Cyber Insurance for Businesses in Quebec | Covalen Cyber Risk Insurance for Small Businesses: Protect Your Company and Meet Your Law 25 Obligations
Get a quick and accurate assessment of your cyber posture. Identify your vulnerabilities, receive concrete recommendations, and improve your insurability in just a few clicks.
In Quebec, a business hit by a data breach doesn't just have to manage the crisis. It also has to meet the strict requirements of Law 25, or face penalities and fines of up to $25 million or 4% of worldwide revenue. Covalen protects Quebec small businesses and companies against ransomware, data breaches and electronic fraud, with a cyber posture assessment included and hands-on support at every step.
Law 25 and your business: what cyber insurance doesn't always cover
Since September 2022, law 25 requires every business operating in Quebec to report confidentiality incidents to the Commission d'accès à l'information (CAI) and to affected individuals, to keep an incident register, and to appoint a person responsible for the protection of personal information. Businesses that fail to comply face administrative monetary penalties imposed by the CAI of up to $10 million or 2% of worldwide revenue, and penal fines imposed by the courts of up to $25 million or 4% of worldwide revenue, doubled for repeat offences. The CAI has had the power to impose these penalties since September 2023.
A well-structured cyber insurance policy helps cover the costs tied to this compliance work (notifying affected individuals, legal advisory services, crisis management), but it does not replace a solid cybersecurity posture upstream. Our specialized brokers help you understand where your coverage ends and your Law 25 obligations begin.
Don't let cybercriminals target your business
Our cyber risk expertise and customized insurance solutions turn your weaknesses into security assets.
Don't leave your digital future to chance. In the ever-evolving cyberspace, the best defence is a proactive one. That's where our insurance solutions come in. Secure your digital future with us.
Cyberattacks are no longer a distant threat; they’re already targeting local SMEs.
We’ve developed a cyber insurance program designed specifically for small and professional businesses:
Cyber posture assessment included,
Coverage tailored to your reality,
Human and personalized support.
Are you insurable against cyber threats?
Find out your insurability level and protect your business today!
The 5 key elements of a cyber risk insurance policy
These elements cover the essential aspects of a comprehensive cyber risk insurance policy, offering both reactive and proactive protection against digital threats offering both reactive and proactive protection against digital threats, including costs tied to your Law 25 reporting obligations.
- Protection against data breaches
- Coverage for ransomware attacks
- Compensation for business interruption losses
- Data/system recovery and restoration costs
- Protection against third-party claims
- Coverage of legal defence costs
- Compensation for regulatory fines and penalties (if insurable)
- Access to cybersecurity and forensic experts
- Coverage of notification costs for affected customers
- Public relations and reputation management services
- Coverage of losses due to cybercrime (e.g. electronic fraud)
- Compensation for loss of income due to cyber incidents
- Coverage of additional costs to maintain operations
- Risk assessments and security audits
- Cybersecurity training for employees
- Post-incident technical support and security improvements
In the cyber world, the best defence is a proactive, scalable strategy.
Protect your digital future today!
Cyber insurance typically covers costs related to data breaches, business interruptions caused by cyber attacks, ransomware extortion, customer notification costs, legal fees and reputational damage. It can also include coverage for financial losses due to cybercrime.
No, company size is not a determining factor. Small and medium-sized businesses are often prime targets for cybercriminals, as they generally have fewer resources dedicated to cybersecurity.
You can lower your premiums by showing the insurer that your business is well protected: multi-factor authentication on email and remote access, regular backups that are isolated from your network and tested, up-to-date firewalls and software, endpoint protection, phishing awareness training for employees, and a procedure to verify payment requests. Our cyber posture assessment shows you what to improve before you request a quote.
Yes, most cyber insurance policies cover incidents caused by employee error, such as clicking on a phishing link or losing an electronic device containing sensitive data. However, employees' intentional malicious acts are generally excluded.
Professional liability insurance generally covers errors and omissions in providing professional services, whereas cyber insurance focuses specifically on data and computer systems risks. Cyber insurance offers specialized coverages such as crisis management in the event of a data breach, which are not included in standard professional liability policies.
Administrative penalties issued by the CAI generally cannot be insured, but a good cyber policy covers the crisis management costs that follow an incident, including notifying affected individuals, legal advisory services, and the notification costs required under Law 25. Talk to a Covalen broker to understand exactly what's covered in your case.