Cyber Insurance and Remote Work: Risks & Exclusions to Cover (2026)

Reviewed by IT Cares certified technicians · Updated July 2026

Cyber insurance and remote work risks — home network, BYOD, and VPN security illustration for Canadian businesses
Remote work moved a meaningful share of business risk outside the office network — cyber insurance policies, and the exclusions inside them, have been catching up ever since.
🏠
Not sure if your remote work setup could jeopardize a future cyber insurance claim? Our certified technicians review your actual remote access controls and close the gaps insurers look for.
Get a Free Assessment →

Cyber insurance was built and priced around a world where business systems mostly lived behind an office firewall — remote and hybrid work quietly moved a huge share of that risk into home networks, personal devices, and consumer software the insurer never underwrote for in the first place. Policies and underwriting questionnaires have been playing catch-up ever since, and the gap between "what a policy assumed about your work environment" and "how your team actually works" is exactly where claim disputes and coverage exclusions tend to surface.

This isn't a reason to panic, and it isn't a reason to assume you're uninsurable or unprotected. It is a reason to understand specifically which remote-work realities insurers now scrutinize, which common exclusion patterns catch businesses off guard, and what concrete, affordable steps close the gap — which is exactly what this guide covers.

It's worth being upfront about scope, too: this guide focuses specifically on the remote-work-related dimension of cyber insurance, not the full policy landscape. If you're starting from scratch on understanding what cyber insurance covers at all — first-party costs like business interruption and forensic investigation versus third-party liability, deductibles, sub-limits, and how Canadian insurers typically structure coverage — our broader cyber insurance guide for small business is the better starting point, with this article picking up specifically where remote and hybrid work introduces its own distinct considerations on top of that foundation.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians who work directly with Canadian small and mid-sized businesses on the IT security side of cyber insurance readiness — MFA rollouts, VPN setup, BYOD policy, endpoint protection. IT Cares is an IT company, not an insurance broker, and nothing here is insurance or legal advice; for coverage interpretation, always consult your broker or the policy wording directly. What we can offer is an accurate picture of the security controls that affect both your real risk and your insurer's view of it.

How Remote Work Expanded the Attack Surface Insurers Underwrite Against

"Attack surface" is insurance-and-security shorthand for everything an attacker could realistically target to get into your systems. For decades, the practical attack surface of a typical small business was reasonably contained: office computers, an office network behind a business firewall, maybe a handful of laptops that occasionally left the building. Insurers built underwriting models and policy language around roughly that picture.

Remote and hybrid work changed the shape of that surface substantially, in ways that are easy to underestimate because nothing about the change feels dramatic day to day:

None of this means remote work is inherently reckless — it means the risk model insurers use has to account for a genuinely different environment than the one their older underwriting assumptions were built around, and it explains why underwriting questionnaires have expanded so much in this specific direction over the past several years.

It's also worth being specific about why each of these factors compounds the others rather than existing in isolation. A weak home router isn't dangerous purely on its own — it's dangerous because it sits between an attacker and a device that also holds an active session into business email, file storage, and possibly financial systems. A personal device mixing work and personal use isn't risky purely because of the mixing — it's risky because a phishing email opened during personal browsing can compromise the same device an employee uses minutes later to approve a wire transfer or access a client record. Insurers who have paid out real claims have seen this compounding effect play out repeatedly, which is exactly why so much current underwriting language focuses on the endpoints and access paths themselves rather than only on the traditional office network perimeter.

📊 IT Cares field note: A recurring pattern we see: a business went remote almost overnight a few years back, kept operating perfectly fine, and never circled back to formally update its security posture or insurance conversation around that shift. The systems work, the team is productive — but nobody ever asked "does our cyber policy actually reflect how we work now?" until a renewal questionnaire or, worse, a claim forced the question.

Hybrid Work: A Middle Ground With Its Own Distinct Risks

Fully remote and fully in-office are the two easiest scenarios to reason about; hybrid work — where the same employee splits time between a home office and a business location, often carrying the same laptop between both — introduces a distinct wrinkle that's easy to overlook. A hybrid employee's device routinely crosses between two very different security environments in the same week, sometimes the same day: a business network with proper firewalls, monitoring, and segmentation, and a home network with none of those protections. If that device picks up a compromise while connected at home, it can carry that compromise directly into the office network on the next commute, effectively bypassing the office's perimeter defences entirely since the device is, by that point, already "inside."

