Cyber Insurance for Small Business in Canada: What It Actually Covers (2026 Guide)

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian small business owner reviewing a cyber insurance policy document alongside a laptop showing a security dashboard
A cyber policy is only as good as what it actually pays out on — reading the coverage grid and the exclusions matters more than the premium quote.

Cyber insurance for a Canadian small business typically covers ransomware incident response and negotiation, business email compromise and wire fraud, business interruption income loss, third-party liability for exposed customer or client data, and the notification and credit monitoring costs a breach triggers. What it typically does not cover is just as important: losses tied to your own negligence, a missing baseline control like multi-factor authentication, a known unpatched vulnerability you never fixed, or damage from state-sponsored attacks carved out under a war exclusion. The gap between what owners assume is covered and what a policy actually pays out on is where most of the bad surprises happen — usually discovered during a claim, which is the worst possible time to learn it.

This guide walks through coverage in real detail rather than marketing language, gives concrete Canadian dollar figures for premiums by business size, explains exactly how your IT security posture moves your price, breaks down the claims process step by step with realistic timelines, and includes a buyer's checklist, a comparison table, and three realistic Canadian business case studies so the numbers feel grounded rather than theoretical. If you've already read a general "do I need cyber insurance" guide and are now trying to actually evaluate a quote in front of you, this is the deeper layer that should come next.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians who work directly with small and mid-sized Canadian businesses on security hardening, incident response, and the technical documentation insurers ask for during underwriting and claims. We're not an insurance brokerage and we don't sell policies — our stake in this is that the businesses we support end up properly covered and, ideally, never need to file a claim in the first place because the underlying security posture is solid.

What Cyber Insurance Actually Covers

Cyber insurance policies are built from a menu of coverage components, and Canadian insurers don't all bundle them identically — some are included by default, others are optional add-ons, and sub-limits within each category vary widely. Here's what the core components actually mean in practice, not just as a line item on a coverage summary.

1. Ransomware incident response and negotiation

This is usually the largest single cost driver in a cyber claim and the reason most small businesses buy the policy in the first place. Coverage typically includes the forensic investigation to determine what happened and what was accessed, a licensed ransomware negotiation firm if negotiation is pursued, and — subject to a specific sub-limit and mandatory sanctions screening — the ransom payment itself. Many policies cap the ransom sub-limit well below the overall policy limit, so a $2 million policy might only cover $250,000 to $500,000 in ransom payment specifically, with the rest of the limit reserved for recovery and liability costs.

2. Business email compromise and funds transfer fraud

Also called social engineering fraud coverage, this pays out when an employee is tricked into wiring money or changing banking details based on a spoofed or compromised email, a scenario that's become one of the most common claim triggers for Canadian SMBs over the last several years. Crucially, this coverage almost always carries its own separate, and often much lower, sub-limit than the main policy — a $1 million cyber policy might only include $50,000 to $100,000 specifically for social engineering fraud, which surprises a lot of business owners who assumed the full limit applied.

3. Business interruption and extra expense

When an attack takes your systems offline, this coverage reimburses the income you lose during the outage and any extra costs incurred to keep operating, such as renting temporary equipment or paying overtime to catch up afterward. It's calculated against your actual historical revenue and typically kicks in only after a "waiting period" deductible measured in hours, commonly 8 to 12 hours, meaning a short outage may not trigger any payout at all.

4. Third-party liability

If a client, patient, or customer sues your business because their data was exposed in a breach you caused, this coverage pays your legal defense costs and any settlement or judgment. For a business handling client financial records, health information, or any regulated personal data, this is frequently the coverage component with the greatest real financial exposure, since a class action or regulatory action following a large breach can dwarf the direct incident response cost.

5. Breach notification and credit monitoring costs

Under Canadian federal privacy law (PIPEDA), businesses must notify affected individuals and the Office of the Privacy Commissioner of Canada when a breach creates a real risk of significant harm, and this notification isn't free — printing, mailing, call centre support, legal review of the notification language, and often a year or more of credit monitoring for affected individuals adds up quickly, frequently running $15,000 to $60,000 even for a breach affecting only a few thousand records. Most cyber policies cover this as a defined line item, sometimes with its own sub-limit tied to a per-record cost.

