CLEVA ITSolutions
Back to Blog
CybersecurityMarch 20, 20257 min read

Cyber Insurance for Alberta Businesses: What's Covered, What Isn't, and How to Qualify

Cyber insurance premiums have risen 80% since 2022. Insurers are now rejecting businesses that can't demonstrate basic security controls. Here's how to qualify — and what the policy actually covers.

By Cleva IT Solutions

Two years ago, any Alberta business could obtain cyber insurance with minimal scrutiny. A brief questionnaire, a competitive premium, and you were covered. Those days are over.

The frequency and severity of ransomware attacks have forced a reckoning in the cyber insurance market. Insurers have paid out more in claims than they collected in premiums in several recent years. The response: dramatically higher premiums, far stricter underwriting requirements, and outright rejection of applicants who can't demonstrate basic cybersecurity controls.

For Alberta businesses that don't carry cyber insurance, the risk exposure is existential. For those that do, the policy language has become more restrictive. This guide covers everything you need to know.

What Cyber Insurance Actually Covers

A comprehensive cyber insurance policy typically covers:

First-Party Costs (your losses)

  • Business interruption: Revenue loss during a cyber incident that takes systems offline
  • Data recovery: Cost of restoring or recreating data lost or encrypted in an attack
  • Ransomware payments: Some policies cover ransom payments (increasingly controversial and restricted)
  • Crisis management: Public relations and communications management after a breach
  • Forensics and investigation: Cost of determining what happened, how, and what data was accessed

Third-Party Liability (claims against you)

  • Privacy breach liability: Claims from individuals whose personal information was exposed
  • Regulatory defense and fines: Legal defense and, in some policies, regulatory fines from the OPC or CRTC
  • Notification costs: PIPEDA requires notification to affected individuals; policies may cover these costs
  • Network security liability: Claims that your security failure enabled an attack on a third party

What's Typically Excluded

  • Property damage from a cyber event (separate policy required)
  • War and nation-state attacks (significant and growing exclusion)
  • Prior known incidents (attacks that started before the policy period)
  • Social engineering fraud (wire transfer fraud is sometimes excluded or sublimited)
  • Bodily injury arising from a cyber event
  • Cryptojacking and certain types of financial fraud

Read the exclusions carefully. Many business owners assume cyber insurance covers "everything digital" — it doesn't.

The New Underwriting Requirements

The questions on a 2025 cyber insurance application look nothing like 2020. Insurers are now asking specifically about technical controls, and applications that can't answer these questions correctly either get rejected or receive dramatically restricted coverage at premium rates.

Multi-Factor Authentication (MFA) This is now the single most important factor in cyber underwriting. Insurers want to see MFA on:

  • Remote access (VPN, RDP, remote desktop solutions)
  • Email (Microsoft 365 or Google Workspace admin access)
  • Cloud infrastructure (AWS, Azure, GCP)
  • Financial systems and banking portals
  • Privileged administrative accounts

Applications without MFA on remote access are frequently rejected outright.

Endpoint Detection and Response (EDR) Basic antivirus is no longer sufficient. Insurers want EDR solutions — tools that provide continuous monitoring, behavioral detection, and response capability beyond signature-based antivirus. Microsoft Defender for Business (included in Microsoft 365 Business Premium), CrowdStrike Falcon, SentinelOne, and similar tools satisfy this requirement.

Privileged Access Management Limiting which accounts have administrative access — and monitoring what those accounts do — is increasingly required by larger policies.

Backup and Recovery Insurers want to see: regular, tested backups; backups stored separately from production systems (air-gapped or immutable); demonstrated ability to recover within a defined timeframe. "We have backups" is no longer sufficient — they want evidence of tested recovery.

Security Awareness Training Many insurers now require documented, annual cybersecurity training for all employees, including phishing simulation exercises.

Patch Management Evidence of a formal process for applying security patches within defined windows (typically 30 days for critical patches).

Incident Response Plan A documented plan for how your organization responds to a cyber incident — who does what, in what order, with what external resources engaged.

How Premiums Are Calculated for Alberta Businesses

Cyber insurance premiums for Canadian SMBs are based on:

  • Revenue: Higher revenue = higher premium (greater business interruption value)
  • Industry: Healthcare, financial services, and legal typically pay more (sensitive data, regulatory exposure)
  • Data handled: Volume and sensitivity of personal information stored
  • Security controls: The single biggest variable — better controls = lower premiums
  • Claims history: Any prior cyber incidents significantly affect pricing
  • Coverage limits and deductibles: Higher limits cost more; higher deductibles reduce premiums

A 25-person professional services firm in Edmonton with strong security controls and $5M in liability coverage typically pays $8,000–$15,000/year in premiums. The same firm with weak controls may pay $20,000–$35,000 or be declined.

Getting Ready for Your Cyber Insurance Application

Before applying or renewing, conduct an honest assessment against the underwriting requirements above.

Immediate priorities (if not in place):

  1. Deploy MFA on all remote access and cloud services — this is the minimum standard
  2. Upgrade endpoint protection from basic antivirus to EDR
  3. Verify that backups exist, are current, and have been successfully tested
  4. Document an incident response plan, even a simple one

Before your application:

  • Prepare evidence of security controls (not just assertions)
  • Document your security training program
  • Be accurate — misrepresentation on a cyber insurance application can void coverage when you need it most

Working with your broker: Cyber insurance is complex enough that working with a broker who specializes in technology or professional risks is worthwhile. They can help you navigate policy language, negotiate terms, and ensure coverage aligns with your actual risk exposure.

The PIPEDA Notification Obligation

Alberta businesses handling personal information need to understand their legal obligations beyond insurance.

Under PIPEDA, organizations must notify the Office of the Privacy Commissioner of Canada (OPC) of any breach that poses a "real risk of significant harm" to individuals. They must also notify affected individuals. Failure to notify carries fines up to $100,000 per violation.

Alberta has its own health information privacy legislation (HIA) with additional requirements for healthcare organizations.

Cyber insurance can cover the cost of managing these notifications — but it can't protect you from the regulatory consequences of failing to notify when required.

What Cleva IT Helps Alberta Businesses Do

We help Alberta businesses meet cyber insurance requirements through:

  • Security gap assessment: Identifying which controls you have, which you lack, and what's required
  • MFA deployment: Configuring and rolling out multi-factor authentication across your environment
  • EDR deployment: Installing and managing endpoint detection and response tools
  • Backup verification: Testing your backup and recovery capability and documenting the results
  • Security awareness training: Delivering phishing simulation and security education programs
  • Incident response planning: Developing a documented response plan appropriate for your business size

If you're facing a cyber insurance renewal or application and aren't sure whether your controls will meet underwriting requirements, we can conduct a pre-application security assessment that gives you a clear picture of where you stand.

A cyber incident without insurance — or with coverage that doesn't pay due to inadequate controls — can end a Canadian business. The investment in qualifying controls is a fraction of the downside risk.

More in Cybersecurity

Ransomware Recovery Guide for Canadian SMBs: What to Do in the First 72 Hours

8 min read

The 5 Cybersecurity Mistakes Canadian SMBs Make — and How to Fix Them

8 min read

PIPEDA Compliance in 2025: What Every Canadian Business Must Know

9 min read