Cyber insurance can help with the financial impact of an attack. Keeping the business running takes more: protected accounts, a team that responds and recovery you have actually tested. Here is how SMBs can bring those pieces together.

Hand beneath illustrated padlock and connected security icons

Insurance helps fund recovery. Resilience makes it possible.

A cyber policy can help pay eligible costs after an incident. It cannot stop a stolen account, keep your point-of-sale system online or restore your order database on its own. Those outcomes depend on the people, controls and recovery arrangements you have in place.

For an SMB, cyber resilience means reducing the chance of a serious incident, detecting problems early and restoring essential work when something goes wrong. Insurance belongs inside that plan. Treating the premium as the entire plan leaves operational gaps.

Two complementary parts of your cyber risk plan
Business needInsurance may help withYour team must prepare
Incident responseCovered specialist services and response costs.Escalation contacts, access, evidence and authority to act.
Business interruptionEligible losses within policy terms and limits.Workarounds and a tested route back to service.
Data compromiseCovered forensic, legal and notification expenses.Data protection, investigation support and communication decisions.

Coverage differs by policy. Review the actual wording with your broker, including exclusions, deductibles, sublimits, waiting periods and conditions.

Understand the underwriting conversation

Insurers need to understand the risk they are accepting. Expect questions about account protection, endpoint security, patching, backups and incident response. Answer based on what is deployed and maintained across the stated scope, including exceptions.

The historical numbers explain some of that scrutiny. In a July 2024 market review, the Insurance Bureau of Canada reported cyber liability premiums rising from CAD $18 million in 2015 to CAD $550 million in 2023. Its reported combined ratio averaged 153% over 2019–2023: claims and operating expenses of $1.53 for each premium dollar earned.

That is a combined ratio, not a claims-only loss ratio. The same review described a stabilizing market and greater competition. These historical figures do not establish that premiums are always rising or predict what your next renewal will cost.

Make the application match reality. Keep supporting records for control statements, document gaps and ask your broker how changes should be reported. No generic checklist guarantees eligibility, a lower premium or payment of a claim.

Plan around the incidents that interrupt work

Ransomware and data extortion

An attacker may encrypt systems, steal data or do both. Recoverable copies help restore operations, but they do not reverse a data leak. Your response plan needs to address containment, recovery and the consequences of compromised information.

Compromised email and payment fraud

A convincing invoice or supplier bank-change request can turn account access into financial loss. Pair identity and email protections with an independent callback to a trusted number before changing payment details. Ask your broker how your policy treats social engineering and funds-transfer fraud.

Supplier and service disruption

Your business may stop even when the affected system belongs to someone else. Identify the providers behind payments, identity, email and line-of-business applications. Agree on escalation contacts and workable alternatives before an outage.

Person using a laptop displaying a padlock symbol

Build a practical security baseline

Use this as a starting point for planning with your IT team. Your insurer’s questions and your own risk assessment determine the specific scope.

  • Protect identity. Enforce MFA on email, remote access and privileged accounts. Prioritize phishing-resistant methods such as supported passkeys or security keys; document systems that cannot support them.
  • Cover endpoints and response. Maintain endpoint detection and response (EDR) coverage, with named people responsible for investigating alerts and authorized to contain threats. Confirm who responds outside business hours.
  • Close exposed weaknesses. Inventory systems, prioritize exposed and actively exploited vulnerabilities, assign remediation deadlines and replace unsupported software.
  • Secure email and payments. Combine filtering, domain authentication, staff training and a simple way to report suspicious messages with payment verification procedures.
  • Limit access. Separate administrative accounts, remove departed users promptly and review supplier access against current needs.
  • Prepare for incidents. Keep response contacts and an actionable plan available when normal email or systems are unavailable.

The Canadian Centre for Cyber Security’s ransomware guidance supports layered preparation, stronger authentication, restricted privileges, updates and recovery planning. For implementation detail, read our guides to business passkeys and EDR versus antivirus.

Prove that recovery works

A successful backup job is useful evidence, but it does not show how quickly staff can work again. Set a recovery time objective for each critical service and agree how much recent data loss the business can tolerate.

Protect recovery copies from the same accounts and failures that could affect production. Use appropriate offline or immutable copies, separate administration and secure access to recovery keys. Test restoration into a suitable environment, including application dependencies and user access.

Run a realistic exercise: email is unavailable, an administrator account is compromised and a key application is down. Who can authorize containment? Who calls the insurer’s incident line? Who tells customers what is happening? Can the team recover the service and complete an actual business transaction?

Record elapsed recovery time, the data point restored, business checks and unresolved gaps. Assign an owner and due date to each corrective action. Our backup and disaster recovery guide explains how to turn those targets into a testable plan.

Person using a laptop beneath illustrated security and file icons

Connect the policy to your incident plan

Review the policy before you need it. Put the insurer’s notification process, approved response providers and any consent requirements into the incident plan. Make sure an authorized person can access those details during an outage.

  • Confirm which incident types, systems and service providers are within scope.
  • Review coverage limits and conditions for interruption, restoration, fraud and third-party claims.
  • Clarify when and how to notify the insurer, and who can approve specialist costs.
  • Retain accurate records of security controls, incidents and recovery exercises.
  • Have the appropriate adviser identify the legal and contractual notification duties that apply to your organization.

Do not assume every SMB has the same reporting obligations. Duties depend on the organization, information involved, jurisdiction and contracts. Build the relevant requirements into your plan with qualified advice.

Insurance can provide valuable funding and expertise. It works best alongside clear responsibilities and a maintained recovery capability.

Start with one critical business service

Choose the service your business can least afford to lose. Map its accounts, devices, suppliers and data. Check the protections in place, confirm who responds to an alert and demonstrate how the service would be restored.

Then compare that evidence with your insurance application and policy requirements. Address mismatches before renewal, and revisit the plan when systems, suppliers or business activities change.

ThinkSwift can help assess your cybersecurity controls, prioritize improvements and plan recovery exercises. Bring your IT team and insurance broker into the same conversation so technical work and coverage decisions reflect the same facts.

Questions answered

01Does cyber insurance replace cybersecurity?

No. It may cover eligible financial losses and response services, but it does not implement controls or restore business services by itself. Keep prevention, detection, response and recovery in your operating plan.

02Will MFA and EDR guarantee coverage?

No. Requirements and coverage decisions depend on the insurer, policy and circumstances. Deploy controls across the agreed scope and describe them accurately in applications and renewals.

03Is 24/7 monitoring the same as 24/7 response?

No. Monitoring can generate alerts without anyone being responsible for taking action. Confirm staffing, escalation times, containment authority and the systems included in the service.

04Are backups enough to handle ransomware?

Backups support restoration when usable copies and recovery tools are available. They do not undo stolen data, remove an attacker or replace a coordinated incident response.

05What should we do first?

Identify one critical service, its owner and its recovery requirements. Check identity protection, endpoint coverage and backup usability, then review the findings alongside your broker’s policy guidance.

Build a recovery plan your business can rely on.

Talk through your security gaps, critical services and recovery priorities with ThinkSwift.

Talk it through
ThinkSwift Cybersecurity Team