📊 IT Cares field note: The single most useful habit when reading a policy is to look up every sub-limit separately, not just the headline coverage number on the quote. A "$2 million cyber policy" that caps social engineering fraud at $50,000 and ransom payment at $250,000 is a very different product than one with matching sub-limits across the board, even though both would be marketed with the same headline figure.

Not sure your current setup would even qualify?

Our certified technicians can run a plain-language security audit and tell you exactly what an insurer's application would flag — before you're mid-quote and scrambling.

What Cyber Insurance Does NOT Cover

Exclusions are where cyber insurance most often disappoints business owners who assumed a policy was broader than it is. Understanding these up front, before a breach, is the difference between a smooth claim and a denied one.

Failure to maintain reasonable security ("negligence" exclusions)

Most policies include language excluding losses that result from a failure to maintain a "reasonable" or "minimum" standard of security, and increasingly, insurers spell out specifically what that means: current antivirus and endpoint protection, applied security patches within a defined window, and access controls. If an insurer's forensic investigation determines the breach happened because a server hadn't been patched in eighteen months, that finding alone can support a full denial under this clause.

Missing multi-factor authentication

This deserves its own line because it has become the single most common reason Canadian cyber claims are contested or denied in the last two years. Insurance applications now routinely ask, in writing, whether MFA is enforced on email, remote access (VPN or RDP), and privileged administrator accounts. If the honest answer was "no" but the application said "yes," or if MFA was later disabled and never re-enabled, insurers increasingly treat this as a material misrepresentation that can void the policy entirely — not just the specific claim.

Known, unpatched vulnerabilities

If a vulnerability was publicly disclosed and a patch was available, and your business hadn't applied it within a reasonable window (often defined explicitly as 30 to 90 days in the policy), an insurer can deny a claim tracing back to that specific hole. This is distinct from a true zero-day, where no patch existed yet — that scenario is generally covered normally.

War and state-sponsored attack exclusions

Following several major global incidents attributed to nation-state actors, most cyber policies now carry a "war exclusion" that can apply to attacks formally attributed to a state or state-backed group, even when the business itself had no connection to the geopolitical conflict involved. This clause has been genuinely contested in court in several jurisdictions, and Canadian insurers have been tightening rather than loosening this language, so it's worth asking your broker directly how attribution is determined and by whom.

Prior known incidents ("prior acts" exclusion)

A policy generally only covers incidents that begin after the policy's retroactive date, and it will not cover a breach that was already underway or already known to you before the policy started, even if it's only discovered later. This matters most when switching insurers — ask specifically whether the new policy's retroactive date matches or predates your old one, or you can end up with an unintended coverage gap between policies.

Bodily injury and property damage

Standard cyber policies are built around data, systems, and financial loss — they generally exclude physical bodily injury or tangible property damage, even when caused by a cyber incident (for example, an attack on building control or industrial equipment causing physical harm). That risk typically needs to sit under a separate liability or specialized policy.

Betterment and upgrades

If your incident response includes replacing an old, vulnerable system with a newer, more secure one, insurers typically only reimburse the cost to restore what you had — the "betterment," meaning the value of the upgrade itself, usually comes out of your own pocket. This is a common point of friction during claims settlement.

Real Canadian Cost Ranges by Business Size

Cyber insurance pricing in Canada is driven primarily by three factors: your revenue and employee count, the sensitivity of the data you handle (health and financial data cost meaningfully more to insure than general commercial data), and your existing security controls. The ranges below reflect typical 2026 Canadian small business market pricing for a standalone cyber policy, not bundled into a broader business owner's policy, which can shift the numbers.

Business sizeTypical coverage limitAnnual premium range (CAD)Typical deductible
Micro (1–9 employees) $500K – $1M $500 – $1,800 $1,000 – $2,500
Small (10–50 employees) $1M – $3M $1,500 – $6,000 $2,500 – $10,000
Growing SMB (50–100 employees) $2M – $5M $4,500 – $14,000 $5,000 – $15,000
Mid-market (100–250 employees) $5M – $10M+ $12,000 – $30,000+ $10,000 – $25,000

Industry matters as much as size. A 20-employee accounting firm or medical clinic handling financial or health data will typically pay 25% to 60% more than a 20-employee retail or trades business with the same employee count, purely because of the data sensitivity and regulatory exposure involved. Professional services, healthcare, legal, and financial businesses consistently sit at the higher end of every bracket above; contractors, trades, and light manufacturing tend to sit at the lower end, all else being equal.

