Cyber insurance can help fund a covered loss, but it cannot replace secure systems or a workable recovery plan. Hamilton’s experience offers a concrete reason to review your controls, incident costs and policy terms together.

What Hamilton’s incident actually shows
Hamilton’s cyberattack occurred on February 25, 2024. In its July 30, 2025 update, the City reported spending CAD $18.3 million through June 30, 2025 on response, recovery and external expertise. This was a dated spending figure, not a final lifetime cost.
The City said it did not pay the approximately CAD $18.5 million ransom demand. It also reported recovering most systems from available backups and maintaining critical services during the incident.
The insurer denied the claim based on coverage terms. According to the City, an independent legal review supported that denial, and it did not pursue further legal action. The release does not establish a universal rule that one missing control automatically invalidates every cyber policy.
For an SMB, the useful lesson is to examine both recovery capability and the actual insurance contract before an incident occurs.
Build a cost picture beyond the ransom
An attack can create expenses even when no ransom is paid. Work may slow down, staff may need manual processes and technical recovery can compete with normal operations for time and money.
Costs to include in an incident scenario| Cost area | Questions for your business |
|---|---|
| Response | Who investigates, contains the incident and coordinates specialist help? |
| Restoration | What must be rebuilt, recovered or replaced before work can resume? |
| Disruption | Which orders, appointments, invoices or production activities would stop? |
| Communication | Who supports affected customers and coordinates any required notices? |
| Follow-up | What extra work is needed to clear backlogs and improve controls? |
Use your own operating figures. A municipal incident is useful context, but its total is not an estimate of what an attack would cost your company. Avoid adding lost revenue and lost profit together without accounting for overlap.

Understand what insurance can contribute
Insurance Bureau of Canada’s Cyber Savvy guidance explains that cyber insurance can help with costs such as forensic investigation, data restoration, breach notification and legal expenses. Coverage varies by insurer and policy.
Some policies can also cover qualifying business interruption or provide access to response specialists. That support can be valuable, but it does not make every incident expense reimbursable or remove the work of restoring service.
Read the policy with your broker or insurer. Ask what events trigger coverage, what limits apply and what you must do when you discover an incident. A headline coverage limit is only the beginning of the review.
Plan for both recovery and funding. Security controls reduce exposure. A tested response plan helps people act. Insurance may help fund covered losses. Each needs its own owner and evidence.
Ask precise questions before renewal
Use realistic scenarios in your policy review: ransomware that stops operations, a fraudulent supplier payment, or an outage at a critical service provider. Ask the broker to explain which wording applies to each.
- What deductibles, retentions and sublimits apply to each scenario?
- How is business interruption calculated, and is there a waiting period?
- Are social engineering, fraudulent transfers and supplier outages addressed?
- Which exclusions or security conditions could affect the claim?
- When must an incident be reported, and which expenses need prior consent?
- Must you use approved response providers, and how do you reach them?
Keep the answers with the policy and endorsements. These questions identify terms to review; they do not mean every policy contains the same restrictions.
Review the application with the person responsible for IT. If it asks whether a control covers every relevant account or device, verify the scope before answering. Where a gap exists, disclose it and ask how it affects the proposed cover rather than assuming it is immaterial.
Make security controls demonstrable
The Canadian Centre for Cyber Security’s baseline controls include incident planning, updates, strong authentication, security software, backups and employee training. These provide a practical starting point for an SMB security review, not a universal insurance eligibility checklist.
Check that controls work across the intended scope. Review MFA coverage, update status, protected devices and whether backup restoration has been tested. Record exceptions and assign someone to resolve them.
For endpoint protection, confirm who receives alerts and who can act on them. Installing a tool is different from maintaining an effective response process. Our EDR and antivirus comparison explains the distinction.
Keep evidence current: dated configuration reviews, device inventories, restore results and training records. Security documentation should describe the environment you operate, including its limitations.

Test the first day of an incident
Run a short exercise with a plausible scenario: staff cannot access the main business application and an administrator account may be compromised. Ask the team to work through the first decisions without relying on normal email or shared drives.
- Name the incident lead. Identify who coordinates technical response and business decisions.
- Reach the right people. Keep trusted IT, insurer, broker and specialist contacts available offline.
- Preserve useful records. Record times, actions and costs while specialists guide containment and evidence handling.
- Prioritize restoration. Decide which services must return first and how staff can work temporarily.
- Coordinate communication. Assign responsibility for staff, customer and any required external notices.
IBC’s cybersecurity planning guidance also emphasizes response planning and regular restore tests. Use an exercise to find missing access, unclear responsibilities and outdated contact details.
Agree on the insurer notification process in advance so urgent containment and policy reporting can proceed together. Do not wait until an outage to discover who has authority to engage help.
Connect prevention, recovery and coverage
Start with a joint review involving the business owner, IT lead and insurance adviser. Identify the systems that would stop essential work, the controls protecting them and the losses the policy is intended to address.
Then create a short improvement list with owners and dates. Focus on concrete gaps: an account missing MFA, a device without monitoring, a backup that has never been restored or an unclear reporting requirement.
Our backup and disaster recovery guide can help frame recovery priorities. The related article on cyber insurance and resilience explores the broader planning approach.
Talk to us about reviewing your security controls and recovery arrangements. Confirm the scope of Cyber360 services and discuss policy interpretation with your insurer or broker. No security service can promise that every claim will be paid.

Frequently asked questions
01Does cyber insurance prevent an attack?
No. It can provide financial protection and response support for covered events. Preventive controls and operational recovery still need to be planned and maintained.
02Does a missing MFA setting automatically void a policy?
There is no universal answer. Coverage depends on the wording, application representations and circumstances. Discuss the specific issue with your insurer or broker instead of assuming either coverage or denial.
03Can insurance cover downtime?
Some policies provide business interruption cover, subject to their terms. Confirm the triggering event, calculation method, waiting period, limits and any supplier-related provisions.
04Should we use Hamilton’s costs to choose our limit?
No. Use a realistic assessment of your own operations, data, dependencies and recovery needs. Hamilton is a case study, not a pricing or loss forecast for an SMB.
05What should we review first?
Start with critical systems, actual control coverage, tested restoration and incident contacts. Review those findings alongside the policy with your IT lead and insurance adviser.
Know how your business would recover.
Talk to us about reviewing security controls, recovery priorities and the gaps to discuss with your insurance adviser.
Talk it through