Cyber Insurance
Cyber insurance covers what actually happens after an attack: the ransomware demand, the payment wired to a fraudster, the days your systems are down, and the legal and regulatory fallout when personal information is exposed. It funds the specialists who take over within the hour, the income you lose while you rebuild, and the claims that follow. Stanhope Simpson places cyber insurance for contractors, developers, manufacturers, processors and professional firms across Atlantic Canada.
What Is Cyber Insurance?
Cyber insurance is a specialist insurance policy that responds to the financial consequences of a cyber incident — an attack, a system failure, a fraudulent payment, or the loss of personal information you were responsible for. It sits apart from the rest of your programme because the loss it addresses is rarely physical, and your other policies are built around damage you can see.
Most Canadian commercial cyber insurance policies are a hybrid. The first-party sections respond to incidents you discover during the cyber insurance policy period; the liability sections respond to claims made and reported during it. Both depend on continuous cover and prompt notice, which is why a gap between policies does more harm here than on almost any other line.
- Your own losses — investigation, restoration, lost income and extortion costs. This is the first-party side of the policy.
- Your liability to others — claims from customers, employees and business partners whose information you held.
- The response itself — round-the-clock access to forensics, breach counsel, negotiators and notification specialists.
- Regulatory obligations — the cost of investigating, reporting and defending a privacy breach.
- Cybercrime — fraudulent payments, invoice redirection and hijacked phone or computing resources, usually written by sublimit.
A standalone cyber insurance policy is materially broader than a cyber insurance endorsement bolted onto a package policy. Endorsements typically carry lower limits, narrower definitions and fewer cyber insurance coverage sections — and in the current market the price difference rarely justifies the gap.

How Businesses Actually Get Hit
Roughly six in ten cyber insurance claims start in an email inbox rather than with a dramatic breach of the network. Ransomware takes the headlines and drives the largest losses, but the everyday claim is a payment that went to the wrong bank account.

Business email compromise
An attacker gets into a mailbox, watches quietly, and waits for a payment conversation. This is the single most common cyber insurance claim, and it almost always begins with a stolen password and no multi-factor authentication.
Funds transfer fraud and invoice redirection
A supplier’s banking details appear to change by email and the payment goes to a fraudster. Recovery is realistic if you move within hours and increasingly unlikely after that — which is why the first call matters more than the paperwork.
Ransomware and data extortion
Systems are encrypted and, in most cases now, data is stolen first so the attacker can threaten publication even if you restore cleanly from backup. This remains the costliest claim type by a wide margin.
Stolen credentials and exposed remote access
VPNs, firewalls and remote desktop reachable from the internet are the most common way ransomware operators get in. Underwriters scan for exactly this before they quote.
Vendor and supply chain compromise
Your own systems are untouched, but your cloud platform, IT provider or ERP supplier is breached or offline. Third-party involvement now features in close to half of all reported breaches.
Insider error
A payroll spreadsheet sent to the wrong recipient, a misconfigured cloud folder, a laptop left in a taxi. No attacker required — and your privacy obligations are exactly the same.
What Does Cyber Insurance Cover?
First-party — your own losses
The costs you carry yourself when systems are attacked, disrupted or held to ransom.
- Incident response — forensic investigation, breach counsel and project management from the first phone call.
- Data and system restoration — recovering, recreating and rebuilding what was encrypted, corrupted or destroyed.
- Business interruption — income lost while systems are down, subject to a waiting period measured in hours rather than a dollar deductible.
- Dependent business interruption — income lost when a cloud platform, managed service provider or IT supplier fails, where the policy includes it.
- Cyber extortion — negotiation, threat intelligence, sanctions screening and, where lawful, the ransom itself.
- Notification and monitoring — telling affected individuals and providing credit or identity monitoring afterwards.
Third-party — your liability to others
Claims brought against you by the people and businesses affected by an incident.
- Privacy liability — claims from individuals whose personal information you held.
- Network security liability — claims alleging your systems were the route into someone else’s.
- Regulatory investigation and defence — responding to a privacy commissioner, with fines covered only where insurable by law.
- Payment card liability — PCI assessments, fines and card reissuance costs passed down by your acquiring bank.
- Media liability — defamation and intellectual property claims arising from your own published content.