It's also worth knowing that the Canadian cyber insurance market has softened somewhat since its peak hardening around 2021-2022, when ransomware claims spiked and premiums roughly tripled for many businesses in a single renewal cycle. Increased insurer competition and a growing baseline of security requirements (MFA in particular) have brought pricing down modestly for well-secured businesses, even as premiums for poorly-secured applicants have, if anything, gotten worse — insurers have simply gotten better at pricing risk individually rather than by industry averages alone.

How Your IT Security Posture Lowers Premiums

Unlike auto or home insurance, where your control over the price is limited, cyber insurance pricing is unusually responsive to specific, documentable security controls. Insurers have converged on roughly the same short list of controls because claims data shows they materially reduce both the likelihood and severity of an incident. Addressing these before you apply, or before renewal, is the most direct lever a small business has over its premium.

Multi-factor authentication (MFA)

MFA on email, remote access, and administrative accounts is now the single most heavily weighted factor on most Canadian cyber applications — some insurers will not quote a policy at all without it, and others apply a meaningful surcharge (often 15% to 30%) in its absence. This one control alone blocks the vast majority of credential-based intrusions, which is why insurers treat it almost as a gate rather than just a discount.

Endpoint detection and response (EDR)

Modern EDR tools that actively monitor and can automatically isolate a compromised device go meaningfully further than traditional antivirus, and insurers increasingly ask about this specifically rather than accepting "we have antivirus" as sufficient. Businesses running a real EDR platform across their fleet typically see a measurable premium reduction, often in the 10% to 20% range, compared to businesses relying on consumer-grade antivirus alone.

Tested, immutable, and offline backups

A backup that's never been tested is a theoretical backup, not a real one — and insurers know this, which is why some applications now ask when you last performed a full test restore, not just whether backups exist. Immutable or offline (air-gapped) backups that ransomware can't reach and encrypt alongside your live systems are increasingly a specific underwriting question, since ransomware groups routinely target connected backup systems first.

Documented employee security training

Since business email compromise and phishing remain the top initial entry point for both ransomware and funds transfer fraud, insurers ask whether staff receive regular, documented phishing-awareness training, ideally including simulated phishing tests with tracked results. A business that can show training records and improving simulation click-rates over time presents a materially lower underwriting risk than one that has never run a test.

A written incident response plan

Even a short, one-to-two page plan naming who does what in the first 24 hours of an incident — who calls the insurer, who has admin credentials, who talks to customers — signals to an underwriter that a claim, if it happens, will move faster and cost less to resolve. Insurers have direct financial incentive to reward this, since slower, more chaotic incident response reliably produces larger claims.

Where IT Cares fits in

Every one of the five controls above is something our security audit and managed IT services engagements are built around — not because we sell insurance, but because these are also simply the right things to have in place regardless of your policy. Clients who go through a hardening pass before their next renewal frequently bring back a quote that's noticeably better than their prior year's, on top of actually being harder to breach in the first place. If you want a plain-language read on where your current setup stands against what insurers are now asking, that's a conversation worth having before you're staring at an application form.

The Claims Process, Step by Step

Knowing what actually happens after you discover an incident, and roughly how long each stage takes, removes a lot of the panic from a genuinely stressful moment. These steps and timelines reflect how most Canadian cyber claims actually unfold, from initial discovery through settlement.

1

Contain the incident first

Isolate affected systems and stop active damage before anything else — disconnect from the network if needed. Resist the urge to wipe or reimage systems immediately; the forensic investigation your insurer requires depends on preserving evidence.

2

Call your insurer's claims hotline immediately

Most Canadian cyber policies require notice within 24 to 72 hours of discovery, and some require notice before you engage any outside vendor. Acting outside that window is one of the most common — and most avoidable — reasons a claim gets contested.

3

Use the insurer's approved incident response panel

Most policies require using pre-approved forensic, legal, and public relations vendors from the insurer's panel. Calling your own IT company first and starting remediation before notifying the insurer can mean those costs simply aren't reimbursed later.

4

Document everything as it happens

Keep a running timeline, preserve logs before they rotate out of retention, and track every hour of downtime and every invoice tied to the incident. The proof of loss submitted later depends entirely on this contemporaneous documentation — reconstructing it after the fact is far harder and less credible.

