What Bajaj Auto Disclosed, and What It Leaves Open About the Plant
Bajaj Auto disclosed a ransomware attack that began on 23 June 2026 at around 8:00 am IST, affecting systems at Bajaj Auto and at Bajaj Auto Technology Limited, its technology subsidiary. The company reported the incident to CERT-In. Reporting by The Record in August 2026 noted that Bajaj Auto did not disclose the threat actor, whether data was stolen, or whether a ransom demand was issued, and stated that mitigation efforts had so far been successful.
CRN Asia placed the incident alongside a breach at Tata Electronics, framing both as tests of manufacturing cyber resilience in India. That framing matters for insurance. Two of India's larger manufacturing groups were hit in short succession, and the question both raise for an insurance buyer is what a cyber policy does when the affected entity makes things rather than holds records.
Bajaj Auto has not said which systems were affected, and the 8:00 am detection time does not establish that plant systems were among them. It does frame the question an underwriter should ask of any manufacturing risk. An intrusion detected at the start of a shift reaches a different set of assets from one detected on a payroll server at 2:00 am: running lines, warehouse management systems, and the machine-level controllers that feed them.
Indian Cyber Wordings Were Built Around Data, Not Machines
The Indian cyber market grew out of privacy and financial-crime exposure. The standard structure of a corporate cyber policy wording reflects that origin, and the insuring agreements typically fall into three buckets:
- First-party breach response: forensic investigation, legal advice, notification, credit monitoring, public relations.
- Third-party liability: claims by data subjects, regulators and contractual counterparties arising from a privacy or security failure.
- Cyber extortion and business interruption: ransom handling and loss of net profit following an interruption to the insured's computer systems.
The first two buckets assume the loss is information. The third bucket is where a manufacturer's actual exposure lives, and it is the least standardised part of the wording. Two policies with identical headline limits can respond very differently to the same plant shutdown depending on how the trigger, the definition of computer system, and the waiting period are drafted.
For a services firm this asymmetry rarely bites, because for a bank or a BPO the IT estate is the business. For a manufacturer it bites hard. The office network can be fully restored while the plant is still down, and the office network is what the policy was written to protect.
The Definition of Computer System Decides Whether the Plant Is Inside the Policy
This is the single most consequential clause in a manufacturing cyber placement, and it is usually read last.
A narrow definition reads along the lines of computers, servers, networks and associated input and output devices, electronic data storage and related communications equipment owned or operated by the insured. Read literally, that language describes an IT estate. Programmable logic controllers, SCADA and HMI stations, distributed control systems, robotic cells, CNC machines, conveyor and AGV controllers, and the industrial gateways that link them can sit outside it, or at best sit in an argued position.
A wording built for a manufacturer says so explicitly. Look for language that names industrial control systems, operational technology, embedded systems and process control equipment, and that captures devices whether owned, leased or operated by the insured.
Three checks worth running before renewal
- Does the definition of computer system name operational technology or industrial control systems explicitly? If it does not, assume a claim on the plant will be argued.
- Does the definition extend to systems the insured operates but does not own, such as vendor-maintained line equipment and machine-builder-supplied controllers?
- Is there an exclusion for damage to tangible property that would sweep in physical consequences of a controller-level event, and is there a carve-back for resulting business interruption?
Waiting Period Against a Manufacturing Outage Curve
Business interruption cover under a cyber policy is time-deductible. Cover responds only after the outage exceeds the waiting period, and it pays for the indemnity period that follows.
Indian wordings cluster into three patterns:
- Hourly waiting period, commonly 8 to 12 hours. The policyholder-favourable structure, and the one appropriate to operational-technology-heavy risks.
- Daily waiting period, commonly 24 to 72 hours. Standard in mid-market placements and in wordings adapted from international templates.
- Tiered structures, where forensic and response costs trigger almost immediately but business interruption itself requires the longer threshold.
The mismatch for a manufacturer is arithmetic. A plant that loses a shift loses a fixed block of units, and the loss is realised the moment production stops, not on day three. Under a 72-hour waiting period, a two-day outage that costs real money produces a nil recovery. Under a 12-hour period, the same outage recovers most of its value.
There is a second trap in how the waiting period interacts with restart. Restoring an IT system is a software event. Restoring a production line is a sequenced one: controllers are revalidated, work-in-progress is reconciled, quality checks are re-run, and output ramps rather than resumes. Ask whether the wording measures interruption to the point of system restoration or to the point of restored throughput, and whether there is an extension for the period of reduced output after systems come back. Our review of 2026 cyber BI wordings sets out how far insurers differ on these two points.
