Cyber Insurance Singapore: The 2026 Buyer Guide

A plain-English walkthrough of what cyber insurance is, what it covers, and what to watch for in Singapore policy wordings.

Editorial review 2026-06-06 · 13 SG insurers tracked · 8 wordings with extracted facts

What is cyber insurance?

Cyber insurance is a commercial policy that pays for the financial damage caused by a cyber incident. In Singapore that damage takes two predictable shapes. First-party loss is what the incident costs you directly: a ransomware payment, the IT bill to rebuild systems, the revenue lost while you were down, the forensics invoice. Third-party liability is what the incident costs others who then sue you: customers whose data leaked, business partners whose systems were exposed through yours, and the Personal Data Protection Commission (PDPC) when it opens an enforcement file.

Cyber insurance bundles both into one policy. A clean Singapore wording will list a dozen or so insuring agreements, each with its own sub-limit, deductible, and waiting period. Reading the wording matters more than reading the marketing brochure — which is why our insurer reviews publish the verbatim PDF.

Why Singapore SMEs buy it

Three forces are pushing demand upward. The first is the PDPA. Since 1 October 2022 the PDPC can fine an organisation up to 10% of annual Singapore turnover (or SGD 1 million, whichever is higher) for a breach involving personal data — a 10× step-up from the previous SGD 1 million flat cap. The second is the contractual ratchet: MAS-supervised firms, large enterprise procurement, and government tenders increasingly require evidence of cyber insurance before signing. The third is ransomware. The Cyber Security Agency of Singapore (CSA) has reported successive year-on-year increases in reported ransomware incidents targeting SG SMEs, and operational paralysis from encryption is now the single most common claim trigger we see in the comparison set.

The two halves of cover

First-party (your own losses)

  • Cyber extortion / ransomware payments — the ransom itself plus the negotiator’s fee. Sub-limits vary by insurer — check each wording explicitly via the ransomware sub-limit clause search.
  • Business interruption — lost revenue while systems are unavailable, after a waiting period (typically 8–12 hours). Indemnity periods vary from 90 days to 12 months.
  • Data restoration — the cost of rebuilding databases, applications, and configurations from backups.
  • Forensics and breach response — incident-response specialists, legal counsel, and PDPC notification logistics.
  • PR and crisis management — communications support during the first 72 hours.

Third-party (claims against you)

  • Privacy and network-security liability — defence costs and damages when a customer or business partner sues over leaked data or downstream malware.
  • Regulatory defence — legal representation in a PDPC inquiry, and (where insurable under SG law) the financial penalty itself.
  • Media liability — defamation, copyright, and IP claims arising from digital content you publish.
  • Payment Card Industry (PCI) assessments — fines and assessments from card schemes after a breach involving cardholder data.

Each of these maps to one of the 13 topics our side-by-side comparison tracks across insurers. Use it to spot where one wording is silent and another is explicit.

What is NOT covered (read this section twice)

The single biggest source of unpleasant surprise is the war and state-sponsored attack exclusion. Since Lloyd’s of London published LMA5564 and LMA5567A in 2023, most SG cyber wordings sold via the London market exclude losses arising from cyber operations attributed to a state. The attribution wording varies sharply. Some policies require government attribution; others permit insurer attribution; a few use a "reasonable inference" standard. We map this exclusion explicitly in our war/state-act topic page.

Other common carve-outs: prior known acts (a retroactive date in the policy), system improvements beyond pre-loss state ("betterment"), bodily injury or property damage (covered by general liability, not cyber), and intentional acts by senior management. Several wordings also exclude social-engineering fraud unless an explicit endorsement is purchased — read the "computer fraud" definition closely if invoice-redirection is a concern.

Premium drivers in Singapore

We deliberately do not publish indicative price ranges per insurer — SG cyber premiums depend on too many variables to summarise honestly. The underwriting questionnaire usually asks for revenue, sector, claims history over the last 5 years, the cover limit you want, and details of your security controls. Multi-factor authentication on remote access and email, EDR or MDR on every endpoint, immutable or offline backups, an incident-response plan, and basic security-awareness training are the five controls that move premiums most.

For real numbers tied to your business, use the quote form — it pushes the same details to a panel of SG cyber insurers and brokers and you receive comparable indications.

