The Answer in 60 Seconds
A cyber policy is built in two halves, and the difference decides what actually gets paid. First-party cover pays for losses to your own business: the cost of responding to a breach, IT forensics to work out what happened, restoring or rebuilding lost data, the income you lose while systems are down, and a cyber-extortion or ransomware demand. It answers one question: what does it cost us to recover.
Third-party cover pays for your liability to other people. That includes claims from customers whose personal data was exposed, the cost of defending an investigation by the Personal Data Protection Commission (PDPC) and any financial penalty it imposes under section 48J of the Personal Data Protection Act 2012, and media liability for content you publish. It answers a different question: what does it cost us when others hold us responsible.
Most SMEs need both halves, but lean on one more than the other depending on what they hold and what they do. The gap that catches businesses out is a policy that buys one half and skips the other, for example data restoration with no liability section. The data gets rebuilt and the customers still sue.
The Sourced Detail
Cyber insurance is sold as a single product, but inside the wording it splits into first-party and third-party insuring agreements, the same structural divide that runs through most liability-linked covers. Getting the two straight matters because they respond to completely different events. A ransomware lockout that never touches customer data is almost entirely a first-party loss. A leaked customer database that you recover from a clean backup in an hour is almost entirely a third-party exposure. Most real incidents land somewhere in between, which is why both halves usually appear in the same policy. But they are priced, limited, and sub-limited separately, and a buyer who does not read them as two things can end up paying for one and assuming the other came free.
First-party cover: your own losses
First-party cover pays the costs your business incurs directly as a result of a cyber incident. The common insuring agreements are:
- Breach response and notification costs. The cost of running the response: legal advice, a breach coach, and the administrative work of notifying affected individuals. This matters in Singapore because notification is not optional. Where a breach is assessable as a notifiable data breach, section 26D of the PDPA requires the organisation to notify the PDPC as soon as practicable and in any case no later than 3 calendar days after it assesses the breach as notifiable, and to notify affected individuals where the breach is likely to result in significant harm.
- IT forensics. Specialist investigators establish how the attacker got in, what they touched, and whether they are still inside. Forensics is the evidence base for the notification assessment and for any later dispute.
- Data and system restoration. The cost of rebuilding corrupted or deleted data and restoring systems to working order. Note the limit of this: restoration rebuilds your own data. It does nothing for a customer who sues because their data was exposed.
- Business interruption. The income lost while systems are down, and sometimes the extra cost of working around the outage. This is the line that often dwarfs the others for a trading business, and it is worth checking how the waiting period and the indemnity period are defined.
- Cyber extortion and ransomware. The ransom demand itself, plus the cost of specialist negotiators. This line carries its own conditions, including insurer consent before any payment and sanctions-screening of the recipient.
What unites these is direction. Every dollar flows toward putting your own business back together. None of it answers to anyone outside the company.
Third-party cover: your liability to others
Third-party cover pays what you owe other people when an incident makes you legally responsible to them. The common insuring agreements are:
- Privacy and network security liability. Defence costs and damages for claims brought by people whose data you held, typically customers and employees, when a breach exposes that data. The legal foundation of that exposure in Singapore is the protection obligation in section 24 of the PDPA, which requires an organisation to make reasonable security arrangements to protect personal data in its possession or control. A failure to meet that standard is the hook on which a privacy claim or complaint hangs.
- Regulatory defence and penalties. The cost of responding to and defending a PDPC investigation, and, where the wording and the law allow it to be insured, the financial penalty the Commission may impose under section 48J of the PDPA. The current penalty ceiling and how it is calculated have moved over time, so treat the figure as something to confirm against a dated source rather than memorise. We track it separately in our note on notification cost in the limit versus a sub-limit for SMEs.
- Media liability. Liability arising from content you publish: defamation, or infringement of someone else's intellectual property, through your website or digital channels. Not every SME needs this, but a content-heavy or publishing business does.
What unites these is, again, direction. Every dollar flows outward, toward a customer, a regulator, or a claimant. None of it rebuilds your systems.
The split, side by side
| First-party (your losses) | Third-party (your liability) | |
|---|---|---|
| Breach response and notification | Yes | - |
| IT forensics | Yes | - |
| Data and system restoration | Yes | - |
| Business interruption | Yes | - |
| Cyber extortion / ransomware | Yes | - |
| Customer / employee data claims | - | Yes |
| PDPC investigation defence and penalties | - | Yes |
| Media liability | - | Yes |
| Core question it answers | What does recovery cost us? | What do we owe others? |
Which SMEs lean on which half
The mix you need follows the shape of your business, not a rule of thumb.
An e-commerce or services business holding a large customer database carries heavy third-party exposure. The asset at risk is other people's personal data, so privacy liability and PDPC defence are the lines that matter most. A breach here is a section 24 and section 26D event before it is anything else.
