↓ Skip to main content

Cyber Insurance in Canada

Also called cyber liability insurance. If a cyberattack, data breach or online scam hits your business, cyber insurance is the policy that helps pay to recover, notify customers and cover the costs that follow.

Written by
Beatriz Alban Cabaco
Content Researcher
Reviewed by
Sean Nolan
10 years in insurance
Last updated
September 20, 2026

What is cyber insurance?

Cyber insurance, also called cyber liability insurance, pays the costs of responding to and recovering from a cyberattack, a data breach or an online scam, and of claims that follow. It’s a separate policy because property and liability policies usually don’t respond to these losses.

Prevention still matters. Insurance helps pay for a loss, it doesn’t stop one. The Government of Canada’s Get Cyber Safe has practical steps for small businesses.

Response and recovery
Investigators, restoring data and systems, notifying customers and credit monitoring.
Lost income
Income you lose and costs that continue while systems are down, subject to a waiting period.
Legal costs and liability
Defence costs and settlements if customers or others claim you failed to protect their data.
Extortion and online fraud
Ransom demands and being tricked into paying a fraudster, often as an optional extra.

Who needs cyber insurance?

A good test: do you hold customer or employee information, take payments online, or depend on your systems to operate? If so, this is worth asking about.

Online sales
A website that takes orders and payments is a target, and an outage stops sales.
Customer records
Clinics and practices hold sensitive personal information that has to be protected and reported if lost.
Card payments
Shops and restaurants that take cards rely on payment systems that can be breached.
Invoices and bank transfers
Businesses that pay suppliers by transfer can be tricked by fake invoices and emails.
Remote and home-based teams
Staff working from home on their own devices and networks add ways in.
Contracts that ask for it
Larger customers may ask their suppliers to carry cyber cover.

What does a real claim look like?

These examples are illustrative, not real cases. In each one, a cyber incident hits a business, and the policy is what helps pay to respond, up to the limit.

A fake invoice gets paid
An employee receives an email that looks like it’s from a regular supplier, with new bank details, and sends a payment. The money is gone before anyone notices. Whether this is covered depends on the policy: it may be a cyber extra for social engineering, or fall under a commercial crime policy. Limits for it are often lower than for other cover.
Ransomware locks the systems
Ransomware encrypts a business’s files and demands payment. Cyber insurance can help pay for specialists to investigate and restore the systems, for extortion cover if it’s included, and for lost income after any waiting period.
Customer records are stolen
A hacker takes patient or customer records from a small practice. The policy can help pay to investigate, to notify the people affected and to defend a claim if someone sues, and the business still has its own reporting duties to meet.

First-party and third-party cover: what’s the difference?

Policies often describe cover in two parts. The names for the whole product vary, so look at what each part pays for.

First-party coverThird-party cover
Whose loss it paysYour own costsA claim made against you by someone else
Typically includesInvestigators, restoring data and systems, notifying customers, lost income, extortionLegal defence, settlements and judgments, regulatory defence
ExampleRansomware locks your systems and you need them restoredA customer sues after their data is stolen from you

What are your duties after a breach in Canada?

Canadian privacy law sets duties for organizations that handle personal information. Under the federal privacy law, known as PIPEDA, an organization that has a breach of security safeguards that creates a real risk of significant harm to someone generally has to report it to the Office of the Privacy Commissioner of Canada, tell the people affected and keep a record of the breach. Some provinces have their own privacy laws with their own rules, and what applies to you depends on your business, where it operates and what information it holds.

This is general information, not legal advice, so check with a lawyer or the Privacy Commissioner’s guidance. Cyber insurance can help pay to respond, for example by notifying customers, but it doesn’t remove the duty.

What to do if it happens

Your policy and its response line come first, so check them before you spend. This is a general sequence, and your policy sets the rules.

01
Contact your insurer promptly
Many policies require prompt notice and come with a response line or team you can call.
02
Check before you spend, and keep records
Insurers often want to approve costs such as investigators first. Save emails, screenshots, logs and invoices, and avoid deleting evidence.
03
Meet your reporting duties
Check what you have to report and to whom, as above, and ask your insurer or lawyer for help if you’re unsure.

Which policy pays for what?

Different losses fall under different policies, and cyber insurance isn’t the answer to all of them. This table gives the general pattern, and your policies decide.

SituationThe policy that usually respondsNotes
A laptop is stolenCommercial propertyLoss of the device itself isn’t a cyber loss
An employee takes money from your accountsCommercial crimeEmployee theft and fraud usually sit under crime cover
You’re tricked into paying a fake invoiceCyber extra or commercial crimeDepends on the policy
A customer sues after their data is stolenCyber (third-party cover)The claim is about failing to protect data
Your systems are down after a cyberattackCyber (lost income)Business interruption usually needs physical damage
A mistake in your professional work costs a client moneyProfessional liabilityA different claim from a breach
Directors are sued over how a breach was handledDirectors and officersA claim about how the company was run

What limits and waiting periods apply?