This is one of the more counterintuitive risk patterns in modern cyber insurance underwriting: a hybrid workforce isn't automatically safer than a fully remote one just because employees spend some time in a protected office environment. In some respects, the constant crossing between environments creates a harder detection problem than either extreme, since security tooling has to account for a device's risk profile changing based on where it connected most recently rather than assuming a stable, consistent environment. Endpoint protection that travels with the device — rather than protection tied to the network it happens to be on — matters more, not less, in a hybrid model, and it's an area worth discussing directly with whoever manages your IT if your team splits time between locations.

Underwriting Changes: What Insurers Actually Ask About Remote Work Today

Cyber insurance underwriting questionnaires have changed substantially over the past several renewal cycles, and the remote-work-specific questions that now appear are a direct reflection of where claims have actually originated. It's worth understanding the pattern of what's being asked, because the questions themselves are a fairly reliable guide to what controls matter most in an insurer's eyes.

Answering these questions accurately — and, more importantly, having the underlying controls actually be true, not just aspirationally true — is where the real work happens. An application answered optimistically ("yes, we require MFA") that doesn't match reality ("MFA is available but half the team never turned it on") is arguably worse than answering honestly in the first place, since it sets up a misrepresentation problem that surfaces at exactly the worst possible moment: during a claim.

Want your remote access setup checked before renewal season?

Our certified technicians review MFA, VPN, and BYOD controls and give you a right-sized action plan — from $119.99.

Personal VPN vs Business VPN: A Distinction That Actually Matters

One of the most common and most misunderstood gaps involves VPN usage. Many employees, especially those already privacy-conscious, use a personal VPN app — the kind marketed for streaming access, general privacy, or public Wi-Fi protection — to connect to business systems remotely, assuming this satisfies "secure remote access" the same way a proper business VPN would. It usually doesn't, and the difference matters more than it might seem.

A consumer VPN app typically routes and encrypts general internet traffic through a third-party provider's servers, with no visibility for the business into who connected, when, from where, or to what. It has no integration with company-managed multi-factor authentication, no centralized policy enforcement, and no logging the business can review during an incident investigation. A business VPN, by contrast, is specifically configured to grant access to business systems, integrates with MFA and identity management, logs connection activity, and can be centrally managed and revoked — for instance, immediately cutting off access for a departing employee.

From an insurance standpoint, if a policy requires or represents that the business maintains "secure remote access," an insurer investigating a claim may reasonably ask what that meant in practice. "Employees used whatever personal VPN app they already had installed" is a materially weaker answer than "the business requires connection through a managed VPN with MFA enforced," and that difference can become the exact fault line a disputed claim turns on.

Common Cyber Insurance Exclusion Patterns Tied to Remote Work

Policy wording varies significantly by insurer, and nothing below should be read as a direct quote from any specific carrier's policy — but several general exclusion and coverage-condition patterns show up repeatedly across the industry and are worth understanding in principle before you're relying on a policy during an actual incident. It's worth stressing that most disputes over these patterns aren't really about whether coverage exists in principle; they're about whether the specific facts of an incident line up with conditions the business may not have realized applied to it until an adjuster started asking pointed questions about how, exactly, a particular employee connected to a particular system on a particular day.

Remote work risk factorWhy insurers careWhat to do about it
BYOD (personal devices)Business has less control/visibility over device security postureWritten BYOD policy with minimum requirements: screen lock, encryption, updated OS, endpoint protection
Personal VPN vs business VPNConsumer VPNs lack MFA integration, logging, and centralized controlMandate a business-grade VPN for all access to business systems
Home network securityHome routers are rarely hardened or patched compared to office firewallsProvide employees baseline guidance: change default admin passwords, keep firmware updated
Shadow IT / unapproved cloud toolsData moved outside sanctioned systems is harder to account for during an incidentIdentify informal tool usage and provide approved, sanctioned alternatives
Lack of MFA on remote accessOne of the most common factors in real-world remote-access breaches and claim disputesEnforce MFA on every remote login, not just make it available
Physical device securityHome offices generally have weaker physical security than a locked business premisesRequire device encryption so a lost/stolen device doesn't expose data even if physically compromised

The specific exclusion and condition language patterns worth understanding include:

Closing Remote Work Insurance Gaps

1

Require MFA on all remote access

Multi-factor authentication on every remote login is close to a universal baseline expectation in current cyber insurance underwriting. If it's "available but optional" today, close that gap first — it's the single most common factor in both real breaches and disputed claims.

2

Mandate a business-grade VPN

Replace ad-hoc personal VPN apps used for business access with a proper business VPN offering access controls, logging, and MFA integration — and communicate clearly to staff why the switch matters, since many won't realize the distinction otherwise.

3

Establish a BYOD policy with minimum security requirements

Personal devices accessing business systems should meet baseline requirements — screen lock, encryption, an up-to-date operating system, and endpoint protection — documented in a short, plain-language written policy employees actually read.

4

Address home network security

Provide simple guidance for employees regularly accessing business systems remotely: change the router's default admin password, keep firmware updated, and use a separate guest network for non-work devices in the household.

5

Read your policy's remote-work and "controlled environment" exclusions carefully

Before renewing or purchasing a policy, have someone — ideally with your broker's help — actually read the exclusions section for language tied to reasonable security measures, controlled environments, or specific technical requirements, and ask direct questions about how remote work is treated.

6

Document your remote access controls for your insurer

Keep dated records of MFA enforcement, VPN deployment, and BYOD policy rollout, so you can demonstrate compliance with policy requirements clearly and quickly if a claim is ever disputed.

7

Review shadow IT and unapproved cloud tool usage

Identify informal tools employees have adopted to fill genuine workflow gaps, and provide sanctioned, monitored alternatives rather than simply banning the workaround without addressing the underlying need.

Working through this list doesn't need to happen all at once, and it doesn't need a dedicated security team to execute — most small businesses can realistically close the first four or five items within a month using existing tools they already pay for (MFA, in particular, is almost always already included in a Microsoft 365 or Google Workspace subscription and simply needs to be turned on and enforced, not purchased separately). The remaining items, particularly the BYOD policy and the exclusions review, benefit from outside help to get right the first time, but none of them require an enterprise budget to complete properly.

A ☐ checklist to review before your next renewal or application:

Questions Worth Asking Your Broker Specifically About Remote Work

A broker relationship works best when the questions are specific rather than general. Beyond the standard "what does this policy cover," the following remote-work-specific questions tend to surface the gaps that matter most before you're relying on the answer during a real incident:

Brokers who work regularly with cyber insurance tend to have a good practical sense of how a given insurer has handled remote-work-related claims in the past, even where the policy wording itself is ambiguous — and that institutional knowledge is often more useful in practice than the wording alone, since it reflects how the insurer actually behaves rather than how the document could theoretically be read.

Real-World-Style Canadian Case Studies

Case study: Montreal marketing agency, a partially denied claim

A 14-person Montreal marketing agency had cyber insurance with a $2 million limit and paid roughly $3,800 CAD annually in premiums. An employee's home network was compromised through a router with an unchanged default admin password, and the attacker pivoted to the employee's laptop, which was used to access the agency's project management and billing systems through a personal VPN app rather than the agency's actual (rarely enforced) business VPN. The attacker spent nearly three weeks quietly monitoring email traffic before attempting a fraudulent wire transfer request impersonating the agency's owner, which an alert bookkeeper caught before funds moved — but the monitoring period itself, plus the subsequent investigation and client notifications, generated real cost. When the claim was filed, the insurer's investigation found MFA had been "available" on the billing system but was not actually required for that employee's account, and that remote access hadn't consistently gone through the business VPN as the application had represented. The claim wasn't denied outright, but the insurer applied a reduced payout citing the security-measures condition, leaving the agency to cover roughly $22,000 CAD of the total $31,000 CAD incident cost out of pocket. The agency has since enforced MFA account-wide and disabled personal VPN access to business systems entirely, and reports the renewal conversation the following year was noticeably smoother once those controls were documented.

Case study: Toronto accounting firm, a premium reduction

A 22-person Toronto accounting firm renewing its cyber policy worked with an IT provider ahead of renewal to formally document MFA enforcement across all remote access, deploy a business VPN replacing informal personal VPN use, and roll out a written BYOD policy covering the roughly one-third of staff who used personal laptops during tax season crunch periods. The remediation cost approximately $6,200 CAD in IT services and licensing, spread over about six weeks of implementation ahead of the renewal date. At renewal, the improved, well-documented security posture — supported by a short written summary the IT provider prepared specifically for the broker conversation — contributed to a premium reduction of roughly 18%, saving the firm about $2,100 CAD annually going forward, meaning the one-time investment paid for itself within about three years purely on premium savings, before accounting for the much larger value of reduced actual breach risk during the firm's busiest and most sensitive season of the year.