5

Submit the formal proof of loss

A detailed written claim covering what happened, when, the financial impact, and supporting documentation, typically due within 60 to 90 days of the incident depending on the policy. This is usually prepared with help from the panel's forensic accountant for business interruption calculations.

6

Cooperate through adjustment and negotiate the settlement

The insurer's adjuster and forensic accountant review the claim against the policy language, a process that can take several weeks for straightforward claims or several months for complex or disputed ones, before a settlement offer is issued.

Realistic overall timeline: a clean, well-documented claim with no coverage disputes commonly settles within 30 to 60 days of the proof of loss being submitted. Claims involving ransomware negotiation, regulatory investigation, litigation from affected third parties, or any dispute over whether an exclusion applies can stretch to four to eight months or longer. Business owners consistently underestimate this second timeline, which is exactly why business interruption coverage and a cash buffer both matter — the insurance payout rarely arrives fast enough to cover the immediate weeks of disruption on its own.

Common Pitfalls That Get Claims Denied

Checklist — Before You Buy Cyber Insurance

  • Confirm MFA is enforced on email, VPN/remote access, and all administrator accounts — not just "available."
  • Have a backup you've actually test-restored within the last 90 days, not just one that "should be working."
  • Know your data inventory: what personal, financial, or health data you hold, where it lives, and who can access it.
  • Put together a written incident response plan, even a simple one-page version naming who does what.
  • Ask your broker for the policy's retroactive date, and confirm it aligns with any prior policy to avoid a coverage gap.
  • Clarify whether ransom negotiation and payment are covered, and what the specific sub-limit is.
  • Understand the business interruption waiting period — how many hours of downtime before coverage kicks in.
  • Confirm the coverage territory matches where your business and clients actually operate (Canada-only vs. including the US).
  • Ask whether you can use your own trusted IT/forensic vendor or must use the insurer's approved panel.
  • Check the social engineering/BEC fraud sub-limit specifically — it's often far lower than the headline policy limit.
  • Read the war and state-sponsored attack exclusion language and ask how attribution is determined.
  • Get every verbal assurance from your broker confirmed in writing before you sign.

Comparing Insurers and Policies: What Actually Matters

Two policies with the same headline coverage limit and a similar premium can differ enormously in what they'd actually pay out in your specific scenario. When comparing quotes, work through these criteria rather than relying on the total limit and price alone.

CriteriaWhat to check
Sub-limits vs. aggregate limit Look up ransom payment, social engineering fraud, and notification cost sub-limits individually — the headline limit rarely applies evenly across categories.
Retroactive date Confirm it matches or predates any prior policy to avoid an unintended gap for incidents that began before this policy's start.
Waiting period (BI deductible) The number of hours of downtime before business interruption coverage activates — shorter is better, and this varies more between insurers than people expect.
Vendor choice Can you use your own IT provider and legal counsel, or are you locked into the insurer's approved panel? Panel-only policies can mean losing an existing relationship mid-crisis.
Application warranty language How strictly the policy treats inaccurate security answers — some insurers void only the specific claim, others can rescind the entire policy.
Regulatory fines & defense coverage Whether the policy covers regulatory investigation costs and fines where insurable by law, which varies by province and by regulator.
Betterment handling Whether replacing outdated, breached systems with more secure ones is reimbursed at restoration cost only, or partially covers the upgrade.
Claims-made vs. occurrence basis Most cyber policies are claims-made, meaning coverage depends on the policy being active when the claim is reported, not just when the incident occurred — relevant if you ever lapse or switch insurers.
Renewal and cancellation terms Whether a claim in one year triggers automatic non-renewal or a steep increase, and how much notice you'd get either way.

Three Real-World Canadian Claim Scenarios

The following case studies are composite, illustrative scenarios built from patterns common to Canadian small business cyber claims — names and identifying details are fictional, but the coverage dynamics and dollar figures reflect realistic outcomes.

Case 1 — Maple Ridge Plumbing & Heating, Ontario (22 employees)

Maple Ridge carried a $2 million cyber policy and was hit by ransomware that entered through an exposed remote desktop connection that had never had MFA enabled, despite the application stating MFA was enforced "on all remote access." The insurer's forensic investigation traced the entry point directly to that gap. Business interruption ($38,000) and the forensic investigation ($22,000) were paid, but the $180,000 ransom payment was denied outright under the material misrepresentation clause, and the policy was flagged for non-renewal. Total out-of-pocket cost to the business: roughly $195,000, plus a scramble to find new coverage mid-year at a significantly higher rate. After the incident, Maple Ridge had IT Cares implement MFA across every remote access point and deploy EDR; at their next renewal eighteen months later, with a clean security audit in hand, their premium came in 22% lower than their pre-incident baseline despite the claim history.

Case 2 — Foothills Family Medical Clinic, Alberta (14 staff)

A finance staff member received a spoofed email appearing to be from the clinic's landlord requesting updated banking details for the monthly rent payment, and $47,000 CAD was wired before anyone noticed the discrepancy. The clinic's policy included a $50,000 social engineering fraud sub-limit against a $10,000 deductible, and the claim paid out $37,000 after the deductible within 41 days — a relatively smooth process because the clinic called their insurer within hours of discovering the fraud and had clear email headers preserved. Separately, because the clinic handles patient health information, they also triggered a breach notification obligation affecting 3,200 patient records tied to the same compromised email account; notification, call centre support, and one year of credit monitoring cost $18,500, fully covered under the policy's notification sub-limit. Total combined payout: $55,500 against a policy that cost the clinic $4,200 annually.

Case 3 — Harborview Accounting Group, British Columbia (9 employees)

A phishing email compromised one employee's mailbox, which the attacker used to quietly monitor client communications for three weeks before Harborview's EDR flagged unusual mailbox forwarding rules and the firm shut it down. No funds were stolen, but roughly 640 client tax and financial records had been exposed to the compromised inbox during that window, triggering PIPEDA notification obligations to affected clients and the federal Privacy Commissioner. The firm's $1 million policy covered the $14,000 forensic investigation confirming the scope of exposure, $9,200 in notification costs, and $6,000 in legal review of the notification language and regulatory correspondence — a combined $29,200 payout, settled in 52 days. Because Harborview had documented, tested backups and MFA already in place at the time of the incident, and reported it within 18 hours of discovery, the claim proceeded with no coverage disputes and no impact on their renewal terms the following year.

Budget and Pricing: What to Actually Plan For

Beyond the premium itself, budget for a few adjacent costs that business owners often overlook when comparing cyber insurance to other expenses. First, the deductible is money you pay before coverage activates on every claim, not a one-time cost — for a small business, that's commonly $2,500 to $10,000 sitting as an expected out-of-pocket cost on any incident, which should factor into your operating cash reserve planning, not just your insurance line item.

Second, expect your premium to move at renewal based on your claims history and any security improvements (or regressions) since the last policy period — a clean year with documented MFA rollout or EDR deployment can lower your renewal quote, sometimes by 10% to 25%, while a claim year commonly raises it 20% to 50% or triggers a request for additional security controls as a condition of renewal at all. Third, budget separately for the security controls insurers are asking about rather than treating the insurance premium as your only cybersecurity spend — a modest annual investment in MFA enforcement, EDR, and tested backups (often $50 to $150 CAD per employee per year for a well-run small business) typically pays for itself through both a lower premium and a meaningfully lower chance of ever needing to file a claim.

A useful way to frame the two spends together: insurance is what protects your business financially after something goes wrong; security spending is what reduces how often something goes wrong and how bad it is when it does. Businesses that treat these as one combined budget line, rather than picking one or the other, consistently come out ahead on both the premium and the actual risk.

Canadian Government and Business Resources

Several Canadian federal and provincial resources exist specifically to help small businesses improve cybersecurity posture and, in some cases, access financing for it — worth knowing about regardless of where you land on insurance.

None of these resources replace a conversation with a licensed insurance broker about your specific policy needs, but several of them — particularly the Cyber Centre's baseline controls and CyberSecure Canada certification — directly overlap with what insurers are already asking about, making them a genuinely efficient starting point rather than a separate task.

If you'd like a professional pass through your current setup before you're mid-application with a broker, our security audit service and cybersecurity services for Canadian businesses are built around exactly the controls this guide covers, and our SMB IT support team can help implement whatever gaps turn up. There's no requirement to figure this out entirely on your own before talking to a broker — a clear, documented security baseline going into that conversation tends to produce a better quote and a smoother underwriting process either way.

