A surprising number of Canadian business owners assume their existing commercial insurance already covers a cyberattack, simply because it's described as covering "the business." It's an understandable assumption, and it's usually wrong. General liability insurance — the policy most businesses already carry — is built almost entirely around physical-world risk: a customer slipping on a wet floor, a contractor damaging a client's property, a product causing physical harm. It was never designed with ransomware, data breaches, or business email compromise in mind, and most modern policies say so explicitly, in the exclusions section most business owners have never actually read.
This matters because the gap only becomes visible at the worst possible moment: after an incident, when a business owner calls their broker expecting coverage and instead learns the claim falls outside what their policy was ever written to address. This guide walks through what general liability insurance actually covers, what cyber insurance adds, why one genuinely cannot substitute for the other, a direct comparison table, real Canadian scenarios where the gap caused real financial pain, a checklist to assess your own exposure, honest CAD cost ranges, and Canadian government resources for further guidance.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians based on helping Canadian small and medium businesses recover from real cyber incidents — including, more than once, a business that discovered mid-crisis that its general liability policy explicitly excluded the exact situation it was facing. We're not an insurance brokerage and don't sell policies; this guide explains the distinction in plain language so you can have a more informed conversation with your own broker.
What General Liability Insurance Actually Covers
Commercial general liability (CGL) insurance is built to protect a business against claims brought by third parties for bodily injury, physical property damage, and certain advertising or reputational harms that arise from the ordinary course of doing business in the physical world. Typical scenarios it's designed for include:
- A customer or visitor is physically injured on your premises — a slip-and-fall in a retail store, an injury during a service call at a client's home or office.
- Your business damages someone else's physical property — a contractor accidentally damaging a client's flooring, a delivery causing damage to a customer's goods.
- A product your business sells or made causes physical harm — often covered under a related products liability extension.
- Certain advertising injury claims — such as accusations of copyright infringement or defamation in marketing materials, in some policies.
What unites all of these examples is that the harm being claimed is physical, reputational in a traditional sense, or tied to a tangible product or premises. Data — its loss, its theft, its corruption, the cost of notifying people it was compromised — sits entirely outside that frame, which is precisely why insurers treat it as a separate risk category requiring separate underwriting.
📊 IT Cares field note: We've sat in more than one post-incident conversation where a business owner pulled out their general liability policy certain it would cover the ransomware attack they'd just experienced, only to find, on the page nobody had ever needed to read before, a clearly worded cyber and data exclusion clause. The policy wasn't written badly — it was simply never designed to cover this category of loss in the first place.
Want an honest read on your actual cyber exposure?
Our certified technicians will assess your systems so you and your insurance broker have real answers — from $119.99.
What Cyber Insurance Actually Covers
Cyber insurance is a dedicated policy built specifically around the financial fallout of a digital incident. Coverage details vary between insurers and policy tiers, but a typical, reasonably comprehensive cyber policy for an SMB includes:
- Forensic investigation costs — hiring specialists to determine what happened, how the attacker got in, and what data was accessed, which is often required before a business can even confirm the scope of an incident.
- Legal costs for breach notification compliance — determining and fulfilling your obligations under privacy law, including notifying affected individuals and regulators such as the Office of the Privacy Commissioner of Canada where required.
- Credit monitoring for affected individuals — commonly offered to customers or employees whose personal information was exposed, both as a good-faith gesture and sometimes as a notification requirement.
- Business interruption / lost income coverage — compensating for revenue lost while systems are down and being restored, in some policies calculated against a documented RTO similar to the concept covered in our business continuity guide.
- Extortion / ransom coverage — negotiation assistance and, in many policies, coverage of the ransom payment itself, subject to policy terms and increasingly subject to regulatory and insurer scrutiny.
- Third-party liability — coverage if a client or customer sues your business over a breach that exposed their data, which is the one place cyber insurance's coverage can start to resemble a liability policy, but specifically scoped to data-related claims rather than physical harm.
Notice how little overlap exists between this list and the general liability list above. That's not an oversight in either policy — it's the entire point. Each policy was built by insurers to underwrite a specific, well-defined category of risk, and neither was designed with the other's scenarios in mind.
The one-sentence version
General liability protects you against claims from the physical world; cyber insurance protects you against the financial fallout of the digital world. A business carrying only one has, whether it realizes it or not, accepted full uninsured exposure to whichever category the missing policy would have covered.
Side-by-Side Comparison
| Scenario | General Liability | Cyber Insurance |
|---|---|---|
| Customer slips and is injured in your store | Covered | Not covered |
| Ransomware encrypts your business's files | Not covered (standard exclusion) | Covered |
| Employee's laptop damages a client's desk during a service call | Covered | Not covered |
| Customer database is stolen in a data breach | Not covered (standard exclusion) | Covered |
| Business email compromise causes a fraudulent wire transfer | Not covered | Often covered (confirm with your specific policy) |
| Legal costs to notify customers of a data breach under privacy law | Not covered | Covered |
| Lost income while systems are down after a cyberattack | Not covered | Often covered as business interruption |
| A client sues over a defamatory statement in your advertising | Often covered under advertising injury | Not covered |
Read plainly, the table makes the case for both policies simultaneously: nearly every row has a clear winner, and almost none overlap. A business relying on only one policy is fully covered for exactly half the risk categories a modern SMB actually faces, and fully exposed for the other half.
Why One Genuinely Doesn't Replace the Other
The confusion here usually comes from a reasonable-sounding but incorrect assumption: "my general liability policy covers my business, so it should cover anything that happens to my business." Insurance doesn't work that way — every policy is underwritten against a specific, defined scope of risk, priced accordingly, and explicitly bounded by its exclusions. General liability insurers price their policies based on physical-world risk data (slip-and-fall statistics, property damage claim history) and exclude cyber risk specifically because it's a fundamentally different actuarial category requiring its own risk modeling, its own claims history, and its own pricing.
This isn't insurers looking for a loophole to deny claims — it's the structural reason cyber insurance exists as a distinct product line at all. Trying to get a general liability policy to cover a data breach is a bit like trying to file a car accident claim on a home insurance policy: both are legitimate insurance products covering real risk, but neither was built to answer the other's claims, and no amount of good faith changes what the policy was actually underwritten to cover.
The mistake we see most often
A business assumes "we have insurance" is a complete answer without asking "insurance for what, specifically?" The two policies were built by insurers for entirely different risk categories, and only one business owner in the room usually knows that distinction going into an incident — often the broker, rarely the business owner, until the claim is already being filed.
Real-World Scenarios: When the Gap Cost Real Money
The following are composite scenarios based on patterns IT Cares technicians have encountered across Canadian small business clients, anonymized and combined rather than describing any single identifiable client.
Case study 1: The retailer who assumed general liability covered the ransomware attack (Mississauga, ON)
A 22-employee specialty retailer in Mississauga was hit with ransomware that encrypted its point-of-sale and inventory systems for four days. The owner filed a claim under the business's existing general liability policy, confident it would cover the loss, and was informed roughly two weeks later that the policy's standard cyber and electronic data exclusion applied — the claim was denied in full. With no cyber policy in place, the business absorbed the entire cost itself: approximately $31,000 CAD in lost sales during the outage, $6,500 CAD in IT recovery costs, and no reimbursement of any kind, a total loss that a modest cyber policy, at a fraction of that annual cost, would very likely have substantially offset.
Case study 2: The accounting firm with both policies, correctly used (Kitchener, ON)
A 9-person accounting firm in Kitchener carried both general liability and a standalone cyber policy after a broker specifically flagged the gap during a renewal conversation. When the firm experienced a business email compromise resulting in a fraudulent $18,000 CAD wire transfer attempt, the cyber policy's coverage for BEC-related fraud combined with forensic investigation coverage meant the firm's out-of-pocket cost was limited to its policy deductible of $2,500 CAD, with the investigation, notification process, and a portion of the financial loss covered by the policy. The firm's broker specifically credited having asked the right coverage question at renewal, rather than assuming the existing general liability policy already had it covered.
Case study 3: The medical clinic with a data breach and no cyber coverage (London, ON)
A small medical clinic in London experienced a breach exposing patient contact and limited health information for approximately 900 patients. With only a general liability policy in place, the clinic had no coverage for the legal costs of determining its notification obligations, no coverage for the credit monitoring it chose to offer affected patients as a goodwill gesture, and no coverage for the forensic investigation required to confirm the scope of the breach. Total out-of-pocket cost, borne entirely by the clinic with no insurance offset, came to approximately $47,000 CAD — a cost the clinic's own post-incident review specifically flagged as the single clearest argument for adding a dedicated cyber policy going forward, given the clinic's ongoing handling of sensitive health information.
Insurance Gap-Check Checklist
Use this checklist to gauge your business's actual insurance exposure, not how covered you assume you are:
- ☐ We have read the cyber/data exclusion clause in our current general liability policy
- ☐ We have asked our broker directly, in writing, whether a ransomware attack would be covered
- ☐ We have a standalone cyber insurance policy, not just an assumption that we're "covered somehow"
- ☐ We know our cyber policy's coverage limit and whether it's realistic against our actual data volume and revenue
- ☐ We know whether our cyber policy covers business email compromise / wire fraud specifically
- ☐ We know whether ransom payment is included in our extortion coverage, if applicable
- ☐ We have confirmed the security controls our cyber policy requires (MFA, backup, EDR) are actually implemented, not just assumed
- ☐ We review both policies together at each renewal, not on a set-and-forget basis
- ☐ We know our policy's incident notification window and reporting requirements
- ☐ We have a named contact (broker or provider) to call immediately if an incident occurs
If more than two or three of these are unchecked, that's a clear, specific conversation to have with your broker at your next renewal — most businesses discover the answer to at least one of these only after an incident has already happened, which is exactly the pattern this guide is meant to help avoid.
Cost Reality Check for Canadian SMBs
Cyber insurance premiums vary based on industry, revenue, data volume, and existing security controls. Here's how it typically breaks down by rough company profile:
- Very small business (1–10 employees, limited sensitive data): Often achievable in the range of $750–$2,000 CAD/year for a modest coverage limit, particularly with basic security controls like MFA and tested backups already in place.
- Small business (10–30 employees, moderate customer data volume): Typically lands in the $1,500–$4,000 CAD/year range, scaling with coverage limit and industry risk profile.
- Growing SMB or higher-risk industry (healthcare, finance, legal, larger customer data volumes): Premiums commonly run $3,000–$10,000+ CAD/year, reflecting both higher coverage limits and the increased regulatory and breach-notification exposure these industries carry.
These are directional ranges to help with budgeting conversations, not a fixed quote — actual premium depends on a formal underwriting process specific to your business. What's consistent across every tier: businesses with strong existing security controls (MFA, tested backups, endpoint detection) routinely qualify for materially lower premiums than those without, which is a meaningful additional argument for the security fundamentals covered throughout our cybersecurity budget guide.
Want your security posture assessed before your next insurance renewal?
IT Cares' security audits give you a documented, honest picture of your actual security controls — the same details insurers ask about on a cyber application — so you walk into a renewal conversation with real answers instead of guesses. Our cybersecurity services and managed IT services can help close specific gaps identified along the way.
Canadian Government Resources
Several Canadian government and institutional bodies publish free, genuinely useful resources relevant to business insurance and cyber risk planning:
- BDC (Business Development Bank of Canada, bdc.ca): Publishes practical business risk management and insurance-planning resources aimed specifically at Canadian small and medium businesses as part of its broader advisory content.
- ISED (Innovation, Science and Economic Development Canada, ised-isde.canada.ca): Canada's federal department for business innovation and growth publishes small business cybersecurity and risk-planning guidance relevant to understanding cyber exposure.
- OPC (Office of the Privacy Commissioner of Canada, priv.gc.ca): Publishes detailed guidance on breach notification obligations under PIPEDA — directly relevant to understanding what a cyber policy's notification coverage needs to actually address.
None of these bodies sell or recommend specific insurance products, but their published guidance is a useful, neutral reference point when evaluating your own coverage against real regulatory obligations, particularly around privacy breach notification requirements that a cyber policy is specifically designed to help fund.
Frequently Asked Questions
Want a Real Picture of Your Cyber Risk Before Your Next Renewal?
IT Cares reviews your actual security posture so you and your insurance broker have real answers, not guesses.
Comments (3)
We genuinely thought general liability had this covered until reading this. Called our broker the same day and confirmed the exclusion clause was exactly as described.
The comparison table made it click instantly — we have both policies now and finally understand why they're priced so differently.
The London clinic case study was a wake-up call about the notification and credit monitoring costs — we hadn't even considered those as a separate expense category.
Leave a Comment