Cybercrime and optional extensions
Usually written as sublimits rather than at the full policy limit — read the numbers, not just the headings.
- Funds transfer fraud and social engineering — the fraudulent payment itself, almost always sublimited.
- Invoice manipulation — where your customers are tricked into paying a fraudster and you are never paid. Ask for it by name.
- Telephone hacking and unauthorised use of computing resources — toll fraud and cryptojacking.
- Reputational harm — income lost because customers left after an incident, even where systems never went down.
- System failure — non-malicious outages of your own systems, where the wording extends to them.
Incident Response: What You Are Really Buying
For most businesses the most valuable part of a cyber insurance policy is not the limit. It is the phone number. A serious incident needs forensics, legal advice and often a negotiator inside the first few hours, and almost no mid-market business has those relationships standing by.
A 24/7 line, not a claims form
Specialist cyber insurance carriers run round-the-clock incident lines and triage within minutes. That single call starts the clock on containment, on your privacy obligations, and on cyber insurance coverage — all at once.
A panel you generally have to use
Forensics, breach counsel, negotiators, notification vendors and public relations are drawn from the insurer’s approved panel. If you want your own lawyers on the file, they usually have to be added by endorsement at placement — not argued about at 2am.
Consent and the first hours
Most wordings allow only limited costs to be incurred before the insurer consents, and only with panel providers. Calling your own IT firm first is the single most common way businesses spend money their cyber insurance will not reimburse.
Services before anything happens
Better policies bundle threat intelligence, external vulnerability scanning, phishing simulation and staff training at no extra cost. They are worth using in their own right, and they improve how you present at renewal.
Why Would I Need Cyber Insurance?
Your other policies will not respond
Commercial general liability wordings carry broad electronic-data exclusions, and property policies need physical damage before business interruption attaches. A ransomware event produces neither.
The money moves by email
If you pay suppliers, subtrades or consultants on emailed instructions, you already carry the most common cyber insurance loss in Canada. The control is a callback procedure; the backstop is a sublimit worth checking.
Reporting a privacy breach is a legal obligation
Federal law requires you to report breaches that create a real risk of significant harm, notify the people affected, and keep a record of every breach — reportable or not — for at least two years. Quebec’s regime is stricter again and reaches any business holding information about Quebec residents.
Downtime is the loss
For a processor in peak season or a manufacturer running continuous shifts, the cost is not the ransom. It is the days of stopped throughput that cannot be made up later in the year.
Most Canadian businesses still are not covered
Statistics Canada found that 22% of businesses carried cyber insurance in 2023. Attackers have little reason to work hard when soft targets are this common.
Recovery needs specialists you do not have
Forensics, breach counsel, ransom negotiation and mass notification are not things an internal IT team or a general lawyer can deliver at speed. The policy buys access as much as it buys indemnity.
Benefits of Cyber Insurance
Financial protection
Investigation, restoration, lost income, extortion costs and third-party claims funded by cyber insurance rather than out of working capital at the worst possible moment.
A response team on standby
Named forensics, legal, negotiation and communications specialists reachable in minutes, at any hour — relationships almost no mid-market business has on its own.
Regulatory support
Practical help meeting your privacy reporting duties correctly and on time, and defending the investigation that can follow.
Business continuity
Cover for income lost during an outage, and for the extra expense of working around it while systems are rebuilt.
Reputation management
Public relations and crisis communications support, so the story is handled while the technical work runs — and customers, lenders and counterparties hear it from you first.
What Underwriters Now Require
Cyber insurance is the one line where your security controls decide not just the price but whether you can buy cyber insurance at all. These are the controls Canadian underwriters ask about — and the accurate answer matters far more than the flattering one.
Multi-factor authentication
On email, remote access, VPN and privileged accounts. This is effectively a gate: without it, expect either a declination or terms with the cybercrime sublimit cut to a token figure.
Endpoint detection and response
Traditional antivirus does not catch attackers using legitimate system tools. EDR, or a managed detection service, is quickly becoming what multi-factor authentication was three years ago.
Backups that are offline and tested
Three copies, two types of media, one off-site, one immutable or air-gapped, and zero errors on a restore test. An untested backup is treated by underwriters as no backup at all.
Patching and vulnerability management
Exploited vulnerabilities are now the leading route in. Some wordings reduce cover where a known vulnerability sits unpatched beyond a stated grace period, so patching cadence has become a cyber insurance underwriting question.
