Skip to main content
Security & Compliance9 min read

Cyber Insurance: What It Covers and What It Wants

September 14, 2026By Ajan Kanagalingam

GreyNoise reported this month that a single threat actor used AI agents to compromise PaperCut print servers at 395 organisations in 48 countries, roughly half of them schools. The vulnerabilities had been patched weeks earlier. Huntress telemetry suggests around 47% of tracked PaperCut installations were still running unpatched versions. Insurers read reports like that too, which is why the cyber insurance application has quietly turned into a controls audit.

What a policy typically pays for

Wordings differ and the wording is what governs, so treat this as a map rather than a promise. Most policies split into costs you incur and claims others bring against you.

SectionTypically includes
Incident responseForensics, containment, a breach coach, PR support
Notification and legalTelling affected people, regulator dealings, credit monitoring
Business interruptionLost income while systems are down, often after a waiting period
Data restorationRebuilding systems and recovering data
ExtortionNegotiation support and, subject to conditions, payment
Third-party liabilityClaims from customers whose data was exposed

The section businesses underestimate is the first one. Most of the value in a claim arrives in the opening 48 hours, in the form of people who have handled this before telling you what to do. A small business without that support tends to make expensive decisions quickly, and the response bill often exceeds the ransom.

The controls that decide your premium

Underwriting for small business cyber has moved from revenue-and-sector to evidence-of-controls. The recurring questions are worth knowing before the form arrives.

Multi-factor authentication. On email and remote access at minimum, enforced rather than available. This is the single most common gate, and a no here can end the conversation with some insurers.

Patching cadence. How quickly you apply security updates, particularly to anything internet-facing. The PaperCut campaign is the illustration: patch available August 28, mass exploitation of the unpatched through September. The discipline behind answering this honestly is in vulnerability management without a security team.

Backups that are offline or immutable, and tested. Insurers ask when you last performed a restore, not whether backups run. An untested backup is a hope.

Endpoint detection coverage. What proportion of your machines are covered, including the laptop the bookkeeper works from at home.

Privileged account management. Who holds domain admin, and whether those accounts are separate from daily-use ones. In the PaperCut campaign the attacker reached domain admin at only 12 of 395 organisations, which is the difference between a bad week and a catastrophic one.

An incident response plan. Increasingly asked for, and increasingly asked to be evidenced rather than asserted.

Answer the questionnaire honestly

Coverage disputes usually turn on two things: whether your application described your controls accurately, and whether the policy carries a condition requiring you to maintain them.

Claiming a 30-day patching cadence you do not follow creates a worse problem than the delay itself. The same applies to MFA that is enabled for most staff, backups that run but have never been restored, and endpoint coverage that omits three machines nobody thought about. Answer as the business actually operates, take the rate that comes with it, and fix the gaps you want to fix on your own timeline. None of this is legal or insurance advice, and the wording of your specific policy governs.

Where AI is entering the conversation

Two directions, and both are early enough that answers vary by insurer.

On the application. Questions about which AI tools staff use, whether company or customer data goes into them, and whether you have a written AI policy. The tool inventory that supports an honest answer is the same one described in an AI governance framework for a small business.

On the coverage. A cyber policy is generally built around unauthorised access and data breach. An AI system that sends a wrong quote, gives poor advice, or makes a decision that harms someone sits closer to professional liability or errors and omissions. Some insurers have started adding AI-specific wording, both to extend and to exclude. We looked at that gap in does insurance cover AI mistakes.

The question worth putting to your broker in writing is which of your existing policies would respond to an AI error, and getting the answer before an incident rather than during one.

Insurance is not a control

A policy pays for consequences. It does not prevent the incident, and it does not restore the customer relationship damaged by the notification letter. Businesses occasionally treat coverage as a substitute for the controls the insurer asked about, which is the one reading of this that leaves you worse off, since the controls are what stop the claim from being needed.

It also does not guarantee a clean outcome even when you did the work. Well-run organisations get breached through a supplier or a zero-day, which we wrote about in you did everything right and got breached anyway. That is precisely the case insurance exists for, and it is a narrower case than most buyers assume.

Before your next renewal

Pull last year's application and read your own answers. Check whether each is still true, and whether it was true when you wrote it. Then pick the one control you cannot honestly claim and close that gap, because it is the same gap a client questionnaire will ask about next quarter.

Frequently Asked Questions

What does cyber insurance actually cover?

Policies vary and the wording is what matters, but most cover a similar spread: incident response and forensics, legal and regulatory costs, notifying affected individuals, credit monitoring, business interruption while systems are down, data restoration, and often extortion payments and negotiation support. Third-party liability for claims brought by customers is usually a separate section from first-party costs you incur yourself. Read which sections you actually bought rather than assuming a policy is one thing.

What do insurers ask for before they will quote?

Application questionnaires have become control audits. Expect questions on multi-factor authentication for email and remote access, how quickly you apply security patches, whether backups are offline or immutable and when you last tested a restore, endpoint detection coverage, whether you have an incident response plan, and how privileged accounts are managed. Increasingly there are questions about AI tools, including which ones staff use and whether company data goes into them.

Will cyber insurance pay if we did not patch?

That depends on the wording and on what you told the insurer. Coverage disputes typically turn on two things: whether your application accurately described your controls, and whether the policy contains a condition requiring you to maintain them. Describing a 30-day patching cadence you do not follow is the problem, more than the delay itself. Answer the questionnaire as your business actually operates, even where the honest answer costs you a better rate.

Does cyber insurance cover mistakes made by AI?

Often unclearly, which is the current state of the market. A cyber policy is generally built around unauthorised access and data breach, so an AI system that sends a wrong quote, gives bad advice or makes a discriminatory decision may fall closer to professional liability or errors and omissions cover. Some insurers have begun adding AI-specific wording, in both directions. Ask your broker in writing which of your policies would respond to an AI error, before you need the answer.

How much does cyber insurance cost for a small business in Canada?

Premiums vary widely with revenue, sector, data held and the controls you can evidence, so any single figure is misleading. The more useful framing is that controls move the number a lot. Businesses that can show enforced MFA, tested offline backups, endpoint detection and a documented patching cadence get quoted differently from those that cannot, and in some cases get quoted at all where others are declined. Talk to a broker who places cyber regularly rather than adding it to an existing package unexamined.

Close the gap before the renewal, not after

We map your real controls against what insurers and client questionnaires now ask for, including the AI questions that have started appearing on both.

Related Articles

Security & Compliance

AI Is Now Your Cyber-Defender, Too

July 20, 2026Read more →
Security & Compliance

Five Eyes Warns AI Cyber Threats Are Months Away: What to Do

June 23, 2026Read more →
Security & Compliance

AI Agents Mass-Exploited a Patch Nobody Applied

September 14, 2026Read more →
AK
Ajan Kanagalingam
Founder & ChatGPT Consultant, ChatGPT.ca

Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.