Skip to content
Financial Security Cybersecurity

// article

Cyber Insurance in Indonesia: What It Covers for Individuals and UMKM, What It Excludes, and When It Pays

A ransomware note asks for 50 million rupiah. A customer data leak triggers a PDP notification. Does insurance pay. Learn what cyber insurance covers in Indonesia, what it excludes, how much it costs, and how you prepare a claim that passes.

9 Aug 2026 13 min read
Cyber Insurance in Indonesia: What It Covers for Individuals and UMKM, What It Excludes, and When It Pays

A customer calls your online shop. The customer says your site leaked checkout data. You check email and see a ransom note that says your files are encrypted and you must pay 50 million rupiah in crypto within 48 hours. You run a small team of five. You have no IT staff. You ask your insurer: does our policy cover this? The answer depends on clauses you signed months ago, not on what you wish now.

Cyber insurance promises to move part of that financial shock from your balance sheet to the insurer. The promise pays only when you match the cover to your actual risk, when you meet the security conditions, and when you follow the claim steps. This guide shows you what cyber insurance covers for individuals and UMKM in Indonesia, what it excludes, how much it costs, and how you prepare so a claim survives review.

What cyber insurance is and who sells it in Indonesia

Cyber insurance is a contract that pays for loss and cost that follows a cyber event. The event list includes data breach, ransomware, business email compromise, funds transfer fraud, network outage from security failure, and privacy liability claim under UU PDP.

In Indonesia you see three product shapes.

Standalone cyber policy for UMKM and enterprise. Insurers such as ACA, BRI Insurance, Sinarmas, Chubb Indonesia, Zurich Indonesia, and broker-placed Lloyd coverage offer this. The policy covers both first-party loss to you and third-party liability to customers or partners.

Add-on or endorsement to property or business package. Some insurers attach a cyber clause to a fire or business interruption package. Limits are small, often 50 to 500 million rupiah, and wording is narrower than standalone.

Personal cyber endorsement or family cyber cover. A few insurers and fintech bundles sell personal cyber for individuals. Cover includes identity theft restoration, online fraud loss, device Repair after malware, and sometimes social media recovery cost.

You buy through an insurer direct, through a broker, or through a bank and marketplace bundle. Brokers add value when they compare wordings across insurers and when they guide you through the security questionnaire.

The two buckets: first-party loss and third-party liability

First-party covers your own cost. The insurer pays you for cost you incur to handle the event.

  • Incident response and forensics. A panel vendor triages, contains, and finds root cause.
  • Data recovery and system restoration. Cost to rebuild from backup or to reinstall.
  • Business interruption. Lost net profit while systems stay down, often with a waiting period like 8 to 12 hours before coverage starts.
  • Ransom payment, where legal and where the insurer approves. Some policies cover the ransom value, some cover only negotiation and not the payment itself.
  • Breach notification and call center. Cost to notify customers and regulator per UU PDP, plus credit monitoring for affected persons.
  • Crisis communication and PR cost.

Third-party covers claims others bring against you. The insurer pays legal and settlement cost when a customer, partner, or regulator claims you failed to protect data.

  • Privacy liability after a breach of personal data you hold.
  • Regulatory defense cost for PDP investigations.
  • Media liability for content you host that infringes or defames.
  • Payment card liability if you handle card data and a card scheme fines you.

An UMKM that stores customer name, phone, address, and order history faces both buckets at once. Recovery cost hits first, then a customer complaint hits third.

What most policies cover well, in plain examples

You can test a wording with scenarios.

Scenario 1: Ransomware locks your POS and accounting laptop. You run a fashion store with two laptops and a cloud POS. Ransomware encrypts the local accounting file. You have cloud backup for POS but not for accounting. The policy with first-party data recovery pays forensic triage, pays the IT vendor to rebuild the accounting laptop from a clean image, and pays business interruption for one day you cannot invoice. The policy without business interruption add-on pays only the rebuild.

Scenario 2: Online shop breach exposes 2,000 customer records. You sell on yourdomain.id plus Tokopedia. An SQL injection dumps customer name and phone. UU PDP requires you to notify affected persons and the authority within 72 hours for certain cases. The policy pays the law firm that drafts the notice, the vendor that runs the call center, and the forensics that scopes the leak.

Scenario 3: BEC email tricks your finance staff. A fake director email says transfer 30 million to a new vendor account. Your staff sends it. The insurer covers social engineering funds transfer only if your policy lists crime or social engineering as a covered peril and if you meet the verification condition, like callback to a known number before transfer. Many base cyber wordings exclude pure funds transfer fraud unless you buy the crime endorsement.

