Risk Management Strategies

TCS and HCLTech Both Said There Was No Breach. An Unverified Leak-Site Claim Can Still Start Your Notification Clock

Two Indian IT majors publicly rejected hacker claims about employee data in August 2026. An unverified allegation can still be a notifiable circumstance under claims-made cyber, D&O and tech E&O wordings, and the public denial becomes evidence of what the insured knew and when.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
11 min read

Listen to this article

Audio version • 11 min read

cyber insuranceclaims-madenotification of circumstancesDPDP Actincident responsedisclosure

Last reviewed: September 2026

Two Denials in Three Days, and the Event Most Indian Corporates Actually Face

In the second week of August 2026, two of India's largest IT services firms publicly rejected hacker claims about exposed employee data. The New Indian Express reported on 10 August 2026 that TCS said there was no credible evidence of a breach after employee data exposure claims surfaced, and The Times of India reported on 11 August 2026 that TCS had flagged the claims and found no breach. CRN Asia reported the same day that TCS described the leaked employee data as appearing to be over four years old. Business Standard reported on 11 August 2026 that HCLTech saw no evidence of a breach or impact on clients, and The Indian Express reported on 12 August 2026 that HCLTech said any stolen data may be years old.

Set aside whether either claim was true. The shape of the event is what matters, because it is the shape most Indian corporates meet before they ever meet a confirmed intrusion: a post on a leak site, a sample file, journalists asking for comment, no forensic confirmation, and a board that would rather say nothing until it knows something.

That is a difficult position, because the insurance consequences start running on facts that look nothing like a loss. Nobody has sued, no regulator has written, no system is down. What exists is an allegation, a date on which the company became aware of it, and an internal view forming about whether it is credible. Under a claims-made policy, those three things can already be enough.

The failure mode is rarely a badly worded press line. It is that the company spends four weeks deciding whether anything happened, concludes nothing did, files nothing with insurers, and then receives a legal notice in month seven from a former employee whose salary data was in the sample. The insurer then asks a simple question with an expensive answer: when did you first become aware of circumstances that might reasonably give rise to a claim?

Claims-Made Cover Turns on Notice, Not on Whether a Breach Happened

Cyber, D&O and technology errors and omissions covers in the Indian market are written on a claims-made basis: cover attaches when a claim is first made against the insured during the policy period and notified as the policy requires, not when the wrongful act occurred. Our post on claims-made, occurrence and the retroactive date sets out the trigger mechanics.

The part that gets missed is the second limb. Nearly every claims-made wording carries a notification of circumstances provision: if during the policy period the insured becomes aware of any circumstance that may reasonably be expected to give rise to a claim, and gives written notice of that circumstance with full particulars during the policy period, any claim later arising from it is deemed to have been first made in the year notice was given.

Three consequences follow, and together they are the argument for taking an unverified leak-site post seriously.

  • The trigger is awareness of a circumstance, not proof of a breach. A credible public allegation that identifiable employee or customer data is in a criminal's hands can be a circumstance, whatever the forensics later show. The provision exists to catch what has not yet crystallised into a demand.
  • The notice locks any later claim into the current year's limit, retention and terms. If the claim lands two renewals later, into a market that has since added a data-exfiltration sub-limit or a wider exclusion, the deemed-notice mechanism is what protects the insured from the worse wording.
  • The window closes at expiry. A circumstance known in the 2026 to 2027 year and not notified is, on most wordings, not notifiable in the 2027 to 2028 year either, because the prior-known-circumstances exclusion in the renewal bites. Silence does not defer the problem, it destroys cover in both years.

One Allegation, Three Towers, Three Different Wordings

A leak-site post naming a listed company is not one insurance issue. It is at least three, and the trigger language differs in each.

  1. Cyber. The heads are privacy liability to affected data principals, regulatory defence costs under Indian or foreign data protection law, incident response and forensic costs, and in some wordings notification costs. The circumstance is the alleged unauthorised access itself.
  2. Directors and officers. The exposure is the response, not the intrusion. A securities or shareholder allegation that the company's statements about data security, about the incident, or about the adequacy of its controls were misleading is a management liability claim, and it can survive even if the underlying breach never happened. The circumstance is the statement and the process behind it.
  3. Technology errors and omissions and professional indemnity. For a firm holding client data under contract, the loss that bites is client-facing: contractual indemnity claims, audit and remediation costs demanded by customers, and claims for failure to meet contracted security standards. The circumstance is the client data allegedly exposed.

