Vancouver · Opens Mon 9am604-324-5711Delta · Opens Mon 9am604-635-0890Surrey · Opens Mon 9am604-319-1000
Business Insurance BC  /  Cyber Insurance for Business BC  /  What Cyber Insurance Will Not Cover
Cyber and directors

The transfer was authorized by your own staff. That is why the cyber policy may not pay.

Cyber insurance is written for an attack on your systems. A great deal of what actually costs businesses money is not an attack on the systems at all. It is somebody being convincingly asked to do something, and doing it.

Start a quote file Read the short answer first
The gap

Tricked is not the same as hacked.

The clock

Downtime cover starts after a waiting period.

The upgrade

Better than before is generally on you.

What it comes down to

What will a cyber insurance policy not pay for?

The common gaps are money sent away by a member of your own staff who was deceived, the cost of improving your systems beyond what they were before the incident, the first hours of downtime that fall inside the waiting period, and losses that flow from a supplier’s outage rather than your own. None of these is unusual. They are the shape of an ordinary bad week, which is why it is worth knowing before you buy which of them your wording actually answers.

Cyber wordings vary widely, because the product is young and there is no standard form. Two policies with the same limit and a similar premium can answer completely different events. Comparing them on price alone is close to meaningless.

The distinction that decides most claims

Insurers separate an attack on your systems from a deception of your people. A criminal who breaks in, encrypts your files and demands payment is attacking the system. A criminal who emails your bookkeeper from what looks like a supplier’s address, with a plausible reason for a change of bank details, is deceiving a person, and your own staff member then makes the payment willingly. The money is just as gone. But the first is core cyber cover and the second usually sits under a separate insuring agreement called social engineering or fraudulent instruction, often with a much smaller limit and its own conditions about verifying requests by telephone. The Canadian Centre for Cyber Security recommends automatic patching as one of its baseline controls for small and medium organizations, because “IT vendors release software and firmware updates (patches) on a regular basis to address defects and security vulnerabilities.” Some wordings exclude loss that flows from a known vulnerability the business had not patched. Insurers also ask about patching, multi-factor authentication and backups on the proposal form, and answers that turn out to be inaccurate can affect whether a claim is paid. Read the baseline cyber security controls (opens in a new tab).

Where the wordings differ most

Four things to check before you compare two quotes.

Social engineering and fraudulent instruction

Whether it is included at all, what the sub-limit is, and what the policy requires you to have done before paying. Some wordings treat a doctored supplier invoice as its own section, called invoice manipulation, so check for that as well. Many wordings require a call-back to a previously known number for any change of banking details, and a claim where nobody made that call is a hard one. Put the call-back into your payment process, not just into the policy.

The waiting period on downtime

Business interruption inside a cyber policy usually starts after a stated number of hours rather than immediately. Wordings do this two ways. Some never pay for the hours inside the waiting period. Others pay from the start once the outage runs past it. Two policies showing the same number of hours can therefore pay very different amounts on the same outage, so ask which way yours is written.

Betterment and system improvement

The policy restores what you had. If the fix involves moving to a better platform, adding controls you did not have, or replacing hardware that was already at end of life, that improvement is generally your cost. It is a reasonable position and it still surprises people.

Your supplier’s outage

When the failure is at a cloud provider, a payment processor or a managed service you depend on, your own systems are fine and you still cannot trade. Some policies extend to dependent business interruption and some do not, and those that do often name the providers or set conditions. Know which of your suppliers your business genuinely cannot function without, then check whether they are covered.

What these losses look like

Three illustrations, not client files.

The invoice with new bank details

A supplier’s email account is compromised and the invoice arrives from their real address. It is paid. Nothing on the buyer’s own network is breached, so the core cyber sections never engage. Whether anything is recovered turns first on whether a fraudulent instruction or invoice manipulation section was bought, and on its limit and conditions.

The short outage

Systems are restored the same day, which is a good outcome. The interruption falls inside the waiting period, so the lost trading is not covered. The response costs, the forensic work and the legal advice usually sit under different sections and are commonly not subject to that waiting period. Knowing which parts respond changes how you plan.

The notification nobody budgeted for

The technical incident is small. The obligation to work out whose information was affected, to assess the risk of harm to those people, and to notify them is not. Response costs, legal advice and a breach coach are the sections that carry that work, and they are the sections that are easiest to trim when a quote is being cut back.

Compare the wording

Send us any cyber quote you are holding.

You will get a written note on the sub-limits, the waiting period and the sections that actually decide a claim, not the headline limit.

Send the quote
Questions from the file

The ones that decide which quote you should take.

Does the policy pay a ransom?

Many wordings include an extortion section that can cover a payment and the negotiation around it. Most require the insurer’s agreement before any payment is made, and whether a payment is lawful is a question for counsel. Whether paying is the right decision is a separate question entirely, and it is one made with the insurer’s incident response team rather than alone. The more useful cover on most files is the restoration and downtime, not the ransom.

Our data is all with a cloud provider. Are we still exposed?

Yes. Using a provider moves where the data sits, not who is responsible for it. Your obligations to the people whose information it is do not transfer with the hosting, and the provider’s own agreement usually limits what they owe you.

We already have crime cover. Is that the same thing?

Not quite, and the overlap is where arguments happen. Crime policies traditionally answer theft by employees and certain kinds of fraud, cyber policies answer attacks on systems, and deception of a staff member falls awkwardly between the two. Having both without checking how they fit can still leave the gap. Send both wordings and they can be read against each other.

What do insurers want to see before they will quote?

Multi-factor authentication on email and remote access, offline or otherwise separated backups that have been tested, some form of endpoint protection, and a payment process with verification for changes to bank details. These have moved from nice to have to close to mandatory, and having them in place changes both the price and whether cover is available at all.

Is a small business really a target?

You do not have to be picked out. Automated scanning does not choose its targets. It finds whatever is exposed, and a small firm with a compromised email account is a perfectly good route to somebody else’s money.

Not the question you had? Send the wording you are being offered through the quote file and you will get a written answer on what it does and does not do, not a sales call.

Worth reading next, if you are a consultant holding client data: which of your two policies answers when it goes missing.

Compare the wordings, not the premiums.

Send any quote you are holding. You will get a written note on the sub-limits, the waiting period and the sections that actually decide a claim.