September 28, 2026

Endorsements That Delete Cyber Cover in Malaysia

Written by
Michelle Chin

Entrepreneur & strategist - experienced in driving digital-first insurance innovation, with extensive experience in scaling successful businesses

"Hereby deleted in its entirety." Six words on a page at the back of an insurance policy, and they can remove the exact cover your client contract asked you to carry.

Your schedule lists the cyber extensions. Your endorsements decide whether they are still in the policy. The two documents do not have to agree, and when they disagree the endorsement wins.

This is about technology professional indemnity policies held by Malaysian software firms, IT services companies, SaaS businesses and digital agencies. It covers which endorsements delete cyber cover, what each one takes away, and how to check your own paperwork.

Not sure whether your cyber extensions survived your last renewal?

Send your schedule and the endorsement pages behind it. You will get back a plain list of what is still in the policy and what has been taken out, alongside your professional indemnity insurance.

WhatsApp Us Now

Key Facts: Endorsements That Delete Cyber Cover in Malaysia

What is an endorsement? An endorsement is a page attached to your policy that changes the standard wording. It can add cover, narrow it, or delete a clause outright, and it carries the same contractual force as the main wording.

Why does the schedule not show the deletion? The schedule lists sections, limits and extensions as they were sold. Deletions are recorded on the endorsement pages behind it, so an extension can appear on your schedule and be absent from your policy.

Who needs to check this? Any Malaysian business holding a technology professional indemnity policy that was sold with cyber extensions. That covers most software vendors, IT services firms, SaaS companies and digital agencies working under client contracts that name cyber cover.

What decides whether you keep an extension? Insurers price and restrict cyber extensions on the data you hold, your security controls, your sector and your claims history. When appetite tightens, the usual move is to remove the extension by endorsement rather than decline the whole policy.

Is cyber cover required in Malaysia? No statute requires it. The Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, sets duties on how you handle data, not a duty to insure. Where you must carry cover, the instrument is your client contract.

What changed recently? Data breach notification became mandatory from 1 June 2025, with the Commissioner to be told within 72 hours and affected individuals within 7 days of that notification. Those duties generate cost, and data breach notification costs is one of the extensions most often deleted.

Last verified: August 2026. Checked against the Personal Data Protection Commissioner's circular on data breach notification, the Personal Data Protection Act 2010 as amended in 2024, and Malaysian technology professional indemnity wordings currently bound in the market, 2025 editions.

Three documents, and only one of them is the policy

A commercial insurance policy arrives as a bundle, and the part people read is the part that is easiest to read. That is the schedule, which is a summary, not the contract.

This table sets out what each part of the bundle tells you and what it cannot tell you.

Document What it tells you What it cannot tell you
The schedule, usually one or two pages Insured name, period, sections bought, limits, deductibles, extensions as sold Whether any of it has since been amended or removed
The policy wording, often 30 to 60 pages The insuring clauses, definitions, conditions and standard exclusions Which of its clauses your particular policy still contains
The endorsement pages, at the back Every change made to the standard wording for you specifically Anything, in plain language. They are written as amendments, not explanations
The certificate of insurance you send clients Insurer, insured, cover type, limit, period Any deletion at all. A stripped policy and a full one produce identical certificates

The last row is the one that causes trouble commercially. Your client asks for evidence of cyber cover, you send a certificate, and the certificate is accurate. It is also silent about the endorsement that removed the section your client cares about.

Six endorsements that delete cyber cover from a technology professional indemnity policy

These are standard insurer boilerplate, not bespoke drafting, and they turn up on technology professional indemnity policies across the Malaysian market. Each has a name, and each removes something specific.

The table below names the endorsement, what it takes out of the policy, and what that leaves you carrying yourself.

Endorsement name What it deletes What you are left carrying
Data breach notification costs exclusion The head of cover for the cost of notifying regulators and affected individuals The entire cost of the work the PDPA breach duties create
Computer system extortion exclusion Cyber extortion expenses and cover for extortion threats Your own response to a ransom demand, including the specialists you need in the first 24 hours
Crisis management and credit monitoring expenses exclusion Crisis communications costs and any monitoring offered to affected people The public side of an incident, which is usually the part clients watch
Breach of privacy regulations civil penalties exclusion The insuring clause dealing with civil penalties under privacy regulations, under the professional indemnity section That head of cover is no longer in the policy in any form. See the section below on penalties
Personal injury and property damage exclusion The liability section covering personal injury and property damage Claims of that kind, which some client contracts require you to be insured for
Deletion of reinstatement Clause 3.2, reinstatement of the limit of indemnity, in the wordings that carry it Once the limit is spent for the year, nothing puts it back

Four of the six take out precisely the cyber extensions a technology professional indemnity policy is sold on. That is the uncomfortable part. The extensions are frequently the reason a buyer chose one quote over another, and they are also the first thing an underwriter removes when appetite for cyber risk tightens.

Clause references here are to technology professional indemnity wordings currently bound in the Malaysian market, 2025 editions, cited by clause number. The insurer is not named, which is standard practice when quoting a bound wording.

