When a cyber incident strikes, the difference between a manageable disruption and an organizational catastrophe often depends on what happens in the first hours and days following detection. Cyber liability insurance exists precisely for these moments, but the mere existence of a policy does not guarantee coverage. The framework governing cyber incident response under an insurance policy creates reciprocal obligations between insurers and policyholders, and understanding these obligations before an incident occurs is essential for anyone managing cyber risk in a Canadian organization. This lesson examines how cyber insurance responds when called upon, what duties policyholders must fulfill to preserve their coverage, and how the claims process unfolds from initial breach detection through resolution.
The legal foundation for cyber insurance claims in Canada rests on provincial insurance legislation that, while not specifically drafted for cyber perils, applies to cyber policies through general principles governing all insurance contracts. The Insurance Act of Ontario, the Insurance Act of Alberta, the Financial Institutions Act of British Columbia, and equivalent statutes in other common law provinces establish baseline requirements for policy interpretation, claims handling, and the duties of both insurers and insureds. Quebec operates under a distinct framework where the Civil Code of Quebec governs insurance contracts, creating somewhat different interpretive principles though arriving at functionally similar outcomes in most cyber claims contexts. As of the date of authorship, no Canadian province has enacted cyber-specific insurance legislation, meaning that cyber liability policies are subject to the same statutory and common law principles that govern commercial general liability, professional liability, and other specialty lines products. Federal legislation also bears on cyber claims, most notably the Personal Information Protection and Electronic Documents Act which creates notification obligations that may trigger coverage and affect claims timelines, along with provincial privacy statutes such as the Personal Information Protection Act in both British Columbia and Alberta that impose their own requirements on organizations experiencing data breaches.