Only 9%of Canadian small businesses carry cyber insurance. Here’s what the other 91 are betting on
A number worth staring at
Only nine per cent of small and medium Canadian businesses carry a dedicated cyber policy.
Think about what that means in practical terms. Walk down the main street of any Manitoba town, count the businesses, and roughly one in 10 has financial protection for the risk that most of them now rank among their biggest worries.
Everybody has building insurance. Almost nobody has cyber. That gap is not because business owners do not believe cyber risk is real. It is because of four specific assumptions we hear over and over. Let’s go through them honestly.
We’re too small to be a target
This is the one we hear most, and it is backwards. Smaller businesses are attractive precisely because the defences are thinner and the person approving payments is often the same person doing five other jobs that day.
Most attacks are also not targeted in any meaningful sense. Nobody picked your business out of a lineup. Automated tools find an exposed remote access point or a reused password, and the business on the other end is whoever happened to be there.
Our IT provider handles it
Your IT provider is your defence. Your insurance is your recovery. They are different jobs, and one does not substitute for the other.
We have seen two businesses with the same managed IT provider get hit by the same scam. Good IT did not stop the fraudulent payment in either case, because the fraud did not exploit a technical weakness; it exploited a person doing their job in good faith.
It’s probably expensive
For a typical small business, cyber coverage tends to land well inside the range of other lines you already pay for without thinking twice. Most owners who ask us for a number are surprised by how modest it is relative to the loss it covers.
You can get an estimate yourself in under a minute on our cyber page: two sliders for employee count and revenue, and a coverage limit. No forms until you actually want a firm quote.
We’d figure it out if it happened
This is the assumption that costs the most, because it underestimates how much of the response is not about your systems.
In the first 48 hours after an incident, you may need a forensics team, legal advice on notification obligations, communications to clients and vendors whose data may be exposed, a decision on whether to engage with an extortion demand, and a plan to keep serving customers while everything is down. That is a lot of specialized help to assemble at 11 pm on a Friday with no prior relationship.
A cyber policy hands you that team on day one. For many owners, that response support turns out to be worth as much as the money.
What to actually do this month
Cyber Awareness Month is a good deadline. Here are five things worth doing before the end of October:
- Turn on multi-factor authentication for email and any system that touches money. This is the single highest-value change most businesses can make.
- Write down a payment verification rule. Any change to banking or payment details gets confirmed by phone, to a number you already had on file, never a number in the request.
- Test a backup restore. Having backups and being able to restore from them are not the same thing.
- Check who can still log in. Former staff, old contractors, dormant admin accounts.
- Get a cyber quote, even if you are not ready to buy. Knowing the number changes the conversation.
Four of those five are free. The fifth takes about a minute.
Where Guild fits
We have been insuring Western Canadian families and businesses since 1907. Cyber is newer than most of what we do, but the job is the same one it has always been: help you understand the risk in plain language, and make sure that when something goes wrong, you are not standing there alone holding the bill.
If you want to talk it through, we are here. And if you would rather just see the number first, the estimator on our cyber page will give it to you without a single phone call.