Closed remote access
Internet-exposed remote desktop is one of the few findings that still draws an immediate decline. Underwriters scan your external footprint before quoting, so this one cannot be answered optimistically.
Email filtering and staff training
External sender banners, impersonation and lookalike-domain detection, and regular phishing simulation. This is what pushes your social engineering sublimit up rather than down.
Privileged access and network segmentation
Day-to-day work should not run on domain administrator accounts, and the plant floor should not sit on the same flat network as the office. Segmentation is what stops one infection becoming a shutdown.
An incident response plan people have used
Written down, rehearsed, and carrying the insurer’s 24/7 number and your policy number in a form you can still read when email is down. A plan nobody has tested is a document, not a plan.
Two warnings worth taking seriously. The application should be completed by someone who genuinely knows the environment, because insurers re-examine those answers after a loss — an overstated answer about multi-factor authentication is the most common reason a cyber insurance claim is challenged. And if a control lapses mid-term, that is a change to notify, not an internal IT matter.
Not sure your controls would get you a quote?
We will walk through what underwriters will ask, tell you plainly where you would struggle, and take your risk to the markets that actually want it.
What Cyber Insurance Does Not Cover
Cyber insurance wordings vary more than almost any other commercial line. These are the limits and exclusions that catch businesses out — and several are negotiable if you raise them before you bind rather than after a loss.
Upgrading to a better system
Betterment is generally excluded. Rebuilding after ransomware to the same vulnerable specification is rarely sensible, so ask what the wording actually allows — some carriers permit a margin for a more secure replacement.
Physical damage and injury
Cyber insurance excludes bodily injury and property damage. Where a cyber event damages plant or equipment, test it against your property policy’s cyber exclusion — the overlap between the two is where businesses discover they are uninsured.
Anything already known
Incidents or circumstances a senior person knew about, or ought reasonably to have known about, before inception are excluded. Continuous cover with an unbroken continuity date is what protects you, and it is a good reason not to move carriers casually.
Grid and internet infrastructure failure
Your own systems going down is covered. A failure of the power supply, or a regional outage of core internet infrastructure, generally is not.
War and state-backed attacks
Standalone cyber policies now carry state-backed cyber attack exclusions. The available clauses differ materially in breadth and in how an attack is attributed to a state, so ask which one is on your cyber insurance policy rather than assuming they are equivalent.
Controls you said you had
Where a wording makes specified security practices a condition, failing to maintain them can reduce or defeat a claim. This is the fastest-growing reason cyber claims are disputed, and it is entirely avoidable.
Contractual obligations
Payment card assessments are contractual rather than statutory, so they have to be named in the cyber insurance policy and carved out of the contractual liability exclusion. Do not assume they are picked up.
Fines that are not insurable
Regulatory defence and investigation costs are broadly available. Fines and penalties are covered only where the law permits, and that varies by jurisdiction — treat any fines cover as conditional.
What Determines the Cost of Cyber Insurance?
Cyber premium is a function of exposure and control maturity — and the second half is the part you can change. There is no useful list price, but there is a fairly consistent set of questions.
Revenue and industry
The primary exposure base, loaded by class of business. Manufacturing, food processing, hospitality and anything handling payment cards attract closer attention.
The data you hold
Volume and sensitivity of personal information. Notification costs scale with the number of people affected, not with the size of your business — which is why a property manager can need a larger privacy limit than its revenue suggests.
How fast revenue stops
Your dependence on systems sets the business interruption rate and the waiting period. Continuous operations and compressed seasonal peaks both change the calculation.
Security control maturity
The controls above. In the current market this is the lever that buys lower retentions and broader terms, not just a lower price.
Claims and incident history
Including near misses and attempted payment fraud — underwriters do ask, and a candid answer with evidence of what you fixed reads better than a bare no.
Vendor concentration
Which cloud platforms, managed service providers and ERP systems you depend on, and whether dependent business interruption needs to be bought.
Where your customers are
Personal information about residents of other provinces or the United States brings other regulators and other claim environments with it.
Limit, retention and waiting period
What you buy, what you keep, and how many hours of downtime you absorb before cover attaches at all.
