India's cyber insurance market reached USD 115 million of gross written premium in 2025 across 62,000 active policies covering USD 18.5 billion of aggregate insured limits, and is forecast to reach USD 321 million by 2031 at 18.66% CAGR with 78,000 policies in 2026 alone, according to Ken Research's "India Cyber Insurance Market Size, Share & Forecast By Product Type, Customer Segment & Distribution Channel, 2026–2031" published August 6, 2026. The report, cited alongside Sberbank India's mass-market analysis, Deloitte's digital-economy risks review, and Reuters' August 2026 note on AI agents going rogue, frames the same turn: cyber cover in India is shifting from imported wordings and large-corporate reinsurance capacity to India-specific products for digital fraud, operational technology, supply-chain interruption and personal cyber, with SME adoption via brokers, banks, aggregators and embedded partnerships as the mass-market engine.

Method: What Data This Guide Uses

This guide uses Ken Research August 2026 as primary for market size, policy-count and limit projections (2020: USD 35m/12k policies/6.0bn limits; 2024: USD 102m/47k/15.8bn +41.7%; 2025: USD 115m/62k/18.5bn +12.7%; 2026E: USD 137m/78k/21.7bn +19.1%; 2031E: USD 321m/48.0bn limits; historical CAGR 26.86% 2020-2025, forecast 18.66%; India ranks 3rd in APAC peer set behind Australia USD 390m and Singapore USD 150m, ahead of UAE 85m). Alternative sizing (MarketResearch.com Sep 16 2025: USD ~580m; IMARC: USD 752.55m 2025 to USD 8,848m by 2034 at 28.09%) is noted to show model divergence. Sberbank IndiaSource discussion of mass-market service design, Deloitte's navigating risks and opportunities note, and Reuters' AI-agents piece provide the coverage and underwriting context.

Mass-Market vs Corporate: Two Different Products

Ken Research is explicit: the 2024 spike (+41.7%) was large buyers raising limits and repricing ransomware, privacy and interruption; the 2025 moderation (+12.7%) reflected reinsurance capacity recovery and rate stabilisation, while aggregate limits still rose +17.1% - volume held, price fell. That split explains the product shift. Corporate standalone remains the largest premium contributor (ICICI Lombard, HDFC ERGO, Bajaj Allianz, New India, Reliance per Ken's cross-comparison on GWP, policy count, CSR and TAT). Packaged SME and retail personal are lower premium per policy but far higher policy volume, which is where mass-market growth lives. IMARC's 28.09% CAGR to USD 8.8bn by 2034 assumes that SME/retail transition accelerates; Ken's 18.66% assumes it does but that affordability and minimum-control requirements (MFA, patching, backup, EDR) constrain conversion as insurers enforce proposal-form hygiene at point of sale (see BimaNiti Aug 28 IRDAI health panel push for point-of-sale underwriting - same principle applied to cyber).

What AI Agents Change in Policy Wording

Reuters (August 2026) reports MSIG, QBE and Beazley reviewing traditional cyber language for AI agents that can act autonomously and create unintended third-party liability. In India that maps to endorsements Ken flags for 2026-2031: dependent business interruption (cloud outage not on your premises), AI misuse/systemic OT, and supply-chain. Expect more sublimits, exclusions and co-insurance on those perils even as overall limits rise to USD 48.0bn by 2031, and more packaged cyber with the 0% GST base helpful for SME perception (individual health/life 0% since Sep 22 2025, but commercial cyber still commercial premium with no GST relief). For MSMEs the practical mass-market question is not "premium per se" but "what controls will insurer require before quoting, and what sublimit will apply to the peril you actually fear (e.g., UPI fraud vs ransomware vs cloud outage)?"

How to Buy: 5 Checks Before You Compare

One, clarify first-party vs third-party: first-party pays your restoration, forensics, notification, BI; third-party pays liability to others for privacy breach. Standalone vs packaged (bundled with property or D&O) matters for limit and exclusion stacking. Two, ask for sublimits in writing: privacy, BI, dependent BI, ransomware, regulatory fines - headline INR 1cr cover with INR 15L sublimit on BI is not 1cr for the event you fear. Three, disclosure: MFA, patch cadence, backup frequency, admin privilege controls - non-disclosure voids cyber faster than health. Four, vendor list: reinsurance capacity remains available per Ken, but systemic cloud/ AI losses will increase co-insurance; confirm panel-forensics firm and 6-hour incident notification window (aligns with CERT-In and IRDAI cyber security guidelines Apr 6 2026: CISO independence, ISRMC quarterly). Five, distribution: broker/bank/digital aggregator/embedded - embedded via e-commerce or banking app is cheapest to start but narrowest limits; broker channel gives wording negotiation for larger SME limits. Keep the SecureNow-style discipline: compare wordings, not just premium, and test claim with a tabletop.

Sources: Ken Research Aug 6 2026 India Cyber Insurance Market Size, Share & Forecast 2026–2031 (USD 115m 2025 → USD 321m 2031, 18.66% CAGR, 62k policies, 18.5bn limits, 3rd in APAC); Deloitte "Cyber insurance in India: Navigating risks and opportunities in a digital economy"; Reuters "As AI agents go rogue, cyber insurers are adapting their policies" Aug 2026 (MSIG, QBE, Beazley); Ken cross-comparison on GWP/CSR for ICICI Lombard, HDFC ERGO, Bajaj Allianz, New India, Reliance.