Skip to main content

Coverage for the costs that can follow a cyber event.

Designed for certain expenses and liability arising from data breaches, ransomware, privacy incidents and network interruption.

Want to talk now?905-573-7471

  • Proudly Canadian

  • Quotes Made
    Simple

  • Compare Canadian Insurers

  • Real Broker Advice

  • Claims Support

WHAT IT DOES

The costs start before anyone works out who is liable.

A cyber event creates two problems: the cost of responding, and the liability that may follow. The response service often matters more than the limit.

01

Customer information is exposed

02

Ransomware disrupts operations

03

A compromised account causes unauthorised activity

04

A privacy incident creates notification and legal costs

A cyber policy may respond in each case, subject to its wording, limits, exclusions and conditions.

WHAT IT MAY COVER

Common areas of coverage.

Breach Response

Access to incident response support, and the forensic work needed to establish what happened.

Privacy Liability

Third-party claims and regulatory costs arising from personal or confidential information being exposed.

Ransomware and Cyber Extortion

Costs associated with an extortion demand, where the policy includes it and the insurer’s conditions are met.

Business Interruption

Income lost while systems are unavailable following a covered cyber event, subject to the waiting period.

Data Restoration

The cost of restoring or recreating data and systems affected by a covered event.

Social Engineering

Where the policy includes it, certain losses from funds transferred after a fraudulent instruction.

Cyber wordings vary, and cover often depends on the controls you declared. A broker can confirm what a policy includes.

WHAT IT DOESN’T REPLACE

A cyber policy is not an IT budget, and not a warranty.

Cyber answers for the consequences of an incident, not for maintaining systems. Several related risks are insured separately.

Technology E&O

Allegations that technology work you delivered for a client was negligent or inadequate.

Crime

Employee dishonesty and certain theft of money or securities, which many wordings treat separately.

Commercial Property

Physical damage to hardware and premises, rather than the data on them.

Commercial General Liability

Third-party bodily injury and property damage from your operations.

Directors and Officers

Claims against directors and officers about how the organisation was governed.

IT Maintenance and Warranty

Patching, upgrades, backups and vendor obligations, which remain your responsibility.

These are general distinctions, not a statement of what any policy does. A broker can review the wording with you.

WHO COMMONLY NEEDS IT

The operations that most often carry a cyber policy.

Anywhere the business holds data it cannot afford to lose or expose. These are the HIFA industry pages where it comes up most often.

NOT SURE WHERE YOU FIT?

A broker can check the controls before the insurer does.

Tell us what data you hold and how your systems are secured. A commercial broker can review the risk and the wording with you before you approach the market.

Want to talk now?

905-573-7471

REAL CLAIM EXAMPLES

Two situations worth thinking through in advance.

Compromised Account

A staff email account is accessed by an unauthorised party and correspondence containing personal information is exposed.

A cyber policy may respond to breach response, forensic and notification costs, and to the privacy liability that follows.

Ransomware Interruption

Systems are encrypted and operations stop for several days while the business restores from backups.

A cyber policy may respond to data restoration costs and to business interruption after the waiting period. What is payable depends on the controls in place and what was declared to the insurer.

Illustrative example

Illustrative only. These are not a statement of coverage. Every claim is assessed on its own facts against the policy in force.

WHAT AFFECTS THE PRICE

Two businesses holding similar data can price very differently.

THE CONTROLS

Multi-factor authentication

How backups are held and tested

Remote and administrative access

Third-party providers you rely on

Staff training and email filtering

THE EXPOSURE

Annual revenue

Type and volume of data held

Industry and regulatory environment

Requested limits and deductible

Prior incidents and claims

Security controls move cyber pricing more than anything else, and some insurers will not quote without them. A broker can tell you what is expected.

WHAT WE’LL ASK YOU

The questions that change the policy.

01

What data do you collect or store, and where does it live?

02

Do you use multi-factor authentication, and on what?

03

How are backups managed, and when were they last tested?

04

Who has remote or administrative access?

05

What third-party providers do you depend on?

06

Have there been prior cyber incidents or near misses?

Common questions

What owners ask about cyber insurance.

I use a secure cloud provider. Do I still need cyber insurance?
Yes. Cloud providers secure the infrastructure, but you control the access. Most breaches happen due to compromised credentials or phishing, which remains your liability.
What is Social Engineering Fraud coverage?
This covers instances where an employee is tricked into voluntarily transferring funds to a fraudulent account (e.g., a fake invoice from a 'vendor'). It is often a sub-limit within a cyber policy.
Will the policy pay a ransom?
Many policies include extortion coverage that may pay a ransom if it is the only way to recover critical data, but insurers have strict protocols and require their incident response teams to manage the negotiation.
Why did I get denied for cyber insurance?
Insurers now mandate basic security hygiene. If your business lacks Multi-Factor Authentication (MFA), secure backups, or basic firewall protections, you may be uninsurable until those are implemented.
What is the most valuable part of a cyber policy?
Beyond the financial payout, the 'Incident Response Panel' is crucial. The policy gives you immediate access to top-tier IT forensics, specialized lawyers, and PR firms to manage the crisis.
How is cyber insurance different from technology errors and omissions?
They answer for different failures. Technology E&O responds to claims that the professional work you delivered was wrong, late or negligent. Cyber responds to the security of the data and systems you hold — a breach, an outage, a ransom demand, the notification obligations that follow. A firm that builds or manages technology for clients often needs both, and the useful question is how the two wordings are meant to meet, because an incident involving a client's systems can engage either.

READY TO TALK?

Let’s look at the data before there is an incident to talk about.

Tell us what you hold, what you rely on and how it is secured. A commercial broker can review the risk before approaching insurers.

Want to talk now?

905-573-7471