General Liability vs Cyber Insurance: The Difference

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian small business owner comparing a general liability insurance policy against a cyber insurance policy at a desk
Two policies, two entirely different kinds of risk — and neither one covers what the other was built for.
🛡️
Not sure if your current insurance would actually respond to a cyber incident? Our certified technicians can review your security posture so you and your broker have real answers.
Get a Free Assessment →

A surprising number of Canadian business owners assume their existing commercial insurance already covers a cyberattack, simply because it's described as covering "the business." It's an understandable assumption, and it's usually wrong. General liability insurance — the policy most businesses already carry — is built almost entirely around physical-world risk: a customer slipping on a wet floor, a contractor damaging a client's property, a product causing physical harm. It was never designed with ransomware, data breaches, or business email compromise in mind, and most modern policies say so explicitly, in the exclusions section most business owners have never actually read.

This matters because the gap only becomes visible at the worst possible moment: after an incident, when a business owner calls their broker expecting coverage and instead learns the claim falls outside what their policy was ever written to address. This guide walks through what general liability insurance actually covers, what cyber insurance adds, why one genuinely cannot substitute for the other, a direct comparison table, real Canadian scenarios where the gap caused real financial pain, a checklist to assess your own exposure, honest CAD cost ranges, and Canadian government resources for further guidance.

Who wrote this guide

This guide was written and reviewed by IT Cares certified technicians based on helping Canadian small and medium businesses recover from real cyber incidents — including, more than once, a business that discovered mid-crisis that its general liability policy explicitly excluded the exact situation it was facing. We're not an insurance brokerage and don't sell policies; this guide explains the distinction in plain language so you can have a more informed conversation with your own broker.

What General Liability Insurance Actually Covers

Commercial general liability (CGL) insurance is built to protect a business against claims brought by third parties for bodily injury, physical property damage, and certain advertising or reputational harms that arise from the ordinary course of doing business in the physical world. Typical scenarios it's designed for include:

What unites all of these examples is that the harm being claimed is physical, reputational in a traditional sense, or tied to a tangible product or premises. Data — its loss, its theft, its corruption, the cost of notifying people it was compromised — sits entirely outside that frame, which is precisely why insurers treat it as a separate risk category requiring separate underwriting.

📊 IT Cares field note: We've sat in more than one post-incident conversation where a business owner pulled out their general liability policy certain it would cover the ransomware attack they'd just experienced, only to find, on the page nobody had ever needed to read before, a clearly worded cyber and data exclusion clause. The policy wasn't written badly — it was simply never designed to cover this category of loss in the first place.

Want an honest read on your actual cyber exposure?

Our certified technicians will assess your systems so you and your insurance broker have real answers — from $119.99.

What Cyber Insurance Actually Covers

Cyber insurance is a dedicated policy built specifically around the financial fallout of a digital incident. Coverage details vary between insurers and policy tiers, but a typical, reasonably comprehensive cyber policy for an SMB includes:

Notice how little overlap exists between this list and the general liability list above. That's not an oversight in either policy — it's the entire point. Each policy was built by insurers to underwrite a specific, well-defined category of risk, and neither was designed with the other's scenarios in mind.

The one-sentence version

General liability protects you against claims from the physical world; cyber insurance protects you against the financial fallout of the digital world. A business carrying only one has, whether it realizes it or not, accepted full uninsured exposure to whichever category the missing policy would have covered.

Side-by-Side Comparison

Scenario General Liability Cyber Insurance
Customer slips and is injured in your store Covered Not covered
Ransomware encrypts your business's files Not covered (standard exclusion) Covered
Employee's laptop damages a client's desk during a service call Covered Not covered
Customer database is stolen in a data breach Not covered (standard exclusion) Covered
Business email compromise causes a fraudulent wire transfer Not covered Often covered (confirm with your specific policy)
Legal costs to notify customers of a data breach under privacy law Not covered Covered
Lost income while systems are down after a cyberattack Not covered Often covered as business interruption
A client sues over a defamatory statement in your advertising Often covered under advertising injury Not covered

Read plainly, the table makes the case for both policies simultaneously: nearly every row has a clear winner, and almost none overlap. A business relying on only one policy is fully covered for exactly half the risk categories a modern SMB actually faces, and fully exposed for the other half.

