Risk Management Strategies

Indian IT Majors Turned Up in an Azure Credential Leak. The Bill Lands on Tech E&O, Not the Cyber Policy

TCS, HCL and Hexaware were named in an August 2026 Azure exfiltration campaign driven by infostealer credentials. For an Indian IT vendor the expensive exposure is the client indemnity, which answers under technology errors and omissions rather than the cyber policy.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

cyber insurancetechnology E&OIT servicesDPDP Actcontractual indemnityvendor risk

Last reviewed: September 2026

What Surfaced in Mid-August, and Why the Entry Point Matters

On 16 August 2026 the research outfit InfoStealers published an account of what it called a massive Azure exfiltration campaign, describing millions of enterprise records pulled out of tenant directories using credentials that had already been stolen by infostealer malware. Within days the story widened. CRN Asia reported on 17 August 2026 that TCS, HCL and Hexaware were named in the leaked directory data. TechRadar on 18 August tied the dumps to an actor operating as Hatman and listed McDonald's and Vodafone among the enterprises whose Azure records appeared. Cybernews on 19 August put a number on one tranche: 1.7 million McDonald's records, in a campaign it described as reaching Fortune 500 firms.

The mechanism is the part that decides which policy pays. There is no reported platform vulnerability here. The attacker signed in. Credentials harvested from infected endpoints were replayed against tenant directory services to enumerate users, groups and attributes at scale. That is authenticated access using valid tokens, which means the usual technical controls that a due-diligence questionnaire asks about, patch cadence and perimeter hardening, would have reported green throughout.

For an Indian services firm the reason this is expensive has little to do with its own servers. The records sitting inside a service provider's tenant are frequently not its own. They are client identity data, employee directories, project artefacts and support tickets from global enterprises that contracted the vendor to run their systems. The exposure that follows travels through the master services agreement, not through the vendor's balance sheet.

The Boundary: Cyber Answers for You, Tech E&O Answers for Your Client

Most mid-size Indian technology vendors buy one cyber policy and treat it as the answer to everything with the word breach in it. The two policies actually divide along a clean line, and it is worth stating plainly before the wordings blur it.

A standalone cyber policy responds to the insured's own consequences of a security failure:

  • Incident response and forensics, on the vendor's own environment
  • Legal and notification cost arising from the vendor's own regulatory duties
  • Data restoration, and business interruption from the vendor's own systems being unavailable
  • Cyber extortion and ransom, subject to sanctions screening
  • The vendor's own regulatory investigation cost, where insurable

Technology errors and omissions, sold in India as an extension of or companion to professional indemnity, responds to third-party claims arising out of the performance of the technology services. When a client asserts that the vendor failed to protect data it was engaged to handle, that is an allegation about the delivery of the professional service. The claim is against the vendor, brought by the client, and it typically bundles the client's own breach cost: its notification programme, its credit monitoring, its regulatory penalties where recoverable, its remediation, and its legal defence.

The line moves in practice because insurers now sell combined cyber and tech E&O forms with shared definitions. That is workable, and often better than two disconnected policies, provided the buyer knows which insuring agreement the client claim will be tendered under and whether that agreement carries its own sub-limit. The gap map across cyber, PI and D&O towers applies with equal force here: exposure lands where the wording sends it, not where the risk register files it.

Where the Client Contract Actually Bites

Open the MSA of any Indian vendor with US or European enterprise clients and the data protection schedule will contain some combination of the following. Each one converts a security event into a payable obligation.

  1. An indemnity for breach of the data protection or confidentiality obligations, usually carved out of the general liability cap so it is uncapped or capped at a multiple of fees.
  2. A cost-shifting clause making the vendor responsible for the client's notification, call-centre, credit-monitoring and forensic cost when the incident originated in the vendor's environment.
  3. A notification obligation of 24 or 48 hours from becoming aware of a security incident, defined broadly enough to include suspected unauthorised access.
  4. An audit and remediation right, letting the client run an assessment at the vendor's cost and require fixes on a stated timeline.
  5. A step-in or termination for cause right, which does not itself cost money but destroys the revenue the limit was sized against.

