(204) 694-6787
Laptop screen with a phishing email warning open.
Commercial8 min read

What cyber insurance actually covers (and what it does not)

A plain-English breakdown of the two halves of a cyber policy, the realistic claims to expect, and the most common misconceptions among small Manitoba businesses.

G
Galaxy Insurance Brokers
Galaxy Insurance Brokers

Cyber insurance was a boutique product five years ago. Today it is on most of our small-business renewals — sometimes because the client asked, more often because their bank, vendor or commercial landlord asked. Here is what a 2026 cyber policy actually does, in plain English.

$2.6M
Average Canadian small-business breach cost (2025, IBM)
60%
Share of cyber claims that include a ransomware demand
$1k–$3k
Typical annual premium for a small Manitoba business

The two halves of a cyber policy

Every modern cyber policy has two distinct coverage parts. First-party coverage pays for damage to your own business — your data, your downtime, your ransom payment. Third-party coverage pays for damage to other people — clients whose information was exposed, vendors who suffered losses through your compromised systems, regulators who issue fines.

A cheap policy covers only one or has tight sub-limits on both. A good policy covers both at meaningful limits. Read the schedule of coverages on every quote and compare them side by side.

First-party: what happens to you

  • Forensic investigation — paying experts to figure out how the breach happened, what data was touched, and whether you have ongoing exposure.
  • Ransomware payments— increasingly negotiated and paid by the insurer’s panel of specialists, not by you directly.
  • Business interruption — the income you lost while your systems were down, plus the cost of getting back up.
  • Data restoration — rebuilding databases and files from backups, or recreating them if backups are also compromised.
  • Notification and credit monitoring — the legal requirement to tell affected individuals and provide monitoring, often more expensive than people expect.
A laptop screen displaying a system warning, taken in a dim office.
A typical small-business breach pattern: a phishing email, a clicked link, and a slow realization that something is wrong.

Third-party: what you owe others

  • Privacy liability — claims and lawsuits from people whose personal data was exposed.
  • Regulatory defence and fines — the cost of responding to a Privacy Commissioner inquiry, plus the fine if one is assessed. (Where insurable by law.)
  • Network security liability — claims from clients, vendors or partners whose own systems suffered because of yours.
  • Media liability — defamation and intellectual property claims arising from your website, social media, or marketing content.

What real claims look like

The Hollywood version is a hacker in a hoodie. The Manitoba version is a bookkeeper clicking a fake DHL link on a Tuesday afternoon.
Galaxy Insurance Brokers

Three patterns we see again and again on small Manitoba files:

The phishing wire transfer

A staff member receives an email that looks like it comes from the owner, asking to transfer money to a new vendor. The transfer goes through. Days later, the real owner asks why. The money is gone.

This is called social engineering fraud, and on many cyber policies it is a separately scheduled coverage with its own sub-limit — often much smaller than the headline policy limit. Confirm you have it, and at what number.

The ransomware demand

A weekend warehouse fire would be no different from a Monday morning ransomware demand for a manufacturer — both freeze the business. Modern policies coordinate the response: forensic team, ransom negotiator, public relations advisor, business-interruption assessment.

The lost laptop

Far less dramatic but more frequent. A staff laptop is stolen from a car. It contained an unencrypted client list. You are now legally required to notify hundreds of clients. Even with no monetary loss, the notification, monitoring and reputational costs can run five figures. Cyber pays for that response.

Common exclusions to watch for

ExclusionWhat it means
Prior known incidentsAnything you already knew about when you bought the policy is excluded.
Failure to maintain securityIf you ignored a vendor patch for months, the carrier may deny.
War and state-sponsored attacksAn evolving area — read the wording carefully.
Bodily injury / property damageCyber covers data and downtime, not physical harm — your CGL covers the physical side.
Acts by insidersSome policies exclude employee-caused losses; ask for the ‘rogue employee’ coverage.

How to qualify in 2026

Cyber insurance underwriting got noticeably stricter between 2022 and 2025 as claim frequency rose. To get a quote today, most carriers want to see:

  • Multi-factor authentication on email and remote access — basically mandatory.
  • Endpoint protection on every machine, ideally a named brand (Defender for Business, CrowdStrike, SentinelOne).
  • Daily backups that are kept offline or immutable, and that you have actually tested.
  • Documented security awareness training for staff (one hour a year is typically enough).
  • A patch management process — not perfect, but a process.

None of this is exotic. If your business does not have these basics in place, get them done — they improve security regardless, and they unlock affordable cyber pricing.

Back to all articles
Written by Galaxy Insurance Brokers · Galaxy Insurance Brokers

Ready to talk to a real Manitoba broker?

Three offices, three languages, one conversation away. We respond within one business day — usually sooner.

Talk to a broker