A plain-English walkthrough of what cyber insurance is, what it covers, and what to watch for in Singapore policy wordings.
Editorial review 2026-06-06 · 13 SG insurers tracked · 8 wordings with extracted facts
Cyber insurance is a commercial policy that pays for the financial damage caused by a cyber incident. In Singapore that damage takes two predictable shapes. First-party loss is what the incident costs you directly: a ransomware payment, the IT bill to rebuild systems, the revenue lost while you were down, the forensics invoice. Third-party liability is what the incident costs others who then sue you: customers whose data leaked, business partners whose systems were exposed through yours, and the Personal Data Protection Commission (PDPC) when it opens an enforcement file.
Cyber insurance bundles both into one policy. A clean Singapore wording will list a dozen or so insuring agreements, each with its own sub-limit, deductible, and waiting period. Reading the wording matters more than reading the marketing brochure — which is why our insurer reviews publish the verbatim PDF.
Three forces are pushing demand upward. The first is the PDPA. Since 1 October 2022 the PDPC can fine an organisation up to 10% of annual Singapore turnover (or SGD 1 million, whichever is higher) for a breach involving personal data — a 10× step-up from the previous SGD 1 million flat cap. The second is the contractual ratchet: MAS-supervised firms, large enterprise procurement, and government tenders increasingly require evidence of cyber insurance before signing. The third is ransomware. The Cyber Security Agency of Singapore (CSA) has reported successive year-on-year increases in reported ransomware incidents targeting SG SMEs, and operational paralysis from encryption is now the single most common claim trigger we see in the comparison set.
Each of these maps to one of the 13 topics our side-by-side comparison tracks across insurers. Use it to spot where one wording is silent and another is explicit.
The single biggest source of unpleasant surprise is the war and state-sponsored attack exclusion. Since Lloyd’s of London published LMA5564 and LMA5567A in 2023, most SG cyber wordings sold via the London market exclude losses arising from cyber operations attributed to a state. The attribution wording varies sharply. Some policies require government attribution; others permit insurer attribution; a few use a "reasonable inference" standard. We map this exclusion explicitly in our war/state-act topic page.
Other common carve-outs: prior known acts (a retroactive date in the policy), system improvements beyond pre-loss state ("betterment"), bodily injury or property damage (covered by general liability, not cyber), and intentional acts by senior management. Several wordings also exclude social-engineering fraud unless an explicit endorsement is purchased — read the "computer fraud" definition closely if invoice-redirection is a concern.
We deliberately do not publish indicative price ranges per insurer — SG cyber premiums depend on too many variables to summarise honestly. The underwriting questionnaire usually asks for revenue, sector, claims history over the last 5 years, the cover limit you want, and details of your security controls. Multi-factor authentication on remote access and email, EDR or MDR on every endpoint, immutable or offline backups, an incident-response plan, and basic security-awareness training are the five controls that move premiums most.
For real numbers tied to your business, use the quote form — it pushes the same details to a panel of SG cyber insurers and brokers and you receive comparable indications.
Any SG business that stores customer personal data, takes electronic payments, or relies on internet-facing systems for operations should hold at least a baseline cyber policy. The risk-weighted argument is strongest for healthcare clinics, law firms, fintech and MAS-supervised firms, and e-commerce platforms. Manufacturing with embedded IoT, professional-services firms holding client confidential material, and managed service providers carrying downstream customer liability are also high-priority buyers.
For most SG SMEs, comparing wordings directly via a platform like this one is the fastest path. For complex risks — multi-entity groups, MAS-licensed firms, MSPs with downstream contractual exposure — a specialist cyber broker can access the wider London/Lloyd’s market and negotiate manuscript endorsements. We are not a MAS-licensed Financial Advisory Act adviser; we are an independent comparison platform that publishes the wording PDFs verbatim, alongside the 13-topic feature comparison.
No. Cyber insurance is not mandated by Singapore law for general businesses. However, the Personal Data Protection Act (PDPA) makes you liable for data-protection breaches, and from 1 October 2022 the PDPC can impose a financial penalty of up to 10% of annual Singapore turnover (or SGD 1 million, whichever is higher). Many SG financial institutions, MSP contracts, and tenders also require evidence of cyber insurance before engagement.
A standard SG cyber policy covers (1) first-party loss — your own ransomware payments, business interruption, data restoration and breach-response costs; and (2) third-party liability — customer lawsuits, PDPC regulatory defence, and the PDPC financial penalty where insurable. Most also include PR/crisis-management costs, forensics and credit-monitoring for affected individuals.
War and state-sponsored cyber attacks (per Lloyd’s 2023 war-exclusion clauses LMA5564 / LMA5567A used by most London-market insurers), prior known incidents, betterment / system upgrades beyond pre-loss state, intentional acts by senior management, and unencrypted PII left on lost devices in some wordings. Always read the war exclusion and the "prior acts" date carefully.
Premiums vary widely — we do not publish indicative ranges because they depend on revenue, sector, claims history, security controls (MFA, EDR, backups), and cover limit. Use our quote tool to receive real numbers from multiple SG insurers.
Most SG cyber policies offer a "regulatory defence" sub-limit that covers PDPC investigation costs and legal representation. Whether the PDPC financial penalty itself is reimbursable depends on the wording and on insurability under Singapore law. Each policy on this site is mapped to the regulatory-defence row of our 13-topic facts comparison.
Under PDPA Section 26D, an organisation must notify the PDPC as soon as practicable, but no later than 3 calendar days after assessing that a notifiable data breach has occurred. Affected individuals must be notified in any reasonable manner where there is significant harm. See our PDPA Sec 26D 3-day rule page for the assessment criteria.
For SMEs under SGD 5m revenue, comparing wordings directly via a platform like this one is usually fastest and free. For larger and more complex risks (multi-entity groups, MAS-supervised firms holding a Financial Adviser licence, IT services with downstream customer liability), a specialist cyber broker can shop the London / Lloyd’s market and negotiate manuscript endorsements. We do not hold a MAS Financial Adviser licence — we are a comparison platform.
13 insurers tracked. Verbatim wordings published. No fabricated prices or ratings.
Get Quotes — Free