The three towers are commonly placed with different insurers, sometimes different brokers, and their circumstance wordings are rarely aligned. A cyber policy may require notice "as soon as practicable", a D&O policy may allow notice of circumstances only at the insured's election, and a tech errors and omissions policy may set a hard number of days from awareness. Reading all three before an incident and mapping the shortest clock is the highest-value hour a risk manager spends all year. Our cyber incident response and insurance claims playbook covers the operational side of that mapping, and for firms with US and UK client bases the cyber liability exposure in US and UK jurisdictions post sets out the foreign-proceedings overlay.

The Awkward Part: Your Press Statement Is Evidence of What You Knew

This is where the two workstreams collide. Communications wants a statement that closes the story: no evidence of a breach, no client impact, the data looks years old. The insurance workstream wants a circumstance notification that preserves rights. Both are defensible, and handled carelessly each undermines the other.

If a late-notice dispute arrives eighteen months later, the insurer will not begin with the forensic report. It will begin with the press statement, because it is dated, public and attributable. Two readings are available, and they point in opposite directions.

The first helps the insurer on lateness. The statement proves the company knew of the allegation on that date, investigated it, and formed a view on the age and provenance of the data. Awareness is dated by the insured's own words, and if notice came six months later the insured has to explain the gap.

The second helps the insured on materiality. The statement records a contemporaneous, reasoned conclusion that there was no credible evidence of a breach, which answers the objective test, provided the conclusion was reached through a process rather than drafted as a holding line. The difference is documentary. A statement backed by a dated internal assessment, a forensic scope and a named decision-maker reads as considered judgement. A statement with nothing behind it reads as a denial the insurer is free to call convenient.

The duty of utmost good faith sits underneath this and cuts both ways. The insured cannot tell the market there was nothing to see, and the insurer at renewal that there was nothing to disclose, while holding a forensic report saying otherwise. Consistency across the two audiences is what survives cross-examination.

Two Clocks, Started by Different Facts

The statutory clock and the policy clock are frequently confused. They are not the same.

Under the Digital Personal Data Protection Act, 2023, a data fiduciary must, on a personal data breach, give intimation to the Data Protection Board of India and to each affected data principal in the form and manner prescribed by the rules made under the Act. The statutory trigger is a personal data breach affecting personal data the fiduciary processes. Separately, the CERT-In directions of April 2022, issued under section 70B(6) of the Information Technology Act, 2000, require specified cyber incidents to be reported within six hours of noticing them.

The insurance clock runs on something different: awareness of a circumstance that may reasonably be expected to give rise to a claim. That can be satisfied by an allegation which, on the statutory side, has not been established as a breach at all.

The result is a window in which the two obligations diverge. A leak-site post asserting old employee data, with no confirmed intrusion into current systems, may leave the statutory duty unengaged while the policy's circumstance duty is already live. Reasoning from the statutory position to the insurance one, and skipping insurer notification because no reportable breach occurred, is the most common way Indian corporates lose the deemed-notice benefit.

A circumstance notification is not an admission of a breach. It is a statement that the insured has become aware of an allegation and is preserving its position under the policy.

Say exactly that in the notification and the tension between the clocks disappears. For firms inside the regulated insurance chain, the parallel reporting duties are set out in our post on IRDAI cyber incident reporting in 2026.

The Same Event Arrives Through the Vendor Chain

The version that catches companies with no leak-site post of their own is the vendor breach. TechCrunch reported on 10 August 2026 that a data breach at shipping group Ceva Logistics was rippling across banks, retailers and other third parties, and Adgully reported on 22 August 2026 that Apollo Global had confirmed a data breach amid a cyber wave targeting financial firms. In that pattern, a company learns its data may be in a criminal's hands because someone else was compromised. The circumstance analysis is identical, but three things get harder.

  • The evidence is not yours. Forensic findings, scope of exfiltration and dwell time sit with the vendor, who has its own counsel, its own insurers and no incentive to characterise the loss broadly.
  • The awareness date is easy to establish and hard to control. A vendor notification email is a timestamped document in the inbox of whoever owns that relationship, frequently procurement rather than risk. If it sits unescalated for two months, the awareness date is still the day it arrived.
  • Contractual indemnities and insurance recoveries pull apart. The vendor contract may promise indemnity, and the vendor's cyber limit may be exhausted by the first three claimants. Treating that indemnity as a substitute for notifying your own tower only works if the vendor stays solvent and the limit holds.

Route every third-party breach notification into the same intake as your own incidents, with the same date-stamped log. The most defensible thing an insured can produce in a late-notice dispute is a register showing when the notification arrived and that it was assessed within days.

