A report aired by QUB radio highlights a hacking case whose losses reportedly were not covered by a standard insurance policy. Precise details of the incident remain limited, but the underlying point applies directly to Quebec SMBs and nonprofits.
Key points
- Standard insurance policies often exclude cyber risks, leaving SMBs exposed to uncovered financial losses.
- According to the report, details of the attack remain limited, but the warning about insurance gaps is clear and applies broadly.
- Dedicated cyber insurance can fill some of these gaps, but it does not replace prevention or an incident response plan.
- Reviewing the exclusions in an insurance contract and formalizing an incident response plan reduces an organization’s financial exposure.
What happened, according to available information?
According to a QUB radio report, a hacking case highlighted that the losses suffered by the affected company were not covered by its standard insurance, as cyber risks are often among the common exclusions in standard business policies.
According to the report, precise details of the incident, including the sector affected, the exact nature of the intrusion, and the amount of the losses, have not been made public. What the report highlights is a broader point: cyber risks, much like certain climate related risks, often fall outside general business insurance contracts. No available information makes it possible to attribute this attack to a specific group or to pinpoint the exact date or location of the incident.
Why are cyber risks often excluded from standard insurance?
Traditional business insurance policies were designed for physical risks such as fire, theft, and water damage, and do not automatically cover losses tied to a computer intrusion, data exfiltration, or a business interruption caused by a cyberattack, unless a specific rider is added.
Historically, general business insurance contracts were built around physical, measurable hazards. Losses tied to a cyberattack, such as business interruption, restoration costs, extortion, and reputational harm, follow a different logic and are often classified as explicit or implicit exclusions in standard policies. This is why dedicated insurance products, known as cyber insurance, now exist on the market, each with its own conditions and limits.
What does this mean for a Quebec SMB or nonprofit?
Without adequate cyber coverage, an organization hit by an attack must absorb on its own the costs of system restoration, crisis management, and potentially notifying affected individuals, which can weigh heavily on its cash flow and operational continuity.
SMBs and nonprofits generally have less financial cushion than larger organizations to absorb an unexpected shock. An uncovered incident can therefore weaken an organization over the long term, even when the attack itself was contained quickly from a technical standpoint. Insurance coverage thus becomes a governance issue, on par with cybersecurity itself.
How can this exposure be reduced before an incident occurs?
Reviewing the exclusion clauses in an insurance contract, applying the baseline cybersecurity controls recommended for small organizations, and keeping an incident register in line with Quebec obligations are concrete steps that make this scenario far harder to face unprepared.
A first step is to ask a broker or insurer for a clear reading of the exclusions related to computer incidents. At the same time, applying baseline controls, such as isolated backups, access management, system updates, and staff awareness training on phishing, reduces the likelihood of an incident occurring and makes recovery easier if one happens anyway. These measures do not rule out any scenario, but they make the overall picture much harder for an attacker to exploit.
FAQ
Is cyber insurance mandatory for SMBs in Quebec?
No, no Quebec law currently requires a business to hold cyber insurance. What the legal framework does impose, through the Act respecting the protection of personal information in the private sector, are security obligations, the maintenance of a confidentiality incident register, and, in certain cases, notification to the Commission d’accès à l’information (Quebec’s access to information and privacy regulator) and to the affected individuals. Cyber insurance remains a risk management choice, separate from these legal obligations. Every client’s situation is unique, which makes it impossible to honestly quote a single flat rate; whether such coverage makes sense depends on the nature of the organization’s activities, the data it handles, and its risk tolerance.
What must a Quebec organization do after a confidentiality breach?
The Act respecting the protection of personal information in the private sector, overseen by the Commission d’accès à l’information du Québec, requires organizations to maintain a confidentiality incident register and, when an incident poses a risk of serious harm, to notify the Commission as well as the individuals whose personal information is affected. These obligations apply regardless of whether insurance covers the associated financial losses. They also apply to nonprofit organizations that handle personal information, not only larger for-profit businesses.
How can an organization assess whether it is sufficiently prepared for this type of risk?
There is no single indicator that confirms sufficient preparation, but certain checks give a reliable picture of actual exposure: reviewing the exclusions in the current insurance contract, verifying whether the baseline cybersecurity controls recommended for small and medium organizations are in place, confirming the existence of an incident register and a tested response plan, and making sure backups are isolated from the main network. These checks do not rule out an incident, but they significantly reduce exposure and make a faster recovery possible if an incident occurs anyway.
Sources
- QUB radio · press, 2026
- Canadian Centre for Cyber Security: baseline cybersecurity controls for small and medium organizations · reference control checklist
- Commission d’accès à l’information du Québec · obligations, incident register, and notification