By Evaa Saiwal, Head – Liability, Credit & Speciality Practice, Policybazaar for Business
For years, cybersecurity conversations have revolved around one question: How do we prevent an attack?
That question is still important. But as cyber threats become more frequent, sophisticated and interconnected, businesses need to ask a second question with equal urgency: If an attack happens tomorrow, how quickly can we contain it, absorb or finance the loss and get the business running again?
The distinction matters because a cyberattack is no longer simply a technology problem. It can quickly become a revenue problem, a cash-flow problem and, ultimately, a balance-sheet problem.
The scale of the threat is becoming harder to ignore. Data reported to CERT-In shows that the number of cyber-security incidents in India rose from 20.41 lakh in 2024 to 29.44 lakh in 2025, an increase of more than 44% in a single year.
The financial consequences are rising too. IBM’s 2026 Cost of a Data Breach study estimates that the average cost of a data breach in India reached Rs 25.5 crore in 2026, up 15.9% from Rs 22 crore in 2025. The average breach in India also involved around 39,500 compromised records.
These numbers make one thing clear: cyber resilience can no longer sit entirely with the IT department. It needs to become part of enterprise risk management.
The real cost begins when systems stop working
The financial damage from a cyber incident is rarely limited to the stolen data or compromised computer.
Take ransomware. If critical systems are encrypted, a company may have to suspend operations while it investigates the incident and works to restore its systems. Every hour of downtime can mean lost sales, delayed deliveries, disrupted customer service and additional pressure on employees.
Then come the costs that may not have been on the balance sheet when the incident began: forensic investigation, data restoration, legal advice, crisis communications, customer notification and potentially regulatory or third-party liabilities.
This is why the severity of a cyber incident should not be measured only by how much data was stolen or how sophisticated the attack was. The duration of business disruption can be just as important.
For many organisations, one of the biggest exposures may actually be the income lost while systems are unavailable. This makes elements such as business interruption coverage, waiting periods, indemnity periods and contingent business interruption particularly important when structuring a cyber programme. The adequacy of the cover should therefore be tested against realistic downtime scenarios rather than viewed only through the overall policy limit.
IBM’s latest findings illustrate the challenge. Organisations in India without AI and security automation took an average of 236 days to identify a breach and another 75 days to contain it.
For a business, those are not merely cybersecurity metrics. They represent time during which uncertainty, operational disruption and financial exposure can accumulate.
Business continuity is the missing link
This is where incident preparedness and business continuity need to come together.
A cyber incident response plan typically answers questions such as: Who investigates the breach? Who shuts down affected systems? Who communicates with customers? Who engages external experts?
A business continuity plan answers another critical question: How does the company continue operating while all this is happening?
The two cannot operate in isolation.
Businesses need to identify their most critical systems and processes before an incident occurs. They need to understand which operations can be temporarily shifted to manual processes, how quickly backups can be restored and who has the authority to take critical decisions when normal systems are unavailable.
They also need to test those plans.
A plan that exists only on paper may offer little comfort when the organisation is dealing with a live ransomware attack at 2 a.m. The companies that recover faster are likely to be those that have already decided what needs to happen, who needs to act and what the financial consequences of different scenarios could be.
Cyber risk increasingly extends beyond the organisation
Another complication is that businesses are no longer operating within clearly defined technology boundaries.
Cloud providers, software platforms, payment processors, managed service providers and other technology partners have become deeply embedded in business operations. An incident at one of these partners can therefore become an incident for the customer as well.
This means cyber resilience cannot stop at the organisation’s own firewall. Companies need to understand where their critical dependencies lie and what happens if one of those dependencies becomes unavailable.
For risk managers and boards, this also changes the question they should be asking. It is not simply, “Are we secure?” It is, “What happens to our business if a critical part of our digital ecosystem is compromised?”
The more important question for businesses is not simply whether they have cyber insurance, but whether the programme reflects their actual exposure. A company heavily dependent on digital operations may need to think differently about business interruption and system failure than one whose principal exposure is large volumes of sensitive customer data. Similarly, reliance on cloud providers and other technology vendors makes contingent business interruption increasingly relevant.
Insurance can help absorb the financial shock
Even the strongest cybersecurity controls cannot eliminate cyber risk entirely. This is where cyber insurance can form another layer of a company’s resilience strategy.
A cyber policy can, depending on its terms and coverage, help businesses manage costs associated with areas such as business interruption, data restoration, forensic investigation, legal assistance, incident response and certain third-party liabilities.
But its value during a cyber event can extend beyond the eventual financial reimbursement.
A serious incident can require specialists who may not be available within the organisation. Forensic investigators need to establish what happened and whether systems remain compromised. Legal experts may need to assess notification and regulatory obligations. Crisis specialists may be required to manage communications with customers, employees and other stakeholders.
Having access to such expertise can help a business move from detection to containment and recovery more quickly.
Cyber insurance should not be viewed as the last step after cybersecurity controls have been put in place. Done properly, it is part of the same resilience architecture: security controls reduce the likelihood and severity of an incident, business continuity limits disruption, and insurance helps protect the balance sheet against the residual risk.
The balance sheet needs a cyber-resilience plan
For boards and business leaders, this calls for a broader approach to cyber risk.
The first step is understanding the organisation’s critical exposures. What systems are essential to revenue generation? Which customer or employee data would create the greatest liability if compromised? How much revenue could be lost during a week of disruption? Which third-party providers are operationally critical?
The next step is translating those risks into response plans and financial scenarios.
If a critical system is unavailable for 24 hours, what is the impact? What about seven days? What happens if customer data is compromised at the same time? How much liquidity would the business need to manage the disruption?
These are uncomfortable questions, but they are more useful than simply asking whether the company has the latest security tools.
CERT-In has continued to emphasise preparedness and response, including through cybersecurity drills and exercises. In 2025, it conducted 122 cybersecurity drills and exercises involving about 1,570 organisations across government and private sectors.
The goal should ultimately be simple: make sure a cyber incident does not become a business-ending event.
Cybersecurity will remain the first line of defence. But resilience is what determines what happens after that defence is breached.
The most prepared businesses will not necessarily be those that can guarantee they will never suffer a cyberattack. They will be those that know their critical exposures, have rehearsed their response, understand the financial consequences of downtime and have the resources to absorb the shock.
In an increasingly digital economy, that may be the more meaningful definition of cybersecurity: not just preventing the breach, but ensuring the business can survive it.