The commercial problem is the gap between what clients demand and what vendors carry. Enterprise procurement routinely specifies technology E&O and cyber limits at levels set with reference to the client's own risk, not the vendor's size, and a mid-size Indian provider signing a large global account may find itself contractually promising limits it has never bought. Firms sign anyway, because the deal is worth more than the deficiency appears to be until an incident tests it.

Contractual Liability: The Exclusion That Decides the Claim

Nearly every liability wording, professional indemnity and tech E&O included, excludes liability assumed under contract. The logic is sound from the underwriter's side. An insurer prices the insured's negligence, not whatever the insured agreed to promise a counterparty in a negotiation the insurer never saw.

The exclusion is then softened by a carve-back, and the drafting of that carve-back is where the claim is won or lost. Two shapes are common:

  • The narrow carve-back, which preserves cover for liability the insured would have incurred in the absence of the contract. This restores nothing beyond common-law negligence. If the vendor met a reasonable standard of care but the contract imposed strict liability for any unauthorised access, the strict-liability element is uninsured.
  • The broader carve-back, which extends to liability assumed under a written agreement for the provision of the technology services, sometimes with a proviso that the agreement was entered into in the ordinary course of business. This is what actually reaches a data protection indemnity.

Ask for the second, and ask in writing at quotation stage rather than after a loss. Where an insurer will not grant it outright, an achievable middle path is a scheduled-contracts endorsement naming the vendor's largest accounts, with the indemnity clause reviewed and the limit set against that specific exposure.

Liquidated damages and service-credit regimes sit outside almost every carve-back. Service credits are a pricing mechanism rather than damages for negligence, and an insurer will decline them. Vendors that negotiate hard on the credit table and softly on the indemnity have optimised the cheap number and left the expensive one alone.

The same reasoning drives contract review for smaller technology firms, covered in more detail in the note on SaaS tech E&O coverage gaps and contract negotiation.

Two Notification Clocks, Running at Different Speeds

A credential-theft event of the Azure type puts an Indian vendor under several simultaneous duties, and they do not align.

CERT-In. The directions issued under section 70B(6) of the Information Technology Act, 2000, in force since 2022, require reporting of specified cyber incidents, including unauthorised access to IT systems and data breaches, within six hours of noticing them. This runs whether or not the affected data belongs to the vendor.

DPDP. Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, a Data Fiduciary must inform each affected Data Principal of a personal data breach without delay, and must give the Data Protection Board of India the detailed particulars within 72 hours of becoming aware. Failure to take reasonable security safeguards carries a penalty of up to INR 250 crore, and failure to notify up to INR 200 crore.

The role question matters here. For data processed on a client's instructions the Indian vendor is generally a Data Processor, and the notification duty to Data Principals rests with the client as Data Fiduciary. For the vendor's own employee and contractor data, the same breach makes it a Data Fiduciary in its own right, with the full duty and the full penalty exposure. One incident, two capacities.

The MSA. A 24-hour contractual notice runs from a different trigger, usually awareness of a suspected incident, and it runs to the client, not to a regulator. Missing it is a breach of contract that can prejudice the indemnity and, separately, prejudice notice under the tech E&O policy if the insurer was told late because the internal process was built around the regulatory clock.

Build one incident playbook with three parallel tracks rather than a sequential escalation. The six-hour CERT-In filing, the client notice, and the notification to brokers and insurers should all start from the same trigger, because the tech E&O policy is claims-made and notice of circumstances is what preserves the right to indemnity later.

The Four Checks in the Vendor's Tower

After an event of this shape, or before it during renewal, these are the four items to verify. Each has produced declined claims in the Indian market.

Check one: the retroactive date. Tech E&O and professional indemnity are claims-made with a retroactive date. Credential theft is slow. Infostealer logs traded in 2024 are being replayed in 2026, and the negligent act, the failure to enforce phishing-resistant multi-factor authentication on a contractor account, may predate the current policy by years. A retroactive date set at the inception of the current insurer's relationship, rather than at the start of continuous cover, silently excludes the very acts that caused the loss. Check that continuity was preserved through every insurer change.