What each deletion costs you when something actually happens

Deletions are abstract until an incident makes them concrete. The table below runs realistic incidents against the head of cover you would expect to use, and says what changes if that head has been endorsed away.

What happened Head of cover you would reach for If the endorsement deleted it
A misconfigured storage bucket exposed customer records you process for a client Data breach notification costs You pay for the legal review, the regulator filing and every individual notice yourself
Ransomware encrypts your production environment and a demand arrives Cyber extortion expenses No negotiator, no forensics retainer, no funded decision. You are on your own clock
A breach becomes public and enterprise clients start asking questions Crisis management expenses You fund the communications work while running the incident
Affected individuals ask what you are doing to protect them Credit monitoring expenses Any monitoring you offer is a goodwill cost with no recovery
A second unrelated claim lands in the same policy year after the first exhausted the limit Reinstatement of the limit There is nothing left to draw on until renewal

Malaysian reporting data gives a sense of which of these arrives most often. The Cyber999 incident response centre received 1,657 incidents in the first quarter of 2025 against 1,550 in the previous quarter, a 7% increase, according to MyCERT's Cyber Incident Quarterly Summary Report for Q1 2025, published on 10 June 2025 by CyberSecurity Malaysia. Fraud was by far the largest category at 1,126 of those incidents, with intrusions at 132.

For scale on what a serious incident costs, IBM's Cost of a Data Breach Report 2026 puts the global average at USD 4.99 million, a 12% rise on the previous year and a record high. That is a global figure across large organisations rather than a Malaysian SME figure, so read it as direction rather than as a number to budget against.

The duties that generate the bill

Notification is no longer optional, and the deadlines are short. The Personal Data Protection Commissioner's circular on data breach notification sets two of them.

"Dalam tempoh tujuh puluh dua (72) jam daripada pelanggaran data peribadi ... Dalam masa tujuh (7) hari selepas pemberitahuan pelanggaran data dibuat oleh pengawal data kepada Pesuruhjaya"

That is Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 2 Tahun 2025, the Commissioner's circular on data breach notification. In English: the required information goes to the Commissioner within seventy two hours of the breach, and affected individuals are told within seven days of that notification where the breach causes or is likely to cause them significant harm.

This table separates the duty from the money, because the duty does not move when your cover does.

Duty Timing Who pays for the work
Notify the Commissioner Within 72 hours of the breach The notification costs head, where it is still in your policy
Notify affected individuals Within 7 days of notifying the Commissioner, where significant harm is likely The same head, and it scales with how many people are involved
Work out what happened, fast enough to file accurately Inside the same 72 hours Incident response and forensics, which sit in a different head again
Appoint a data protection officer where the thresholds apply Effective 1 June 2025 You, as an ongoing operating cost. No policy covers it

One point takes no hedging at all. Whether any insurance policy responds to a regulatory penalty is a question about your specific wording and about the law that applies to insuring penalties, and it is not safe to assume in either direction. Ask your insurer directly and get the answer in writing before you rely on it in a board paper or a client response.

That matters here because one of the six endorsements is named after civil penalties. What the endorsement does is remove a clause from the policy. It says nothing about what that clause would have paid, and neither should anyone selling you the policy.

Client contract asks for cyber cover and you are not certain what you hold

The gap between what a schedule shows and what a policy contains is where these conversations go wrong. We can map your endorsement pages against the clause your client wrote, including on cybersecurity insurance.

Get a Quote

How to read your own endorsement pages in ten minutes

You do not need to understand the whole wording. You need to find the amendments and work out what each one points at.

Step What to do What you are looking for
1 Open the full policy PDF, not the schedule your finance team filed Pages titled Endorsement, Memorandum, or Amendment, usually at the very back
2 Search the document for the word "deleted" Every hit. Each one is a clause that is no longer in your policy
3 Write down the clause number each endorsement names The numbers, not the endorsement titles. Titles are marketing, numbers are the contract
4 Look each clause number up in the main wording What that clause actually said before it went
5 Compare that list against your client contract's insurance clause Anything your contract names that your endorsements have removed

Step three is the one people skip and it is the one that matters. An endorsement titled after an exclusion tells you the subject. The clause number tells you the scope, and the scope is often wider than the title suggests.

Endorsement pages use a small vocabulary. This table decodes the phrases that signal something has gone.

Phrase on the page What it means for you
"deleted in its entirety" The whole clause is gone. Nothing of it survives anywhere else in the policy
"is hereby amended to read" The clause survives in changed form. Read the replacement text word for word
"notwithstanding anything to the contrary" This endorsement beats the main wording wherever they conflict
"sub-limit of liability" The cover is present but capped below the headline limit, and usually carved out of it
"shall not apply to" A carve-out. Cover remains, except in the circumstances listed after it
"all other terms and conditions remain unchanged" Standard closing line. It confirms the change above it is real and deliberate

So do you need standalone cyber cover?

This is the question the endorsement pages actually answer, and the answer is specific to what your own pages say rather than general.

