Cyber Business Insurance - bestmoney.ca

On this page

  • What is cyber business insurance?
  • Why cyber insurance matters for Canadian businesses
  • What does cyber business insurance cover?
  • What cyber business insurance does NOT cover
  • Cost of cyber business insurance in Canada
  • Who needs cyber business insurance?
  • What insurers expect from your business
  • How to choose a cyber business insurance policy
  • The cyber insurance claims process
  • Cyber insurance vs cybersecurity tools
  • Real-world cyber attack scenarios
  • Other ways to lower your premiums
  • Alternatives to cyber business insurance
  • Final thoughts

Key Points About Cyber Business Insurance

🔐 Cyber business insurance protects businesses from cyber attacks, ransomware, data breaches, and online fraud.
⚖️ Standard business insurance usually does not cover cyber incidents, making separate cyber coverage important for many Canadian businesses.
💰 Premiums depend on business size, industry, data sensitivity, claims history, and cybersecurity protections in place.
🛡️ Most policies cover business interruption, data recovery, legal costs, breach notifications, and cyber extortion, but exclude preventable security failures and state-sponsored attacks.
📋 Insurers increasingly require MFA, employee training, secure backups, and cybersecurity controls to approve or maintain coverage.

On February 25, 2024, the City of Hamilton was struck by a ransomware attack that took down more than 80% of its network. Cybercriminals demanded $18.3 million to release the systems. The city could not pay, and the insurance claim was rejected. According to the insurer, multi-factor authentication had not been fully rolled out across Hamilton’s systems when the breach happened.

That story captures the current state of cyber business insurance in Canada. Coverage is available. The conditions attached to it are stricter than ever.

Do you run a Canadian tech startup or a growing business? You will be able to understand what cyber business insurance covers. This guide explains the registration stage, costs, and documentation your business needs to keep coverage current. You will also see what insurers expect from you and where coverage tends to fall short.

What is cyber business insurance?

Cyber business insurance is a specialized policy that some carriers brand as cyber liability insurance or cyber risk insurance. The product helps your business recover from incidents such as ransomware attacks, email fraud, and stolen customer data.

Coverage falls into two categories of loss. First-party losses cover the direct expenses your business absorbs after an attack. Third-party losses cover legal claims and regulatory penalties from customers, business partners, or government bodies.

How it differs from general business insurance

Most Canadian businesses already carry commercial general liability (CGL) insurance and commercial property insurance. These policies protect against physical risks like fires, theft, and injuries on your premises.

They almost never cover cyber incidents. Aviva, CNA, Federated, and most other Canadian insurers explicitly exclude cyber losses from their CGL and property policies. If a ransomware attack shuts down your business for two weeks, your standard business insurance will not pay for the lost income.

That’s why cyber business insurance exists as a separate product.

Why traditional insurance doesn’t apply

Cyber incidents involve intangible assets like data, software, and digital systems. Traditional insurance was designed for physical assets you can see and touch. A burned-down warehouse is easy to value. A leaked database of 50,000 customer records is much harder.

Insurers also faced massive losses when major cyber attacks hit, and traditional policies were used to file claims. The NotPetya attack in 2017 caused over $10 billion in global damage. After that, insurers began carving out clear cyber exclusions from their standard policies.

Why cyber insurance matters for Canadian businesses

Cyber attacks are no longer a theoretical risk for Canadian businesses. They are a near-certainty for any company that stores customer data or relies on connected systems.

The Canadian threat landscape

Statistics Canada’s most recent national figures paint a clear picture. About 1 in 6 Canadian businesses (16%) were affected by a cyber security incident in 2023. Large businesses were hit at nearly twice the national rate. Recovery costs across Canadian businesses reached approximately $1.2 billion, double the $600 million spent two years earlier. IBM’s 2025 Cost of a Data Breach Report places the average Canadian breach at CA$6.98 million, a 10.4% increase from the year before.

Hackers don’t target only large corporations. Smaller businesses are often easier to compromise because they lack dedicated security staff and budgets.

Common attack types Canadian businesses face

Three attack types dominate the Canadian threat landscape:

  • Ransomware: Criminals lock up your data and demand a payment to release it. The City of Hamilton case is one well-known Canadian example, but private businesses face the same threat daily.
  • Phishing: Here, cybercriminals send employees of their target company fake emails that trick them into sharing company passwords or transfer funds. The 2025 CIRA Cybersecurity Survey found that close to half of Canadian organizations make cybersecurity training mandatory for all employees. The majority still do not.
  • Business email compromise (BEC): Attackers impersonate a vendor or executive and trick staff into wiring money to fraudulent accounts.

Financial impact of a single incident

A 2021 Léger survey for the Insurance Bureau of Canada looked at the costs faced by small businesses hit by a cyber attack. Among those affected, 58% reported total costs under $100,000, while 41% said the bill came in higher than that. More recent data from IBM puts the average Canadian breach at nearly $7 million, with detection and escalation alone averaging $470,000. For most small businesses, a six-figure unbudgeted loss is enough to threaten survival.

Regulatory pressure

PIPEDA, Canada’s federal privacy law, sets the baseline for how businesses must respond to breaches. Under PIPEDA, you must notify affected individuals and the Privacy Commissioner whenever a breach creates a real risk of significant harm. Reporting failures can result in penalties and serious reputational damage.

There are also provincial privacy regimes in Quebec, Alberta, and British Columbia that businesses operating in those provinces must satisfy. Specific sectors such as healthcare and financial services face their own additional rules on top of these.

Cyber business insurance helps cover the legal, forensic, and notification costs that follow a breach.

What does cyber business insurance cover?

Policies vary by carrier, but most Canadian cyber business insurance policies include both first-party and third-party protection. The breakdown below covers what you should expect to find in a standard policy.

Common Coverage What It Covers
Incident response costForensics, legal, PR, and crisis management costs
Business interruptionLost income during system downtime
Data & system restorationRecovering damaged data, software, and networks
Ransomware & cyber extortionRansom payments, negotiators, and investigation costs
Notification costsCustomer and regulator breach notifications under PIPEDA
Data breach liabilityLawsuits and legal costs from exposed customer data
Regulatory investigationsPrivacy investigation legal costs and some fines
Payment fraudLosses from fraudulent wire transfers or scams

First-party coverage

This part of the policy pays for the direct financial hit your own business takes after a cyber incident.

  • Incident response costs: Pays for the forensic specialists, breach counsel, crisis advisors, and PR support needed after an attack. Aviva includes 24/7 incident response with their cyber business insurance policy.
  • Business interruption: Pays for the income you lose and the extra expenses you incur while your systems are offline. For most businesses, the downtime ends up costing more than the attack itself.
  • Data restoration: Covers the cost of restoring, recreating, or reconstructing data from compromised systems.
  • Ransomware payments: Some carriers will reimburse ransom payments, but more policies now attach conditions to this and require the insurer to sign off first.
  • Cyber extortion: Covers the cost of negotiators, investigators, and other expenses related to extortion threats.
  • System restoration: Pays to rebuild or restore networks, servers, and software that were damaged in the attack.
  • Notification costs: Covers the mandatory breach notification required under PIPEDA. This includes notifying customers, the Privacy Commissioner, and any provincial regulators.

Third-party coverage

Third-party coverage applies when other parties such as customers, suppliers, or regulators make a claim against your business after a cyber incident.

  • Data breach liability: Pays the legal defence and settlement costs when lawsuits follow the loss of personal information.
  • Network security liability: Covers defence costs from claims that your security failures harmed others.
  • Regulatory investigations and fines: Covers legal costs and penalties from privacy investigations. Some policies cover the fines themselves, where legally insurable.
  • Media liability: Covers defamation, copyright, or privacy claims arising from your website, social media, or other digital content.
  • PCI DSS liability: If your business handles credit card payments, this covers fines and assessments from card networks for security failures. CNA Canada specifically calls this out as part of their cyber business insurance product.
  • Misdirected payment fraud: Reimburses funds lost when an attacker tricks your business or financial institution into sending money to a fraudulent account.

Sublimits matter

A policy will typically apply sublimits to certain coverage areas, meaning specific incidents are capped well below the policy’s headline limit. Social engineering fraud is a common example. The sublimit often pays out only a small portion of what the full policy would otherwise allow.

When you review a policy quote, look at the sublimits, not just the headline number.

What cyber business insurance does NOT cover

Knowing what falls outside the policy matters just as much as knowing what is covered. The list below covers the standard exclusions you’ll find in most Canadian cyber business insurance policies.

Common ExclusionWhy It Matters
Known vulnerabilitiesClaims may be denied if issues existed before coverage
Missing security controlsInsurers may reject claims if promised protections like MFA were not in place
State-sponsored attacksMost policies exclude cyber warfare or nation-state attacks
Internal fraudDeliberate employee misconduct is not covered
Late reportingDelayed notification can void the claim

Pre-existing vulnerabilities

Did you know about a security issue before buying the policy and not disclose it? Any claim tied to that known issue can be refused by the insurer. Some carriers go further and exclude losses tied to vulnerabilities that existed before the policy began.

Failure to maintain stated security controls

This is the leading cause of denied cyber insurance claims. If your application says you had a control in place when you actually didn’t, the insurer can refuse the claim. A stated MFA deployment that doesn’t exist in practice is the classic example.

In 2022, Travelers Property Casualty Company filed suit against an Illinois manufacturer called International Control Services after a ransomware attack. Travelers alleged that ICS had stated MFA was in place on its application when it wasn’t. The case resolved in a stipulated judgment that voided the policy entirely. ICS got no coverage at all.

War and state-sponsored attacks

Most modern cyber business insurance policies explicitly exclude losses from war or state-backed cyberattacks. This became standard practice after Lloyd’s of London issued Market Bulletin Y5381 in 2022. The bulletin required clear state-action exclusions in cyber policies starting in March 2023.

If you’re concerned about attacks attributed to nation-state actors, ask your broker exactly how your policy treats them. The boundary between criminal hacking and state-sponsored attack isn’t always clear in practice.

Intentional internal misconduct

Crimes committed by your own staff or leadership fall outside cyber insurance coverage. Embezzlement by a CFO, or deliberate sabotage by an IT administrator, is not a covered event.

Late notification

Most policies require you to notify the insurer quickly after a discovery, with typical windows of 24 to 72 hours. Miss that window, and the carrier has grounds to refuse the entire claim.

Cost of cyber business insurance in Canada

Every business owner asks about cost upfront. The honest answer is that pricing depends on several factors specific to your business.

Why specific prices are hard to give

Cyber business insurance pricing is quote-based. Premiums shift based on your business’s size, industry, annual revenue, the sensitivity of data you handle, and how strong your existing security controls are.

Most Canadian insurers, including Aviva, CNA, and Federated, don’t publish standard rates. You get a quote based on a detailed application.

What affects pricing

Insurers consider several factors when setting your premium:

  • Business size and revenue: Bigger businesses face higher premiums because they store more data and stand to lose more in a single incident.
  • Industry risk level: Healthcare, financial services, and tech companies typically pay more than retail or hospitality.
  • Data sensitivity: Businesses holding payment card data, health records, or government data pay more.
  • Security posture: Strong controls like MFA, EDR, and tested backups can significantly lower your premium.
  • Claims history: A previous cyber incident or any insurance claim on your record will increase your premium.
  • Coverage limits and deductibles: Premiums move up when your coverage limit goes up and your deductible goes down. The reverse also applies.

Who needs cyber business insurance?

Almost any Canadian business that uses computers or holds customer information has some level of cyber risk. The more useful question is different. How urgently do you need cyber business insurance, and what coverage level fits your situation?

Your risk level depends less on what industry you’re in and more on what you actually do with data. Here are the business activities that significantly increase your need for cyber business insurance.

High urgency: must have coverage

Your business almost certainly needs cyber business insurance if you do any of the following:

  • Handle payment card data. PCI DSS fines and assessments can run into hundreds of thousands of dollars after a breach.
  • Store health records or medical information. Provincial laws like PHIPA in Ontario impose strict notification and security requirements with real financial penalties.
  • Hold financial account data, SINs, or government IDs. These are the data types most commonly targeted by attackers.
  • Run an e-commerce site. Online retailers face risks from website attacks, payment fraud, and large-scale data theft.
  • Offer SaaS platforms or technology services that other businesses depend on. One incident in your environment can cascade through every customer you serve, exposing you to substantial third-party claims.
  • Sign contracts with enterprise customers. Many enterprise contracts now require their vendors to carry cyber insurance.

Moderate urgency: strongly consider coverage

Cyber business insurance is highly recommended if you:

  • Store customer contact details, addresses, or order history 
  • Use cloud services for any business-critical operations 
  • Have a workforce that operates remotely or relies on personal devices for work 
  • Move funds through wire transfers or sizeable electronic payments 
  • Manage email communication with sensitive attachments

Lower urgency: still worth evaluating

Even smaller, less data-intensive businesses face some risk. A local trades business with a few computers may not face the same exposure as a healthcare clinic. But ransomware doesn’t discriminate by industry. Even a brief network shutdown can cost more than a year of premiums.

For these businesses, basic cyber business insurance can be priced more affordably. It may also be available as an add-on to your commercial property or liability policy. Aviva, for example, offers cyber coverage as an extension of their Enterprise Property or Liability policies.

A note on business size

A small footprint doesn’t keep your business off the target list. Statistics Canada’s 2023 Canadian Survey of Cyber Security and Cybercrime shows that large businesses face higher attack rates, with 30% impacted. Small businesses report lower incident rates, but they have fewer resources to bounce back. A single incident can be catastrophic for a small business in a way it wouldn’t be for a large one. The Business Development Bank of Canada reports that 73% of small businesses have already experienced a cyber security incident.

Attackers also use automated tools that scan thousands of businesses at once, looking for any weakness. What keeps your business safe isn’t its size. It’s the strength of the security controls you have in place.

What insurers expect from your business

This is where many businesses stumble. Cyber business insurance is no longer just about paying a premium. Insurers expect you to maintain specific security controls, both when you apply and throughout the policy period.

Multi-factor authentication

MFA tops the list of controls insurers ask about. Carriers typically expect it deployed across:

  • Remote access systems like VPNs 
  • Email tools, including Microsoft 365 and Google 
  • Workspace Accounts with privileged or administrative access 
  • Systems and infrastructure used for backups

The Travelers v. ICS case demonstrated what happens when an applicant misstates the MFA setup. The carrier walked away from the entire policy. Hamilton’s experience reinforced the same point: incomplete MFA coverage across critical systems can sink an otherwise valid claim.

Endpoint detection and response (EDR)

Most insurers no longer treat traditional antivirus as adequate protection. Managed EDR is the new baseline expectation. EDR solutions watch endpoints in real time, flag unusual behaviour, and can act against threats without waiting for a human review.

Data backup policies

Insurers care a lot about backups because tested backups can dramatically reduce the cost of a ransomware attack. Common requirements include:

  • Offline, air-gapped, or immutable backups, not just cloud-synced copies 
  • Tested backup restoration on a regular schedule 
  • Backup credentials separate from production credentials 
  • Following the 3-2-1 backup standard: three copies of your data, on two different types of storage, with one stored offsite

Patch management

Carriers want to see that you have a written patching process and a defined turnaround time for fixing critical vulnerabilities. Many specify a hard window, typically between 14 and 30 days, for closing critical and high-severity vulnerabilities.

Employee cybersecurity training

Phishing remains a leading entry point for attackers. Insurers expect regular security awareness training for all staff, including simulated phishing exercises. The 2025 CIRA Cybersecurity Survey found that 98% of Canadian organizations conduct cybersecurity training, but only about half make it mandatory for every employee. Insurers want yours to fall on the mandatory side of that line.

Incident response plan

A written incident response plan is something most cyber business insurance applications now ask for directly. Carriers expect that plan to have been reviewed or tested in the last twelve months. At minimum, the document needs contact details for the response team, steps for isolating affected systems, and the protocol for alerting your insurer.

Email security

Carriers will ask about the email authentication standards you have in place, including SPF, DKIM, and DMARC. They also ask about email filtering, attachment scanning, and whether suspicious emails are flagged for employees.

How to choose a cyber business insurance policy

Once you decide you need cyber business insurance, narrowing down the right policy comes down to five things.

Coverage limits

The coverage limit is the ceiling on what your policy will pay out for a covered event. A small business might choose limits of $1 million to $5 million. Larger businesses or those holding large volumes of sensitive data may need $10 million or more. Check whether the limits operate per individual incident or as a total across the whole policy year.

Deductibles

Your deductible is the dollar amount you cover yourself before the insurer’s payment begins. A higher deductible reduces what you pay in premiums but leaves you exposed to bigger out-of-pocket costs when a smaller claim comes in. Pick a number that fits your business’s cash position.

Exclusions

Read the exclusions section carefully. Common exclusions include pre-existing vulnerabilities, failure to maintain security controls, war and state-sponsored attacks, intentional misconduct, and bodily injury (which falls under other policies). When something in the exclusions section is unclear, get your broker to walk you through it in writing before the policy is finalized.

Incident response support

Some insurers, like Aviva and CNA, include 24/7 incident response services with their cyber business insurance policies. This includes access to forensic specialists, breach counsel, and crisis management experts. This kind of bundled support is genuinely valuable, especially for businesses without their own internal security team.

Legal and forensic services

Look for policies that include or provide easy access to data breach lawyers, forensic investigators, and PR firms. The window between hours 1 and 72 after a breach is the most consequential. Having pre-vetted experts ready to engage saves time and money.

The cyber insurance claims process

Filing a claim under a cyber business insurance policy is more complex than filing a typical insurance claim. Here’s how it usually works.

Step 1: Report the incident immediately

Cyber business insurance policies typically expect a call within a 24 to 72 hour window after the incident is discovered. Some require notification even before you confirm whether a breach occurred. Filing late ranks among the leading causes of denied claims.

The notification typically goes through a dedicated hotline. Aviva’s cyber business insurance includes a 24/7 incident response phone line specifically for this purpose.

Step 2: Engage incident response services

The insurer typically connects you with their incident response team or pre-approved third-party experts. These professionals handle forensic investigation, legal counsel, and breach notification. Trying to handle these tasks yourself without insurer pre-approval can lead to expenses not being covered.

Step 3: Investigation and assessment

The insurer’s forensic team investigates the scope of the breach. They determine what data was accessed, how the attacker got in, and what controls failed. This step also confirms whether your stated security controls were actually in place. The findings affect whether your claim is covered.

Step 4: Coverage approval and payouts

If your claim is covered, the insurer either pays expenses directly or reimburses you. Some expenses, like ransomware payments, may require explicit pre-approval. Others, like notification costs and business interruption losses, are paid as incurred.

Common reasons claims are denied

The Travelers v. ICS and Cottage Health cases set the pattern. Claims get denied for several reasons:

Application errors, especially around MFA, backups, or other claimed security controls Allowing claimed controls to lapse during the policy period Filing the claim outside the notification window Pre-existing vulnerabilities or conditions Excluded causes (war, state-sponsored attacks, intentional misconduct) Activities not covered by the policy (such as bodily injury or property damage)

Cyber insurance vs cybersecurity tools

A common misconception is that buying cyber business insurance replaces the need for security tools. It doesn’t.

Insurance is recovery, not prevention

Cyber business insurance pays for the aftermath of an attack. It doesn’t stop attacks from happening. If your business has weak security, you’ll still get breached. You’ll just have someone helping pay the bill afterward.

How insurance and security work together

Good security reduces both how often incidents happen and how bad they get. Insurance reduces the financial damage when incidents happen anyway. They’re complementary, not interchangeable.

Real-world cyber attack scenarios

Real cases are the clearest way to see what cyber business insurance does well and where it falls short. The Hamilton ransomware case opened this guide. The three cases below add more context to how policies play out in practice.

Customer data breach: Cottage Health (California)

In 2015, Columbia Casualty Company (a CNA subsidiary) took the unusual step of suing its own policyholder, Cottage Health System, a California healthcare network. The lawsuit followed a breach that exposed roughly 32,500 patient records. The root cause was a server containing patient information that had been left exposed online without basic security controls.

Columbia Casualty’s argument was that Cottage Health’s application overstated the security controls actually in place. The court eventually dismissed the coverage dispute on a procedural point. The underlying breach still ended in a $4.125 million class-action settlement against Cottage Health.

The lesson: every statement you make on an application carries weight. Insurers do investigate, and they’re willing to fight.

Business email compromise (BEC)

BEC scams have become one of the most common cyber threats facing Canadian businesses. The attacker poses as a senior executive or a known vendor. The employee is then convinced to authorize a wire transfer to a bank account the attacker controls. The Canadian Anti-Fraud Centre tracks losses from BEC fraud in the hundreds of millions of dollars each year.

Most cyber business insurance policies cover BEC losses, often under a “misdirected payment fraud” or “social engineering fraud” coverage section. These coverages typically have sublimits much lower than the overall policy limit. The coverage might be $250,000 even on a $5 million policy.

Nation-state attack: Mondelez v. Zurich

In June 2017, the NotPetya malware swept through Mondelez International’s worldwide operations. The attack destroyed around 1,700 of the company’s servers and 24,000 laptops. Mondelez then submitted a claim of roughly $100 million in losses to its property insurer, Zurich.

In 2018, Zurich refused to pay, pointing to the “hostile or warlike action” carve-out in the policy. The insurer argued that NotPetya had been traced to the Russian military and aimed at Ukraine. On that basis, Zurich treated the attack as a state-sponsored act of war and excluded it from coverage. After several years of dispute, the two sides reached a confidential settlement in late 2022.

This case led directly to Lloyd’s of London requiring cyber insurance policies to include clear state-action exclusions starting in March 2023.

The lesson: read the war and state-action exclusions carefully. Nearly every current cyber business insurance policy contains them.

Other ways to lower your premiums

Putting the security controls insurers expect into practice is the most important factor in reducing your cyber business insurance premium. Three other moves can also make a measurable difference.

Run a security risk audit

Bring in a third-party security assessor to evaluate your defences. The resulting report shows you exactly where your weaknesses are and creates the kind of documentation insurers want to see during underwriting. Some insurers even refer to specific frameworks like the Canadian Centre for Cyber Security’s Baseline Controls.

Bundle with other coverage

Some insurers offer discounts when you bundle cyber business insurance with commercial property, liability, or professional coverage. Ask your broker if bundling makes sense for your business.

Re-shop your policy each year

Don’t auto-renew. The Canadian cyber insurance market has been volatile, and premiums change significantly year to year. When your renewal date approaches, gather quotes from a minimum of two or three carriers. Putting carriers in competition with each other is what keeps your premium honest.

Alternatives to cyber business insurance

Cyber business insurance isn’t the only way to handle cyber risk. Here are three alternatives, each with trade-offs.

Self-insurance (risk retention)

Some businesses choose to set aside funds to cover potential cyber losses themselves, rather than paying premiums. This can make sense for businesses with very low cyber risk or very deep pockets. For most small and medium businesses, self-insurance is risky because a single incident can exceed your reserves.

Managed security service providers (MSSPs)

An MSSP runs your cybersecurity function for you as an outsourced service. Their offerings usually cover continuous monitoring, threat detection, incident handling, and the day-to-day security operations of your environment. Bringing in an MSSP doesn’t substitute for insurance. It does cut your odds of being breached, which can lower your premium and make you more attractive to underwriters.

Hybrid risk management

Most businesses end up with a hybrid approach. They buy cyber business insurance for catastrophic events. They use security tools and MSSPs to reduce risk. And they set aside some funds for smaller incidents that fall under the deductible.

This combined approach gives you protection at multiple levels. It’s the most common strategy among Canadian businesses serious about cyber risk.

Final thoughts

Cyber business insurance has become essential for most Canadian businesses, but it’s not a magic shield. The policies are getting stricter. The security requirements are getting higher. Denied claims are becoming more common when businesses don’t meet what they promised on their applications.

Think of cyber business insurance as one piece of a wider risk management approach. Pair the policy with serious security controls, ongoing staff training, and a documented incident response plan. Doing all three gives you both the protection you need and the favourable premiums that go to businesses insurers consider low-risk.

Talk to a Canadian commercial insurance broker who specializes in cyber risk. Get multiple quotes. Read the exclusions. And make sure every security control you claim on your application is actually in place.

FAQs about Cyber Business Insurance

Is cyber business insurance mandatory in Canada?

For most Canadian businesses, cyber business insurance is not a legal requirement. Some sectors, such as healthcare and financial services, may face indirect pressure from regulatory frameworks or contract requirements set by larger clients. A growing number of enterprise buyers also expect their suppliers to hold cyber insurance before signing a contract.

How much does cyber insurance cost in Canada?

The only way to get an accurate price is to request quotes from a commercial insurance broker who handles cyber risk.

What does cyber insurance typically cover?

Most cyber business insurance policies cover first-party losses (incident response, business interruption, data restoration, ransomware payments) and third-party liability (regulatory defence, lawsuits, fines).

Does cyber insurance cover ransomware?

Most cyber business insurance policies cover ransomware-related losses, including ransom payments, data restoration, business interruption, and incident response.

Is cyber business insurance worth it for a small business?

For most Canadian small businesses, the answer is yes. Recent Canadian data shows the average breach now costs nearly $7 million. Even smaller incidents routinely run past $100,000, which is more than many small businesses can absorb.