Every Canadian business already carries cyber risk one of two ways: it either transfers that risk to an insurer for a premium, or it keeps the risk on its own books and hopes it can absorb whatever happens. The second path has a name — self-insurance — and for a genuine subset of very small, low-exposure businesses, it can be a rational, deliberate strategy rather than a mistake. The trouble is that most businesses currently self-insuring never actually made that choice on purpose. They simply never requested a quote, assumed a company their size wasn't a realistic target, or looked at a premium number without ever pricing out what the alternative — paying for an incident entirely out of pocket — would actually cost.
This guide walks through the actual decision honestly, with real Canadian-dollar numbers rather than vague reassurance in either direction. It covers what self-insurance means in practice, the expected-loss math that should drive the decision, the specific thresholds where self-insurance stops making sense for most businesses, a side-by-side comparison, the hybrid approaches many Canadian SMBs land on in practice, and three fictional but numerically realistic case studies showing the threshold in action. The goal isn't to argue that every business needs a policy — it's to make sure the decision, whichever way it goes, is made on purpose.
It's worth naming the emotional shortcut up front, because it shapes more decisions than owners like to admit: many small business owners treat "we haven't been breached yet" as evidence the risk is overstated. It isn't evidence of anything except that an incident hasn't happened yet. Insurance and reserve-funding decisions should be driven by the probability and cost of what could happen, not by what has happened so far — a distinction that becomes very expensive to relearn after the fact.
Not legal, financial, or insurance advice
This article is educational information based on general market patterns Canadian brokers, insurers, and IT security practitioners commonly report. It isn't a substitute for reading your actual policy wording, working through your own numbers with an accountant, or getting advice from a licensed insurance broker or lawyer about your specific situation. Every business's risk profile, every carrier's underwriting criteria, and every policy's terms differ — confirm specifics with a professional before making a coverage or reserve decision based on this article.
What "Self-Insurance" Actually Means for a Canadian SMB
Self-insurance, in the cyber risk context, doesn't mean doing nothing. It means a business deliberately decides to retain the financial risk of a cyber incident itself rather than pay a premium to transfer that risk to an insurance carrier. Done properly, it involves three concrete pieces: an honest estimate of what a realistic incident would cost the business, a dedicated cash reserve sized to cover that estimate, and a written internal plan for how the business would respond operationally and financially if an incident actually occurred. That's the deliberate version — and it's genuinely rare.
The far more common version, and the one worth being honest about, is accidental self-insurance: a business that has never purchased a policy, has no dedicated reserve, and has no incident response budget, simply because nobody ever priced it out. Ask most small business owners why they don't carry cyber insurance and the answers cluster around a handful of assumptions rather than a considered decision — "we're too small to be a target," "we don't hold anything valuable," "IT handles that," or simply "nobody's ever brought it up." None of those is a risk calculation. They're reasons the calculation never happened.
This distinction matters because the two versions carry very different actual risk. A business that deliberately self-insures with a properly funded reserve and a tested response plan has, in effect, built its own private insurance function — smaller in scale, but structurally similar in intent. A business that has simply never gotten a quote has none of that infrastructure. If an incident hits, the second business isn't just retaining risk on purpose — it's discovering the size of that risk for the first time, under the worst possible conditions, while also trying to keep the business running.
There's a second reason accidental self-insurance is more common than the deliberate kind: cyber incidents targeting small businesses are frequently underreported and under-discussed in local business networks, which quietly reinforces the "it won't happen to us" assumption. Ransomware groups, business email compromise scammers, and opportunistic attackers running automated scans for exposed remote-access ports or unpatched software genuinely do not care how small a company is — automated attacks scale to thousands of targets a day regardless of company size, and a $2-million-revenue business with weak controls is frequently an easier, faster payday than a well-defended enterprise. Size doesn't create the target list. Exposure does.
The Cost-Benefit Math: Expected Loss vs. Premium
The cleanest way to think about the self-insurance decision is the same way an actuary thinks about it: expected annual loss compared to the actual annual cost of transferring that risk. Expected annual loss is calculated as the probability of a cyber incident happening to a business like yours in a given year, multiplied by the average cost of that incident for a business of your size and sector. That number, compared honestly against your actual insurance premium, tells you far more than gut instinct does.
Here's a simplified worked example using realistic assumptions for a mid-sized Canadian SMB. Say you run a 25-employee professional services firm in Canada with roughly $3 million in annual revenue, moderate data sensitivity (client files, some financial data, no health records), and reasonably standard IT hygiene — some controls in place, nothing exceptional. Brokers and underwriters commonly cite an annual cyber incident probability in the rough range of 15% to 25% for a business of this profile once ransomware, business email compromise, and smaller breach events are all counted together, not just headline-grabbing ransomware. For this example, use 20%.
Next, estimate the average cost of an incident for a business this size. For a moderate-severity event — a business email compromise with a fraudulent wire transfer, or a ransomware incident that's contained without a full-scale breach notification obligation — total costs including forensic investigation, incident response, some downtime, and remediation commonly land somewhere between $60,000 and $130,000 CAD for a company this size. Use a midpoint of $95,000.
Worked example: expected annual loss vs. premium
Expected annual loss = probability of an incident (20%) × average incident cost ($95,000) = $19,000 CAD per year.
Typical annual premium for this business's profile, at roughly $1 million in coverage, commonly runs $4,000 to $6,000 CAD per year.
On a pure expected-value basis, the premium ($4,000–$6,000) sits well below the expected annual loss ($19,000) — which looks, at first glance, like transferring the risk is the obvious better deal every time.
That comparison is useful but incomplete, and the incompleteness matters. Insurance is never sold at the actuarially "fair" price — carriers build in their own operating costs, claims administration, broker commissions, and a profit margin, which means the premium you pay is always somewhat higher than the insurer's own estimate of your expected loss. If insurance were priced exactly at expected loss with no markup, buying it would always be a break-even proposition and self-insuring would always be mathematically equivalent over a long enough time horizon. The premium markup is the real "cost" of insurance — and in the worked example above, that markup looks unusually favourable to the buyer only because $19,000 in expected loss compares so cheaply against a $4,000–$6,000 premium. In practice, for many smaller and lower-risk businesses, the premium markup is large enough relative to expected loss that the pure expected-value math tilts toward self-insuring instead.
This is exactly why expected value alone is the wrong lens for the full decision. What actually justifies paying more than your expected loss for insurance is variance, not the average outcome — the fact that a bad year isn't "pay $19,000," it's "pay $250,000 or $600,000 in the specific year an incident actually happens, all at once, with no advance warning." Insurance exists to smooth that volatility, not to beat the average. A business that can comfortably absorb its worst realistic single-incident cost in cash, without threatening payroll, supplier payments, or its ability to operate, is in a genuinely different position than one that can't — even if their expected-value math looks identical on paper. The rest of this article is really about identifying which side of that line your business sits on.
When Self-Insurance Becomes Risky: The Threshold Factors
There isn't a single dollar figure where self-insurance stops working for everyone — it's a combination of factors, and any one of them being severe enough can flip the math on its own. Here are the five that matter most for Canadian SMBs.
1. Revenue and company size crossing an existential point
The core question is simple: could a single worst-case incident genuinely end the business? For a solo consultant with minimal overhead, a $40,000 hit is painful but survivable — cut expenses, take on debt, keep going. For a 30-person company with payroll obligations, lease commitments, and client contracts, that same relative-sized hit scaled to a larger, more complex incident can consume the entire cash position in days, at exactly the moment the business most needs liquidity to keep operating. As headcount, payroll obligations, and fixed costs grow, the size of an incident that would be merely painful also grows — but cash reserves rarely grow proportionally, since more of that cash is already committed to operating the larger business.
2. Handling data that triggers larger regulatory and notification costs
Health records, financial account data, and payment card information all carry materially higher breach costs than ordinary business records, largely because they trigger mandatory notification obligations, potential regulatory investigation, and in some cases sector-specific fines that have nothing to do with the technical remediation cost. A business holding a modest customer list faces a fundamentally smaller notification bill than one holding health records for the same number of people — Canadian privacy law under PIPEDA requires notifying affected individuals and the Office of the Privacy Commissioner of Canada of breaches posing a real risk of significant harm, and the administrative cost of doing that properly, often with legal counsel involved, routinely runs into the tens of thousands of dollars even before considering any fine or settlement.
3. Contractual requirements from clients or partners
This threshold has shifted faster than almost any other in the past few years. A growing share of B2B contracts, especially with larger clients, financial institutions, healthcare organizations, and government-adjacent entities, now explicitly require vendors to carry cyber insurance at a specified minimum limit as a condition of doing business. For a business that lands even one client of this type, the decision stops being a risk calculation and becomes a contractual requirement — self-insurance simply isn't an option regardless of how the underlying math works out.
4. Being in a regulated or high-target sector
Healthcare, legal, financial services, and any business handling regulated personal information face both a higher probability of being targeted and a higher cost per incident once regulatory obligations are factored in. Attackers increasingly target specific sectors precisely because the data is more valuable on dark web markets or because the victim organization is more likely to pay a ransom quickly to avoid regulatory exposure — which raises both sides of the expected-loss equation simultaneously.
5. Reliance on a single critical system where downtime means immediate lost revenue
An e-commerce business that can't process orders, or a professional services firm that bills by the hour and can't access client files or its time-tracking system, loses revenue the moment a critical system goes down — not eventually, immediately. For these businesses, the cost of an incident isn't just the technical remediation bill; it's every hour of lost operating capacity multiplied across the outage. A four-day outage for an online retailer doing $30,000 a day in sales isn't a $95,000 incident — cleanup costs are on top of $120,000 in lost revenue that doesn't get recovered once the outage ends.
Self-Insurance vs. Cyber Insurance: Side-by-Side Comparison
| Factor | Self-insurance | Cyber insurance |
|---|---|---|
| Upfront cost | No premium, but requires building and maintaining a dedicated cash reserve, which is opportunity cost on capital that could otherwise fund growth. | Fixed annual premium, typically $2,000–$15,000+ CAD depending on size, sector, and coverage limits. |
| Cash flow impact | Reserve sits idle until needed; a real incident requires immediate large cash outlay from the business's own accounts. | Predictable, budgetable annual expense; incident costs are largely paid by the carrier, not drawn from operating cash. |
| Expertise & incident response access | Business must independently source and vet forensic investigators, breach counsel, and PR support during the incident itself, under time pressure. | Most policies include a pre-vetted incident response panel — forensics, legal, PR, negotiation — activated within hours of a claim being filed. |
| Regulatory defense support | Business bears the full cost of legal counsel for notification obligations and any regulatory inquiry, with no cap. | Policies typically cover breach notification costs, regulatory defense expenses, and often fines/penalties where legally insurable. |
| Scalability as the company grows | Reserve requirements grow with the business, but rarely keep pace automatically — requires active, disciplined re-evaluation every year. | Coverage limits can be increased at renewal to match growth, with the insurer absorbing the risk of underestimating exposure. |
| Worst-case exposure | Uncapped — a catastrophic incident can exceed the reserve entirely, forcing emergency borrowing or risking insolvency. | Capped at the policy limit purchased, providing a known ceiling on financial exposure for a known annual cost. |
Hybrid Approaches Many Canadian SMBs Actually Use
In practice, the choice isn't binary, and most Canadian SMBs that think carefully about this land somewhere in the middle rather than at either extreme. Three hybrid patterns show up repeatedly.
Higher deductible, lower premium, paired with real security investment. Choosing a higher deductible — say $10,000 or $25,000 instead of $1,000 — meaningfully lowers the annual premium, while the business self-insures just that deductible layer with a modest reserve. This works best when combined with genuine security investment (multi-factor authentication, endpoint detection and response, tested backups) that both reduces the odds of needing to file a claim at all and, in many cases, further improves the quote a business qualifies for at renewal. This pairing — a real security budget plus a higher-deductible policy — is covered in more depth in our companion guide on lowering your cyber insurance premium through IT security.
A modest self-funded reserve for smaller incidents, alongside a policy for catastrophic scenarios. Rather than filing a claim — and accepting the premium increase that often follows — for a minor incident like a contained phishing attempt or a small, quickly resolved malware infection, some businesses keep a few thousand dollars set aside to absorb those smaller events directly, reserving the policy specifically for the scenario that could otherwise be existential. This keeps the claims history clean, which itself can support better renewal pricing over time, while still protecting against the tail risk that actually matters most.
Captive insurance arrangements. For larger or multi-entity businesses — a group of related companies under common ownership, or a larger enterprise with the scale to justify it — setting up a captive insurance company, essentially a formal, regulated internal insurer owned by the business itself, can combine some of the tax and risk-pooling advantages of formal insurance with more direct control over claims and reserves. This is a meaningfully more complex and costly structure to set up and maintain, involving actuarial studies, regulatory filings, and ongoing compliance costs, and it's typically only worth considering for businesses well beyond the SMB range covered in this guide, or groups of related SMBs pooling risk together. Most single-location, single-entity Canadian SMBs won't find a captive arrangement cost-justified, but it's worth knowing the option exists as businesses scale.
Three Canadian SMBs, Three Different Outcomes
The following case studies are illustrative composites built from realistic Canadian SMB numbers and patterns — not real, identifiable businesses — but the dollar figures and decision logic reflect the kind of math brokers and IT security practitioners see repeatedly across similarly sized companies.
Regina, SK: the sole-proprietor-plus-two consultancy where self-insurance genuinely made sense
A three-person management consulting practice in Regina, Saskatchewan — the owner plus two employees — generates roughly $340,000 in annual revenue, holds no client payment card data, no health information, and stores client deliverables in a well-maintained cloud environment with MFA enabled and automated backups. Getting a quote, the owner found premiums for a modest $250,000 policy running around $1,400 to $1,900 CAD a year. Running the expected-loss math: an estimated 12% annual incident probability for a business this size and profile, against an average incident cost for a business this small — mostly business email compromise or a contained malware event — of roughly $18,000, produces an expected annual loss of about $2,160. That's close enough to the premium range that the deciding factor became the reserve requirement, not the math: the business kept $15,000 in a separate savings account explicitly earmarked for a cyber incident, roughly 4.4% of annual revenue, genuinely liquid and accessible within a day. No client contracts required proof of insurance, no regulated data was involved, and the owner could personally absorb a bad year without payroll or lease obligations at risk. For this specific business, deliberate self-insurance with a real reserve was a defensible, informed choice — not an accident.
Vancouver, BC: the e-commerce company that outgrew self-insurance
A Vancouver-based e-commerce retailer selling home goods grew from $600,000 to $4.2 million in annual revenue over three years, all self-insured the entire time, largely because nobody had revisited the decision since the business was two people working from an apartment. The wake-up call came from a near-miss: an automated bot attack attempted credential stuffing against customer accounts, and while no significant data was ultimately exposed, the site's checkout system went down for six hours during the response and investigation — during a period when the business was doing roughly $9,000/day in sales, meaning the outage alone cost an estimated $2,250 in lost revenue, on top of the IT contractor's emergency response invoice of $4,800. The founder ran the numbers afterward: at their current size, a genuinely successful ransomware attack against their order-processing and customer database systems, with the multi-day outage that would likely follow, was realistically estimated at $180,000-$260,000 all-in, against a cash reserve that had never been formally sized past roughly $12,000. The gap between what the business could actually absorb and what a real incident would cost was the deciding factor, not any single dollar figure. Within two months, the business secured a $1 million cyber policy at approximately $7,200 CAD a year, reflecting both its e-commerce profile and the payment card data it processes.
Kitchener-Waterloo, ON: the professional services firm that self-insured, had an incident, and did the 5-year math afterward
A 14-person accounting and bookkeeping firm in Kitchener-Waterloo, Ontario, had self-insured for five years, reasoning that their IT provider's basic antivirus and firewall setup was "enough." A ransomware attack encrypted their file server and email archive, discovered on a Monday morning right in the middle of a client's payroll processing deadline. The firm paid $22,000 to a data recovery and incident response contractor, lost an estimated $31,000 in billable hours across five staff members over eight days of reduced operations, and spent a further $6,500 on legal counsel to assess notification obligations to affected clients under Ontario privacy requirements, since some client financial records were involved. Total out-of-pocket cost: approximately $59,500 CAD, paid entirely from the firm's operating line of credit, which strained the business's relationship with its bank for the better part of a year afterward. Running the comparison after the fact, the firm's broker estimated that a $1 million cyber policy, appropriate for a firm of this size and sector, would have cost roughly $4,200 to $5,500 CAD a year — meaning five years of premiums, even at the higher end, would have totalled around $27,500, less than half of what the single incident actually cost once it happened. The firm now carries a policy and has never let it lapse since.
Not Sure Which Side of the Math You're On?
IT Cares can walk through your actual exposure — data sensitivity, systems, contracts, and reserves — and help you figure out whether self-insurance, a policy, or a hybrid approach genuinely fits your business.
Quick Checklist: Is Self-Insurance Still Right for Us?
Decision checklist: is self-insurance still right for us?
- ☐ We could pay our realistic worst-case incident cost — not the average, the worst case — entirely in cash without touching payroll, rent, or supplier payments.
- ☐ We have an actual dedicated reserve set aside for this specific purpose, sitting in a genuinely liquid account, not just "the business has some cash in general."
- ☐ We don't hold health records, payment card data, or other regulated personal information beyond basic contact details.
- ☐ No current or prospective client contract requires proof of cyber insurance as a condition of doing business.
- ☐ We're not in a heavily regulated or frequently targeted sector (healthcare, legal, financial services, critical infrastructure).
- ☐ A multi-day outage of our core system would be inconvenient, not immediately revenue-threatening.
- ☐ We've actually calculated our expected annual loss and compared it honestly against real premium quotes, not assumptions.
- ☐ We revisit this decision at least once a year, or whenever revenue, headcount, or client mix changes meaningfully.
- ☐ We have a written (even if brief) incident response plan naming who does what if something happens.
- ☐ Leadership has explicitly signed off on self-insuring as a deliberate choice, not by default.
If you checked fewer than seven of these, formal cyber insurance is very likely worth pricing out, even if you ultimately decide against it.
Budget & Pricing: Coverage Costs vs. Reserve Requirements
Concrete numbers make this decision easier than abstract advice. Here's what Canadian SMB cyber insurance premiums and self-insurance reserves realistically look like across three size tiers.
Micro businesses (1-10 employees, under $1M revenue)
Typical annual cyber insurance premiums for $250,000-$500,000 in coverage commonly run $800 to $2,200 CAD, depending on sector and data sensitivity. A comparably sized self-insurance reserve, if going that route deliberately, should realistically hold $10,000 to $25,000 in genuinely liquid funds — enough to cover a moderate incident and a meaningful share of a severe one.
Small businesses (11-50 employees, $1M-$10M revenue)
Premiums for $500,000-$2 million in coverage commonly run $2,500 to $9,000 CAD annually, with the range driven heavily by sector, data types held, and the strength of existing security controls. A properly sized self-insurance reserve at this tier realistically needs to hold $40,000 to $150,000 to cover a moderate-to-serious incident without threatening operations — a figure that, for most businesses in this tier, starts to look uncomfortably close to a full year of premiums many times over, which is exactly why this tier is where most businesses shift toward formal coverage or a hybrid approach.
Mid-sized businesses (51-200 employees, $10M-$50M revenue)
Premiums for $2 million-$5 million in coverage commonly run $9,000 to $30,000+ CAD annually, scaling with sector risk, regulated data exposure, and prior claims history. At this tier, a self-insurance reserve sized to genuinely cover a catastrophic scenario — potentially $500,000 to $1 million or more once regulatory, legal, and extended business interruption costs are included — represents a level of idle, dedicated capital that very few businesses this size can justify holding outside of formal insurance. This tier is where self-insurance, absent a captive structure or a very deliberate risk-retention strategy backed by real actuarial analysis, becomes difficult to justify for most companies.
Canadian Government & Regulatory Resources
Several Canadian government and regulatory bodies offer resources directly relevant to this decision, and they're worth consulting before finalizing either path.
The Business Development Bank of Canada (BDC) offers risk management advisory services and financing specifically aimed at helping SMBs invest in cybersecurity and business resilience, including guidance that can inform how much of a security and reserve budget makes sense relative to overall business risk. Their advisory team can be a useful independent sounding board when weighing insurance against self-funded reserves, particularly for businesses that don't already have a relationship with a risk management consultant.
Innovation, Science and Economic Development Canada (ISED) runs the CyberSecure Canada certification program, a baseline cybersecurity standard designed specifically for small and medium businesses. Beyond the direct security benefit, certification under this program can support a stronger cyber insurance application and, for businesses leaning toward self-insurance, provides an external benchmark for what "reasonably secure" looks like — useful both for internal confidence and for demonstrating due diligence if an incident and any resulting dispute ever occurs.
The Office of the Privacy Commissioner of Canada (OPC) is the regulator whose guidance and breach-reporting requirements directly drive a meaningful share of the cost side of the self-insurance math under discussion in this article. Under PIPEDA, organizations must report breaches posing a real risk of significant harm to both affected individuals and the OPC, and must keep records of every breach assessed, even ones not ultimately reportable. Reviewing the OPC's breach reporting guidance before finalizing a self-insurance reserve estimate is one of the most concrete ways to make sure the regulatory cost component of that estimate isn't underbuilt.
Frequently Asked Questions
Get an Honest Read on Your Actual Exposure
Before deciding to self-insure, a policy, or a hybrid approach, it helps to know exactly what you're protecting — and what a realistic incident would actually cost your specific business. IT Cares can help.
Comments (3)
The expected-loss vs premium markup explanation finally made this click for me. I run a tiny shop and always assumed insurance was a "just in case" purchase, never actually ran the numbers on our own reserve.
The e-commerce case study is basically our story. We had a near-miss last year and it took that scare to actually get quotes. Should have done it a year earlier.
The 5-year premium comparison against the actual incident cost is the number that convinced our partners we needed a policy after our own scare. Painful lesson but at least we learned it.
Leave a Comment