On limits, the honest test is not the average claim — the average is survivable at almost any limit. Model the bad outcome instead. Canadian capacity is currently plentiful and terms have loosened: cybercrime sublimits once capped at $100,000 are now commonly written between $250,000 and $1 million, and primary limits up to $10 million are available again. If your programme was placed during the hard market, it is very likely built to terms you no longer have to accept.
Cyber Risk by Industry
The exposure changes with the business. These are the patterns we see most often across the sectors we place.
Contractors and developers
Large, scheduled payments to subtrades, suppliers and joint-venture partners, with banking details exchanged over email. Progress-draw cycles are predictable, which is exactly what invoice fraud is built around. Design, tender and project files are a second target.
Real estate and property management
A dense concentration of tenant personal information — credit applications, income verification, guarantor details — against relatively modest revenue, which pushes notification costs up fast. Deposit and closing-fund fraud is a live exposure, and building systems often share a network with the office.
Manufacturing
The most-targeted sector for ransomware. Where the plant floor shares a flat network with corporate IT, an office infection reaches production, and every hour of downtime converts straight into lost revenue and late-delivery penalties.
Seafood and food processing
Traceability and lot data are a regulatory and commercial necessity, and refrigeration monitoring is increasingly networked. The distinguishing risk is seasonality — throughput lost in a peak week cannot be made up in the autumn, so a standard indemnity period may not fit.
Hospitality
Payment card data, booking engines and property management systems, most of them third-party hosted. PCI assessments and dependent business interruption both matter more here than in most sectors.
Technology
You hold your clients’ data, so your breach becomes their breach and returns as a third-party claim under your contracts. The critical issue is the seam between the cyber policy and technology errors and omissions.
Renewables and energy
Distributed assets with remote monitoring, often reachable through a vendor’s remote-access tooling. Revenue is metered and continuous, so any curtailment is a direct loss — and physical damage caused by a cyber event falls in the gap between cyber and property.
How Cyber Insurance Works With Your Other Coverage
Cyber sits in the gaps your traditional policies were never built to reach. The dangerous assumption is that one of them will step in — most of the time, none of them will.

Commercial General Liability
Bodily injury and property damage arising from your premises and operations. Modern CGL wordings carry broad electronic-data exclusions, which is precisely why cyber exists as a separate policy.
Commercial Property
Physical damage to buildings, plant and stock. Property policies generally exclude loss arising from a cyber event — check that exclusion against your cyber policy’s property damage exclusion, because the overlap is where businesses find themselves uninsured.
Errors & Omissions (E&O)
Claims about the professional service you delivered to a client. Technology firms in particular need cyber and E&O written so there is no gap between the two triggers.
Directors & Officers (D&O)
Claims that the board failed to oversee cyber risk properly. D&O funds that defence; it does not pay any part of the incident itself.
Crime and fidelity cover
Employee theft and certain fraudulent transfers. Crime and cyber overlap awkwardly on social engineering, and a loss can fall between the two — which is why they should be reviewed together rather than separately.
Cyber sits inside a wider commercial program. See business insurance for how it fits alongside liability, property and professional cover.
Frequently Asked Questions About Cyber Insurance
Ransomware and data extortion, business email compromise, hacking and unauthorised access, malware, denial-of-service attacks, fraudulent payment instructions, insider error such as a misdirected email or a misconfigured cloud folder, and — on broader wordings — non-malicious system failure. The trigger is the financial consequence, not the technique, so a policy that lists coverage by outcome tends to age better than one that lists it by attack type.
Any business that holds personal information, depends on systems to earn revenue, or moves money on emailed instructions — which is very nearly all of them. In practice the exposure is highest where large payments are made on schedule (contractors and developers), where downtime cannot be recovered later (manufacturers and processors), where payment card data is handled (hospitality and retail), and where you hold clients’ data under contract (technology and professional firms).
Usually yes, alongside negotiation, threat intelligence and forensic support — but with conditions. Paying a ransom is not in itself unlawful in Canada, provided the payment does not breach sanctions, terrorist-financing or proceeds-of-crime law. Before any payment the insurer will require compliance screening of the attacker and the cryptocurrency wallet involved. Note also that a policy placed on international paper is bound by several sanctions regimes at once, so a payment lawful under Canadian law alone can still be uninsurable. Many wordings reimburse rather than pay directly, so the business funds it first.