Scenario 4: Your child falls for a purchase scam that steals your card. A personal cyber endorsement covers the fraudulent online purchase loss up to a sublimit like 5 to 10 million per event, with a deductible. The same policy can cover cost to restore locked social accounts after a takeover.

What policies exclude or cap with sublimits you must read

Exclusions decide the claim outcome. Read these sections word for word.

Prior known circumstances. The policy does not cover a breach you knew about before you bought cover or a vulnerability you left unpatched after a known notice.

Failure to maintain security. Insurers require you to keep security controls you attested in the proposal form. Wording like failure to maintain reasonable security means that if you said you use MFA for email and then you turn it off, the claim for email compromise can fail. If you said you run offline backup and then you stop, the ransomware recovery can reduce.

War and infrastructure. Claims that stem from war, nation-state attack tagged as war, or from a failure of public internet or power grid fall outside. LOFI and cloud platform outages without a security failure also fall outside.

Bodily injury and property damage. Cyber policy does not replace property insurance. If ransomware causes a freezer to fail and food spoils, the cyber policy covers the system restoration but not the spoiled stock unless you add specific extension.

Cryptocurrency and market loss. A personal policy that covers stolen e-wallet balance may cap crypto at a low sublimit or exclude it. Business policies often exclude loss of crypto keys unless endorsed.

Sublimits and waiting periods. A headline limit of 1 billion rupiah can contain sublimits. Forensics may cap at 100 million, ransom at 50 million, business interruption at 10 million per day with max 5 days. A waiting period of 12 hours means the first 12 hours of outage generate no business interruption pay.

Retroactive date and discovery period. The policy covers events that happen after the retroactive date. If you discovered a breach in June but you bought cover in July, it does not cover. Some policies give a 60-day discovery tail after you cancel, where you can report events that happened during the policy but you discovered late.

How much cover an UMKM and an individual need and what it costs

Match limit to loss you cannot absorb.

  • A micro UMKM with one site and 1,000 customer records can face breach notice cost around 20 to 50 million for legal, forensics, and call center for a small scope. A limit of 500 million to 1 billion can handle that plus a short interruption.
  • A small UMKM with 5 to 20 staff, 10,000 records, and daily online sales of 10 to 30 million may want 1 to 2 billion so business interruption for 3 to 5 days stays inside.
  • A personal buyer who wants fraud and identity restoration can live with 50 to 250 million with sublimits per event.

Premium bands in the Indonesian market in 2025 to 2026 for context, not a quote:

  • Personal and family cyber endorsement: 300 thousand to 1.5 million per year.
  • Micro UMKM standalone cyber 500 million to 1 billion limit: 2 to 6 million per year.
  • Small UMKM 1 to 2 billion limit: 6 to 20 million per year, depending on revenue, sector, and controls.

E-commerce, fintech, health, and education pay more per limit because they hold more sensitive data.

The insurer prices from your proposal answers. MFA on email and on admin panels, offline backup tested, patch within 30 days, no open RDP, and a short incident plan reduce premium and also improve claim acceptance.

Security hygiene the insurer expects before it binds cover

You fill a proposal that asks 10 to 30 questions. Treat each answer as a warranty you will keep for the policy year. The common list:

  • You use MFA for email, for cloud admin, and for remote access.
  • You keep offline or immutable backup for critical data and you test restore quarterly.
  • You patch OS and apps within 30 days of a high severity update.
  • You use endpoint protection on laptops and phones that access business data.
  • You train staff to verify transfer requests with a second channel.
  • You encrypt personal data at rest for customer records.
  • You have an incident contact list and a vendor you can call.

The insurer can ask for a short external scan. The scan checks open ports, exposed admin panels, and known CVEs. Close what the scan flags before you bind.

For an individual, the insurer expects far less, often just device lock and updated OS, but still read the conditions.

The claim flow that keeps your payout alive

A claim fails more often from late notice and poor evidence than from the wording itself. Follow this order when you suspect an event.

Hour 0 to 1: Contain without destroying evidence. Disconnect the affected laptop from Wi-Fi, but do not wipe. Take photos of ransom notes or error screens. Note time.

Hour 1: Call the insurer hotline before you call a random IT friend. Most cyber policies require you to use a panel vendor or to get consent before you incur cost. A call to the hotline opens the claim and connects you to the approved forensics and legal counsel. Cost you incur with panel vendors gets reimbursed smoother than cost from a vendor you chose without notice.

Hour 1 to 4: Preserve logs. Save router logs, cloud audit logs, email headers, and the ransom sample. Copy to a separate drive. Keep the original. Forensics needs that chain.

Hour 4 to 24: Scope and notify. Forensics scopes how many records were accessed. Counsel advises if the event triggers UU PDP notification. Notify the authority and affected persons within the window with drafts counsel approves. Keep all drafts.

Day 2 to 7: Restore with approval. Rebuild from clean backup, reset credentials, and reimage affected devices with insurer consent. Keep invoices for every vendor.

Throughout: Keep a single timeline file. That file lists who did what at which time, which devices were touched, which cost was approved. The adjuster asks for that file.

When you should not buy cyber insurance and what you do instead

Not every risk needs a transfer.

  • You hold no customer personal data beyond a marketplace that already handles it. You sell only via Tokopedia and Shopee and keep no customer sheet locally. Your residual cyber risk is small. Use the premium to buy MFA hardware keys and a backup drive instead.
  • You cannot meet the security conditions without help and you have no time to fix them. A policy that excludes claims for failure to maintain MFA will not pay when MFA is missing. Fix MFA and backup first, then buy.
  • Your max loss is low enough to self-fund. If two days of sales loss plus one forensics visit is 20 million and you keep 30 million emergency cash, you can self-insure and review next year.

For many UMKM, a better first spend is a 5-hour hardening sprint that satisfies the insurer questionnaire, then a small limit policy that covers notice and forensics so a single breach does not wipe cash flow.

How you compare two wordings side by side

Take two proposals and check the same ten lines.

  • Headline limit and each sublimit for forensics, legal, notification, ransom, business interruption, crime.
  • Deductible or retention per event and per claim.
  • Waiting period for business interruption.
  • Retroactive date.
  • Consent clause for vendors.
  • Security conditions and what breach of condition does to the claim.
  • Definition of cyber event and does it include social engineering, dependent system failure, and cloud outage.
  • Territory and jurisdiction.
  • Panel vendor list and can you use your own counsel.
  • Renewal condition after a claim.

The cheaper premium with a 25 million deductible and a 50 million forensics sublimit can leave you with more out-of-pocket than a higher premium with a 5 million deductible and a 200 million forensics sublimit.

Who to talk to and what to bring to the meeting

Bring three items to the broker meeting.

  • A one-page asset list: domain, cloud provider, POS, number of customer records, where you store KTP or payment data if any, backup method and last restore test date.
  • A one-page control list: which systems have MFA, patch cadence, endpoint product, admin count.
  • A one-page loss estimate: daily sales you lose if the shop is down 3 days, cost to notify 1,000 customers, cost for one forensics visit in your city.

With that, the broker can place you in a market that fits, not just the cheapest market.

Checklist before you pay premium

  • You inventory where personal data lives and how you back it up.
  • You enable MFA on email, on cloud, on marketplace admin, on bank portals.
  • You test one restore from backup and note the date.
  • You close open RDP and exposed admin panels on the router scan.
  • You write a one-page incident plan with names and phone numbers and with the insurer hotline.
  • You buy a limit that covers notice and forensics for the actual record count you hold.
  • You read the exclusions and you know which social engineering loss needs an endorsement.
  • You store the policy PDF where two people can find it without a login that may be locked during an incident.

Why cyber insurance matters for AdSense and for business continuity

A breach that triggers a PDP notification forces you to pause ads and to handle customer calls for days. Ad revenue dips while your site is marked for review. Insurers that cover PR and notification let you keep a vendor on the phones while you rebuild, which protects customer trust and lets ads return faster. That link between cover and continuity is why a small limit can still carry outsized value for a content or commerce site.

Sources and where you verify further

  • OJK regulations on insurance product approval and broker licensing
  • UU PDP No. 27/2022 articles on breach notification and controller obligations
  • Advisories from BRI Insurance, ACA, Sinarmas on standalone cyber product summaries 2024 to 2025
  • Lloyd market cyber wording guidance on war exclusion and ransom coverage
  • ENISA and NIST IR guidance on incident response cost categories
  • Local broker case notes on UMKM claims in Jakarta and Surabaya 2023 to 2025

You buy cyber insurance for the cost you cannot fund alone, not for the risk you can fix with a free toggle. Fix MFA and backup first, then pick a limit that funds a single breach notice and a short outage. That order gives you a policy that pays when you need it.

About the author

Syukra
SyukraIndependent Cybersecurity Researcher

Saya riset threat intelligence dan hardening. Saya pakai Microsoft DR, Verizon DBIR, FBI IC3, ENISA sebagai sumber primer. Saya uji panduan di perangkat saya.

Comments

comments powered by Disqus