Cyber insurance is abstract until 7:40 on a Tuesday morning, when the office manager calls because every file share is locked and there's a text file on the server titled READ_ME. What follows — the first 72 hours of a ransomware incident — is the best argument for the coverage ever written, because almost nothing in it can be improvised by a business alone.
This is a composite walkthrough of how those hours actually run for a small Ontario company with a proper cyber policy. Names invented; sequence utterly typical.
Hour zero: the call that isn't to IT
The first correct move is counterintuitive: before the IT contractor starts rebuilding anything, someone calls the policy's 24/7 incident line. That call activates a breach coach — a privacy lawyer who quarterbacks the response — and pulls in an approved forensics firm. The sequencing matters enormously: work directed by counsel is structured for privilege, evidence gets preserved instead of trampled, and well-meaning cleanup doesn't destroy the answers to 'what did they touch?'
Within a couple of hours the shape of the engagement exists: forensics imaging systems, the coach setting communication rules (including the underrated one — assume email is compromised; coordinate off-platform), and containment beginning. A business without the policy is, at this same hour, googling 'ransomware what to do' while the clock runs.
Day one: containment, triage, and the backup question
Forensics establishes the entry point — this composite's is the classic: a credential phished weeks earlier, no MFA on remote access — and whether the attackers exfiltrated data before encrypting. Meanwhile the practical triage: what still works, what's isolated, what the business can operate manually. Payroll is Friday; that's suddenly a workstream.
The pivotal technical question is backups. Tested, offline backups turn ransomware from an extortion negotiation into an infrastructure rebuild — painful, but bounded. Backups that were connected (and are now encrypted too) change the conversation entirely. Every underwriting form asks about backups because this exact fork in the incident is where the loss size gets decided.
Day two: the ransom decision and the legal duties
If restoration can't beat the business-down clock, the ransom conversation happens — run by specialists, not the owner. Professional negotiators handle contact; sanctions screening happens before any payment is even lawful to consider; and the decision weighs recovery time against payment risk with the insurer involved throughout. There's no glamour in it, only grim math, and businesses that face it alone reliably get both the negotiation and the compliance wrong.
Parallel track: the data. If personal information was exposed, PIPEDA's machinery engages — breach records, notification to affected individuals and the Privacy Commissioner where the harm threshold is met. The coach runs this too; it's the privacy-breach half of the coverage, and doing it correctly is the difference between an incident and an incident plus a regulatory problem.
Day three and after: restoration, income, and the long tail
By hour 72 the pattern is set: systems rebuilding in priority order, customers hearing a controlled message instead of rumours, and the claim widening to its financial dimensions — business interruption for the down days, extra expenses for the rush work, forensics and legal fees accumulating under the policy. Full recovery runs weeks; the incident's paper tail (final forensics report, notification records, control improvements) runs longer.
The postscript every business writes afterwards is the same: MFA everywhere, backups tested monthly, the incident line saved in phones. The controls that would have prevented the incident are the ones the renewal application was asking about all along.
The bill, itemized: where the money actually goes
Deconstructing the composite's costs makes the coverage concrete. Forensics and incident response: specialist firms bill enterprise rates, and even a small-business engagement runs well into five figures across investigation and remediation oversight. Legal: the breach coach, privilege structuring, and notification advice add five figures on files with personal-information exposure. Notification and credit monitoring: unit costs look small until multiplied by a customer database. Restoration: IT rebuild labour, software relicensing, and the occasional hardware replacement. Business interruption: for a firm billing $60,000 a month, two down weeks is $30,000 before overtime for catch-up.
Stack it and a 'contained' incident at a twenty-person firm plausibly totals $75,000–$200,000 — squarely consistent with published Canadian averages when scaled for size. The extortion payment, if one occurs, sits on top; so does the long tail of client attrition no policy line captures. Against that stack, typical SME cyber premiums — often $1,500–$5,000 for meaningful limits — explain themselves.
