Technology Industry

00 / Industry Practice

Technology Industry

Technology insurance in Canada is now mostly one policy rather than two: the market has converged on combined forms that put technology errors and omissions, cyber and media on a single wording. That convergence matters, because the classic technology insurance failure is a loss falling into the seam between a separate E&O policy and a separate cyber policy. Canada has roughly 48,000 ICT companies and about 41,000 of them employ fewer than ten people — very small companies signing contracts with very large ones. This page sets out what the coverage does, who writes it here, and where placements go wrong.

02 / The Core Distinction

Tech E&O and Cyber Do Different Jobs

These two coverages are routinely confused, and in technology insurance the confusion is expensive. The short version: cyber answers when your systems are attacked; tech E&O answers when your product does not work. Most Canadian technology insurance now carries both.

What technology E&O actually responds to

A Canadian-market carrier describes it as third-party financial losses from errors, omissions or negligence in technology products or services — software errors and operational failures causing service disruption, delays or failures in product delivery, intellectual property claims related to software code, implementation and installation errors in IT services, manufacturing defects causing financial loss, and breach of contract requirements. No attacker is involved in any of that.

What cyber responds to

Within a technology insurance programme, cyber splits into first-party and third-party. First-party pays your own costs: incident response, forensics, data restoration, business interruption, extortion. Third-party answers claims against you for a security or privacy failure. It is built around an attack, a breach or a system compromise — not around whether your software did what you sold it to do.

Which is why the Canadian market combines them

For technology companies specifically the market here has converged on a single form. Chubb’s DigiTech puts technology E&O, media and cyber on one policy. Zurich’s Pro Plus provides technology, media and cyber on a single form with integrated limits. Liberty’s Tech Resolution carries technology errors and omissions as a third-party agreement inside a full cyber form. CFC’s Canadian wording lists technology errors and omissions as a named insuring agreement. Markel’s Tech 360 adds management liability to the same modular policy.

And why buying them separately is a decision, not a default

A Canadian underwriting manager for technology, cyber and E&O makes the structural point directly: technology liability policies combine professional liability with cyber, which is what distinguishes them from the standard cyber products bought by other service professionals. Two separate towers can be made to work — but the retro dates, notice provisions and definitions then have to be reconciled deliberately rather than assumed to line up.

03 / The Canadian Market

Who Writes This Class Here, and What They Are Offering

Technology insurance is a specialist class with a small, identifiable market. Knowing who writes it — and what is currently available — is most of a technology insurance placement.

The carriers actually writing Canadian technology risk

Chubb Canada, Zurich Canada, Liberty Mutual Canada, AIG Canada, Markel Canada, Beazley, CFC, Coalition, Intact’s specialty team, Berkley Canada, Victor Canada, Ridge Canada and SUM Insurance all publish Canadian technology or cyber offerings. Berkley Canada states it insures over five hundred Canadian technology companies, including more than forty per cent of the top public software and IT companies by revenue.

Capacity has changed materially — as of January 2026

Most Canadian carriers had been capped around ten million dollars per risk. Effective 1 January 2026 Mosaic more than doubled its Canadian cyber capacity to about forty million dollars per risk, writing primary or excess, with its Canadian president on record that Canada had lagged the UK and US on capacity. Coalition brought its Active Cyber Policy to Canada in March 2026 with limits to twenty million for companies up to five billion in revenue. Arch launched a Canadian primary cyber product in April 2026.

Rates are soft, and two credible indices disagree on how soft

Marsh puts Canadian cyber at down five per cent in the first quarter of 2026 and down six in the second. Aon reports Canadian cyber down about twenty per cent on primary layers and twenty-two across all layers at the end of 2025. These are different books and different methods — the honest reading is that the direction is clear and the magnitude depends on your programme. A Canadian technology underwriter put it more plainly: it is probably the softest the class has been in seven years of underwriting it.

Retentions and incident response have loosened too

Canadian forms increasingly carry a zero retention where you use the insurer’s own incident response panel, and one Canadian wording applies no deductible at all to initial incident response. Cybercrime sublimits that were commonly capped at a hundred thousand dollars now run from two hundred and fifty thousand to a million, on the account of a Canadian technology and cyber underwriter. Reduced retentions for funds transfer fraud reported quickly, and retentions that shrink with claim-free years, are both live in this market.

What underwriters now require before they will bind

Multi-factor authentication, endpoint detection and response, privileged access management and encryption are what Canadian brokers report underwriters asking for. Requirements have eased against the 2020 to 2022 hard market, and a strong security posture now buys long-term pricing agreements and rate guarantees rather than just a discount. But controls are a condition, not a discount — and a Canadian organisation has already had a major cyberattack claim denied specifically because MFA had not been implemented.

