Cyber insurance covers the costs of dealing with a cyber incident — the forensic and legal response, the ransom negotiation, the downtime, the customer notifications — and your liability to others whose data or systems were compromised through you. It has moved from a big-company nicety to a practical SME cover for a simple reason: attackers automate, and automation doesn't care that you only have eight staff.
First-party vs third-party cover: the two halves of a cyber policy
Cyber policies bundle two distinct types of protection, and understanding the split is the fastest way to read any quote:
- First-party cover pays your own costs after an incident: IT forensics and system restoration, legal advice on notification duties, ransom payments and negotiation where insurable, data recovery, crisis communications, and often loss of income while systems are down.
- Third-party cover pays your liability to others: claims from customers or partners whose data was exposed, regulatory investigation defence costs and — where insurable — financial penalties, and claims arising from malware spreading from your systems to someone else's.
For most SMEs, first-party costs arrive first and hit hardest — the incident-response bill lands within days, long before any lawsuit. A policy's real value often lies in its incident response service: a hotline that puts vetted forensic, legal and PR specialists on your problem immediately, at negotiated rates, when you have no idea whom to call.
| Cost | First-party or third-party | Typically covered? |
|---|---|---|
| Incident response and IT forensics | First-party | Usually a core part of the cover, often via a 24-hour response panel |
| Data restoration and system rebuild | First-party | Typically covered |
| Lost income while systems are down | First-party | Commonly covered, often after a waiting period — check how the outage is defined |
| Ransom payment and negotiation | First-party | Contentious and varies widely by policy — may be sub-limited, excluded, or restricted by law |
| Breach notification costs | First-party | Typically covered |
| Claims from customers whose data was exposed | Third-party | Typically covered |
| Regulatory investigation costs | Third-party | Defence costs are commonly covered; whether any penalty itself is insurable depends on the law and the policy |
The incidents that actually hit Singapore SMEs
- Ransomware. Attackers encrypt your systems and increasingly also steal data first, threatening to publish it — so backups alone no longer make the problem go away. Costs include forensics, restoration, downtime and, sometimes, a negotiated payment. A cyber policy typically covers the response and the business interruption; cover for ransom payments themselves varies by policy and circumstances.
- Business email compromise (BEC). A fraudster impersonates a supplier, a director or you, and a genuine payment goes to the wrong account. This is one of the most common losses for small firms — and one of the most variable in cover. Funds-transfer fraud and social engineering cover is often an optional extension with its own sub-limit: check it's included, and at a meaningful amount.
- Data breaches. Customer or employee personal data is exposed through hacking, a lost device or a misdirected email. Under the PDPA, breaches meeting certain thresholds must be handled and notified properly, and financial penalties can follow — for larger firms, up to S$1 million or up to 10% of annual Singapore turnover. The policy funds the legal guidance, notification and monitoring costs, and defence of any regulatory action.
What cyber insurance typically doesn't cover
Reading the exclusions is where cyber policies are won and lost:
- Poor security hygiene. Insurers increasingly ask about multi-factor authentication, backups and patching in the proposal — misstate them and claims can fail. Some policies exclude incidents traceable to specific unpatched, known vulnerabilities.
- Prior known incidents — anything you knew about, or should have, before the policy started.
- Bodily injury and property damage — cyber covers data and money, not physical harm; those belong to your liability and property policies.
- Sub-limits that quietly cap the headline. A S$1 million policy may carry a much lower sub-limit for social engineering fraud or PDPA penalties. The headline limit matters less than the sub-limit on the loss you're most likely to have.
Also worth knowing: professional firms whose service to clients fails because of a cyber event may find that claim sitting in professional indemnity territory rather than cyber — the two policies are designed to interlock, so buy them with that in mind.
What cyber insurance costs
For small Singapore firms, indicative premiums run from around S$500–1,500 a year for entry-level limits, rising with revenue, the volume and sensitivity of data you hold, your industry, and the state of your security controls. Firms with MFA, tested backups and staff phishing training generally see better pricing and smoother underwriting; firms handling medical, financial or large consumer databases pay more.
Actual premiums depend on your business and vary widely between insurers — cyber is a young market and quotes for the same risk genuinely differ. Get comparative quotes, and see our guide on whether cyber insurance is worth it for a framework to decide the limit.
Frequently asked questions
What does cyber insurance cover?
Cyber insurance covers your own costs after a cyber incident — forensics, system restoration, legal advice, notification, lost income during downtime — and your liability to others whose data or systems were compromised through you, including defence of regulatory action. The first set is called first-party cover and the second third-party cover; most SME policies bundle both, plus access to an incident-response hotline.
Is cyber insurance worth it for a small business in Singapore?
For most SMEs that take payments, hold customer data or depend on their systems day-to-day, it's worth serious consideration — small firms are attacked because attacks are automated, not because attackers pick targets. The strongest argument is practical: a policy buys an immediate, funded response team when you'd otherwise be searching for a forensics firm mid-crisis. Weigh the premium against what a week of downtime plus a PDPA breach response would cost you.
Does cyber insurance cover PDPA fines?
Many cyber policies cover regulatory defence costs and, where insurable at law, financial penalties under data protection legislation — but cover for penalties varies by policy and by the circumstances of the breach, so check the wording rather than assuming. Under the PDPA, financial penalties for larger firms can reach up to S$1 million or up to 10% of annual Singapore turnover, and the policy's more certain value is funding the legal handling, notification and investigation response that every breach requires. Confirm current requirements with the PDPC.
Does cyber insurance cover ransomware payments?
Policies typically cover ransomware response — forensics, negotiation, restoration and business interruption — while cover for the ransom payment itself varies by policy and circumstances, and payment is never the default first step. Modern attacks usually steal data before encrypting it, so the response is as much a legal and PDPA exercise as a technical one, which is exactly the work the policy funds.
What's the difference between first-party and third-party cyber cover?
First-party cover pays your own losses from an incident — response costs, data recovery, downtime — while third-party cover pays claims made against you by others, such as customers whose data you exposed, plus regulatory defence. SMEs usually feel first-party costs first and hardest; larger data holders and B2B firms carry meaningful third-party exposure too. A good SME policy includes both halves with sensible sub-limits.
How much does cyber insurance cost in Singapore?
Indicatively from around S$500–1,500 a year for a small firm at entry-level limits, with premiums rising on revenue, data sensitivity, industry and security posture. Basic controls — multi-factor authentication, tested backups, staff training — both reduce premiums and are increasingly required by insurers before they'll quote. Actual pricing varies widely between insurers, so compare quotes on your specific setup.
Related cover & guides
Is Cyber Insurance Worth It for Singapore SMEs?
Honest cost-benefit on cyber cover for SMEs: PDPA exposure, email-compromise risk, and when a small firm can reasonably skip it.
Read more →Insurance for Tech Startups
Tech E&O for client contracts, cyber cover, D&O for funded startups, group benefits — and the WICA rule founders miss.
Read more →Professional Indemnity Insurance
Covers negligence, errors and omissions in professional work. Required by some professional bodies and many B2B contracts.
Read more →Insurance for Clinics & Healthcare Practices
Malpractice/PI as the core cover, plus clinic property, WICA for staff and premises liability — insurance for healthcare practices.
Read more →