The claims-experience footnote worth knowing: insurers report that insureds who engage the response panel immediately consistently see materially smaller totals than those who improvise for days first. Speed is the cheapest variable in the whole equation, and it's entirely behavioural.
What the policy did NOT cover — and how to close each gap
An honest anatomy includes the edges. In our composite, three items tested wordings. The fraudulent transfer that preceded the ransomware — an invoice redirected during the initial intrusion — fell to the social-engineering sub-limit, a fraction of the headline limit; firms with real payment volumes should size that sub-limit deliberately. The aging server that IT recommended replacing anyway: policies restore you, they don't upgrade you — 'betterment' stays on your tab. And the second week's revenue dip after systems returned: interruption coverage ran to restoration-of-operations, and the wording's definition of that moment decided the claim's edge.
Other classic edges to map with your broker before an incident: contractual penalties owed customers for downtime (coverable, but only via specific wording), regulatory fines (limited insurability by law), incidents traced to your outsourced IT provider (the seam between your cyber policy and their technology E&O), and prior-acts — intrusions that began before your policy did, which retroactive dates govern.
None of these edges is an argument against the coverage; every one is an argument for buying it with a map. The forty-five-minute wording review that walks these scenarios is the difference between owning a policy and owning the policy you think you own.
The aftermath nobody budgets: weeks two through twelve
The 72-hour story ends; the incident doesn't. Weeks two through four carry the operational tail: systems rebuilt in priority order still means weeks of degraded workflow, staff simultaneously catching up and adopting new controls, and the customer-communication follow-through — the promised update, the answered questions, the handful of accounts that need personal calls. Somewhere in there, the team's adrenaline crash arrives; plan for it like any operational surge, because burnout after incidents is a documented pattern.
Weeks four through twelve are paperwork and hardening: the final forensics report (read it — it's the most expensive document your business owns), the insurance claim's financial reconciliation with receipts and revenue records, notification-record retention per PIPEDA's requirements, and the control upgrades that the incident made undeniable. Expect your renewal application to ask about the incident forever after; expect the honest answer plus documented improvements to be entirely insurable — carriers re-quote post-incident businesses with upgraded controls routinely.
And expect one more thing: perspective. Businesses that have run this gauntlet describe a permanent shift — backups get tested, MFA exceptions stop being granted, the incident line stays taped to the wall. The cheapest version of that wisdom is borrowing it from this composite instead of earning it. Price the coverage, run the thirty-minute tabletop, and file this article where the READ_ME would appear.
Small-business variations: how the anatomy changes by size
The composite above described a twenty-person firm; the anatomy scales in both directions with instructive differences. At five people, the incident is existential faster — there's no parallel manual workaround when the whole operation is three laptops and a cloud account — but recovery is also simpler: fewer systems, smaller data sets, restoration measured in days if backups exist. The coverage question at this scale is mostly whether any policy exists at all; the majority of micro-businesses still carry none, which converts a $30,000 incident into a personal financial event.
At a hundred people, the mechanics thicken: segmented networks slow attackers but complicate forensics, notification populations reach thousands, and the business-interruption measurement becomes a genuine accounting exercise. Governance enters too — boards asking who knew what, D&O-adjacent questions about oversight, and customer contracts with breach-notification clauses running their own clocks alongside PIPEDA's.
The constant across sizes: the first-hour sequence never changes. Policy hotline, breach coach, forensics, containment — the order is the order whether the company is five people or five hundred. Which is why the one-page plan scales perfectly, and why not having one doesn't.
The bottom line
A cyber claim is a project with a dozen specialists and legal deadlines, compressed into the worst week of a company's year. The policy's real product is the machinery — coach, forensics, negotiators, notification, income coverage — pre-assembled and a phone call away.
If your incident plan is currently 'call IT and hope', two moves: price the coverage, and read our claims guide so the first hour goes right regardless. The rehearsal costs thirty minutes; the improvisation costs the year.