The amount a policy pays isn’t one number. It helps to understand four terms before you compare.

  • Limits: the most the policy pays. Some policies have one combined limit shared across all cover, while others set a separate limit for each part.
  • Sublimits: lower limits for particular extras, such as extortion or social engineering, which are often lower than the main limit.
  • Retention: the amount you pay before the policy responds, like a deductible.
  • Waiting period: for lost income, the time after an outage before payments start.

Ask how each works on the policy you’re considering, and whether cover for response costs sits inside or outside the limit.

What can be added?

Some of the risks people worry about most are extras, not part of the base cover. Availability and wording vary by insurer, so ask about each one.

ExtraWhat it typically does
Social engineering and funds-transfer fraudCovers money lost when you’re tricked into sending it
Cyber extortionCovers the cost of responding to a ransom demand, including specialists
Dependent businessCovers lost income when a supplier or cloud provider’s outage stops you working
Reputational costsCovers the cost of public relations help after an incident

How much does cyber insurance cost?

There isn’t one price. What you pay depends on your business, what it holds and the controls you have. The only reliable number is a quote for your own business, and Clearly Rate doesn’t set prices. The insurer does.

What affects the price

  • Your annual revenue
  • Your industry and how risky it is
  • The type and amount of data you hold
  • Your security controls, such as multi-factor authentication and backups
  • Your claims history
  • The limits, retention and extras you choose

How to keep your premium down

Put basic protections in place and be ready to show them, since insurers often ask. Choose limits based on what you hold and what you’d lose, not on the lowest price. Ask what a higher retention would save, and whether you’d be comfortable paying that amount yourself.

Is cyber insurance required?

No general law requires it, but others may ask for it.

SituationWhat’s usually expected
A larger customer buys from youContracts may require you to carry cyber cover
You take card paymentsYour payment provider or processor may have security requirements, so check the terms
You hold sensitive informationNot a requirement, but a practical reason to ask about it

Get ready: what an insurer will ask

Having these to hand makes a quote faster, and accurate answers matter at claim time.

  • Whether you use multi-factor authentication, and where
  • How you back up your data, and whether you test restoring it
  • How you keep software and devices up to date
  • Whether staff get security training
  • Whether you have a plan for responding to an incident
  • What data you hold, and roughly how much
  • Any past incidents

What cyber insurance doesn’t cover

It responds to losses from cyber incidents. It generally won’t cover:

  • Loss or damage to computers and equipment, which is a claim under commercial property insurance
  • Theft by employees, which usually needs crime cover
  • Losses from known weaknesses left unfixed, or from not meeting security conditions in the policy, depending on the wording
  • Incidents that started before the policy
  • Lost income beyond the period the policy sets
  • Upgrades to make your systems better than they were
  • Injury to people or damage to their property, which falls under general liability insurance

Exclusions vary by insurer, so read the list before you buy.

Business insurance FAQs

Does a small business need cyber insurance?
Size doesn’t decide it. What you hold and depend on does. If you take payments online, keep customer or employee records, or couldn’t operate without your systems, it’s worth asking about. A licensed insurer or broker can help you work out what fits, and this page isn’t a recommendation either way.
Is cyber insurance the same as cyber liability insurance?
The two names are usually used for the same product, but not always. Some insurers use “cyber liability” for cover against claims made against you, and others for the whole policy. Check what a policy actually includes, not just what it’s called.
Does it cover ransomware payments?
Often, cyber extortion cover is included or available as an extra, and it can help pay for negotiators and for restoring your systems. Terms and limits vary, so ask what’s included. This page can’t tell you whether to pay a ransom.
Does it cover paying a fake invoice?
It depends. Cover for being tricked into sending money, often called social engineering or funds-transfer fraud, is sometimes an optional cyber extra and sometimes falls under a commercial crime policy. Limits are often lower than for other cover, so ask which policy responds.
Does it cover employee mistakes?
Often, a breach that starts with an employee’s error, such as clicking a phishing link, can be covered. But some policies limit or exclude losses from known weaknesses left unfixed, or from not following security conditions in the policy. Read the wording.
Will an insurer require security controls?
Often, insurers ask about controls such as multi-factor authentication, backups, software updates and staff training before they quote. Your answers can affect whether you’re offered cover and what it costs, and some policies make certain controls a condition of cover.

Ready to compare?

Tell us about your business and we'll refer you to licensed insurers.

Get your quote