The Sequence to Run Between the Leak-Site Post and the Insurer Email

Four workstreams, in this order, run in parallel where they can.

  1. Triage and preserve. Within the first day, scope what is being claimed: which dataset, which systems, what the sample shows, and whether the fields match a real internal schema. Preserve logs, images and the leak-site post itself, including the sample file and its metadata. If the data really is four years old, check log retention first, since it is the first thing to have expired.
  2. Write the assessment down, and date it. A short internal memo recording what was alleged, what was checked, who checked it, what was concluded and on what date is the document that decides a future late-notice argument. It turns an internal belief into evidence of a reasoned process. Create it contemporaneously, assuming an insurer's counsel will read it.
  3. Notify circumstances, without conceding a breach. Send a written notification under every tower capable of being engaged: cyber, D&O and technology errors and omissions. State the date and source of the allegation, what the company has done and concluded so far, and that notice is given under the notification of circumstances provision to preserve rights, without admission that a breach occurred. Attach the public statement if one exists.
  4. Decide who signs the public statement, before drafting it. The person who signs owns the sentence in cross-examination, and the statement should be cleared by whoever saw the internal assessment, so the public words and the private record cannot diverge. Legal holds the pen on any sentence containing the words evidence, breach or impact.

Do not wait for forensic certainty before notifying. It may take longer than the policy period.

What to Change in the Wording at Renewal

Once a company has lived through one unverified allegation, the wording gaps become visible. Raise four things at the next renewal, in this order.

  1. The definition of circumstance. Some wordings define it narrowly by reference to a specific wrongful act, while broader forms reach any fact or matter that may give rise to a claim. Broader is better for the insured, and it is negotiable in a market with capacity.
  2. Alignment of the notice clock across the three towers. If cyber requires notice as soon as practicable and technology errors and omissions requires it within thirty days of awareness, the operating standard is the shorter one. Ask the broker to endorse consistent language rather than run two internal timetables.
  3. The prior-known-circumstances exclusion at renewal. Ask how a notified circumstance is carved out of it, and confirm in writing that a circumstance notified in the expiring year is accepted as notified for renewal purposes.
  4. The incident response panel. Check whether counsel and forensic providers can be instructed on an unverified allegation without insurer pre-approval, or only once a claim exists. Cover that pays for forensics only after a breach is confirmed is no use here.

None of this is unusual to ask for, and in a competitive placement none of it costs premium.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Does notifying a circumstance to my cyber insurer count as admitting a breach happened?
No. A notification of circumstances records that the insured has become aware of an allegation and is preserving its position under the policy. Word it explicitly that way: state the date and source of the allegation, what has been investigated, what has been concluded so far, and that notice is given under the notification of circumstances provision without admission that any breach or wrongful act occurred. Insurers receive these routinely and a notified circumstance is not a claim on the loss record until a claim actually arises from it.
Will a circumstance notification affect my renewal pricing?
It can influence how an underwriter reads the account, which is a reason to notify well and with particulars rather than a reason to stay silent. The alternative is materially worse: a known but unnotified circumstance is usually excluded by the prior-known-circumstances wording in the renewal policy, so the insured ends up with no cover in either year. Discuss the framing with the broker before the notice goes out, so the same facts are presented consistently to the incumbent and the market.
Our vendor was breached, not us. Do we still notify our own insurers?
Yes, if the vendor's notification tells you that data you are responsible for may have been exposed. That is awareness of a circumstance regardless of whose systems were compromised, and a contractual indemnity from the vendor is not a substitute, since the vendor's own limit may be exhausted by earlier claimants. Route third-party breach notifications into the same date-stamped incident intake as your own, because the awareness date runs from when the email arrived, not from when risk management finally saw it.
If the DPDP Act notification duty is not engaged, is the policy duty also not engaged?
The two run on different facts. The statutory duty is triggered by a personal data breach affecting personal data the data fiduciary processes, and the CERT-In directions of April 2022 run from noticing a specified cyber incident. The policy duty is triggered by awareness of a circumstance that may reasonably be expected to give rise to a claim, which an unproven allegation can satisfy. Treating the statutory conclusion as the insurance conclusion is the most common route to a late-notice dispute.
How specific does a circumstance notification have to be?
Most wordings require full particulars, and a bare notice that fails to identify the circumstance with particularity may not attract the deemed-notice benefit later. Identify the allegation, the alleged dataset and time period, the source and date, the systems and jurisdictions potentially affected, the categories of person whose data is implicated, the steps taken, and the current internal assessment with its date. Attach the public statement if one has been issued.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform