The risks that do not damage anything you can see.
A wire transfer to the wrong account. A ransomware note on a Monday morning. A claim against a director personally. None of it touches your building, and none of it is covered by a standard business policy.
Build the cyber file Talk to a broker See what’s coveredRansomware, funds transfer fraud, breach response and board liability
Any business holding customer data or moving money
How you verify payment changes, and whether backups are tested
What does cyber insurance actually pay for?
Mostly people, not technology. When something goes wrong, a cyber policy pays for the specialists who get you running again, incident responders, forensic investigators, legal advice on what you must disclose, and the cost of notifying customers. It also covers money lost to fraud, the income lost while you are down, and claims from people whose information was exposed. The computers are rarely the expensive part.
Money sent on a convincing fake instruction is usually not covered by a business policy. It is simply gone, along with the days of work spent proving what happened and telling clients their information was exposed. The Canadian Centre for Cyber Security describes the loss without a single broken window: “When ransomware infects a device, it renders the system unusable or encrypts its storage, preventing access to the information and systems.” Nothing is damaged. Nothing works. Read the Cyber Centre on ransomware (opens in a new tab).
Much of the cyber loss Canadian small businesses suffer is not dramatic hacking. It is a convincing email that redirects a payment to a criminal’s account.
Cover for the modern side of a business.
Ransomware and extortion
Response, negotiation, recovery and the cost of getting operating again.
Funds transfer fraud
Money sent to a criminal because an email looked real. The claim small businesses make most.
Privacy breach response
Notifying affected people, legal advice, credit monitoring and regulator dealings.
Directors & officers liability
Personal liability for the people running the company, decisions, oversight, employment and financial matters.
Employment practices liability
Claims from staff about dismissal, harassment or discrimination, defence costs included.
Technology errors & omissions
For businesses whose product is software or IT services, where a failure causes a client a loss.
We can give you a cyber indication in minutes rather than days, including an automated scan of what is publicly exposed about your business.
Three things insurers will ask before they quote cyber.
Cyber underwriting has tightened considerably. These are not paperwork exercises. They are the controls that decide whether you get cover, and at what price.
Multi-factor authentication
On email and remote access.
Backups you have tested
Held separately from your main network, and actually restored at least once. Untested backups fail exactly when they matter.
A payment verification step
Calling a known number before changing any bank details. It takes one phone call, and it is the step that stops this.
The application is worth doing even if you do not buy.
Answering the questions makes you a better risk.
A cyber application is effectively a security checklist written by people who see the claims. Working through it tells you where you are exposed, and most of the fixes are free, turning on multi-factor authentication, testing a backup, agreeing a rule that nobody changes payment details without a phone call.
We will send you the questions and walk through them with you. If you decide not to buy, you are still better protected than you were, and we would rather that than sell you a policy you did not understand.
How this can play out.
An email that looks like your supplier asks you to update their bank details. The payment goes out on Thursday. By the time the real supplier calls about the overdue invoice, the money has moved three times.
Directors are personally exposed. Including volunteers.
If you sit on a board, claims about decisions the board made can be brought against you personally. Your personal assets are what stand behind them. That is true of a company board, a strata council, a housing society or a sports association.
Employment claims
Claims about hiring, firing and how people were treated. They arrive with legal costs from day one.
Volunteer boards are not exempt
Serving unpaid does not remove the exposure. Ask what cover for a small non-profit costs before you rule it out.
Your indemnity may not hold
Organizations promise to indemnify directors, but only if they still have the money to do so when it matters.
How cyber cover gets argued out of paying.
Cyber policies lean hard on the application form. The controls you tick on day one become promises, and the promises are checked on the day of the breach, not the day of the quote.
The controls you said you had
Multi-factor sign-in, backups and patching: if the application says they are in place, they have to actually be in place. A breach that walks through the gap between the form and the truth is the hardest claim to win.
Backups that were never tested
Having backups and being able to restore from them are two different facts. Some wordings care about the second one, and after ransomware, so do you.
Telling them late
Cyber policies expect fast notice, because the insurer brings the response team. Waiting a week to see if the problem goes away can cost the response and strain the cover at the same time.
Money moved without the callback
Fraud cover for transferred funds often expects a verification step: a call back on a known number before money moves. Skip the callback and the payment can land outside the cover that was bought for exactly this.
The fix is unglamorous: answer the application honestly, and call the moment something looks wrong. Check that your renewal answers still match your systems.
What business owners and boards ask us.
My business is small. Would anyone target us?
Most attacks are not targeted at all. They are automated, and small businesses are hit precisely because their defences are lighter. The common losses are fraudulent payment redirection and ransomware, neither of which requires anyone to have singled you out.
We use cloud services. Is that not their responsibility?
Their platform is their responsibility. Your data, your accounts and your payments remain yours, and an attacker who gets into your email account is inside your business regardless of who hosts it.
Is money stolen through email fraud covered?
Under a cyber policy with the right section, generally yes. Under a standard business policy, generally no. This is one of the clearest gaps between the two.
Do we need directors and officers cover for a non-profit?
It is worth having. Volunteer directors can be named personally in claims, employment disputes are a frequent source of them.
Our clients are starting to require cyber insurance. Is that normal?
Increasingly, yes, particularly if you hold client data or connect to their systems. Send us the requirement and we will check what we arrange against it, line by line, and tell you where it falls short.
What should we do first if we think we have been breached?
Call us. If you have a cyber policy, there is an incident response team you are entitled to use, and using it early materially improves the outcome. Do not start deleting things or paying anyone before that call.
Not the question you had? Build the cyber file and set out your own situation in plain words. A licensed broker reads it and replies in writing.
Ask for the questionnaire.
We will send the security questions and go through them with you. No obligation, and you end up safer either way. Tell us how you verify payment changes, and whether backups are tested.
Sitting on a volunteer board? Non-profits & societies covers the exposure that comes with it.
Accountant, bookkeeper, lawyer or advisor? See cyber cover for professional firms. You hold client money and client data, which changes the risk.
Consultant or IT firm? consultants & E&O covers claims that your work caused a loss.
Not every loss comes from outside. crime & employee theft covers the person with a login and your trust.
Ready for numbers instead of reading? Build the cyber and directors file: a few minutes, one question per screen. Build the file →