← All insights

Myths · 5 min read

"My liability policy covers a hack." It almost certainly doesn't.

It's one of the most common, and most expensive, assumptions I hear from Canadian business owners: "We have commercial general liability, so if we get breached, we're covered." In most cases, you're not. Here's why the policy you already pay for usually sits this one out, and what actually responds.

Short answer: Almost never. Commercial general liability is built for physical injury and property damage, electronic data is generally not treated as tangible property, and most CGL wordings now carry a specific cyber exclusion. A dedicated cyber policy is what responds.

What your CGL policy was built to do

Commercial General Liability (CGL) is a workhorse policy, and a good one, but it was designed for a pre-internet kind of risk. It responds when your business causes bodily injury or physical property damage to someone else: a customer slips in your shop, your product injures a user, your sign falls on a parked car. That's its job, and it does it well.

A cyber attack is a different animal entirely. There's no slip, no broken window, no physical injury. The harm is to data, to operations, and to money moving electronically, none of which CGL was ever meant to address.

Why a cyber claim falls outside it

Two things usually keep a CGL policy from responding to a breach:

1. Data isn't "property" in the way the policy means it. CGL pays for damage to tangible property. Most policies are clear that electronic data is not tangible property, so encrypting your files with ransomware, or losing a database, doesn't trigger the property-damage coverage the way a fire or flood would.

2. Explicit cyber exclusions. Insurers saw this coming. For years now, most CGL wordings have carried a specific exclusion for the access to, or disclosure of, confidential or personal information, and often a broader electronic-data exclusion on top. In plain terms: the policy language was deliberately written to carve cyber out.

So even where a creative argument might exist, the wording is usually built to shut it down. You can't rely on a coverage the policy was specifically edited to exclude.

What that means when an incident actually hits

Here's the part that stings. When a real cyber event happens, these are the costs that land, and that a standard CGL policy typically won't pay:

That's the entire bill from a typical SME cyber incident, and it's exactly the part most owners assume is already handled.

"What about my commercial property policy, or my BOP?" Same answer, same reasons. Property and package policies are built around physical assets and tangible loss. A few may offer a small data add-on, but it's rarely enough to cover a real incident, and it's never a substitute for dedicated cyber coverage.

What actually responds

A purpose-built cyber insurance policy is what fills this gap. A good one covers both sides of an incident: your own losses (first-party, recovery, ransom, lost income) and claims from others affected by your breach (third-party). It's designed for the way attacks actually happen today, and increasingly it comes paired with services, 24/7 breach response, monitoring, not just a cheque after the fact.

The danger isn't being uninsured. It's being confidently uninsured, believing a policy has your back when its wording was written to do the opposite. That confidence usually only breaks at the worst possible moment: claim time.

Frequently asked questions

Does commercial general liability cover a data breach?

In most cases no. CGL covers bodily injury and physical property damage, and modern wordings usually exclude access to or disclosure of confidential information.

Why isn't data covered as property under CGL?

Most policies state that electronic data is not tangible property, so encrypting or losing data does not trigger the property damage coverage the way a fire would.

What policy actually covers a cyber attack?

A dedicated cyber insurance policy, which covers both your own losses (first-party) and claims from others affected by your breach (third-party).

Not sure what your current program actually covers?

Let's take a look together. I'll walk through what you have, point out where a cyber event would fall through the cracks, and talk through the questions worth asking, no obligation, no pitch.

Book a free review Check my coverage gaps

By J.R. Genua, CCIS, Certified Cyber Insurance Specialist. Educational only; coverage terms vary by insurer and province. Always confirm your specific wording with your licensed broker.