The warning that comes with a soft market

A Canadian technology underwriting manager warns that some new entrants are underpricing policies or paring back coverage to win share, potentially leaving clients with protection gaps, and that losses are accumulating in cybercrime, fraudulent payment transfers and notification expenses. Her forward call: pricing will have to catch up, and that will create some hardening — just not immediately. Cheap capacity that is quietly narrower is the technology insurance risk to manage this year.

04 / Where Placements Fail

Where Technology Placements Actually Go Wrong

Six failure modes that Canadian brokers and underwriters have publicly flagged. None of them are exotic — they are the ordinary ways a technology insurance programme turns out not to respond.

The dependency nobody schedules

If your entire delivery model rests on one hyperscaler, a failure there is your business interruption, not theirs. Dependent or contingent business interruption is an available, named Canadian coverage — one carrier publishes contingent business interruption for outsourced technology provider interruptions specifically. It is rarely bought at a limit that reflects how concentrated the dependency actually is.

And the one that runs the other way

The Canadian Centre for Cyber Security states plainly that managed service providers are increasingly targeted because of their client access, and notes a trend toward multi-extortion tactics targeting supply chains and third parties. For an MSP or a multi-tenant SaaS provider, one incident is not one claim — it is every customer at once, and how the policy aggregates that is an underwriter conversation worth having before binding.

05 / Privacy Law

What Canadian Privacy Law Actually Requires in 2026

The regulatory picture behind technology insurance moved in June 2026, and a great deal of published material is now out of date. Here is where it actually stands.

PIPEDA governs you here, and the record-keeping rule is the one that gets missed

Only Alberta, British Columbia and Quebec have private-sector laws deemed substantially similar, so PIPEDA applies to Nova Scotia companies. Report to the Privacy Commissioner where a breach creates a real risk of significant harm — but note separately that you must keep a record of every breach of security safeguards for twenty-four months, whether or not it was reportable. Knowingly contravening those provisions is an offence carrying fines to ten thousand dollars on summary conviction and a hundred thousand on indictment.

Bill C-27 is dead; Bill C-36 is the successor and is not law

The Consumer Privacy Protection Act, the Tribunal Act and the Artificial Intelligence and Data Act all died when Parliament was prorogued — Canada has no enacted AI statute. Bill C-36 received first reading on 15 June 2026 and is at second reading. It would bring administrative penalties up to the greater of ten million dollars or three per cent of gross global revenue, most serious offences to twenty-five million or five per cent, and a private right of action. Real, but not imminent — and worth building your technology insurance and privacy programme toward now.

Quebec is already there, and it has a statutory floor

Law 25 is in force with administrative penalties to the greater of ten million dollars or two per cent of worldwide turnover, and penal fines to twenty-five million or four per cent. The number that matters for a SaaS company with Quebec users is section 93.1: where an infringement is intentional or results from gross fault, the court shall award punitive damages of not less than one thousand dollars. That converts a breach affecting a hundred thousand Quebec residents into a class action with a floor rather than a ceiling.

Bill C-8 does not apply to you — but it will reach you

The Critical Cyber Systems Protection Act received Royal Assent on 15 June 2026 and covers designated operators in six federally regulated vital services — telecom, pipelines and power, nuclear, federal transportation, banking, and clearing and settlement. An ordinary SaaS company or MSP is not a designated operator. But designated operators must manage supply-chain and third-party risk, and they will push that down through contracts, questionnaires and incident-notification clauses.

06 / Contracts

What Your Customers’ Contracts Are Really Asking For

In this industry the customer contract usually sets the technology insurance requirement before an underwriter does. Two Canadian regulatory regimes explain why enterprise and public-sector buyers ask for what they ask for.

Contract negotiation meeting — technology insurance and customer contract requirements in Canada
07 / Artificial Intelligence

AI: What Canadian Insurers Are Actually Doing

There is a loud narrative that AI exclusions are proliferating. In Canada that is not yet what is happening, and it is worth being precise about the difference.

No AI statute, and no AI exclusions yet

Canada has no enacted AI legislation — AIDA died with Bill C-27. On the insurance side, Gallagher’s national technology practice leader for Canada said in July 2026 that insurers are adding affirmative AI language but that it is more just clarifying their intent as opposed to necessarily adding coverage, and that she has not yet seen exclusionary language around AI risks. Broad AI exclusions are, so far, a US and global development Canadian buyers should watch rather than a Canadian reality.