Case study: Ottawa consulting firm, a BYOD incident

A small Ottawa consulting firm allowed staff to use personal laptops for client work with no written BYOD policy, largely because the firm had grown quickly from three to twelve people without ever formalizing IT policy along the way. An employee's personal laptop, shared with family members, was infected with malware through an unrelated download unrelated to work at all, and the malware later facilitated unauthorized access to a client project folder synced through a personal cloud storage account the employee had been using informally to move files between home and office because the firm's own file system felt clunky over a slow home connection. The resulting incident cost approximately $9,500 CAD in forensic investigation and client notification, plus an uncomfortable conversation with the affected client about how their project files had ended up on an unmanaged personal cloud account in the first place. While the claim was ultimately paid, the insurer flagged the absence of any BYOD or acceptable-use policy as a factor likely to affect terms at the next renewal. The firm has since implemented a written BYOD policy and moved file sharing entirely onto its sanctioned business platform, with a faster, better-configured sync client that removed the original workaround's appeal.

Budget: Cost of Closing These Gaps (CAD)

ItemTypical cost range (CAD)
Business VPN licensing (per user, annual)$50 – $150 / user / year
MFA rollout (often included in existing Microsoft 365 / Google Workspace plans)$0 – $500 one-time setup effort
Endpoint protection for BYOD and remote devices (per device, annual)$40 – $120 / device / year
Written BYOD policy development$500 – $1,500 one-time
Full remote-access security review before renewal$1,500 – $4,000 for a small business
Cost of a partially denied claim due to unaddressed gaps (illustrative, as above)$15,000 – $30,000+ out of pocket

The comparison speaks for itself: the full set of remote-work security improvements for a small business typically costs a few thousand dollars, against a realistic downside of tens of thousands in an inadequately covered claim — before even factoring in the premium reductions that often follow a documented security improvement. It's also worth noting that most of these costs aren't one-time in the sense of "pay once and forget it" — VPN licensing and endpoint protection are ongoing subscription costs that scale with headcount, which is actually a point in their favour from a budgeting standpoint: they're predictable, recurring line items rather than the unpredictable, potentially much larger cost of an inadequately covered incident landing at an unplanned moment.

Canadian Resources

None of these resources replace a conversation with your specific insurer or broker about your specific policy, but they're useful, credible references when building an internal business case for the security investments this guide recommends — particularly when explaining to ownership or partners why a few thousand dollars in VPN licensing and MFA rollout is worth prioritizing before the next renewal cycle rather than after an incident forces the question.

For the broader picture of what cyber insurance actually covers for a Canadian small business, see our cyber insurance guide for small business, our guide on lowering your premium through IT security, and our explainer on first-party vs third-party coverage, all of which connect directly to the remote-work considerations covered here.

Why This Matters a Little Differently in Canada

A few genuinely Canadian factors make the remote-work insurance picture slightly distinct from a generic "remote work risk" discussion. First, geographic dispersion: Canadian small businesses are more likely than average to have staff spread across multiple provinces, sometimes working from smaller communities with less robust local internet infrastructure and, in some cases, more limited access to IT support to help configure things like a proper business VPN correctly the first time. Second, seasonal remote-work spikes: winter weather events regularly push otherwise office-based Canadian teams into unplanned remote work for days at a time, often without the lead time a planned remote-work policy would assume — meaning the controls discussed in this guide need to work not just for a stable, predictable remote workforce, but for a sudden, weather-driven shift too. Third, the interplay between provincial privacy law and insurance underwriting is a distinctly Canadian wrinkle: a Quebec business's Law 25 compliance posture and a business's cyber insurance readiness increasingly overlap, since insurers are paying closer attention to documented privacy and security practices together rather than treating them as separate conversations.

None of this changes the fundamental guidance in this article, but it does mean a Canadian small business planning its remote-work security investment should build in a bit more resilience than a bare-minimum checklist might suggest — for instance, making sure MFA and VPN access work reliably over the kind of variable rural or small-town internet connections some employees may be using, not just over a fast urban home connection.