A manufacturer, logistics operator, or any business that runs on operational systems leans first-party. The pain of an attack is the outage: production stops, orders cannot ship, systems need rebuilding. Business interruption and restoration carry the weight, even if the customer-data exposure is modest.
A professional or B2B firm usually needs both in balance: confidential client data on the third-party side, and dependence on its own systems on the first-party side.
The point is not to pick one half. It is to know which half does the heavy lifting for your business, so the limits and sub-limits are set where your real exposure sits rather than spread evenly by default.
The gap that catches SMEs out
The expensive mistake is a policy that covers one half and is read as if it covered both. Three versions of it recur.
The first is a restoration-only or first-party-heavy policy with thin or no liability cover. The business recovers its data, then discovers there is no cover when affected customers bring a claim or when the PDPC opens an investigation under the PDPA. The data is fine. The liability is uninsured.
The second is the reverse: liability cover with weak first-party lines, where business interruption is sub-limited so low that the income lost in a real outage exhausts it in days.
The third is a sub-limit hidden inside a headline figure. A policy may advertise a large overall limit while capping the line you most need, regulatory defence, or extortion, or business interruption, at a small fraction of it. The total looks reassuring and the relevant line is small. We cover that specific trap in notification cost in the limit versus a sub-limit.
A note on honesty about sourcing: the statutory backdrop here, the PDPA protection obligation, the breach-notification duty, and the penalty power, is primary law and is linked above. The cover mechanics, what a given insuring agreement includes and how sub-limits are structured, vary by insurer and by wording. Those are described here as market convention, not as a rule fixed in statute. The only way to know what a specific policy pays is to read that policy's schedule and wording.
Common Mistakes
-
Buying first-party cover and assuming liability came with it. Restoration rebuilds your data. It does nothing when customers sue or the PDPC investigates. Confirm the policy has a third-party section, and check its limit.
-
Treating the headline limit as the figure that matters. The line you will actually claim on, regulatory defence, business interruption, or extortion, is often sub-limited well below the headline. Read the sub-limits, not the cover page.
-
Setting limits evenly instead of by exposure. A data-heavy retailer and a systems-heavy manufacturer have opposite risk profiles. Spreading the limit evenly under-insures whichever half does the heavy lifting.
-
Ignoring the notification clock. Section 26D sets a 3-calendar-day window to notify the PDPC after assessing a breach as notifiable. A policy whose breach-response line is too thin to fund a fast forensic assessment puts that deadline at risk.
-
Overlooking media liability when it is genuinely needed. A content or publishing business that skips media liability leaves a real third-party gap that the privacy section will not fill.
-
Assuming a PDPC financial penalty is automatically insurable. Whether a section 48J penalty can be insured, and to what extent, depends on the wording and the law. Confirm it rather than assume it.
What This Means for Your Business
Start by deciding which half carries your real exposure. List what would actually hurt: a multi-day outage, a leaked customer database, a ransom demand, a regulator at the door. Map each to first-party or third-party, and you will see quickly where your weight sits.
Then read the policy as two documents. Check that both a first-party and a third-party section exist, and read the sub-limits inside each. The most common failure is not the absence of a section but a section capped so low it cannot do its job. Business interruption, regulatory defence, and extortion are the lines worth checking line by line.
Tie the third-party side back to the law you actually live under. Your liability to customers runs through the section 24 protection obligation, and your operational duty after a breach runs through the section 26D notification timeline. A policy that funds a fast forensic assessment and a clean notification is a policy that helps you meet those duties, not just pay for the aftermath.
Covarage helps with the part that quietly goes wrong: keeping the policy schedule and its sub-limits organised in one place so you can see both halves at a glance, sending renewal reminders before cover lapses, and routing you to a licensed adviser when you need to compare how two policies split first-party and third-party cover.
Questions to Ask Your Adviser
- Does this policy have both a first-party and a third-party section, and what is the limit on each?
- For my business, which half carries the larger exposure, and are the limits set accordingly?
- What are the sub-limits on business interruption, regulatory defence, and cyber extortion, and how do they compare to the headline figure?
- Does the third-party section respond to a PDPC investigation under the PDPA, and is a section 48J financial penalty insurable under this wording?
- Is the breach-response line large enough to fund a forensic assessment fast enough to meet the section 26D notification deadline?
Related Information
- PDPA Section 24: The Protection Obligation Every Organisation Owes
- PDPA Section 26D Mandatory Data Breach Notification: The 3-Day Clock Explained
- Cyber Notification Cost: In the Limit vs a Sub-Limit for SMEs
- Cyber Incident: The First 72 Hours for a Singapore SME
Published 31 May 2026. Source verified 31 May 2026. COVA is an introducer under MAS Notice FAA-N02. We do not recommend insurance products. We provide factual information sourced from primary regulators and route you to a licensed IFA who can match a policy to your specific situation.

