
Cyber Insurance in Canada
Also called cyber liability insurance. If a cyberattack, data breach or online scam hits your business, cyber insurance is the policy that helps pay to recover, notify customers and cover the costs that follow.


What is cyber insurance?
Cyber insurance, also called cyber liability insurance, pays the costs of responding to and recovering from a cyberattack, a data breach or an online scam, and of claims that follow. It’s a separate policy because property and liability policies usually don’t respond to these losses.
Prevention still matters. Insurance helps pay for a loss, it doesn’t stop one. The Government of Canada’s Get Cyber Safe has practical steps for small businesses.
Who needs cyber insurance?
A good test: do you hold customer or employee information, take payments online, or depend on your systems to operate? If so, this is worth asking about.
What does a real claim look like?
These examples are illustrative, not real cases. In each one, a cyber incident hits a business, and the policy is what helps pay to respond, up to the limit.
First-party and third-party cover: what’s the difference?
Policies often describe cover in two parts. The names for the whole product vary, so look at what each part pays for.
| First-party cover | Third-party cover | |
|---|---|---|
| Whose loss it pays | Your own costs | A claim made against you by someone else |
| Typically includes | Investigators, restoring data and systems, notifying customers, lost income, extortion | Legal defence, settlements and judgments, regulatory defence |
| Example | Ransomware locks your systems and you need them restored | A customer sues after their data is stolen from you |
What are your duties after a breach in Canada?
Canadian privacy law sets duties for organizations that handle personal information. Under the federal privacy law, known as PIPEDA, an organization that has a breach of security safeguards that creates a real risk of significant harm to someone generally has to report it to the Office of the Privacy Commissioner of Canada, tell the people affected and keep a record of the breach. Some provinces have their own privacy laws with their own rules, and what applies to you depends on your business, where it operates and what information it holds.
This is general information, not legal advice, so check with a lawyer or the Privacy Commissioner’s guidance. Cyber insurance can help pay to respond, for example by notifying customers, but it doesn’t remove the duty.
What to do if it happens
Your policy and its response line come first, so check them before you spend. This is a general sequence, and your policy sets the rules.
Which policy pays for what?
Different losses fall under different policies, and cyber insurance isn’t the answer to all of them. This table gives the general pattern, and your policies decide.
| Situation | The policy that usually responds | Notes |
|---|---|---|
| A laptop is stolen | Commercial property | Loss of the device itself isn’t a cyber loss |
| An employee takes money from your accounts | Commercial crime | Employee theft and fraud usually sit under crime cover |
| You’re tricked into paying a fake invoice | Cyber extra or commercial crime | Depends on the policy |
| A customer sues after their data is stolen | Cyber (third-party cover) | The claim is about failing to protect data |
| Your systems are down after a cyberattack | Cyber (lost income) | Business interruption usually needs physical damage |
| A mistake in your professional work costs a client money | Professional liability | A different claim from a breach |
| Directors are sued over how a breach was handled | Directors and officers | A claim about how the company was run |
What limits and waiting periods apply?
The amount a policy pays isn’t one number. It helps to understand four terms before you compare.
- Limits: the most the policy pays. Some policies have one combined limit shared across all cover, while others set a separate limit for each part.
- Sublimits: lower limits for particular extras, such as extortion or social engineering, which are often lower than the main limit.
- Retention: the amount you pay before the policy responds, like a deductible.
- Waiting period: for lost income, the time after an outage before payments start.
Ask how each works on the policy you’re considering, and whether cover for response costs sits inside or outside the limit.
What can be added?
Some of the risks people worry about most are extras, not part of the base cover. Availability and wording vary by insurer, so ask about each one.
| Extra | What it typically does |
|---|---|
| Social engineering and funds-transfer fraud | Covers money lost when you’re tricked into sending it |
| Cyber extortion | Covers the cost of responding to a ransom demand, including specialists |
| Dependent business | Covers lost income when a supplier or cloud provider’s outage stops you working |
| Reputational costs | Covers the cost of public relations help after an incident |
How much does cyber insurance cost?
There isn’t one price. What you pay depends on your business, what it holds and the controls you have. The only reliable number is a quote for your own business, and Clearly Rate doesn’t set prices. The insurer does.
What affects the price
- Your annual revenue
- Your industry and how risky it is
- The type and amount of data you hold
- Your security controls, such as multi-factor authentication and backups
- Your claims history
- The limits, retention and extras you choose
How to keep your premium down
Put basic protections in place and be ready to show them, since insurers often ask. Choose limits based on what you hold and what you’d lose, not on the lowest price. Ask what a higher retention would save, and whether you’d be comfortable paying that amount yourself.
Is cyber insurance required?
No general law requires it, but others may ask for it.
| Situation | What’s usually expected |
|---|---|
| A larger customer buys from you | Contracts may require you to carry cyber cover |
| You take card payments | Your payment provider or processor may have security requirements, so check the terms |
| You hold sensitive information | Not a requirement, but a practical reason to ask about it |
Get ready: what an insurer will ask
Having these to hand makes a quote faster, and accurate answers matter at claim time.
- Whether you use multi-factor authentication, and where
- How you back up your data, and whether you test restoring it
- How you keep software and devices up to date
- Whether staff get security training
- Whether you have a plan for responding to an incident
- What data you hold, and roughly how much
- Any past incidents
What cyber insurance doesn’t cover
It responds to losses from cyber incidents. It generally won’t cover:
- Loss or damage to computers and equipment, which is a claim under commercial property insurance
- Theft by employees, which usually needs crime cover
- Losses from known weaknesses left unfixed, or from not meeting security conditions in the policy, depending on the wording
- Incidents that started before the policy
- Lost income beyond the period the policy sets
- Upgrades to make your systems better than they were
- Injury to people or damage to their property, which falls under general liability insurance
Exclusions vary by insurer, so read the list before you buy.
Business insurance FAQs
Does a small business need cyber insurance?
Is cyber insurance the same as cyber liability insurance?
Does it cover ransomware payments?
Does it cover paying a fake invoice?
Does it cover employee mistakes?
Will an insurer require security controls?
Ready to compare?
Tell us about your business and we'll refer you to licensed insurers.