Some Canadian carriers have taken an affirmative position

One Canadian cyber form published in March 2026 includes AI and deepfake coverage, addressing malicious use of AI technology, machine learning exploits and deepfake-enabled social engineering. Another Canadian carrier publishes that generative AI falls within its definition of computer systems on both its technology and cyber forms. Those are scope positions rather than standalone AI products — and no Canadian carrier publishes a standalone AI liability policy separate from its technology insurance forms.

What does govern AI here — and where the exposure sits

Existing law applies. Every Canadian privacy regulator jointly confirmed in 2023 that public accessibility of data does not mean it can be indiscriminately collected or used — the direct answer on scraped training data — and named prompt injection, model inversion and jailbreaking as security risks to safeguard against. Quebec’s automated-decision provision is in force. Ontario has required disclosure of AI use in job screening since January 2026. Underwriters have started asking about AI deployment and governance. If you build AI, the exposure lands on your existing technology insurance — E&O and cyber — rather than somewhere new.

08 / Beyond E&O and Cyber

The Other Lines a Technology Company Needs

Six exposures that sit outside the combined technology insurance form, each with a concrete Canadian source of liability behind it and none of them answered by technology insurance alone.

Directors and officers — the statutory grounding is real

Under the federal corporate statute directors are jointly and severally liable for up to six months’ wages owed to employees, and owe a duty of care in their own right. Tax legislation makes them personally liable for unremitted source deductions and GST or HST, subject to a due diligence defence. Quebec’s privacy law reaches officers and directors who direct, authorise or acquiesce. Canada’s anti-spam legislation does the same. This is not theoretical liability.

CASL catches software companies, not just marketers

Canada’s anti-spam legislation carries administrative penalties to one million dollars per violation for individuals and ten million for businesses. Beyond commercial electronic messages, it prohibits installing a computer program on another person’s system without express consent in the course of commercial activity, with enhanced disclosure where the program collects personal information, interferes with control or alters settings. That applies to vendors, updaters, agents and SDKs.

Marketing claims got riskier in June 2025

Private parties may now apply directly to the Competition Tribunal for deceptive marketing practices, in force since 20 June 2025, with the leave test lowered and a public-interest route available. For a technology company making performance claims, accuracy claims or “AI-powered” claims, that is a new and under-discussed avenue of exposure — and it sits alongside, not inside, the media liability in your technology insurance.

Funds transfer fraud is the loss that actually happens

Canadian cyber wordings offer computer fraud, funds transfer fraud and social engineering fraud, often by endorsement and often sublimited. The RCMP reports business email compromise losses of almost thirty million dollars in Canada in 2020 and over twenty-six million in the first half of 2021 alone, and recommends a two-step verification process for payment requests using a different channel. Canadian underwriters name fraudulent payment transfers among where losses are currently accumulating.

Intellectual property, and the demand-letter provision

A Canadian-market technology E&O contemplates intellectual property claims tied to software code, and media liability commonly covers copyright and trademark infringement. Worth knowing separately: Canada’s Patent Act includes a written demand provision, so a recipient of a non-compliant demand letter — or a person aggrieved by another’s receipt of one — can bring proceedings in Federal Court for damages, punitive damages, an injunction or costs.

Employment practices, and management liability generally

Employment-related claims sit outside a liability policy. In this sector the exposure is heightened by rapid hiring, equity compensation disputes and the speed at which technology companies restructure. The Canadian market has responded by bundling — one Canadian technology insurance product combines technology E&O, cyber and management liability — directors and officers, employment practices and fiduciary — in a single modular policy.

09 / The Local Picture

The Sector Here, and How Little of It Is Insured

Three numbers that frame the technology insurance conversation for a Canadian company deciding what to buy.

Nova Scotia’s digital economy is now a primary sector

Digital Nova Scotia’s 2026 study counts roughly fifteen hundred digital economy firms supporting about thirty-seven thousand jobs and more than eleven per cent of provincial GDP, with sector unemployment at one point seven per cent. Halifax has been ranked North America’s second emerging tech market. Nationally there are more than forty-eight thousand ICT companies, and software and computer services alone account for over ninety per cent of them.

Most of the sector is very small — and signing very large contracts

Of those forty-eight thousand Canadian ICT companies, roughly forty-one thousand employ fewer than ten people. Small and medium firms are about ninety-nine per cent of ICT firms and around sixty-two per cent of the employment. That is the structural fact behind most technology insurance placements: a ten-person company negotiating an indemnity with a bank, a hospital or a government department.

And most of it is not covered

Statistics Canada found twenty-two per cent of Canadian businesses carried cyber insurance in 2023, up from sixteen per cent in 2021 — meaning more than three-quarters do not. Sixteen per cent of businesses were hit by a cyber incident that year, thirty per cent among large businesses, with total recovery costs of one point two billion dollars, double the level of two years earlier. The Insurance Bureau of Canada reports Canadian ransomware incidents rising an average of twenty-six per cent a year since 2021.