Proving a Throughput Loss When the Policy Expects Records
A breach-response claim is documented by invoices from forensic and legal vendors. A production claim is documented by evidence the insured has to construct, and insurers test it hard.
What a manufacturer needs ready before an incident, not after:
- Baseline output data by line and by shift for at least the preceding twelve months, so lost units are measurable against a defensible run rate.
- Standing charges analysis separating costs that continued during the outage from costs that were saved, since the recovery is loss of gross profit, not loss of revenue.
- Make-up production records, because output recovered through overtime or weekend running reduces the claim, and insurers will look for it whether or not the insured volunteers it.
- Order book evidence showing demand existed for the lost units, which is the point at which claims with weak commercial documentation get discounted.
- Increased cost of working records covering expedited freight, third-party machining and temporary manual workaround costs.
The valuation basis also deserves a read. Where a cyber wording borrows consequential loss machinery from fire business interruption practice, the gross profit definition and the specified working expenses schedule may not have been re-fitted to the insured's cost structure. Where it does not borrow that machinery, the wording may pay net profit on a much thinner definition. Both happen in the Indian market, and the difference shows up only at settlement.
CERT-In's Six Hours and the Policy Notification Condition
CERT-In directions require organisations to report cyber incidents within six hours of detection, an obligation that runs alongside breach reporting under the DPDP framework. Bajaj Auto reported the June 2026 incident to CERT-In.
Cyber policies carry their own notification condition, usually requiring notice as soon as practicable and often within a stated number of days, and usually requiring insurer consent before incurring response costs or engaging vendors. These two clocks are not aligned, and they pull in different directions.
The regulatory clock forces an early, incomplete statement of facts. The policy clock rewards accuracy, because the notification and any early written account become part of the claim record. A statement filed in hour five that characterises an event in a way the forensic report later contradicts is a document the insurer will read back to the insured at settlement.
Practical sequencing
- Treat the CERT-In filing as a factual report of what is known at that moment, describing observed effects and detection time, without characterising cause, actor, or scope.
- Notify the insurer and the broker in the same window, before the picture firms up, since notification costs nothing and late notice can prejudice cover.
- Use the insurer's panel forensic vendor, or obtain written consent before appointing an alternative. Costs incurred without consent are commonly disallowed.
- Keep the CERT-In filing, the insurer notification and the internal incident log consistent. Divergence between them is the most common self-inflicted wound in a cyber claim.
Our note on incident reporting timelines covers how the reporting obligations sit together for regulated entities.
Group Structures and the Technology Subsidiary Problem
The Bajaj Auto disclosure named two entities, the parent and Bajaj Auto Technology Limited. That shape is common across Indian manufacturing groups, where a captive technology company runs the applications, the integration layer and often the plant-adjacent systems for the operating company.
It creates three questions for a placement:
- Is the technology subsidiary a named insured? If it is a service provider to the parent rather than an insured entity, its own recovery costs may sit outside the policy.
- If the subsidiary is not insured, does the parent have contingent or dependent business interruption cover that names it? Dependent cover written around cloud and SaaS vendors may not extend to an affiliate that is neither a named provider nor within the defined category.
- Does the intra-group services agreement carve out liability in a way that also removes the group's subrogation recovery? Insurers will read that agreement, and a waiver of subrogation granted casually inside the group can affect the loss economics.
The same logic applies outward to tier-one suppliers. A ransomware event at a single-source component supplier stops the assembly line as effectively as an event on the insured's own controllers, and only dependent business interruption cover with an appropriate scope will respond. The supply-chain view of ransomware exposure sets out how that concentration builds up.
What to Fix at the Next Renewal
A manufacturer buying cyber insurance in the current market has more negotiating room on wording than on price. The items worth spending that room on, in order:
- Amend the definition of computer system to name industrial control systems, operational technology and process control equipment, covering assets owned, leased or operated by the insured.
- Move to an hourly waiting period of 8 to 12 hours, or a tiered structure, and price the alternative so the board sees what a 72-hour threshold costs on a realistic outage.
- Add a restoration and ramp-up extension so the interruption period ends at restored throughput rather than at system restoration.
- Name group technology entities and single-source suppliers in the dependent business interruption schedule rather than relying on categorical language.
- Reconcile the cyber and property placements on physical damage from a cyber cause, in writing, before the incident that tests it.
- Pre-agree the claim evidence pack: baseline output data, standing charges, order book and make-up production records, retained in a form that survives an encrypted network.
None of this is expensive at placement. All of it is expensive to discover during a claim, which is the point at which a manufacturer learns whether the policy it bought covers the plant or only the office.