Frequently Asked Questions

Is cyber insurance mandatory for small businesses in Canada?
No federal or provincial law in Canada requires small businesses to carry cyber insurance, unlike commercial general liability in some sectors. That said, some clients, particularly larger enterprises, government contracts, and healthcare or financial partners, increasingly require proof of cyber coverage as a condition of doing business, which is making it a de facto requirement in certain industries even without a legal mandate.
How much does cyber insurance cost for a small business in Canada?
For a Canadian business with 10 to 50 employees, annual premiums typically range from about $1,500 to $6,000 CAD for $1 million to $3 million in coverage, though this varies significantly based on industry, the sensitivity of data handled, and existing security controls like multifactor authentication and endpoint detection. Businesses handling healthcare, financial, or large volumes of personal data typically pay toward the higher end of that range or beyond.
Will cyber insurance pay out if we didn't have multi-factor authentication enabled?
It depends heavily on the policy's application questions and warranty language, but this is one of the single most common reasons Canadian insurers deny or reduce claims. Most applications now explicitly ask whether MFA is enabled on email, remote access, and privileged accounts, and a false or outdated answer can void coverage entirely, even if MFA absence wasn't the direct cause of the breach. Insurers increasingly treat MFA as a baseline condition of coverage rather than an optional best practice.
How long does a cyber insurance claim take to pay out in Canada?
Straightforward claims with clear documentation and no coverage disputes are often resolved within 30 to 60 days after the formal proof of loss is submitted. Complex claims involving ransomware negotiation, regulatory investigation, or disputed coverage can take four to eight months or longer, particularly when the insurer's forensic accountant and your business disagree on the business interruption calculation.
Does cyber insurance cover ransomware payments in Canada?
Many Canadian cyber policies do include a sub-limit for ransom payment and negotiation costs, but usually capped well below the overall policy limit, and always subject to sanctions screening to confirm the ransomware group isn't on a restricted list. Some insurers now discourage or restrict ransom coverage entirely in response to regulatory pressure, so this is a specific line item worth confirming rather than assuming, since "cyber insurance" as a category doesn't guarantee it.
What's the difference between first-party and third-party cyber coverage?
First-party coverage pays for costs your business incurs directly from an incident: forensic investigation, business interruption, ransom negotiation, and your own data recovery. Third-party coverage, also called cyber liability, pays for claims made against you by others harmed by the breach, such as customers whose data was exposed suing for damages, or regulatory fines. A well-rounded small business policy includes meaningful limits in both categories, since a single incident often triggers both types of cost simultaneously.
Do I need cyber insurance if I already have a managed IT security provider?
Yes, generally — strong IT security reduces the likelihood and severity of an incident and can lower your premium, but it doesn't replace insurance. Even the best-defended businesses get breached, often through a vendor, a sophisticated phishing attempt, or a zero-day vulnerability no defense could have caught in time. Insurance and security are complementary: one reduces risk, the other transfers the financial impact of the risk that remains after your defenses are in place.
Can a cyber insurance claim be denied after the breach has already happened?
Yes, and it happens more often than business owners expect. Common reasons include inaccurate answers on the original application (particularly about MFA and patching), failing to notify the insurer within the required window, using vendors outside the insurer's approved panel without prior authorization, or the incident falling under a specific exclusion like prior known vulnerabilities or acts of war. Reading the exclusions section of a policy before buying it, not after a breach, is the single best way to avoid this.

Want a Straight Answer on Where Your Security Stands?

IT Cares can review your current setup against what Canadian insurers are actually asking for and tell you plainly what's solid and what needs work — no pressure, no jargon.

Comments (3)

RT
Robert T., Mississauga
July 24, 2026

The sub-limit explanation was the missing piece for me. Our broker quoted "$1M coverage" and I never thought to ask what the social engineering fraud limit actually was inside that.

MD
Manon D., Calgary
July 23, 2026

The Maple Ridge case study is basically what happened to a friend's shop, minus the name. MFA on remote desktop should not be optional in 2026.

JP
Jean-Philippe R., Vancouver
July 22, 2026

Printed the checklist and went through it with our broker on the renewal call. Turns out our old policy's retroactive date had a gap nobody caught. Worth the twenty minutes.

Leave a Comment

Need Help?