← All insights

Guide · 6 min read

10 Things Canadian Businesses Should Know About Cyber Insurance

Cyber insurance has more moving parts than most people expect, and the parts that matter are not the ones on the price line. Here are ten things worth knowing before you buy.

Short answer: The essentials. Cyber insurance covers first-party and third-party losses. Your overall limit is not what pays, the sublimits are. Controls like MFA are often required. Wire fraud needs a specific endorsement. And policies should be reviewed yearly, because wordings change.

1. Small businesses are targeted more, not less.

Ransomware and phishing against smaller firms keep climbing. Small and medium businesses are hit several times more often than large organizations, because attackers automate and smaller firms usually have thinner defences. That is the case for treating cyber as core coverage, not an add-on.

2. Premiums move with the market.

Cyber premiums are not fixed. The hard market of 2021 and 2022 pushed prices up sharply as attacks spiked. Since then it has settled and softened as insurers got a better handle on the risk. The constant in every cycle: businesses with strong controls, MFA, training, and tested backups, get the better pricing. Good controls are the surest way to manage your premium.

3. Canadian privacy law has teeth.

Under PIPEDA, breach reporting has been mandatory since November 2018. If a breach poses a real risk of significant harm, you have to notify the people affected and the Privacy Commissioner, and keep records of all breaches. A cyber policy helps cover the legal, notification, and regulatory costs of meeting those obligations.

4. The policy should fit your business.

No two cyber policies are the same, and they should not be. A retailer cares about point-of-sale exposure. A services firm cares about client data. Go through the wording with a broker who knows cyber and make sure it matches how you actually operate.

5. Incident response is the part you will use.

The best modern policies come with a response team. IT forensics, legal, PR, even ransom negotiation. Businesses with that support recover faster and lose less. Make sure it is included, not an afterthought.

6. Security and insurance are a package.

Insurers now expect proactive security, and many run a pre-binding assessment. Fail it and you can be declined. Endpoint protection, patching, and staff training are what keep you insurable.

7. Know first-party from third-party.

First-party covers your own losses, like ransom payments and data restoration. Third-party covers claims from customers or partners hurt by your breach. A complete policy has both.

8. New tech, new exposure.

As AI and connected (IoT) devices spread, so does the attack surface. Canadian businesses have already been hit through IoT weaknesses. Make sure your policy accounts for these newer risks.

9. People are still the weak point.

Verizon’s 2024 Data Breach Investigations Report found the human element, phishing and simple mistakes like a misdirected email, was involved in roughly two-thirds of breaches. Insurance covers the fallout, but training and phishing tests are what prevent it.

10. Review it every year.

Cyber requirements keep tightening and wordings keep shifting. Review your policy annually, stay current on the threats, and keep investing in your defences. A broker who specializes in cyber for smaller businesses earns their keep here.

Cyber insurance is not a luxury anymore. It is basic protection for any Canadian business that runs on computers. Understand the parts that matter, get the controls in place, and you are protecting your customers, your reputation, and your bottom line.

Frequently asked questions

What should every business know before buying cyber insurance?

That the headline limit, the sublimits, the required controls, and the exclusions matter more than the price. A cheap policy that does not pay is the most expensive one you can buy.

Does cyber insurance replace good security?

No. Insurance is the financial safety net. Controls like MFA, backups, and training are the foundation, and insurers increasingly require them.

How often should I review my cyber policy?

At least once a year, and any time your business changes, because cyber wordings and sublimits shift often.

Not sure where your coverage stands?

Run the free Coverage Assessment, or book a no-pressure review and I'll read your actual policy and tell you exactly where the gaps are.

Book a free review Assess my coverage

By J.R. Genua, CCIS, Certified Cyber Insurance Specialist and Registered Insurance Broker. Insurance services provided by St. Andrews Insurance Brokers Ltd.