
Cyber Insurance
Sutherland Insurance is a fifth-generation independent brokerage in Guelph, Ontario, founded in 1870, that places cyber insurance for businesses across Canada. Cyber insurance covers breach response, ransomware and extortion, business interruption from a network outage, and privacy liability to affected individuals. Sutherland Insurance places cyber business across the Canadian markets it represents.
Key takeaways
- Cyber insurance is not required by Canadian law, and it is increasingly required by client contracts, lenders and supply-chain agreements.
- Under PIPEDA, a Canadian organization must report a breach of security safeguards posing a real risk of significant harm to the Privacy Commissioner of Canada and notify affected individuals.
- PIPEDA requires organizations to keep records of every breach of security safeguards for 24 months, whether or not the breach was reportable.
- A cyber policy has a first-party side covering the organization's own costs and a third-party side covering claims brought against it.
- Who it is for
- Ontario businesses holding personal data, taking payments, or depending on networked systems
- Legally required in Canada
- No, not required by federal or provincial statute
- Commonly required by
- Client contracts, lenders, supply-chain agreements and professional bodies
- Coverage trigger
- Commonly claims-made, with a retroactive date governing prior acts; some insurers write on an occurrence basis
- Federal breach-reporting duty
- Report to the Privacy Commissioner of Canada where there is a real risk of significant harm
- Breach record-keeping duty
- 24 months, under PIPEDA, for every breach of security safeguards
- Markets compared
- The Canadian cyber markets Sutherland Insurance represents, as an independent brokerage
What is cyber insurance?
Cyber insurance is a policy covering the financial consequences of a data breach, a ransomware attack or a network failure. It has two halves: first-party coverage for the organization's own costs, including forensics, notification, data restoration and lost income, and third-party coverage for claims brought by customers, partners and regulators. The coverage trigger varies by insurer: cyber is commonly written on a claims-made basis, and some insurers write it on an occurrence basis.
The first-party half is where most Canadian cyber claims land. An incident produces an immediate bill for forensic investigators, legal counsel, breach notification, credit monitoring and system restoration, long before anyone sues. Most Canadian policies attach a 24-hour incident response line, and using it is commonly a condition of the coverage.
What can an Ontario cyber insurance policy cover?
What a policy can cover
- Breach response costs including forensic investigation, legal counsel, notification of affected individuals and credit monitoring
- Ransomware and cyber extortion, including negotiation, the ransom payment where permitted by law, and system restoration
- Business interruption and extra expense arising from a network outage, and dependent interruption from a supplier or hosting provider
- Data restoration, including the cost of recreating or repairing corrupted or destroyed digital assets
- Privacy and network security liability for claims brought by customers, employees or business partners
- Regulatory defence and, where insurable, fines and penalties, along with payment card industry assessments
Commonly excluded under standard Ontario cyber insurance wordings
- Loss arising from a known vulnerability or a prior incident disclosed before the retroactive date on the policy
- The cost of upgrading, patching or improving systems beyond restoring them to their pre-incident state
- Bodily injury and physical property damage, which commercial general liability and property policies address
- Loss caused by a failure to maintain the security controls the application warranted, such as multi-factor authentication
- Fines and penalties that are uninsurable at law in the applicable jurisdiction
- Loss of intellectual property value, contract disputes, and ordinary business loss unconnected to a covered incident
Exclusions vary by insurer and by policy form; the issued policy governs.
How much does cyber insurance cost in Ontario?
The factors that move a Canadian cyber insurance premium, in approximate order of influence, and why insurers look at each one.
| Rating factor | Why |
|---|---|
| Volume and sensitivity of records held | Notification and liability costs scale with the number of individuals affected. |
| Industry sector | Regulated data and high-value targets attract more attacks. |
| Annual revenue | Revenue proxies both the data footprint and the business interruption exposure. |
| Multi-factor authentication on remote access and email | Most Canadian markets now decline or surcharge risks without it. |
| Backup regime, including offline and tested backups | Recoverable backups are the single largest determinant of ransomware severity. |
| Endpoint detection and response in place | Monitored endpoints shorten dwell time and reduce loss. |
| Limits and sub-limits selected | Ransomware and business interruption sub-limits set the real exposure. |
| Prior cyber incidents and claims | Previously breached organizations are re-targeted at higher rates. |
What situations does cyber insurance commonly address in Canada?
Cyber policies are arranged for a wide range of business circumstances across Ontario and Canada, and the coverage available differs in each. The situations below are common among Sutherland Insurance clients in Guelph and across the province, and each one changes which markets will write the risk.
