Back to Blog
Cybersecurity9 min read

The Cyber Insurance Gap: What 73% of Canadian SMBs Are Missing and What Insurers Now Require to Issue a Policy

By Anton Kuznetsov

Three in four Canadian small businesses have experienced a cyberattack or data breach. Only one in five carries cyber insurance.

The gap between those two numbers is the financial exposure that a growing number of Canadian SMB owners are discovering after an incident — too late to close it.

This article covers what the exposure looks like in dollar terms, what has happened to the Canadian cyber insurance market over the past five years, and — most practically — what underwriters now require before they will issue a policy in 2026.

What a Cyber Incident Costs a Canadian Organization

The average cost of a data breach at a Canadian organization reached CA$6.98 million in 2025, a 10.4% increase from CA$6.32 million in 2024, according to the IBM Cost of a Data Breach Report 2025. While breach costs are declining globally, they continue to rise in Canada — a distinction IBM explicitly flagged in its Canadian-market analysis.

The ransomware numbers are particularly relevant for small businesses. The Verizon 2026 Data Breach Investigations Report found ransomware present in 48% of all confirmed breaches, and — critically — that 96% of ransomware victims were SMBs. The DBIR recorded 7,152 confirmed SMB breaches in 2026.

At the aggregate level, Canadian businesses spent approximately CA$1.2 billion recovering from cybersecurity incidents in 2023 — double what they spent in 2021 — according to Statistics Canada's survey on the impact of cybercrime on Canadian businesses.

For a Canadian SMB without cyber insurance, an incident results in: paying for forensic investigation and incident response out of pocket, covering legal fees and breach notification costs for affected individuals under PIPEDA, absorbing business interruption losses during recovery, and managing the reputational fallout without professional crisis communications support. None of those categories are covered by a general commercial liability policy.

The Coverage Gap

The Insurance Bureau of Canada's 2025 SMB Cybersecurity Survey — conducted with 308 Canadian business owners and decision-makers — found that only 22% of Canadian SMBs carry cyber insurance. This figure has risen from 16% in 2021, but remains low given the incident rate.

The Business Development Bank of Canada estimates that 73% of small Canadian businesses have already experienced a cybersecurity incident, with 41% reporting that the incident disrupted operations, 23% reporting increased ongoing security costs, and 20% incurring significant unplanned expenses, according to data cited in the IBC's September 2025 release. The math is worth sitting with: roughly seven in ten Canadian SMBs have had an incident, but only one in five has coverage for the next one.

It is worth noting a contrast from a different surveyed population: among the 500 cybersecurity decision-makers surveyed by CIRA in August 2025, 84% reported that their organization carries cyber insurance, up from 59% in 2021. This divergence reflects who is being asked. Organizations large and mature enough to employ a dedicated cybersecurity decision-maker behave very differently from the broader SMB market of 20–150-person companies without in-house IT leadership. Both numbers are accurate — they measure different populations. The IBC figure is more representative of the audience most likely reading this article.

Why the Canadian Cyber Insurance Market Tightened

Understanding current insurer requirements requires understanding what happened to the Canadian market over the past decade.

The Insurance Bureau of Canada's cyber market analysis documents the scale of the change: Canadian cyber insurance premiums grew from $18 million in 2015 to $550 million in 2023 — a 30-fold increase in eight years. The combined ratio for Canadian cyber insurers averaged 153% from 2019 through 2023, meaning insurers paid out CA$1.53 in claims and expenses for every CA$1.00 they collected in premiums. The market was deeply unprofitable.

The correction took two forms. From 2021 to 2023, premiums spiked sharply — in some cases 50–100% year-over-year. By 2024, stronger underwriting practices and increased market capacity drove approximately a 15% rate decrease. Rates have continued to stabilize.

The critical point for Canadian SMBs: insurers compensated for rate relief by tightening what they require before issuing a policy. It is now possible to qualify for coverage at premiums well below the 2022 peak — but only if your security controls meet a bar that underwriters have moved significantly higher. The IBC publishes a self-assessment tool specifically for small businesses evaluating whether they currently meet that bar.

What Underwriters Now Require

Across the major Canadian cyber insurers active in the SMB market — Intact, Aviva Canada, Chubb, and Coalition among them — underwriting requirements have converged around a core set of controls. Missing any of these does not produce a higher premium. It produces either a declined application or a policy with exclusions that materially reduce its value at the moment you need it.

