Insights Header image
Insights Header image
Insights Header image

Cyber risk insurance: driving the risk management process

October 2015 Insurance Bulletin 2 minute read

Insurers and other insurance professionals have traditionally been well positioned to drive improvements in risk management processes. Cyber-security risk is a modern phenomenon which has arisen in the electronic information and internet age, and the insurance industry is demonstrating that it can play a key role both in educating and equipping public and private sector organisations to manage this emerging risk, and in providing insurance protection.

In Canada, as in other jurisdictions, a number of insurance professionals are leading the charge by providing a host of cyber risk-related services, including:

  • performing comprehensive analyses of the types of risk to which their clients are exposed;
  • matching the risk profile to the insurance available; and
  • providing education on risk management and the risk mitigation efforts that can help to reduce the risk of loss.

These efforts can also reduce the cost of insurance because they align the insurer’s interests with those of the insured organisation through the effective management of risks that are now shared with the insurer.

Some insurers and insurance professionals also offer cyber-security risk related services for after an event, including through third-party service providers such as breach consultation, forensic analysis, notification services, call centre services, credit and identity theft monitoring, fraud consultation and credit and identity restoration services.

Organisations that, due to the nature of their operations, are vulnerable to cyber-attacks or privacy or data security breaches should seriously consider obtaining insurance coverage against these risks. Today, insurance products are evolving in this area, and in some cases can be tailored to an organisation’s specific needs. In applying for coverage, organisations should be prepared to demonstrate to the insurer that cyber risk is an integrated part of their overall enterprise-wide risk management framework and that appropriate risk management tools and processes are in place. Insurers, brokers and other specialists will be involved in the process in order to analyse and assess the potential risk and the effectiveness of the measures in place to mitigate losses. In this way, as in other areas of risk, the insurance industry can drive overall improvements in cyber-risk management.

by Carol Lyons

A Cautionary Note

The foregoing provides only an overview and does not constitute legal advice. Readers are cautioned against making any decisions based on this material alone. Rather, specific legal advice should be obtained.

© McMillan LLP 2015

Insights (5 Posts)View More

Featured Insight

Ready for Change? Bill C-59 Rewrites the Competition Playbook

Bill C-59 has been enacted, introducing significant changes to all aspects of Canada’s competition law regime.

Read More
Jun 21, 2024
Featured Insight

BC Court of Appeal Improves Predictability for Employers Relying on Termination Provisions

In a recent decision, the BCCA provides the clarity sought by employers and employees alike for what is needed for an enforceable termination provision.

Read More
Jun 19, 2024
Featured Insight

Corporate Restructuring Meets Intellectual Property: Quebec Superior Court Overturns Disclaimer Notice and Issues the First Canadian Interpretation of Usage Rights under the CCAA

In the context of a restructuring, the debtor's right to resiliate a contract under s. 32 of the Companies' Creditors Arrangement Act is far from absolute.

Read More
Jun 19, 2024
Featured Insight

Court Upholds Shareholder-Employee Loan to Acquire a Residence

Discussion of a recent Court decision that a loan to an owner-manager to refinance his home was not a "shareholder benefit".

Read More
Jun 19, 2024
Featured Insight

Time to Get Tough! CARR Provides Guidance for CDOR Tough Legacy Contracts

CARR released guidance with respect to tough legacy contracts in Canada that don't have workable CDOR fallback language; who this applies to; why it was issued.

Read More
Jun 18, 2024