10 / Common Questions

Frequently Asked Questions About Technology Insurance

Technology insurance is rated on revenue, what you build, who you sell to, your contract terms, your claims history and your security controls. A ten-person agency building marketing sites and a ten-person firm running payment infrastructure for credit unions carry very different technology insurance costs. The more useful early question is what limits your customer contracts already oblige you to carry, because that usually sets the programme before an underwriter does.

Cyber answers when your systems are attacked or data is exposed. Tech E&O answers when your product or service does not work and a customer suffers financial loss — a software error, a failed implementation, a missed delivery. No attacker is involved in a tech E&O claim. In the Canadian market the two are now usually written on one combined form for technology companies specifically.

For a technology company, combined is the market default here and it removes the argument about which policy responds. Chubb, Zurich, Liberty, CFC, Markel, Intact, Ridge and Victor all publish Canadian combined forms. Two separate towers can work, but the retro dates, notice provisions and definitions then have to be reconciled deliberately — which is the single most common technology insurance oversight we see.

Only if you bought for it. Insurers commonly exclude system failure as distinct from a security attack, so an outage with no attacker involved can fall outside a cyber form. Dependent or contingent business interruption is an available named Canadian coverage — one carrier publishes it specifically for outsourced technology provider interruptions — but it is often bought at a limit that does not reflect how concentrated the dependency really is. Note too that carriers apply a cooling-off period of at least forty-eight hours before business interruption attaches.

Send us the clause. General liability forms accommodate additional insureds routinely; professional liability and cyber forms often do not, or only on a limited basis, and granting one can create insured-versus-insured problems. This is one of the most common places where a signed contract and an issued policy quietly fail to match — and it is much cheaper to resolve before signature than to discover at claim.

Usually not for a technology company. Canadian underwriters distinguish explicitly between standalone cyber policies, which are broader with higher limits, and package endorsements, which are stripped-down versions — and note that contractual requirements increasingly drive demand for the standalone form. An enterprise MSA will typically not accept an endorsement. There is also a legal point: the Supreme Court of Canada confirmed in 2026 that endorsements build on the base policy and general exclusions persist unless expressly overridden.

Not yet, on the evidence available. Gallagher’s national technology practice leader for Canada said in July 2026 that insurers are adding affirmative AI language to clarify intent rather than to add coverage, and that she had not yet seen exclusionary AI language. Some Canadian forms have gone the other way — one publishes AI and deepfake coverage, another includes generative AI within its definition of computer systems. Broad AI exclusions are so far a US development to watch.

No enacted AI statute — the Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued. What governs AI here is existing law: privacy legislation, Quebec’s automated-decision provision, Ontario’s job-posting disclosure rule since January 2026, and a voluntary federal code of conduct. Canada’s privacy regulators have jointly confirmed that public accessibility of data does not mean it can be indiscriminately collected or used.

Almost certainly not directly. The Critical Cyber Systems Protection Act received Royal Assent in June 2026 and covers designated operators in six federally regulated vital services — telecom, pipelines and power, nuclear, federal transportation, banking, and clearing and settlement. A SaaS company or MSP is not a designated operator. It reaches you commercially instead, because designated operators must manage supply-chain and third-party risk and will push that down through your contract.

Multi-factor authentication, endpoint detection and response, privileged access management and encryption are what Canadian brokers report being asked for. Requirements have eased against the hard market of 2020 to 2022, and a strong posture now buys longer-term pricing agreements. But treat these as conditions rather than discounts — a Canadian organisation has already had a major cyberattack claim denied because MFA had not been implemented.

Better than they were. Most Canadian carriers had been capped around ten million dollars per risk; since January 2026 a single market can write about forty million, and another brought a Canadian form offering up to twenty million for companies to five billion in revenue. Excess towers remain the route above that. Cybercrime sublimits have moved from a typical hundred thousand up to a range of two hundred and fifty thousand to a million.

Pricing-wise, yes — the class is as soft as it has been in years, with capacity expanding and retentions falling. The caution comes from the market itself: a Canadian technology underwriting manager warns that some new entrants are underpricing or paring back coverage to win share, potentially leaving clients with gaps, and expects pricing to have to catch up eventually. Buy technology insurance on wording in a soft market, not on price.

Technology company office workspace — technology insurance for Canadian software and IT firms

Schedule a Consultation Today

Bring us your customer contracts, not just your renewal. Most technology insurance failures are visible in the insurance and indemnity clauses of an MSA long before they become claims — and in a soft market, wording is the thing worth negotiating.