BEC). A fraudster impersonates a supplier, a director or you, and a genuine payment goes to the wrong account. This is one of the most common losses for small firms — and one of the most variable in cover. Funds-transfer fraud and social engineering cover is often an optional extension with its own sub-limit: check it's included, and at a meaningful amount.
  • Data breaches. Customer or employee personal data is exposed through hacking, a lost device or a misdirected email. Under the PDPA, breaches meeting certain thresholds must be handled and notified properly, and financial penalties can follow — for larger firms, up to S$1 million or up to 10% of annual Singapore turnover. The policy funds the legal guidance, notification and monitoring costs, and defence of any regulatory action.

What cyber insurance typically doesn't cover

Reading the exclusions is where cyber policies are won and lost:

  • Poor security hygiene. Insurers increasingly ask about multi-factor authentication, backups and patching in the proposal — misstate them and claims can fail. Some policies exclude incidents traceable to specific unpatched, known vulnerabilities.
  • Prior known incidents — anything you knew about, or should have, before the policy started.
  • Bodily injury and property damage — cyber covers data and money, not physical harm; those belong to your liability and property policies.
  • Sub-limits that quietly cap the headline. A S$1 million policy may carry a much lower sub-limit for social engineering fraud or PDPA penalties. The headline limit matters less than the sub-limit on the loss you're most likely to have.

Also worth knowing: professional firms whose service to clients fails because of a cyber event may find that claim sitting in professional indemnity territory rather than cyber — the two policies are designed to interlock, so buy them with that in mind.

What cyber insurance costs

For small Singapore firms, indicative premiums run from around S$500–1,500 a year for entry-level limits, rising with revenue, the volume and sensitivity of data you hold, your industry, and the state of your security controls. Firms with MFA, tested backups and staff phishing training generally see better pricing and smoother underwriting; firms handling medical, financial or large consumer databases pay more.

Actual premiums depend on your business and vary widely between insurers — cyber is a young market and quotes for the same risk genuinely differ. Get comparative quotes, and see our guide on whether cyber insurance is worth it for a framework to decide the limit.

Frequently asked questions

What does cyber insurance cover?

Cyber insurance covers your own costs after a cyber incident — forensics, system restoration, legal advice, notification, lost income during downtime — and your liability to others whose data or systems were compromised through you, including defence of regulatory action. The first set is called first-party cover and the second third-party cover; most SME policies bundle both, plus access to an incident-response hotline.

Is cyber insurance worth it for a small business in Singapore?

For most SMEs that take payments, hold customer data or depend on their systems day-to-day, it's worth serious consideration — small firms are attacked because attacks are automated, not because attackers pick targets. The strongest argument is practical: a policy buys an immediate, funded response team when you'd otherwise be searching for a forensics firm mid-crisis. Weigh the premium against what a week of downtime plus a PDPA breach response would cost you.

Does cyber insurance cover PDPA fines?

Many cyber policies cover regulatory defence costs and, where insurable at law, financial penalties under data protection legislation — but cover for penalties varies by policy and by the circumstances of the breach, so check the wording rather than assuming. Under the PDPA, financial penalties for larger firms can reach up to S$1 million or up to 10% of annual Singapore turnover, and the policy's more certain value is funding the legal handling, notification and investigation response that every breach requires. Confirm current requirements with the PDPC.

Does cyber insurance cover ransomware payments?

Policies typically cover ransomware response — forensics, negotiation, restoration and business interruption — while cover for the ransom payment itself varies by policy and circumstances, and payment is never the default first step. Modern attacks usually steal data before encrypting it, so the response is as much a legal and PDPA exercise as a technical one, which is exactly the work the policy funds.

What's the difference between first-party and third-party cyber cover?

First-party cover pays your own losses from an incident — response costs, data recovery, downtime — while third-party cover pays claims made against you by others, such as customers whose data you exposed, plus regulatory defence. SMEs usually feel first-party costs first and hardest; larger data holders and B2B firms carry meaningful third-party exposure too. A good SME policy includes both halves with sensible sub-limits.

How much does cyber insurance cost in Singapore?

Indicatively from around S$500–1,500 a year for a small firm at entry-level limits, with premiums rising on revenue, data sensitivity, industry and security posture. Basic controls — multi-factor authentication, tested backups, staff training — both reduce premiums and are increasingly required by insurers before they'll quote. Actual pricing varies widely between insurers, so compare quotes on your specific setup.

Related cover & guides

Get cyber insurance quotes for your business

Tell us about your business once. We pass your enquiry to a licensed insurance professional who quotes the cover you actually need — no obligation, no spam.

Get cyber quotes