Does a cyber policy guarantee you will be paid?
Short answer: no. The question is no longer the price of the premium but eligibility and whether coverage holds. A growing share of claims is denied or partially denied, almost always for the same reason: a gap between the security controls declared on the underwriting application and what the forensic investigation actually observes at the time of loss.
The Canadian market has stabilized. After two years of sharp rate increases, premiums have levelled off. But insurers have shifted their approach: rather than pricing the risk, they select it. Multi-factor authentication, endpoint detection and response, offline backups and an incident response plan have become conditions of access, not pricing bonuses.
And it is precisely at that selection point that indemnity disputes now arise.
The five most common causes of denial
1. MFA declared but incomplete
The application asks: "Is MFA deployed across all remote access and all privileged accounts?" The box is ticked yes. Forensics shows the service account the attacker used, the managed service provider's access or the cloud administration console was exempt.
A recent technical nuance compounds this: several carriers no longer treat SMS codes or simple push notifications as sufficient for sensitive accounts. Number matching has become the floor, and phishing-resistant MFA the reference standard.
2. Partial EDR coverage
The overwhelming majority of underwriters now require endpoint detection and response across all managed devices : traditional antivirus alone will not secure the policy. The dispute arises around the word "all": legacy servers, hypervisors, contractor laptops and production machines are frequently out of scope, and those are exactly what the attacker uses.
3. Backups that are neither immutable nor tested
The declaration mentions offline backups. The incident reveals a permanently mounted network share, encrypted along with everything else. Or an offsite copy never restored, whose gaps surface at the worst possible moment. The impact is not only denial: it drives downtime, and therefore the size of the loss itself.
4. Late notification
Policies impose short reporting deadlines, sometimes 72 hours from discovery. An organization that first tries to handle things alone, then calls its broker a week later, exposes itself to reduced indemnity : especially since costs incurred before insurer consent are not always covered.
5. Using non-panel responders
Many policies impose a panel: breach counsel, forensic team, negotiator. Engaging a provider outside the panel without prior approval can void coverage of those costs, even when the work is impeccable.
What the forensic investigation actually verifies
When a loss occurs, the insurer appoints a forensic team whose report serves two purposes: understanding the incident and verifying the substance of the declarations. Concretely, the team examines:
Authentication logs : which accounts, with which factors, from which addresses and devices
Actual EDR coverage : agent inventory, versions, configured exclusions
Backup history : dates, scope, immutability, last tested restore
Patch levels : known unpatched vulnerabilities on exposed assets
Response timeline : time of detection, time of notification, decisions taken
None of this is declarative. All of it is verifiable after the fact in the logs. That is why the best protection against denial is to build the evidence before the loss.
How to protect your indemnity
Have the application completed by the people who operate the systems, not by management alone, and keep evidence for every answer (configuration screenshots, inventory reports, restore test logs)
Date and archive that evidence at every renewal: this is the file that will protect you three years later
Handle exceptions explicitly: if a legacy system cannot take MFA, declare it and document the compensating control instead of ticking yes
Time a restoration test every quarter and keep the report
Pre-clear your responders: confirm with your broker that your usual response team is accepted, before you need them
Notify fast, even with an incomplete diagnosis : an early notification can be corrected, a late one cannot
SMB underinsurance remains the blind spot
Only a small minority of Canadian small businesses carry a standalone cyber policy. Many rely on an endorsement to their commercial insurance, whose limits (often a few tens of thousands of dollars) bear no relation to the real cost of an incident, which runs into the hundreds of thousands.
The right question for your broker is not "am I covered?" but "how much, for which cost categories, and under which control conditions?". Forensics, negotiation, restoration, individual notification, business interruption and third-party liability are not automatically included.
The ITCS Group angle
We work both sides of the table: forensics on behalf of insurers, and advisory work for organizations before and during a loss. That dual position lets us prepare an underwriting file that survives investigation, document the expected evidence, and mobilize in under two hours when an incident hits. Contact us for a review of your underwriting application before your next renewal.
Sources
McCarthy Tétrault : Cyber Insurance Trends: 2026 Privacy Breach Insights
Marsh : 2026 cyber insurance market outlook
ITCS Group forensic engagements for insurers : 2024-2026