Yes — income lost while your systems are unavailable, plus the extra expense of working around the outage. Better wordings extend to dependent business interruption, covering income lost when a cloud platform, managed service provider or IT supplier goes down instead. Two things determine whether the cover is worth much: the waiting period, and the length of the indemnity period. A seasonal business should check both carefully.
A deductible is a dollar amount. A waiting period is a number of hours of downtime that must pass before business interruption cover attaches at all — commonly around twelve. Many outages resolve inside it, which surprises people. It is also worth asking how the waiting period operates: on some wordings cover then runs from the first minute of the outage, and on others the insurer applies the greater of the waiting-period loss or the retention. On a long outage that difference is worth real money.
Regulatory defence and investigation costs are broadly available and are among the most useful parts of the policy. Fines and penalties are a different question: they are covered only where insurable by law, and insurability varies by jurisdiction. Quebec’s administrative monetary penalties under its modernised privacy regime are substantial and their insurability is not settled. Treat regulatory defence as the reliable cover and any fines cover as conditional.
Generally yes, but by sublimit rather than at the full policy limit, and often subject to conditions such as out-of-band callback verification on any change of banking details. This is the most common cyber loss in Canada and the most common place a policy disappoints. Two points to press: make sure the sublimit is sized against the payments you actually make, and ask specifically about invoice manipulation — where your customers are deceived into paying a fraudster, so you are simply never paid. That cover is frequently withheld unless requested by name.
Bodily injury and property damage, upgrades and betterment, incidents or circumstances already known before inception, failures of the power grid or of core internet infrastructure, patent infringement, and — on current wordings — state-backed cyber attacks meeting the policy’s threshold. Fines are covered only where insurable. And where a wording makes specified security controls a condition, failing to maintain them can reduce or defeat a claim.
In practice, yes — on email and remote access at a minimum, and ideally on privileged accounts too. It is the closest thing to a hard gate in Canadian cyber underwriting. Without it, expect either a declination or terms with the cybercrime sublimit cut to a token figure. Answer the question accurately: insurers re-examine applications after a loss, and an overstated answer about multi-factor authentication is the single most common reason a cyber insurance claim gets challenged.
There is no formula, and the average claim is the wrong benchmark — the average is survivable at almost any limit. Model the bad outcome instead: several days of stopped operations, forensics and legal costs, notifying everyone whose information you held, and the claims that follow. Then check the sublimits separately, because a $5 million policy with a $100,000 cybercrime sublimit will not answer the loss you are most likely to have.
Revenue and industry set the starting point. From there underwriters weigh the volume and sensitivity of the personal information you hold, how quickly revenue stops when systems stop, your claims and incident history, which cloud and IT providers you depend on, where your customers are located, and the limit, retention and waiting period you select. The largest discretionary factor is your security controls — and in the current market they buy lower retentions and broader terms rather than just a lower price.
Rarely. Endorsements added to a commercial package are typically stripped-down: lower limits, fewer coverage sections, narrower definitions, and often no meaningful incident response service behind them. Given how competitively standalone cyber is currently priced in Canada, the saving seldom justifies the gap. If you do carry an endorsement, read what it actually grants before you assume you are covered.
Under federal privacy law you must assess whether the breach creates a real risk of significant harm; if it does, report it to the Privacy Commissioner and notify the affected individuals as soon as feasible, and notify any other organization that could reduce the harm. Separately — and this is the obligation most often missed — you must keep a record of every breach, whether reportable or not, for at least two years. Alberta and Quebec have their own regimes, and Quebec’s applies to any business holding information about Quebec residents regardless of where you operate. Your insurer’s breach counsel will guide the assessment; call them before you notify anyone.
Call the insurer’s 24/7 cyber incident line first — before your own IT provider, and before you talk to anyone outside the business. Most wordings only allow costs to be incurred without prior consent for a short window, and only with approved panel providers, so engaging your own consultants first is the most common way businesses spend money the policy will not reimburse. Keep that number, and your policy number, somewhere reachable if your systems and email are down. Then call your Stanhope Simpson broker.

Still have a question?
Ask a Stanhope Simpson broker directly. We will give you a straight answer about your own wording and your own controls, not a generic one.
Schedule a Consultation Today
Personalized insurance and surety solutions backed by decades of industry expertise.
Reach out to us today and experience the Stanhope difference!