Who should buy

Any SG business that stores customer personal data, takes electronic payments, or relies on internet-facing systems for operations should hold at least a baseline cyber policy. The risk-weighted argument is strongest for healthcare clinics, law firms, fintech and MAS-supervised firms, and e-commerce platforms. Manufacturing with embedded IoT, professional-services firms holding client confidential material, and managed service providers carrying downstream customer liability are also high-priority buyers.

How to buy

For most SG SMEs, comparing wordings directly via a platform like this one is the fastest path. For complex risks — multi-entity groups, MAS-licensed firms, MSPs with downstream contractual exposure — a specialist cyber broker can access the wider London/Lloyd’s market and negotiate manuscript endorsements. We are not a MAS-licensed Financial Advisory Act adviser; we are an independent comparison platform that publishes the wording PDFs verbatim, alongside the 13-topic feature comparison.

Quick start: three things to do this week

  1. Read the verbatim wording of the two or three insurers you are most likely to choose. Start with the Chubb Cyber ERM, AIG CyberEdge, and QBE Cyber & Data Security wordings — the three with the most extracted facts on this site.
  2. Compare the ransomware sub-limit, the PDPA regulatory-defence sub-limit, and the war exclusion across those three on the comparison page.
  3. Use the quote form to receive real indications from the SG market.

Frequently asked questions

Is cyber insurance mandatory in Singapore?

No. Cyber insurance is not mandated by Singapore law for general businesses. However, the Personal Data Protection Act (PDPA) makes you liable for data-protection breaches, and from 1 October 2022 the PDPC can impose a financial penalty of up to 10% of annual Singapore turnover (or SGD 1 million, whichever is higher). Many SG financial institutions, MSP contracts, and tenders also require evidence of cyber insurance before engagement.

What does cyber insurance typically cover in Singapore?

A standard SG cyber policy covers (1) first-party loss — your own ransomware payments, business interruption, data restoration and breach-response costs; and (2) third-party liability — customer lawsuits, PDPC regulatory defence, and the PDPC financial penalty where insurable. Most also include PR/crisis-management costs, forensics and credit-monitoring for affected individuals.

What is NOT covered by cyber insurance?

War and state-sponsored cyber attacks (per Lloyd’s 2023 war-exclusion clauses LMA5564 / LMA5567A used by most London-market insurers), prior known incidents, betterment / system upgrades beyond pre-loss state, intentional acts by senior management, and unencrypted PII left on lost devices in some wordings. Always read the war exclusion and the "prior acts" date carefully.

How much does cyber insurance cost in Singapore?

Premiums vary widely — we do not publish indicative ranges because they depend on revenue, sector, claims history, security controls (MFA, EDR, backups), and cover limit. Use our quote tool to receive real numbers from multiple SG insurers.

Does cyber insurance cover PDPC fines?

Most SG cyber policies offer a "regulatory defence" sub-limit that covers PDPC investigation costs and legal representation. Whether the PDPC financial penalty itself is reimbursable depends on the wording and on insurability under Singapore law. Each policy on this site is mapped to the regulatory-defence row of our 13-topic facts comparison.

How long does PDPC give me to notify a data breach?

Under PDPA Section 26D, an organisation must notify the PDPC as soon as practicable, but no later than 3 calendar days after assessing that a notifiable data breach has occurred. Affected individuals must be notified in any reasonable manner where there is significant harm. See our PDPA Sec 26D 3-day rule page for the assessment criteria.

Broker, direct, or comparison platform — which is best?

For SMEs under SGD 5m revenue, comparing wordings directly via a platform like this one is usually fastest and free. For larger and more complex risks (multi-entity groups, MAS-supervised firms holding a Financial Adviser licence, IT services with downstream customer liability), a specialist cyber broker can shop the London / Lloyd’s market and negotiate manuscript endorsements. We do not hold a MAS Financial Adviser licence — we are a comparison platform.

Sources and further reading

  • Personal Data Protection Commission (PDPC) — pdpc.gov.sg — financial penalty cap, PDPA Section 26D notification rule
  • Cyber Security Agency of Singapore (CSA) — csa.gov.sg — annual Singapore Cyber Landscape report
  • Lloyd’s Market Association — lmalloyds.com — LMA5564 / LMA5567A war and cyber-operation exclusions
  • Monetary Authority of Singapore (MAS) — mas.gov.sg — Technology Risk Management (TRM) Guidelines

Compare Singapore cyber insurance wordings now

13 insurers tracked. Verbatim wordings published. No fabricated prices or ratings.

Get Quotes — Free