- A Guelph professional firm whose staff email is compromised and client data is exposed.
- A manufacturer whose production systems are encrypted by ransomware and whose lines stop for a week.
- A retailer whose payment card environment is breached and who faces a card brand assessment.
- A business whose cloud hosting provider suffers a multi-day outage that halts its own operations.
- A finance department that wires funds after receiving a spoofed supplier invoice.
- A health-sector employer required to report a privacy breach to its provincial regulator.
How Do I Get Business Insurance Through Sutherland Insurance?
Getting insurance through Sutherland Insurance is simple. You can request a quote online or call 519-822-0160 to speak with a licensed broker. We take the time to understand your business, identify your exposures, and find coverage options that fit your needs.
Our Process:
- Request a Quote. Complete an online quote request or call our office to speak with a licensed insurance broker.
- Tell Us About Your Business. Your broker will gather information about your operations, property, revenues, employees, vehicles, contracts, and any other areas that may require coverage.
- Review Your Risks and Coverage Needs. We assess your business exposures and insurance requirements to determine the appropriate coverage limits and options.
- Market Your Account. Sutherland Insurance compares the available commercial markets to help find the best combination of coverage, service, and price.
- Present Your Options. Your broker will review the available quotes and provide recommendations based on your specific needs and goals.
- Bind Coverage and Provide Documentation. Once you select coverage, we arrange the policy and provide any required documentation, including certificates of insurance for clients, landlords, lenders, or other third parties.
What makes Sutherland Insurance different from a direct insurer?
When a claim happens, Sutherland Insurance acts for the client with the insurer, and an in-house claims representative is available on any claim. Sutherland Insurance is an independent brokerage and compares the markets it holds contracts with rather than selling one company’s product. A person answers the phone at Sutherland Insurance, 519-822-0160, Monday to Friday, 8:30 a.m. to 5:00 p.m.

Frequently asked questions
What does cyber insurance cover for a small business?
Cyber insurance covers breach response costs including forensics, legal counsel and notification; ransomware and extortion, including restoration; business interruption from a network outage; data restoration; and liability to customers, partners and regulators. First-party costs arrive immediately after an incident, and third-party claims arrive later. Coverage varies by insurer, and the issued policy governs.
Does business insurance cover a ransomware attack?
A commercial property or general liability policy does not respond to ransomware. Property policies require physical damage, and liability policies respond to bodily injury and property damage. Ransomware costs (negotiation, payment where lawful, restoration and the income lost while systems are down) sit on a cyber policy, commonly within a specific ransomware sub-limit.
Does a Canadian business have to report a data breach?
Under PIPEDA, an organization must report a breach of security safeguards to the Privacy Commissioner of Canada where the breach creates a real risk of significant harm to an individual, and must notify the affected individuals. Organizations must also keep records of every breach of security safeguards for 24 months, whether reportable or not.
How much does cyber insurance cost in Canada?
Cyber premiums are driven by the volume and sensitivity of records held, the industry sector, annual revenue, the limits selected, and the security controls in place. Multi-factor authentication, tested offline backups and endpoint monitoring now govern both price and availability. Sutherland Insurance markets each risk across the cyber markets it represents to compare terms.
What is the difference between first-party and third-party cyber coverage?
First-party coverage pays the insured organization's own costs after an incident: forensics, notification, credit monitoring, data restoration, extortion payments and lost income. Third-party coverage pays claims brought against the organization by customers, employees, business partners and regulators. Most Canadian cyber policies include both, with separate limits and sub-limits for each.
Does cyber insurance require multi-factor authentication?
Most Canadian cyber markets now require multi-factor authentication on remote access, administrative accounts and email before they will quote, and the application forms a warranty. Where a control stated on the application was not in place at the time of a loss, the insurer can dispute the claim. Requirements differ by insurer and by wording.
Which markets does Sutherland Insurance place cyber insurance across?
Sutherland Insurance places commercial business, including cyber, across the Canadian markets it represents, together with multiple managing general agents and affiliates across Canada. It is an independent brokerage licensed by the Registered Insurance Brokers of Ontario, and has brokered insurance in Guelph since 1870. It is not tied to any single insurer.
Get your cyber insurance quote
A licensed Sutherland Insurance broker compares the available markets on every quote request.
Get your cyber insurance quote Call 519-822-0160
A real person answers, Monday to Friday, 8:30 a.m. to 5:00 p.m.
