Summit Commercial Insurance Solutions
Back to Insights

What Cyber Insurance Actually Covers for Canadian Businesses (and What It Doesn't)

Summit Insurance4 min read

Key takeaways

  • Cyber insurance combines first-party cover (your own costs after an incident) with third-party cover (claims from customers, partners and regulators).
  • Business interruption is often the largest part of a cyber loss, so check the waiting period and how lost income is calculated.
  • PIPEDA requires breaches that pose a real risk of significant harm to be reported and affected people notified, and a cyber policy can cover the cost of doing that.
  • Insurers now expect MFA, tested offline backups and endpoint detection before they offer terms, and gaps can mean higher premiums or a decline.
  • Common exclusions include known prior incidents, betterment of systems, war and infrastructure failure.

Laptop showing a locked screen in a small business office at dusk

Cyber insurance is one of the most requested policies we place, and one of the most misunderstood. Many business owners assume it is an IT product, or that their general liability policy already responds to a hack. In most cases it doesn't.

This guide explains what a standalone cyber policy typically covers in Canada, where the gaps usually sit, and what insurers will ask you before they offer terms.

First-party cover: your own costs

First-party cover pays for losses your business suffers directly after a cyber incident. Depending on the policy, that can include:

  • Incident response. Breach coaches, forensic investigators and legal counsel who help you contain the incident and work out what happened. Many insurers give you access to a pre-approved response panel around the clock.
  • Data restoration. The cost of recovering or recreating data and restoring systems from backups.
  • Ransomware and cyber extortion. Negotiation support and, where lawful and approved by the insurer, the extortion payment itself.
  • Business interruption. Lost income and extra expenses while your systems are down. For most businesses this is the largest part of a loss.
  • Funds transfer and social engineering fraud. Money lost when an employee is tricked into sending payment to a fraudster. This is often sublimited, so check the amount.
  • Breach notification and credit monitoring. The cost of notifying affected people and offering them monitoring services.

Third-party cover: claims against you

Third-party cover responds when someone else holds you responsible for the incident:

  • Privacy and network security liability. Claims from customers or partners whose data was exposed, or who were harmed by malware spreading from your systems.
  • Regulatory defence and penalties. Costs of responding to privacy regulators and, where insurable by law, fines and penalties.
  • Media liability. Claims arising from content you publish online, such as copyright or defamation allegations.
  • PCI fines and assessments. Amounts owed to card brands after a breach of payment card data.

Breach notification in Canada

Under PIPEDA, private-sector organizations must report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada when there is a real risk of significant harm, notify the affected individuals, and keep records of every breach. Quebec's Law 25 adds its own requirements for businesses that handle personal information of Quebec residents.

Working through notification obligations across provinces is time-consuming and expensive. A cyber policy pays for the legal advice and logistics so you can focus on running the business.

The controls insurers now expect

After several years of heavy ransomware losses, insurers underwrite cyber far more carefully than they used to. Expect questions about:

  • Multi-factor authentication on email, remote access and administrator accounts
  • Backups that are encrypted, kept offline or immutable, and regularly tested
  • Endpoint detection and response (EDR) on laptops and servers
  • Patching timelines for critical vulnerabilities
  • Employee training on phishing and payment verification
  • Payment verification procedures, such as calling back on a known number before changing banking details

Weak answers don't always mean a decline, but they can mean higher premiums, a higher retention or a lower ransomware sublimit. Answer the application accurately. Overstating your controls can put a claim at risk.

What cyber insurance usually doesn't cover

  • Betterment. Upgrading your systems beyond where they were before the incident.
  • Known incidents. Events you knew about before the policy started.
  • Infrastructure failure. Outages of the power grid, internet backbone or telecom networks.
  • War and state-backed attacks. Most policies now include specific wording on these.
  • Lost intellectual property value. The future value of stolen trade secrets is generally not covered.
  • Bodily injury and property damage. These usually sit with your other policies.

Is your general liability policy enough?

Usually not. Most commercial general liability (CGL) policies now exclude electronic data and cyber events, and they never covered your own first-party costs such as forensic work or lost income. If your business relies on email, online payments or customer data, it needs a standalone cyber policy.

How Summit can help

We compare cyber options across multiple carriers, help you prepare the security information underwriters ask for, and explain the differences in wording, sublimits and waiting periods before you choose. For growing companies with more complex exposures, our mid-market team can structure larger programs and excess layers.

Share this article

ArticleTechnology

Tech E&O and Cyber: Why SaaS Companies Need Both

Technology errors and omissions and cyber insurance protect against different failures. For SaaS companies, gaps between them are where claims fall through.

3 min read

Have a question about your own coverage?

Our brokers work with cyber clients every day and can review your program.

Get a Quote