Risk Management Strategies

Bajaj Auto's Ransomware Disclosure and the OT Gap in Indian Manufacturing Cyber Policies

Bajaj Auto's June 2026 ransomware incident, reported to CERT-In and following a breach at Tata Electronics, has put manufacturing cyber resilience back in focus. Most Indian cyber wordings were drafted for data loss, and the definition of computer system, the waiting period and the notification condition decide what a manufacturer actually recovers.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
9 min read

Listen to this article

Audio version • 9 min read

ransomwareoperational technologycyber business interruptioncert-inmanufacturing

Last reviewed: August 2026

What Bajaj Auto Disclosed, and What It Leaves Open About the Plant

Bajaj Auto disclosed a ransomware attack that began on 23 June 2026 at around 8:00 am IST, affecting systems at Bajaj Auto and at Bajaj Auto Technology Limited, its technology subsidiary. The company reported the incident to CERT-In. Reporting by The Record in August 2026 noted that Bajaj Auto did not disclose the threat actor, whether data was stolen, or whether a ransom demand was issued, and stated that mitigation efforts had so far been successful.

CRN Asia placed the incident alongside a breach at Tata Electronics, framing both as tests of manufacturing cyber resilience in India. That framing matters for insurance. Two of India's larger manufacturing groups were hit in short succession, and the question both raise for an insurance buyer is what a cyber policy does when the affected entity makes things rather than holds records.

Bajaj Auto has not said which systems were affected, and the 8:00 am detection time does not establish that plant systems were among them. It does frame the question an underwriter should ask of any manufacturing risk. An intrusion detected at the start of a shift reaches a different set of assets from one detected on a payroll server at 2:00 am: running lines, warehouse management systems, and the machine-level controllers that feed them.

Indian Cyber Wordings Were Built Around Data, Not Machines

The Indian cyber market grew out of privacy and financial-crime exposure. The standard structure of a corporate cyber policy wording reflects that origin, and the insuring agreements typically fall into three buckets:

  • First-party breach response: forensic investigation, legal advice, notification, credit monitoring, public relations.
  • Third-party liability: claims by data subjects, regulators and contractual counterparties arising from a privacy or security failure.
  • Cyber extortion and business interruption: ransom handling and loss of net profit following an interruption to the insured's computer systems.

The first two buckets assume the loss is information. The third bucket is where a manufacturer's actual exposure lives, and it is the least standardised part of the wording. Two policies with identical headline limits can respond very differently to the same plant shutdown depending on how the trigger, the definition of computer system, and the waiting period are drafted.

For a services firm this asymmetry rarely bites, because for a bank or a BPO the IT estate is the business. For a manufacturer it bites hard. The office network can be fully restored while the plant is still down, and the office network is what the policy was written to protect.

The Definition of Computer System Decides Whether the Plant Is Inside the Policy

This is the single most consequential clause in a manufacturing cyber placement, and it is usually read last.

A narrow definition reads along the lines of computers, servers, networks and associated input and output devices, electronic data storage and related communications equipment owned or operated by the insured. Read literally, that language describes an IT estate. Programmable logic controllers, SCADA and HMI stations, distributed control systems, robotic cells, CNC machines, conveyor and AGV controllers, and the industrial gateways that link them can sit outside it, or at best sit in an argued position.

A wording built for a manufacturer says so explicitly. Look for language that names industrial control systems, operational technology, embedded systems and process control equipment, and that captures devices whether owned, leased or operated by the insured.

Three checks worth running before renewal

  1. Does the definition of computer system name operational technology or industrial control systems explicitly? If it does not, assume a claim on the plant will be argued.
  2. Does the definition extend to systems the insured operates but does not own, such as vendor-maintained line equipment and machine-builder-supplied controllers?
  3. Is there an exclusion for damage to tangible property that would sweep in physical consequences of a controller-level event, and is there a carve-back for resulting business interruption?

Waiting Period Against a Manufacturing Outage Curve

Business interruption cover under a cyber policy is time-deductible. Cover responds only after the outage exceeds the waiting period, and it pays for the indemnity period that follows.

Indian wordings cluster into three patterns:

  • Hourly waiting period, commonly 8 to 12 hours. The policyholder-favourable structure, and the one appropriate to operational-technology-heavy risks.
  • Daily waiting period, commonly 24 to 72 hours. Standard in mid-market placements and in wordings adapted from international templates.
  • Tiered structures, where forensic and response costs trigger almost immediately but business interruption itself requires the longer threshold.

The mismatch for a manufacturer is arithmetic. A plant that loses a shift loses a fixed block of units, and the loss is realised the moment production stops, not on day three. Under a 72-hour waiting period, a two-day outage that costs real money produces a nil recovery. Under a 12-hour period, the same outage recovers most of its value.

There is a second trap in how the waiting period interacts with restart. Restoring an IT system is a software event. Restoring a production line is a sequenced one: controllers are revalidated, work-in-progress is reconciled, quality checks are re-run, and output ramps rather than resumes. Ask whether the wording measures interruption to the point of system restoration or to the point of restored throughput, and whether there is an extension for the period of reduced output after systems come back. Our review of 2026 cyber BI wordings sets out how far insurers differ on these two points.

Proving a Throughput Loss When the Policy Expects Records

A breach-response claim is documented by invoices from forensic and legal vendors. A production claim is documented by evidence the insured has to construct, and insurers test it hard.

What a manufacturer needs ready before an incident, not after:

  • Baseline output data by line and by shift for at least the preceding twelve months, so lost units are measurable against a defensible run rate.
  • Standing charges analysis separating costs that continued during the outage from costs that were saved, since the recovery is loss of gross profit, not loss of revenue.
  • Make-up production records, because output recovered through overtime or weekend running reduces the claim, and insurers will look for it whether or not the insured volunteers it.
  • Order book evidence showing demand existed for the lost units, which is the point at which claims with weak commercial documentation get discounted.
  • Increased cost of working records covering expedited freight, third-party machining and temporary manual workaround costs.

The valuation basis also deserves a read. Where a cyber wording borrows consequential loss machinery from fire business interruption practice, the gross profit definition and the specified working expenses schedule may not have been re-fitted to the insured's cost structure. Where it does not borrow that machinery, the wording may pay net profit on a much thinner definition. Both happen in the Indian market, and the difference shows up only at settlement.

CERT-In's Six Hours and the Policy Notification Condition

CERT-In directions require organisations to report cyber incidents within six hours of detection, an obligation that runs alongside breach reporting under the DPDP framework. Bajaj Auto reported the June 2026 incident to CERT-In.

Cyber policies carry their own notification condition, usually requiring notice as soon as practicable and often within a stated number of days, and usually requiring insurer consent before incurring response costs or engaging vendors. These two clocks are not aligned, and they pull in different directions.

The regulatory clock forces an early, incomplete statement of facts. The policy clock rewards accuracy, because the notification and any early written account become part of the claim record. A statement filed in hour five that characterises an event in a way the forensic report later contradicts is a document the insurer will read back to the insured at settlement.

Practical sequencing

  1. Treat the CERT-In filing as a factual report of what is known at that moment, describing observed effects and detection time, without characterising cause, actor, or scope.
  2. Notify the insurer and the broker in the same window, before the picture firms up, since notification costs nothing and late notice can prejudice cover.
  3. Use the insurer's panel forensic vendor, or obtain written consent before appointing an alternative. Costs incurred without consent are commonly disallowed.
  4. Keep the CERT-In filing, the insurer notification and the internal incident log consistent. Divergence between them is the most common self-inflicted wound in a cyber claim.

Our note on incident reporting timelines covers how the reporting obligations sit together for regulated entities.

Group Structures and the Technology Subsidiary Problem

The Bajaj Auto disclosure named two entities, the parent and Bajaj Auto Technology Limited. That shape is common across Indian manufacturing groups, where a captive technology company runs the applications, the integration layer and often the plant-adjacent systems for the operating company.

It creates three questions for a placement:

  • Is the technology subsidiary a named insured? If it is a service provider to the parent rather than an insured entity, its own recovery costs may sit outside the policy.
  • If the subsidiary is not insured, does the parent have contingent or dependent business interruption cover that names it? Dependent cover written around cloud and SaaS vendors may not extend to an affiliate that is neither a named provider nor within the defined category.
  • Does the intra-group services agreement carve out liability in a way that also removes the group's subrogation recovery? Insurers will read that agreement, and a waiver of subrogation granted casually inside the group can affect the loss economics.

The same logic applies outward to tier-one suppliers. A ransomware event at a single-source component supplier stops the assembly line as effectively as an event on the insured's own controllers, and only dependent business interruption cover with an appropriate scope will respond. The supply-chain view of ransomware exposure sets out how that concentration builds up.

What to Fix at the Next Renewal

A manufacturer buying cyber insurance in the current market has more negotiating room on wording than on price. The items worth spending that room on, in order:

  1. Amend the definition of computer system to name industrial control systems, operational technology and process control equipment, covering assets owned, leased or operated by the insured.
  2. Move to an hourly waiting period of 8 to 12 hours, or a tiered structure, and price the alternative so the board sees what a 72-hour threshold costs on a realistic outage.
  3. Add a restoration and ramp-up extension so the interruption period ends at restored throughput rather than at system restoration.
  4. Name group technology entities and single-source suppliers in the dependent business interruption schedule rather than relying on categorical language.
  5. Reconcile the cyber and property placements on physical damage from a cyber cause, in writing, before the incident that tests it.
  6. Pre-agree the claim evidence pack: baseline output data, standing charges, order book and make-up production records, retained in a form that survives an encrypted network.

None of this is expensive at placement. All of it is expensive to discover during a claim, which is the point at which a manufacturer learns whether the policy it bought covers the plant or only the office.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Does a standard Indian cyber policy cover a ransomware attack that stops a production line?
Only if the wording supports it. Cover turns on whether the definition of computer system extends to industrial control systems and operational technology, whether the business interruption trigger is drafted around a security failure rather than a data event, and whether the waiting period is short enough for a plant outage measured in shifts. Many Indian wordings satisfy none of the three without amendment.
What did Bajaj Auto actually disclose about the June 2026 incident?
That a ransomware attack on 23 June 2026 at around 8:00 am IST affected systems at Bajaj Auto and Bajaj Auto Technology Limited, that the incident was reported to CERT-In, and that mitigation efforts had so far been successful. The company did not disclose the threat actor, whether data was stolen, or whether a ransom demand was issued.
How does the CERT-In six-hour reporting requirement affect a cyber claim?
CERT-In directions require reporting within six hours of detecting an incident, which forces an early filing on incomplete facts. That filing becomes part of the claim record, so it should describe observed effects and detection time without characterising cause, actor or scope. The insurer should be notified in the same window, and the regulatory filing, the insurer notification and the internal incident log should stay consistent.
What waiting period should a manufacturer buy on cyber business interruption?
An hourly waiting period of 8 to 12 hours, or a tiered structure where response costs trigger early and business interruption follows. A plant loses a fixed block of units the moment production stops, so a 24 to 72 hour threshold can wipe out the recovery on outages that were commercially significant.
Is a captive technology subsidiary covered under the parent's cyber policy?
Not automatically. Check whether the subsidiary is a named insured. If it is treated as a service provider instead, the parent needs dependent business interruption cover that names it, since categorical language written around cloud and SaaS vendors may not reach an affiliate.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform