Who it’s for

  • Any business that keeps client names, contact details, financial or health information
  • Accountants, bookkeepers, agencies, clinics and other office-based firms
  • Retailers and online stores that take payments
  • Contractors and manufacturers who rely on email to send invoices and receive payments
  • Owners who run part of the business from home or on family devices

What it covers

Cyber liability insurance responds when your systems or your data are compromised. A typical policy has two sides.

Your own costs (first-party coverage):

  • Breach response: forensic investigators to find out what happened, breach lawyers, notifying affected clients, and credit monitoring where it’s needed.
  • Ransomware and extortion: expert help to deal with an attacker who has locked your systems or is threatening to release data.
  • Data restoration: rebuilding systems and recovering lost or corrupted data.
  • Business interruption: income you lose while your systems are down.
  • Social engineering fraud: money lost when someone tricks your staff into paying a fake invoice or changing banking details. This is often limited and worth checking.

Claims against you (third-party coverage):

  • Lawsuits from clients or others whose information was exposed.
  • Defence costs and, where insurable, regulatory proceedings related to privacy.

One of the most useful parts of a cyber policy isn’t the money; it’s the breach response team. When something goes wrong, you get a phone number and people who deal with this every week. In the first few hours of a breach, knowing who to call, what to shut down and what not to delete can make a real difference to how the rest of it goes.

What it doesn’t cover, and common gaps

  • Weak security you said you had. Applications ask about multi-factor authentication, backups and updates. If the answers aren’t accurate, a claim can be in trouble.
  • Fraud limits that are too small. The most common loss for small businesses is a fake invoice or a changed bank account, and that coverage is often sublimited.
  • Your own errors in professional work. If you’re an IT or software firm and the problem is your service, that’s errors and omissions territory. See our technology page.
  • Property damage and bodily injury. Those usually stay with your property and liability policies.
  • Personal devices. Not every policy covers laptops, phones and home networks the business doesn’t own.

Where your business and family policies overlap

For a lot of small businesses, the business network is the family network.

  • Family devices used for business email. Say you run a renovation company and answer client emails from the family iPad, while your kids use the same device for games and downloads. If that device is compromised and someone gets into your business email, does the cyber policy treat it as your system? Some policies do and some don’t.
  • The home network. If you or your bookkeeper work from home, client files travel over the home Wi-Fi and may sit on a home computer. The cyber policy needs to recognize where the work actually happens.
  • Personal cyber coverage. Some home policies now include a small amount of cyber or identity theft coverage for the family. It is not built for a business breach, and it may exclude business activity entirely.
  • A spouse or family member who helps out. If a family member handles invoices or banking for the business, they’re part of the fraud risk and should be part of the conversation about controls.

Steve asks where the business’s data actually lives, which devices are used to reach it, and who has access, then checks whether the cyber policy and the home policy line up with that.

How Steve works on this

Cyber applications can be confusing, and wrong answers matter. Steve goes through the application with you so the answers are accurate, explains what each part of the policy does in plain terms, and points out where coverage is limited, especially for fraud. He’ll give you options and his honest view on what’s worth adding. At renewal, he calls to ask what’s changed: new staff, new software, people working remotely, new types of client data.

If you’d like a second set of eyes on your cyber exposure, book a review.

Common questions

Doesn't my general liability policy cover a data breach?

Usually not. General liability is written for bodily injury and physical property damage. Most commercial package policies either exclude cyber losses or give a very small amount of coverage, which is why cyber is normally bought as its own policy.

I'm a small business. Am I really a target?

Small businesses are often easier targets because they have fewer controls. Many cyber losses aren't sophisticated hacks at all; they start with a phishing email, a stolen password or a fake invoice.

What do I have to do if client information is breached?

Under PIPEDA, the federal privacy law that covers most Ontario businesses, you must report a breach to the Privacy Commissioner of Canada and notify affected individuals when it creates a real risk of significant harm. You also have to keep a record of every breach for 24 months. A cyber policy usually gives you access to breach lawyers and response firms to help with this.

Does cyber insurance cover money lost to a fake invoice or email fraud?

Sometimes. Social engineering and funds transfer fraud are often limited or need to be added specifically. It's one of the first things worth checking on any cyber policy.

Will my cyber policy cover my home computer?

It depends on the wording. Some policies cover systems the business owns or controls; others extend to personal devices used for work. If you or your staff work from home, this needs to be confirmed in writing.

Want a second set of eyes on your insurance?

Book a review with Steve. He’ll go through what you have now, show you where the gaps are, and give you his honest opinion. If everything’s in order, he’ll tell you that too.

Book a ReviewCall 905-407-7071