Want your remote access setup reviewed before it becomes a claims problem?

IT Cares' security audits look at your actual remote access controls — MFA enforcement, VPN usage, BYOD policy, home network guidance — and translate them into a concrete action plan. If ongoing management makes sense for your business, our managed IT services can maintain these controls over time rather than leaving them to drift as your team changes.

Frequently Asked Questions

Does my cyber insurance cover a breach that starts on an employee's home network?
Generally yes, in principle — most cyber policies don't exclude an incident simply because it originated on a home network rather than an office network. However, coverage can become contested if the policy required specific security measures (like MFA on remote access) that weren't actually in place, or if the insurer argues the business failed to maintain "reasonable security measures" more broadly. The home network itself usually isn't the issue; what controls were or weren't in place around it typically is.
Are personal devices (BYOD) covered by cyber insurance?
Most cyber policies cover an incident regardless of which device it originated on, but many include conditions around "reasonable security measures" that can apply to BYOD just as much as company-owned equipment. An unencrypted personal laptop with no password, used to access sensitive business systems, is a more likely point of dispute during a claim than a properly configured personal device meeting a written BYOD policy's minimum requirements.
What is a "controlled environment" exclusion?
This is a general term for policy language that ties certain coverage or conditions to data or systems being maintained in an environment the business controls and secures — historically assumed to mean an office network with business-grade equipment. Remote work complicates this because a home office is a materially different environment, and some policy wording has not been fully updated to reflect that reality, creating ambiguity that can surface during a claim dispute.
Does using a personal VPN app instead of a business VPN void coverage?
It depends on the specific policy wording, but it's a real risk worth taking seriously. A personal, consumer-oriented VPN app (typically marketed for privacy or geo-unblocking) generally lacks the access logging, MFA integration, and centralized control a business VPN provides. If a policy requires "secure remote access" as a condition and an insurer argues a consumer VPN doesn't meet that bar, it can become a point of dispute during a claim — even though the policy may not use the word "VPN" explicitly.
What happens if MFA wasn't enabled and a claim comes from a remote-access breach?
This is one of the most common and consequential claim disputes in current cyber insurance. If an application or policy specifically represented or required that MFA was enabled on remote access, and it turns out it wasn't, an insurer may argue misrepresentation (potentially voiding the policy) or that a specific security requirement condition wasn't met (potentially denying that claim while keeping the policy in force). Either outcome is costly, which is why confirming MFA is genuinely and fully enforced, not just "available," matters enormously before a claim is ever needed.
Do insurers ask about remote work policies during underwriting?
Increasingly, yes. Underwriting questionnaires have expanded well beyond office-network security questions to specifically ask about remote access controls, VPN usage, BYOD policy, and MFA enforcement for remote logins, reflecting how much of the current claims landscape traces back to remote or hybrid work exposure.
What is shadow IT and why does it matter for insurance claims?
Shadow IT refers to cloud tools, apps, or file-sharing services employees adopt informally to get work done, without IT department approval or visibility — a personal Dropbox account used to move client files, for instance. It matters for insurance because data moved through unapproved, unmonitored channels is harder to account for during an incident investigation, and its existence can undermine an insurer's confidence that the business maintained the data governance the policy assumed.
How can I lower my premium by improving remote work security?
Enforcing MFA on all remote access, replacing personal VPN use with a business VPN, documenting a BYOD policy, and demonstrating these controls clearly during the underwriting questionnaire are the most direct levers. Insurers price remote work risk based on what they can verify, so having documented, enforced controls — not just controls that technically exist somewhere — is what typically moves the premium needle.

Want Your Remote Work Security Reviewed Before Renewal?

IT Cares reviews your real remote access setup and gives you a right-sized plan to close the gaps insurers actually look for.

Comments (3)

RK
Ryan K., Ottawa
July 21, 2026

Had no idea our team was using their own personal VPN apps to log into our project system. Turned out to be exactly the gap this article describes. Fixed it same week.

SB
Sophie B., Laval
July 19, 2026

The "controlled environment" exclusion explanation was eye opening. Our broker never explained it in plain language like this.

TW
Tom W., Mississauga
July 17, 2026

We got a premium discount after documenting our MFA enforcement at renewal, exactly like the Toronto case study here. Wish we'd done it a year earlier.

Leave a Comment

Need Help?