Check two: the contractual liability carve-back. As set out above. Read the exclusion and the carve-back together, and test them against the actual indemnity clause in the two or three largest client contracts.

Check three: the definition of professional services. This is the coverage trigger. A definition drawn as "software development and information technology consultancy" may not obviously cover managed hosting, identity administration, or an offshore delivery centre running the client's own tenant. Where the vendor administers a client's cloud environment, the definition must say so. The alternative is an insurer arguing that directory administration was not a professional service as defined, at the moment the claim depends on it.

Check four: shared limit or separate towers. A combined cyber and tech E&O form frequently carries one aggregate across both. A serious incident spends the first-party budget on forensics, notification and restoration, and the client claim then arrives against a depleted limit twelve months later. Ask explicitly whether the limits stack or share, model the depletion, and price a separate tech E&O tower if the client contracts justify it.

Sizing the tower against a modelled number rather than a peer benchmark is the subject of the note on cyber limit sizing with loss-exceedance modelling; the same method applies to the third-party side once the indemnity clauses are quantified.

Buying Into a Falling Market Without Buying the Wrong Thing

The pricing backdrop is unusually favourable. CNBC TV18 reported on 12 August 2026, citing Marsh data, that Indian commercial insurance rates fell sharply in the second quarter, with cyber cover down 25 to 30 per cent. Capacity is available and underwriters are competing.

A soft market rewards buyers who ask for wording rather than discount. The saving on the cyber line can fund a properly scoped tech E&O tower, a broadened contractual liability carve-back, a professional services definition that matches the delivery model, and a retroactive date extension. None of those show up on a premium comparison, and all of them decide whether a client indemnity is paid.

The infrastructure side is moving the same way. Inc42's 20 August 2026 piece on India's data centre buildout described a security blind spot growing alongside capacity, which is the same story at a different layer: identity and credential hygiene lagging the pace of expansion. For vendors operating client environments in Indian facilities, the diligence questions clients ask in 2027 will be about privileged access and token lifetime, not about firewalls.

At renewal, bring the indemnity clauses from your three largest client contracts to the underwriter. A vendor that can show what it has actually promised, and to whom, gets better carve-back terms than one that presents a proposal form and a turnover figure. Cross-border exposure adds a further layer, addressed in the note on Indian IT companies and cyber liability in US and UK jurisdictions.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Our cyber policy has a third-party liability section. Is that not the same as tech E&O?
It overlaps but rarely matches. The third-party section of a cyber policy typically responds to privacy liability, meaning claims by individuals whose data was exposed and related regulatory proceedings. A client claim under a master services agreement is a claim about the performance of the contracted service, and insurers often route it to the professional services insuring agreement instead. Where the two sit in one form, confirm in writing which agreement responds and whether it carries a separate sub-limit.
We are a Data Processor for client data. Does the DPDP penalty exposure sit with the client?
The notification duty to Data Principals and the primary DPDP obligations rest with the Data Fiduciary, which for client data is usually the client. Two things follow anyway. The processing agreement will normally pass the cost of that failure back to the vendor by indemnity, which is a contractual liability question rather than a regulatory one. And the vendor remains a Data Fiduciary for its own employee, contractor and candidate data, so the same incident can create direct DPDP exposure in that capacity.
How much technology E&O limit should a mid-size Indian IT services firm carry?
Start from the contracts rather than from turnover. Take the largest three or four client agreements, extract the liability cap and the data protection indemnity, note which ones are uncapped, and add the client's plausible notification and remediation cost given the record counts held. That produces a defensible figure. Benchmarking against peer revenue produces a number that has no relationship to what has actually been promised.
The breach came from stolen credentials on a contractor's laptop, not from our systems. Does that change the coverage position?
It does not help as much as vendors expect. Under most master services agreements the vendor is responsible for personnel and subcontractors accessing the client environment, so the indemnity engages regardless of whose device was infected. On the insurance side the question becomes whether the contractor falls within the definition of insured or of employee. Check that contractors and offshore delivery staff are captured, because a wording drawn around permanent employees can leave the exact population that caused the loss outside the policy.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform