What Surfaced in Mid-August, and Why the Entry Point Matters
On 16 August 2026 the research outfit InfoStealers published an account of what it called a massive Azure exfiltration campaign, describing millions of enterprise records pulled out of tenant directories using credentials that had already been stolen by infostealer malware. Within days the story widened. CRN Asia reported on 17 August 2026 that TCS, HCL and Hexaware were named in the leaked directory data. TechRadar on 18 August tied the dumps to an actor operating as Hatman and listed McDonald's and Vodafone among the enterprises whose Azure records appeared. Cybernews on 19 August put a number on one tranche: 1.7 million McDonald's records, in a campaign it described as reaching Fortune 500 firms.
The mechanism is the part that decides which policy pays. There is no reported platform vulnerability here. The attacker signed in. Credentials harvested from infected endpoints were replayed against tenant directory services to enumerate users, groups and attributes at scale. That is authenticated access using valid tokens, which means the usual technical controls that a due-diligence questionnaire asks about, patch cadence and perimeter hardening, would have reported green throughout.
For an Indian services firm the reason this is expensive has little to do with its own servers. The records sitting inside a service provider's tenant are frequently not its own. They are client identity data, employee directories, project artefacts and support tickets from global enterprises that contracted the vendor to run their systems. The exposure that follows travels through the master services agreement, not through the vendor's balance sheet.
The Boundary: Cyber Answers for You, Tech E&O Answers for Your Client
Most mid-size Indian technology vendors buy one cyber policy and treat it as the answer to everything with the word breach in it. The two policies actually divide along a clean line, and it is worth stating plainly before the wordings blur it.
A standalone cyber policy responds to the insured's own consequences of a security failure:
- Incident response and forensics, on the vendor's own environment
- Legal and notification cost arising from the vendor's own regulatory duties
- Data restoration, and business interruption from the vendor's own systems being unavailable
- Cyber extortion and ransom, subject to sanctions screening
- The vendor's own regulatory investigation cost, where insurable
Technology errors and omissions, sold in India as an extension of or companion to professional indemnity, responds to third-party claims arising out of the performance of the technology services. When a client asserts that the vendor failed to protect data it was engaged to handle, that is an allegation about the delivery of the professional service. The claim is against the vendor, brought by the client, and it typically bundles the client's own breach cost: its notification programme, its credit monitoring, its regulatory penalties where recoverable, its remediation, and its legal defence.
The line moves in practice because insurers now sell combined cyber and tech E&O forms with shared definitions. That is workable, and often better than two disconnected policies, provided the buyer knows which insuring agreement the client claim will be tendered under and whether that agreement carries its own sub-limit. The gap map across cyber, PI and D&O towers applies with equal force here: exposure lands where the wording sends it, not where the risk register files it.
Where the Client Contract Actually Bites
Open the MSA of any Indian vendor with US or European enterprise clients and the data protection schedule will contain some combination of the following. Each one converts a security event into a payable obligation.
- An indemnity for breach of the data protection or confidentiality obligations, usually carved out of the general liability cap so it is uncapped or capped at a multiple of fees.
- A cost-shifting clause making the vendor responsible for the client's notification, call-centre, credit-monitoring and forensic cost when the incident originated in the vendor's environment.
- A notification obligation of 24 or 48 hours from becoming aware of a security incident, defined broadly enough to include suspected unauthorised access.
- An audit and remediation right, letting the client run an assessment at the vendor's cost and require fixes on a stated timeline.
- A step-in or termination for cause right, which does not itself cost money but destroys the revenue the limit was sized against.
The commercial problem is the gap between what clients demand and what vendors carry. Enterprise procurement routinely specifies technology E&O and cyber limits at levels set with reference to the client's own risk, not the vendor's size, and a mid-size Indian provider signing a large global account may find itself contractually promising limits it has never bought. Firms sign anyway, because the deal is worth more than the deficiency appears to be until an incident tests it.
Contractual Liability: The Exclusion That Decides the Claim
Nearly every liability wording, professional indemnity and tech E&O included, excludes liability assumed under contract. The logic is sound from the underwriter's side. An insurer prices the insured's negligence, not whatever the insured agreed to promise a counterparty in a negotiation the insurer never saw.
The exclusion is then softened by a carve-back, and the drafting of that carve-back is where the claim is won or lost. Two shapes are common:
- The narrow carve-back, which preserves cover for liability the insured would have incurred in the absence of the contract. This restores nothing beyond common-law negligence. If the vendor met a reasonable standard of care but the contract imposed strict liability for any unauthorised access, the strict-liability element is uninsured.
- The broader carve-back, which extends to liability assumed under a written agreement for the provision of the technology services, sometimes with a proviso that the agreement was entered into in the ordinary course of business. This is what actually reaches a data protection indemnity.
Ask for the second, and ask in writing at quotation stage rather than after a loss. Where an insurer will not grant it outright, an achievable middle path is a scheduled-contracts endorsement naming the vendor's largest accounts, with the indemnity clause reviewed and the limit set against that specific exposure.
Liquidated damages and service-credit regimes sit outside almost every carve-back. Service credits are a pricing mechanism rather than damages for negligence, and an insurer will decline them. Vendors that negotiate hard on the credit table and softly on the indemnity have optimised the cheap number and left the expensive one alone.
The same reasoning drives contract review for smaller technology firms, covered in more detail in the note on SaaS tech E&O coverage gaps and contract negotiation.
Two Notification Clocks, Running at Different Speeds
A credential-theft event of the Azure type puts an Indian vendor under several simultaneous duties, and they do not align.
CERT-In. The directions issued under section 70B(6) of the Information Technology Act, 2000, in force since 2022, require reporting of specified cyber incidents, including unauthorised access to IT systems and data breaches, within six hours of noticing them. This runs whether or not the affected data belongs to the vendor.
DPDP. Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, a Data Fiduciary must inform each affected Data Principal of a personal data breach without delay, and must give the Data Protection Board of India the detailed particulars within 72 hours of becoming aware. Failure to take reasonable security safeguards carries a penalty of up to INR 250 crore, and failure to notify up to INR 200 crore.
The role question matters here. For data processed on a client's instructions the Indian vendor is generally a Data Processor, and the notification duty to Data Principals rests with the client as Data Fiduciary. For the vendor's own employee and contractor data, the same breach makes it a Data Fiduciary in its own right, with the full duty and the full penalty exposure. One incident, two capacities.
The MSA. A 24-hour contractual notice runs from a different trigger, usually awareness of a suspected incident, and it runs to the client, not to a regulator. Missing it is a breach of contract that can prejudice the indemnity and, separately, prejudice notice under the tech E&O policy if the insurer was told late because the internal process was built around the regulatory clock.
Build one incident playbook with three parallel tracks rather than a sequential escalation. The six-hour CERT-In filing, the client notice, and the notification to brokers and insurers should all start from the same trigger, because the tech E&O policy is claims-made and notice of circumstances is what preserves the right to indemnity later.
The Four Checks in the Vendor's Tower
After an event of this shape, or before it during renewal, these are the four items to verify. Each has produced declined claims in the Indian market.
Check one: the retroactive date. Tech E&O and professional indemnity are claims-made with a retroactive date. Credential theft is slow. Infostealer logs traded in 2024 are being replayed in 2026, and the negligent act, the failure to enforce phishing-resistant multi-factor authentication on a contractor account, may predate the current policy by years. A retroactive date set at the inception of the current insurer's relationship, rather than at the start of continuous cover, silently excludes the very acts that caused the loss. Check that continuity was preserved through every insurer change.
Check two: the contractual liability carve-back. As set out above. Read the exclusion and the carve-back together, and test them against the actual indemnity clause in the two or three largest client contracts.
Check three: the definition of professional services. This is the coverage trigger. A definition drawn as "software development and information technology consultancy" may not obviously cover managed hosting, identity administration, or an offshore delivery centre running the client's own tenant. Where the vendor administers a client's cloud environment, the definition must say so. The alternative is an insurer arguing that directory administration was not a professional service as defined, at the moment the claim depends on it.
Check four: shared limit or separate towers. A combined cyber and tech E&O form frequently carries one aggregate across both. A serious incident spends the first-party budget on forensics, notification and restoration, and the client claim then arrives against a depleted limit twelve months later. Ask explicitly whether the limits stack or share, model the depletion, and price a separate tech E&O tower if the client contracts justify it.
Sizing the tower against a modelled number rather than a peer benchmark is the subject of the note on cyber limit sizing with loss-exceedance modelling; the same method applies to the third-party side once the indemnity clauses are quantified.
Buying Into a Falling Market Without Buying the Wrong Thing
The pricing backdrop is unusually favourable. CNBC TV18 reported on 12 August 2026, citing Marsh data, that Indian commercial insurance rates fell sharply in the second quarter, with cyber cover down 25 to 30 per cent. Capacity is available and underwriters are competing.
A soft market rewards buyers who ask for wording rather than discount. The saving on the cyber line can fund a properly scoped tech E&O tower, a broadened contractual liability carve-back, a professional services definition that matches the delivery model, and a retroactive date extension. None of those show up on a premium comparison, and all of them decide whether a client indemnity is paid.
The infrastructure side is moving the same way. Inc42's 20 August 2026 piece on India's data centre buildout described a security blind spot growing alongside capacity, which is the same story at a different layer: identity and credential hygiene lagging the pace of expansion. For vendors operating client environments in Indian facilities, the diligence questions clients ask in 2027 will be about privileged access and token lifetime, not about firewalls.
At renewal, bring the indemnity clauses from your three largest client contracts to the underwriter. A vendor that can show what it has actually promised, and to whom, gets better carve-back terms than one that presents a proposal form and a turnover figure. Cross-border exposure adds a further layer, addressed in the note on Indian IT companies and cyber liability in US and UK jurisdictions.
