Cyber insurance has gone from an exotic add-on to one of the most-quoted commercial coverages in Canada, for the unglamorous reason that the claims stopped being theoretical. It is also the line where two apparently similar businesses see wildly different premiums, and where the difference is almost never about size. Here's what a policy actually does, what it doesn't, and why the quotes vary so much.
What a cyber policy actually pays for
First-party coverage handles your own costs after an incident: forensic investigation to establish what happened, restoring systems and data, legally required notification of affected individuals, credit monitoring, public relations, and lost income while you're down. This is the part that gets used, and it's the part that makes the policy worth having for a business that holds no especially sensitive data.
Third-party coverage responds when customers, partners, or payment processors come after you over a breach of their data — defence costs, settlements, and regulatory proceedings, closely related to privacy breach coverage.
The piece that's genuinely hard to buy anywhere else is the breach response panel: a coach who has run this before, pre-vetted forensics, and lawyers who know the notification rules. In the first twenty-four hours that access is worth more than the indemnity. Buying those services cold, mid-incident, means negotiating rates with firms you've never used while your systems are down — which is exactly when nobody negotiates well.
The controls that decide your premium
Cyber underwriters price on your controls, not primarily on your revenue. Multi-factor authentication on email and remote access is close to non-negotiable. Tested, offline backups are the next question, followed by endpoint detection, patching discipline, and whether staff have had any phishing training at all.
The gap between a business with those controls and one without is not a few percentage points — it's the difference between a standard rate and a loaded one, or between being quotable and being declined outright. Insurers withdrew a great deal of capacity from this line after the ransomware years, and they got specific about what they'd write.
There's a happy accident in this: the same improvements that reduce your premium reduce the odds you'll ever need the policy. It's the rare insurance where the underwriting checklist doubles as free, well-prioritised security advice.
Answer the application carefully, too. Cyber proposals ask specific questions about controls, and the answers form part of the contract. Saying multi-factor authentication is enabled everywhere when it covers only some accounts is the kind of inaccuracy that surfaces during a forensic investigation, at the precise moment you need the policy to respond without argument.
Why two similar businesses get very different quotes
Beyond controls, underwriters look at what you hold and who depends on you. A firm holding health records, financial data, or a large volume of personal information carries more notification exposure than one holding invoices. A managed service provider or software vendor carries the risk of a single incident cascading into every client it serves — which is priced accordingly.
Dependency runs the other way too. If your operations sit entirely on one cloud platform, an outage at that provider is your business interruption, and whether the policy responds to a third party's downtime rather than your own is a real coverage difference between insurers. It's worth asking about explicitly.
Ransomware: what's covered, and what the policy asks of you
Most modern policies cover ransomware response — negotiation, forensics, restoration, and in many cases the ransom itself, subject to sanctions screening and the insurer's consent. That consent requirement matters: paying before speaking to your insurer can prejudice the claim.
The pivotal question is always backups. Tested offline backups turn ransomware from an extortion negotiation into an infrastructure rebuild — painful and expensive, but bounded and largely covered. Backups that were connected to the network, and are therefore encrypted too, change the situation entirely. Every underwriting form asks about backups for exactly this reason.
Social engineering — the exclusion that surprises people
The most common loss small businesses actually suffer isn't encryption, it's a person. An employee receives a convincing email, believes it, and wires money to a fraudster or changes a supplier's bank details. No malware, no breach, no systems compromised.
That's social engineering or funds transfer fraud, and it is frequently a separate sub-limit rather than part of the main cyber limit — sometimes a fraction of it, sometimes excluded unless specifically added, and often conditional on you having a call-back verification procedure that was actually followed. This is one of the most important lines to compare between quotes, and one of the least likely to be volunteered.
The legal duty that makes this a compliance issue
Canadian businesses subject to federal privacy law must report breaches of security safeguards that create a real risk of significant harm to affected individuals, notify those individuals, and keep records of every breach — including the ones they concluded didn't meet the threshold. Several provinces layer their own requirements on top, and health information is regulated separately again.
The judgement call about whether an incident crosses the threshold is genuinely difficult, and it has to be made quickly, under pressure, by people who are simultaneously trying to get the business running. A cyber policy's breach coach and legal panel exist precisely to make that call properly. That's a service you're buying as much as an indemnity.
What cyber does not cover
It won't pay to fix the underlying weakness. Replacing end-of-life hardware, buying the security tooling you should have had, or upgrading systems to something defensible are business costs, not claim costs — betterment is excluded almost universally.
It generally won't cover your own lost intellectual property value, reputational damage beyond the specified PR response, or the contractual penalties you owe clients for missed deliverables. And it typically excludes losses arising from unencrypted devices or known unpatched vulnerabilities you were warned about and didn't address. Failing to act on your own security advice is one of the more reliable ways to complicate a claim.
What the first day looks like
Worth knowing before you need it: the first call is not to your IT provider, it's to the number on your policy. That triggers the breach coach, and it starts the clock on the obligations you're about to have. Calling IT first is understandable and it's how businesses lose the forensic evidence that later determines whether the claim is straightforward.
From there the sequence is fairly consistent — contain, establish scope, work out whether data left the building, and only then decide about restoration or negotiation. Most policies require the insurer's consent before you engage vendors or pay anything, so getting them involved first is a coverage condition, not just good practice. We walked through a full response hour by hour if you want the detailed version.
Sizing the limit without guessing
The usual mistake is buying a limit that sounds reassuring rather than one built from your actual exposure. Start with the mechanical numbers: how many individuals' records you hold, since notification and credit monitoring scale directly with that count, and what a week of downtime costs you in gross profit.
Then add the legal and forensic layer, which is largely fixed regardless of your size — a small breach and a large one both need a lawyer and an investigator. That fixed cost is precisely why very small businesses are often underinsured at limits that feel generous relative to their revenue.
Check the sub-limits while you're there. The headline number rarely applies to everything: social engineering, business interruption, and regulatory fines commonly sit at a fraction of it, and those sub-limits vary far more between insurers than the main limit does.
Three things businesses get wrong about this policy
The first is assuming it's about hackers. Most claims small businesses actually make involve a person being deceived, a laptop going missing, or an email account being accessed with a stolen password. The stereotype is a targeted attack; the reality is usually mundane.
The second is assuming cloud software means the risk is someone else's. Your provider is responsible for their platform, not for your account being compromised or your staff sending data to the wrong recipient — and their terms will say so.
The third is assuming a small business is too small to be worth attacking. Most attacks aren't chosen, they're automated and opportunistic, and being less defended is what makes a target attractive rather than being large. Being small changes the size of the loss, not the odds of it.
The bottom line
If your business runs on email, cloud software, or card payments, you have cyber exposure regardless of what you hold. Get multi-factor authentication and tested offline backups in place first — they improve your terms and your odds. Then compare quotes on the social engineering sub-limit, the dependency wording, and the response panel, not just the headline limit and premium.
Get a quote and we'll compare cyber markets alongside the rest of your commercial programme, and tell you plainly where the policies differ.