What your endorsement pages show What it points to
No cyber-related deletions, extensions intact, sub-limits reasonable against your data volume The extensions may be enough. Check the sub-limits against a realistic notification exercise
Notification costs or extortion deleted The two most likely bills are uninsured. A standalone policy is the usual answer
Extensions present but sub-limited far below your headline limit Partial cover. Price both a higher sub-limit and a standalone policy before deciding
Reinstatement deleted and you serve many clients from one platform A single bad year can exhaust the policy. Look at limit structure before adding products
Your client contract names cyber cover and your extensions were deleted You are potentially in breach of the contract now, not after an incident. Fix this first

That last row is worth reading twice. An insurance clause in a services agreement is a continuing obligation, so cover that was deleted at renewal puts you outside the contract from the day the endorsement took effect.

Five mistakes that keep repeating

These come up whenever a technology business compares what it thought it bought against what the policy says.

Mistake Consequence How to avoid it
Filing the schedule and never opening the full policy You find out what was deleted during an incident Read the endorsement pages once a year, at renewal, before you sign
Assuming a renewal is the same policy as last year Renewal is where deletions are introduced, quietly and legitimately Ask for a list of changes against the expiring policy, in writing
Treating the certificate of insurance as proof of scope It proves a policy exists and nothing about what is in it Where a client needs scope, send the schedule and endorsement list, not the certificate
Reading the endorsement title instead of the clause number The title understates what came out Look up every clause number named, in the main wording
Answering the proposal form loosely about security controls A disclosure argument at the worst possible moment Answer against reality. A business buyer's duty sits in Schedule 9, paragraph 4(1) of the Financial Services Act 2013

FAQ

Can an insurance endorsement remove cover that my schedule still lists?

Yes. The schedule records what was sold and the endorsement pages record what was subsequently changed, so the two can disagree. Where they do, the endorsement governs. This is normal contractual practice rather than anything irregular, which is why the endorsement pages need reading rather than filing.

How do I know whether my technology professional indemnity policy still has cyber cover?

Open the full policy document and search it for the word "deleted". Note every clause number named on the endorsement pages, then look those clause numbers up in the main wording to see what each one said. Anything relating to notification costs, extortion, crisis management or credit monitoring is a cyber extension.

What is the "data breach notification costs" head of cover?

It funds the work required after a personal data breach: legal review of whether the duty is triggered, preparing and filing the notification, and telling affected individuals. In Malaysia the Commissioner must be notified within 72 hours of the breach and affected individuals within 7 days of that notification where significant harm is likely. Deleting this head leaves that work entirely at your own cost.

Does insurance pay a PDPA penalty?

That depends on your specific wording and on the law applying to the penalty in question, and it is not safe to assume either way. Put the question to your insurer directly and ask for the answer in writing. Do not treat the presence or absence of a penalties clause on your policy as the answer on its own.

Why would an insurer delete an extension it sold me last year?

Cyber risk appetite moves quickly, and removing an extension at renewal is a normal underwriting response to that. It can also follow a change in your business, such as holding more personal data or entering a new sector. The change is legitimate; the problem is that it usually arrives without anyone drawing attention to it.

My client contract requires cyber cover. What do I send them?

Send the schedule together with the list of endorsements, not just the certificate of insurance. A certificate confirms a policy exists and says nothing about deletions, so it can satisfy a client while leaving you exposed on the clause. If an endorsement has removed something the contract names, resolve that before the next reporting date rather than after an incident.

Contingent Conclusion

The schedule is a summary written to be read. The endorsement pages are the contract, written to be filed. Almost every surprise in a commercial insurance claim lives in the gap between those two facts.

For a Malaysian technology business, the practical work is small. Find the word "deleted" in your policy, list the clause numbers, and compare that list against the insurance clause in your largest client contract. If the two do not match, you have found a problem that is cheap to fix now and expensive to discover later.

Contingent helps Malaysian businesses get the cover their contracts and landlords require. Whether you're comparing options or checking whether your existing policy actually does what the contract asks, we can help.

Get a quote · or WhatsApp us directly

Related reading: PI for IT consultants and software companies, data breach cover and the PDPA, and insurance for tech and SaaS startups.

Primary sources: the Personal Data Protection Commissioner's circular on data breach notification, the MyCERT Cyber Incident Quarterly Summary Report published by CyberSecurity Malaysia, and IBM's Cost of a Data Breach Report. Wording references are to technology professional indemnity wordings currently bound in the Malaysian market, 2025 editions, cited by clause number without naming the insurer.

Published by Contingent, the commercial insurance brand of Emerge Insurtech (Malaysia) Sdn. Bhd.

Disclaimer: This article describes how these policy terms commonly operate in the Malaysian market as of August 2026, with clause references drawn from wordings currently in use. Wordings differ between insurers and between policy years, and endorsements can delete or amend any clause described here. Always read your own schedule and endorsement pages, and consult a qualified insurance professional before relying on any of it.

Protect your revenue, people and systems today