Cyber insurance usually enters the conversation the wrong way. Not as a proactive purchase, but as a renewal notice with a nine-page security questionnaire attached: MFA on every account? Endpoint detection and response? A tested incident response plan? Someone, usually the CFO, sits down to fill it out and realizes they can’t actually answer half of it. Neither can anyone else in the building.
That questionnaire nobody can complete has become one of the most reliable reasons organizations end up calling an MSP. It’s also the clearest way to understand what cyber insurance actually is: financial protection for the moments prevention fails, built on top of a level of security discipline insurers now expect you to prove, not just claim.
The stakes are real. IBM’s 2026 Cost of a Data Breach Report puts the average breach cost in Canada at $7.11 million CAD, the highest since the report began. This isn’t about fear, though. It’s about clarity: what the coverage does, who actually needs it, and what it takes to qualify.
Who Actually Needs It
Every organization handling other people’s information is a candidate. A few categories make it close to non-negotiable.
Organizations bound by data governance standards
If you’re ISO 27001 certified, subject to PCI DSS because you process payment cards, or operating under a data governance framework tied to a government or enterprise contract, cyber insurance is frequently a contractual requirement, not a choice.
Organizations under privacy law
In BC, that’s PIPA. Federally, it’s PIPEDA, which applies to any private-sector organization handling personal information in the course of commercial activity. Both carry breach notification obligations, and PIPEDA carries penalties of up to $100,000 for knowingly failing to report. Insurance doesn’t remove that obligation, but it funds the legal, forensic, and notification work that comes with meeting it.
Non-profits
Boards sometimes treat cyber insurance as an enterprise problem. It isn’t. Non-profits hold donor payment details, beneficiary records, and grant data, often on leaner security budgets than a comparably sized business, which is exactly what makes them an efficient target. If your organization runs on donor trust, a breach becomes a governance conversation your board will want answered directly.
Specific industries
Healthcare, financial services, professional services like legal and accounting, and any organization where client records are core to the business carry higher exposure by default, because the data itself is the target.
The simplest test: if a breach would trigger a legal notification requirement, a contractual obligation, or a hard conversation with your board or clients, you need it.
What a Standard Policy Typically Covers
Coverage splits into two categories, and most policies bundle both.
First-party coverage covers costs you incur directly:
- Forensic investigation to determine what happened and how far it went
- Legal counsel for notification compliance
- Breach notification: letters, call centres, credit monitoring for affected individuals
- Business interruption: lost income and extra expense while systems are down
- Cyber extortion and ransomware: negotiation and, where authorized, payment
- Data restoration
Third-party coverage covers what you owe others:
- Legal defence and settlements from client or third-party lawsuits
- Regulatory investigation defence and fines, where insurable by law
- Privacy liability claims
The number on the declarations page tells you less than you’d think. Most policies carry sub-limits that cap ransomware payouts well below the overall policy limit, and a growing number of insurers now require the insured to co-pay a share of any ransom, typically around 50%. That’s a deliberate structural nudge: insurers would rather you invest in defences than lean on their cheque book.
Questions to Ask Yourself
Before shopping for a policy, or sitting down to renew one, it’s worth answering these honestly:
- If we lost access to our systems for a week, what would it cost us, in revenue, client trust, and staff time spent recovering?
- Do we hold personal, financial, or health information that would trigger a legal notification requirement if it were exposed?
- Are we contractually required to carry coverage, whether by a client, a government contract, or a certification we hold?
- Could we currently answer an insurer’s security questionnaire without guessing?
- If the answer to #4 is no, who in the organization would find that out, and when?
That last one is the one boards and CFOs consistently underestimate. It’s usually discovered during renewal, under a deadline, which is the worst possible time to discover a gap.
The Checklist Insurers Actually Use
Underwriting has changed. A few years ago, a checkbox attestation was enough to bind a policy. Now, insurers want evidence the controls are actually running, not just installed. The baseline most carriers require before they’ll write or renew a policy:
- Multi-factor authentication on email, remote access, and privileged accounts
- Endpoint detection and response (EDR) across all endpoints and servers, not just workstations
- Backups that are tested and immutable or offline, not just scheduled
- A documented, exercised incident response plan
- Patch management, with no unsupported end-of-life systems still in production
- Privileged access management, limiting who can do what
- Email security paired with phishing-awareness training
- Network segmentation
This isn’t an aspirational list; it’s close to the actual floor. According to CIRA’s 2024 Cybersecurity Survey, 82% of Canadian organizations now carry cyber insurance, up from 59% in 2021, and nearly four in ten report their insurer has tightened eligibility rules or raised premiums based on what they found during underwriting.
Where Tecnet Fits In
We approach this the same way we approach any security engagement: assess first, then build, then keep it running.
We start with an assessment of your current posture measured against exactly what insurers are asking for (MFA coverage, backup integrity, endpoint protection, incident response readiness), so you know your real gaps instead of guessing at renewal time. From there, we implement the specific controls that close them, using tools we already manage across our client base, so nothing gets bolted on as an afterthought. Once it’s in place, our team monitors it 24/7, because a control nobody is watching isn’t one an insurer will credit you for. And because requirements shift with every underwriting cycle, we keep it current: testing backups, updating the incident response plan, revisiting access permissions, so you’re not scrambling nine months from now.
For our managed services clients, that changes what renewal season looks like. The questionnaire stops being a scramble, because the assessment and the evidence already exist. You’re not trying to reconstruct twelve months of security decisions in an afternoon.
What now?
Cyber insurance is a financial backstop, not a security strategy. The strategy is what makes the backstop affordable, and renewable.
Want to know where your organization actually stands against what insurers are asking for? Reach out to your Tecnet account manager, or contact us to start with a cybersecurity assessment.
This article is for general information and isn’t legal or insurance advice. Talk to a licensed broker and legal counsel about the coverage and obligations specific to your organization.








