Vancouver · Closed, opens 9am604-324-5711Delta · Closed, opens 9am604-635-0890Surrey · Closed, opens 9am604-319-1000
Business Insurance BC  /  Cyber Insurance for Business BC
Cyber · directors & officers · corporate risk

The risks that do not damage anything you can see.

A wire transfer to the wrong account. A ransomware note on a Monday morning. A claim against a director personally. None of it touches your building, and none of it is covered by a standard business policy.

Build the cyber file Talk to a broker See what’s covered
Covers

Ransomware, funds transfer fraud, breach response and board liability

Who needs it

Any business holding customer data or moving money

Send us

How you verify payment changes, and whether backups are tested

The short answer

What does cyber insurance actually pay for?

Mostly people, not technology. When something goes wrong, a cyber policy pays for the specialists who get you running again, incident responders, forensic investigators, legal advice on what you must disclose, and the cost of notifying customers. It also covers money lost to fraud, the income lost while you are down, and claims from people whose information was exposed. The computers are rarely the expensive part.

What it costs you

Money sent on a convincing fake instruction is usually not covered by a business policy. It is simply gone, along with the days of work spent proving what happened and telling clients their information was exposed. The Canadian Centre for Cyber Security describes the loss without a single broken window: “When ransomware infects a device, it renders the system unusable or encrypts its storage, preventing access to the information and systems.” Nothing is damaged. Nothing works. Read the Cyber Centre on ransomware (opens in a new tab).

Much of the cyber loss Canadian small businesses suffer is not dramatic hacking. It is a convincing email that redirects a payment to a criminal’s account.

What we arrange

Cover for the modern side of a business.

Ransomware and extortion

Response, negotiation, recovery and the cost of getting operating again.

Funds transfer fraud

Money sent to a criminal because an email looked real. The claim small businesses make most.

Privacy breach response

Notifying affected people, legal advice, credit monitoring and regulator dealings.

Directors & officers liability

Personal liability for the people running the company, decisions, oversight, employment and financial matters.

Employment practices liability

Claims from staff about dismissal, harassment or discrimination, defence costs included.

Technology errors & omissions

For businesses whose product is software or IT services, where a failure causes a client a loss.

What we can confirm

We can give you a cyber indication in minutes rather than days, including an automated scan of what is publicly exposed about your business.

Three things insurers will ask before they quote cyber.

Cyber underwriting has tightened considerably. These are not paperwork exercises. They are the controls that decide whether you get cover, and at what price.

Multi-factor authentication

On email and remote access.

Backups you have tested

Held separately from your main network, and actually restored at least once. Untested backups fail exactly when they matter.

A payment verification step

Calling a known number before changing any bank details. It takes one phone call, and it is the step that stops this.

Being straight with you

The application is worth doing even if you do not buy.

Answering the questions makes you a better risk.

A cyber application is effectively a security checklist written by people who see the claims. Working through it tells you where you are exposed, and most of the fixes are free, turning on multi-factor authentication, testing a backup, agreeing a rule that nobody changes payment details without a phone call.

We will send you the questions and walk through them with you. If you decide not to buy, you are still better protected than you were, and we would rather that than sell you a policy you did not understand.

An illustration

How this can play out.

An email that looks like your supplier asks you to update their bank details. The payment goes out on Thursday. By the time the real supplier calls about the overdue invoice, the money has moved three times.

Directors are personally exposed. Including volunteers.

If you sit on a board, claims about decisions the board made can be brought against you personally. Your personal assets are what stand behind them. That is true of a company board, a strata council, a housing society or a sports association.

Employment claims

Claims about hiring, firing and how people were treated. They arrive with legal costs from day one.

Volunteer boards are not exempt

Serving unpaid does not remove the exposure. Ask what cover for a small non-profit costs before you rule it out.

Your indemnity may not hold

Organizations promise to indemnify directors, but only if they still have the money to do so when it matters.

The application is part of the policy

How cyber cover gets argued out of paying.

Cyber policies lean hard on the application form. The controls you tick on day one become promises, and the promises are checked on the day of the breach, not the day of the quote.

The controls you said you had

Multi-factor sign-in, backups and patching: if the application says they are in place, they have to actually be in place. A breach that walks through the gap between the form and the truth is the hardest claim to win.

Backups that were never tested

Having backups and being able to restore from them are two different facts. Some wordings care about the second one, and after ransomware, so do you.

Telling them late

Cyber policies expect fast notice, because the insurer brings the response team. Waiting a week to see if the problem goes away can cost the response and strain the cover at the same time.

Money moved without the callback

Fraud cover for transferred funds often expects a verification step: a call back on a known number before money moves. Skip the callback and the payment can land outside the cover that was bought for exactly this.

The fix is unglamorous: answer the application honestly, and call the moment something looks wrong. Check that your renewal answers still match your systems.

Common questions

What business owners and boards ask us.

My business is small. Would anyone target us?

Most attacks are not targeted at all. They are automated, and small businesses are hit precisely because their defences are lighter. The common losses are fraudulent payment redirection and ransomware, neither of which requires anyone to have singled you out.

We use cloud services. Is that not their responsibility?

Their platform is their responsibility. Your data, your accounts and your payments remain yours, and an attacker who gets into your email account is inside your business regardless of who hosts it.

Is money stolen through email fraud covered?

Under a cyber policy with the right section, generally yes. Under a standard business policy, generally no. This is one of the clearest gaps between the two.

Do we need directors and officers cover for a non-profit?

It is worth having. Volunteer directors can be named personally in claims, employment disputes are a frequent source of them.

Our clients are starting to require cyber insurance. Is that normal?

Increasingly, yes, particularly if you hold client data or connect to their systems. Send us the requirement and we will check what we arrange against it, line by line, and tell you where it falls short.

What should we do first if we think we have been breached?

Call us. If you have a cyber policy, there is an incident response team you are entitled to use, and using it early materially improves the outcome. Do not start deleting things or paying anyone before that call.

Not the question you had? Build the cyber file and set out your own situation in plain words. A licensed broker reads it and replies in writing.

Ask for the questionnaire.

We will send the security questions and go through them with you. No obligation, and you end up safer either way. Tell us how you verify payment changes, and whether backups are tested.

Sitting on a volunteer board? Non-profits & societies covers the exposure that comes with it.

Accountant, bookkeeper, lawyer or advisor? See cyber cover for professional firms. You hold client money and client data, which changes the risk.

Consultant or IT firm? consultants & E&O covers claims that your work caused a loss.

Not every loss comes from outside. crime & employee theft covers the person with a login and your trust.

Ready for numbers instead of reading? Build the cyber and directors file: a few minutes, one question per screen. Build the file →

Business insurance

Tell us about the business.

The more you tell us here, the fewer questions we have to ask later. Nothing is priced automatically. A broker reads it.

English, Punjabi, Hindi, Italian, Cantonese and Mandarin are spoken across our counters.

What are you looking for?
Tick everything that applies. If you are not sure, tick nothing and tell us below.
In your own words. “We frame houses” tells us more than a category ever will.
If it is inside 30 days, tell us now. Some markets need lead time.
If yes, paste the insurance clause here. Reading the actual wording is what stops a certificate being rejected.
How would you like us to reply?
We will use exactly this and nothing else.
We read the contract wording, not a summary of it.
Sent securely · never sold · see how we handle it