Multi-factor authentication on every account that matters

MFA is the single most scrutinized control on a cyber insurance application, and coverage must be comprehensive. Underwriters require MFA enforced on: all remote access and VPN connections, all email accounts (not just administrative ones), all cloud services and SaaS applications, and all privileged and administrative accounts. SMS-based MFA is no longer accepted by many carriers as the sole factor — number-matched push MFA is the floor in 2026, with FIDO2 hardware tokens or passkeys increasingly expected for administrative access. The CIRA 2025 Cybersecurity Survey found that 39% of Canadian organizations had insurers verify their current security measures before renewal — MFA coverage is the first thing that verification checks.

Endpoint detection and response (EDR) on every device

Traditional antivirus is explicitly insufficient. Underwriters require EDR or XDR solutions — Microsoft Defender for Business, CrowdStrike Falcon Go, SentinelOne, or equivalent — deployed on every managed endpoint. The emphasis on "every" is not rhetorical. Forensic investigation after an incident identifies unmanaged devices, and a deployment that covers 80% of your fleet leaves the remaining 20% as an unmonitored entry point. Underwriters treat partial EDR coverage as no EDR coverage for risk-rating purposes.

Immutable backups with documented restore tests

Backups must be isolated from the production environment — air-gapped or stored in immutable cloud storage such as AWS S3 Object Lock or Azure Immutable Blob Storage — so ransomware cannot encrypt them alongside live data. Critically, underwriters now ask not only whether you have backups but when you last tested a restore. An untested backup is a theoretical asset. Most carriers expect documented quarterly restore tests, with evidence available at renewal.

A documented and tested incident response plan

Underwriters want evidence that your organization has a pre-written plan for the first hours of an incident: who declares a breach, who is notified (legal counsel, leadership, your insurer's breach hotline), and how containment begins. Several carriers now specifically require that the plan reference the insurer's own incident notification number — because late breach notification is one of the most common grounds for claim denial. An incident response plan that was accurate 18 months ago and has not been reviewed since is treated differently from one that was updated after your last tabletop exercise.

Security awareness training with phishing simulations

The CIRA 2025 Cybersecurity Survey found that 38% of Canadian organizations saw premium increases at their most recent renewal, and 37% experienced changes to their eligibility criteria. Security awareness training — documented, with phishing simulation results — is among the controls that shape both eligibility and premium. Monthly phishing simulations with tracked phish-prone rates are the expectation for standard coverage; annual-only training is treated as a partial control that may trigger higher premiums or coverage sub-limits.

Privileged access management

Elevated accounts — domain administrators, local admins, cloud console root credentials — must be managed separately from standard user accounts, with unique credentials per system, no shared administrative passwords, and session logging for privileged activity. Privileged access management determines how far an attacker can move from their initial foothold. Without it, a single compromised credential provides domain-level access within minutes of initial breach.

Email authentication at enforcement policy

Business email compromise remains a leading claim category. Underwriters expect DMARC, SPF, and DKIM records configured in DNS, with DMARC set to p=quarantine or p=reject. A DMARC record set to p=none is monitoring only — it does not prevent spoofed email delivery to recipients and does not satisfy the underwriting requirement. Many SMBs have added DMARC at p=none after reading about it and believe this addresses the insurer's concern. It does not.

Patch management with evidence

An unpatched software vulnerability is now the dominant initial access vector in data breaches globally. Underwriters expect a documented patch cadence — critical patches within 72 hours of release, high-severity within two weeks — with evidence from your endpoint management platform (Microsoft Intune, WSUS, or a third-party RMM tool) available at renewal. A stated patch policy with no evidence of enforcement carries limited weight in underwriting.

Why Claims Get Denied

Qualifying for a policy and collecting on it are not the same thing. The single most common cause of cyber insurance claim denial is misrepresentation on the application: the insured attested to controls that were not fully deployed at the time of the incident. After a breach, insurers commission forensic investigations that map the environment as it actually existed — and that map does not always match what the application described.

The most frequent misrepresentation involves MFA. An organization attests that MFA is enforced on all remote access, and the forensic investigation finds that a legacy VPN endpoint, a vendor service account, or a specific cloud application was excluded. The policy exclusion is then applied to the claim. A material misrepresentation on the application gives the carrier grounds to reduce or deny the entire claim — not just the portion attributable to the control gap.