Why One Genuinely Doesn't Replace the Other

The confusion here usually comes from a reasonable-sounding but incorrect assumption: "my general liability policy covers my business, so it should cover anything that happens to my business." Insurance doesn't work that way — every policy is underwritten against a specific, defined scope of risk, priced accordingly, and explicitly bounded by its exclusions. General liability insurers price their policies based on physical-world risk data (slip-and-fall statistics, property damage claim history) and exclude cyber risk specifically because it's a fundamentally different actuarial category requiring its own risk modeling, its own claims history, and its own pricing.

This isn't insurers looking for a loophole to deny claims — it's the structural reason cyber insurance exists as a distinct product line at all. Trying to get a general liability policy to cover a data breach is a bit like trying to file a car accident claim on a home insurance policy: both are legitimate insurance products covering real risk, but neither was built to answer the other's claims, and no amount of good faith changes what the policy was actually underwritten to cover.

The mistake we see most often

A business assumes "we have insurance" is a complete answer without asking "insurance for what, specifically?" The two policies were built by insurers for entirely different risk categories, and only one business owner in the room usually knows that distinction going into an incident — often the broker, rarely the business owner, until the claim is already being filed.

Real-World Scenarios: When the Gap Cost Real Money

The following are composite scenarios based on patterns IT Cares technicians have encountered across Canadian small business clients, anonymized and combined rather than describing any single identifiable client.

Case study 1: The retailer who assumed general liability covered the ransomware attack (Mississauga, ON)

A 22-employee specialty retailer in Mississauga was hit with ransomware that encrypted its point-of-sale and inventory systems for four days. The owner filed a claim under the business's existing general liability policy, confident it would cover the loss, and was informed roughly two weeks later that the policy's standard cyber and electronic data exclusion applied — the claim was denied in full. With no cyber policy in place, the business absorbed the entire cost itself: approximately $31,000 CAD in lost sales during the outage, $6,500 CAD in IT recovery costs, and no reimbursement of any kind, a total loss that a modest cyber policy, at a fraction of that annual cost, would very likely have substantially offset.

Case study 2: The accounting firm with both policies, correctly used (Kitchener, ON)

A 9-person accounting firm in Kitchener carried both general liability and a standalone cyber policy after a broker specifically flagged the gap during a renewal conversation. When the firm experienced a business email compromise resulting in a fraudulent $18,000 CAD wire transfer attempt, the cyber policy's coverage for BEC-related fraud combined with forensic investigation coverage meant the firm's out-of-pocket cost was limited to its policy deductible of $2,500 CAD, with the investigation, notification process, and a portion of the financial loss covered by the policy. The firm's broker specifically credited having asked the right coverage question at renewal, rather than assuming the existing general liability policy already had it covered.

Case study 3: The medical clinic with a data breach and no cyber coverage (London, ON)

A small medical clinic in London experienced a breach exposing patient contact and limited health information for approximately 900 patients. With only a general liability policy in place, the clinic had no coverage for the legal costs of determining its notification obligations, no coverage for the credit monitoring it chose to offer affected patients as a goodwill gesture, and no coverage for the forensic investigation required to confirm the scope of the breach. Total out-of-pocket cost, borne entirely by the clinic with no insurance offset, came to approximately $47,000 CAD — a cost the clinic's own post-incident review specifically flagged as the single clearest argument for adding a dedicated cyber policy going forward, given the clinic's ongoing handling of sensitive health information.

Insurance Gap-Check Checklist

Use this checklist to gauge your business's actual insurance exposure, not how covered you assume you are:

If more than two or three of these are unchecked, that's a clear, specific conversation to have with your broker at your next renewal — most businesses discover the answer to at least one of these only after an incident has already happened, which is exactly the pattern this guide is meant to help avoid.

Cost Reality Check for Canadian SMBs

Cyber insurance premiums vary based on industry, revenue, data volume, and existing security controls. Here's how it typically breaks down by rough company profile:

These are directional ranges to help with budgeting conversations, not a fixed quote — actual premium depends on a formal underwriting process specific to your business. What's consistent across every tier: businesses with strong existing security controls (MFA, tested backups, endpoint detection) routinely qualify for materially lower premiums than those without, which is a meaningful additional argument for the security fundamentals covered throughout our cybersecurity budget guide.

Want your security posture assessed before your next insurance renewal?

IT Cares' security audits give you a documented, honest picture of your actual security controls — the same details insurers ask about on a cyber application — so you walk into a renewal conversation with real answers instead of guesses. Our cybersecurity services and managed IT services can help close specific gaps identified along the way.

Canadian Government Resources

Several Canadian government and institutional bodies publish free, genuinely useful resources relevant to business insurance and cyber risk planning:

None of these bodies sell or recommend specific insurance products, but their published guidance is a useful, neutral reference point when evaluating your own coverage against real regulatory obligations, particularly around privacy breach notification requirements that a cyber policy is specifically designed to help fund.

Frequently Asked Questions

Does general liability insurance cover a ransomware attack?
In almost all standard commercial general liability policies, no. Most modern general liability policies contain explicit exclusions for cyber incidents, data breaches, and electronic data loss, specifically because insurers underwrite that risk separately through dedicated cyber insurance policies. A business relying on general liability alone should assume a ransomware attack, data breach, or business email compromise would not be covered unless a specific cyber endorsement or standalone cyber policy is in place.
What exactly does cyber insurance cover that general liability doesn't?
Cyber insurance typically covers costs specific to a digital incident: forensic investigation to determine what happened, legal costs for breach notification compliance, credit monitoring for affected individuals, ransom negotiation and payment in some policies, business interruption income lost during system downtime, and third-party liability if a client sues over a breach originating from your systems. General liability, by contrast, covers physical bodily injury and property damage claims from third parties — a customer slipping in your office, for example — and was never designed to address purely digital, data-related losses.
Do I need both general liability and cyber insurance?
For almost any business handling customer data, accepting electronic payments, or depending on IT systems to operate, yes — the two policies cover fundamentally different risks and neither substitutes for the other. General liability protects against physical and reputational harm claims from third parties in the physical world; cyber insurance protects against the financial fallout of a digital incident. A business carrying only one is knowingly or unknowingly accepting full, uninsured exposure to whichever risk category the missing policy would have covered.
How much does cyber insurance cost for a small business in Canada?
Premiums vary based on industry, revenue, data volume, and existing security controls, but small businesses typically see annual premiums somewhere in the range of $750 to $5,000 CAD for a modest coverage limit, with cost rising for higher limits, higher-risk industries (healthcare, finance, legal), or businesses that store large volumes of sensitive customer data. Businesses with strong existing security controls (MFA, tested backups, endpoint detection) often qualify for meaningfully lower premiums than those without.
Will my insurer deny a cyber claim if I didn't have basic security controls in place?
This is an increasingly common and serious risk. Many cyber insurance applications ask direct questions about MFA, backup practices, and endpoint protection, and a material misrepresentation on that application — claiming a control was in place when it wasn't — can be grounds for a denied claim after an incident. Insurers have denied claims specifically over this issue, which is exactly why security controls should be verified as actually implemented, not just assumed, before a policy is bound.
Does cyber insurance cover the cost of paying a ransom?
Many, though not all, cyber insurance policies include coverage for ransom payments as part of extortion coverage, often alongside professional ransom negotiation services. Coverage details, limits, and whether ransom payment is included at all vary significantly between policies and insurers, so this is a specific point worth confirming directly with a broker rather than assuming it's automatically included in every cyber policy.
What's a professional liability (errors and omissions) policy, and is it different from cyber insurance too?
Yes, it's a third distinct category. Professional liability (errors and omissions) insurance covers claims that a business's professional advice, service, or work product caused a client financial harm — for example, a consultant being sued for a mistake in delivered work. It's related to but distinct from cyber insurance, which covers incidents involving data breaches and system compromise specifically. Some insurers bundle limited cyber coverage into a professional liability policy, but the scope is usually narrower than a dedicated cyber policy, so it's worth confirming exactly what's included rather than assuming full cyber protection comes bundled in.
Does having cyber insurance mean I don't need strong cybersecurity controls?
No — if anything, the opposite is increasingly true. Cyber insurers are tightening underwriting requirements and routinely require MFA, tested backups, and endpoint protection as a condition of coverage, sometimes verified through a security questionnaire or audit before binding a policy. Strong security controls also reduce the odds a claim is ever needed in the first place and can lower your premium, so cyber insurance should be viewed as a financial backstop layered on top of real security practices, not a substitute for them.

Want a Real Picture of Your Cyber Risk Before Your Next Renewal?

IT Cares reviews your actual security posture so you and your insurance broker have real answers, not guesses.

Comments (3)

FL
François L., Longueuil
July 21, 2026

We genuinely thought general liability had this covered until reading this. Called our broker the same day and confirmed the exclusion clause was exactly as described.

DP
Diane P., Oakville
July 20, 2026

The comparison table made it click instantly — we have both policies now and finally understand why they're priced so differently.

MG
Marc G., Saint-Jean-sur-Richelieu
July 19, 2026

The London clinic case study was a wake-up call about the notification and credit monitoring costs — we hadn't even considered those as a separate expense category.

Leave a Comment

Need Help?