The second most common denial cause is drift: the controls were in place when the policy was bound but were not maintained throughout the policy term. Underwriting increasingly includes conditions requiring that attested controls remain in force continuously, not just at application time. A patch cadence that was documented at renewal but was never followed operationally is a post-incident liability.

For any Canadian SMB completing a cyber insurance application: validate that every control you intend to attest to is actively enforced, not planned or partially deployed, before signing. Have your IT team or managed service provider generate evidence — Entra ID MFA enrollment reports, Intune compliance dashboards, backup restore test logs — before the application goes in.

How CCCS Baseline Controls and Insurer Requirements Align

The Canadian Centre for Cyber Security's ITSM.10.089 Baseline Cyber Security Controls for Small and Medium Organizations documents thirteen control areas the CCCS identifies as the minimum defensible security posture for Canadian SMOs. The alignment with cyber insurer requirements is direct:

CCCS Baseline ControlCorresponding Insurance Requirement
1 — Incident Response PlanningDocumented and tested incident response plan
2 — Patch ManagementDocumented patch cadence with evidence
5 — Authentication (MFA, PAM, role-based access)MFA on all accounts; privileged access management
6 — Security Awareness TrainingTraining with documented phishing simulation results
7 — Data Backup and RecoveryImmutable backups with restore-tested evidence
9 — Network and Perimeter SecurityEmail authentication (DMARC at enforcement)

Implementing the CCCS ITSM.10.089 baseline does not just improve your security posture — it simultaneously positions your organization for cyber insurance qualification. The controls that produce the largest measurable reduction in breach probability are the same controls that reduce expected claim costs, which is what insurers are pricing. The CCCS guidance is published at no cost and is updated regularly to reflect the current threat landscape.

What PIPEDA Adds to the Decision

Under PIPEDA, any organization that suffers a security breach posing a real risk of significant harm to an individual is required to report to the Office of the Privacy Commissioner of Canada and notify affected individuals. Records of all breaches — whether reportable or not — must be kept for 24 months. Knowingly failing to report a qualifying breach is an offence under PIPEDA, with fines of up to $100,000 per violation.

Cyber insurance does not remove the reporting obligation. What it covers is the cost of fulfilling it: breach counsel, forensic investigation to determine the scope of the incident, notification letters, credit monitoring services for affected individuals, and public relations support. Those costs accumulate quickly following a breach involving personal information, and without coverage, they are absorbed directly by the business.

A Practical Starting Point

For Canadian SMBs that do not yet carry cyber insurance — or that are approaching renewal and unsure whether they will qualify — the most productive first step is an honest gap assessment against the eight controls above. Before completing any application:

Confirm MFA coverage. Pull a report from Entra ID or your identity provider listing all accounts with remote access, VPN, or administrative privileges, and verify that MFA is enrolled and enforced — not just available. Exceptions undermine the attestation.

Verify EDR deployment. Compare your Intune, RMM, or endpoint management device count against your actual device inventory. Any gap between managed and unmanaged endpoints is an underwriting exposure and a security exposure simultaneously.

Test a backup restore. Run a documented restore from your most recent backup and record the result. If you cannot restore a representative dataset, the backup is not functioning as intended and will not satisfy an underwriter's question about tested restores.

Check your DMARC policy. Look up your domain's DMARC record and confirm the policy is set to p=quarantine or p=reject. If it is at p=none, the upgrade is typically a DNS record change that takes minutes.

Locate your incident response plan. If it references your current insurer's breach hotline, was reviewed in the past 12 months, and includes named individuals responsible for each response step, you have a defensible document. If it was written once and filed, treat it as a draft that needs updating before your application.

Cyber insurance does not prevent incidents. The Canadian cyber threat landscape in 2026 makes some level of incident statistically likely for organizations that operate digitally. What coverage does is ensure that a CA$6.98 million average financial exposure does not become a CA$6.98 million unrecoverable loss — and what the application process does, when treated honestly, is tell you exactly where your gaps are before the incident finds them first.


Sources


Cloud Forces helps Canadian SMBs assess their cyber insurance readiness and close the control gaps that underwriters now require — from MFA enforcement and EDR deployment to backup verification and incident response planning. Explore our Cybersecurity services or contact us to schedule a complimentary cyber insurance gap assessment.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation