On this page
A ransomware attack hit a mid-sized accounting firm in Ontario on a Tuesday morning. By noon, every workstation was locked. Client files were encrypted. The firm’s shared drive — years of financial records — was inaccessible. Within 48 hours, the attackers demanded $85,000 in Bitcoin.
The firm had no cyber insurance. They had no incident response plan. They had no offsite backups that weren’t also encrypted. They paid.
This scenario plays out hundreds of times a year across Canada, and smaller businesses are increasingly the target. Here’s why cybersecurity isn’t optional for SMBs, what happens when you skip it, and how the right combination of active security, insurance, and an MSP partner changes the outcome.
Why SMBs Are the Primary Target
There’s a persistent myth that cyberattacks are aimed at large enterprises — that small and mid-sized businesses are too small to bother with. The opposite is true.
Large enterprises have security operations centres, dedicated IT security teams, and incident response retainers. SMBs typically have none of these. They have less sophisticated defenses, less staff training, and less visibility into what’s actually happening on their network. For attackers, they’re the path of least resistance.
The Insurance Bureau of Canada has found that more than 60% of small businesses believe their business is too small to be targeted by cybercriminals — which is exactly why they’re targeted. That false confidence translates directly into under-investment in security and under-insurance. Automated scanning tools probe thousands of business networks daily, looking for unpatched software, exposed remote desktop ports, and weak credentials. When they find an opening in a small business, they take it.
The consequences are severe. IBM’s Cost of a Data Breach Report puts the average cost of a data breach for a Canadian organization at nearly $7 million, but smaller businesses face per-incident costs in the $150,000–$300,000 range when you factor in investigation, recovery, legal obligations, and reputational damage. For a business operating on tight margins, that’s often fatal.
What “Not Having Cybersecurity” Actually Looks Like
When businesses say they “have cybersecurity,” they often mean they have antivirus software. That’s not cybersecurity — that’s one tool out of dozens required for a functional security posture.
A business without real cybersecurity protection typically has:
- No Multi-Factor Authentication (MFA) on email, remote access, or cloud services. A single stolen password becomes a full network compromise.
- No endpoint detection and response (EDR). Traditional antivirus misses modern malware. EDR tools detect behaviour, not just signatures — the difference between catching an attack in progress versus discovering it after the damage is done.
- No regular, tested backups. Many businesses discover their backups are incomplete, corrupted, or also encrypted after a ransomware incident.
- No employee security training. Compromised credentials and phishing remain the top two entry points for breaches. A staff member reusing a leaked password or clicking a malicious link can bypass every technical control.
- No incident response plan. When an attack happens, the hours immediately following determine whether the damage is contained or catastrophic. Without a plan, teams improvise — and pay for it.
The absence of these controls doesn’t just increase risk. It increases the cost of any incident that does occur, and it increasingly disqualifies businesses from obtaining cyber insurance at all.
Cyber Insurance: What It Covers — and What It Doesn’t
Cyber insurance has become a necessity for any business that holds client data, processes payments, or depends on digital operations to generate revenue. For businesses operating in healthcare, legal, construction, and professional services, that’s essentially everyone.
What a quality cyber insurance policy typically covers:
- Cyber extortion (ransomware): Covers ransom negotiation support and, where appropriate, extortion payments. Critically, it also covers the forensic investigation to determine whether payment actually resulted in full data recovery.
- Data breach response: Covers the cost of breach notifications required under PIPEDA (Canada’s federal privacy law), which requires reporting to the Office of the Privacy Commissioner and notifying affected individuals when there is a real risk of significant harm — as well as legal fees and credit monitoring services where applicable.
- Business interruption: Covers revenue losses and extra expenses incurred while systems are being restored following an attack.
- Forensic investigation: Covers the cost of determining how the attack occurred, what data was accessed, and what needs to be remediated.
- Regulatory defence: Covers legal costs associated with regulatory investigations and privacy commissioner complaints.
What cyber insurance does not cover:
Insurance is not a security strategy. Insurers are increasingly explicit about this. Policies now routinely exclude incidents that result from basic security failures — such as a breach that occurred because MFA wasn’t enabled on a system the insurer required it for, or where the business failed to apply security patches within a defined timeframe.
Aviva Canada, Coalition, and other major cyber insurers now require verifiable evidence of MFA deployment, regular offline backups, and documented employee training as baseline requirements for coverage. Businesses that can’t demonstrate these controls may be denied coverage entirely, or find their claims disputed post-incident.
The message from insurers is clear: insurance covers residual risk after security controls are in place. It does not cover negligence.
The Insurance Bureau of Canada’s Guidance
The Insurance Bureau of Canada (IBC) publishes the Cyber Savvy Insurance Guide specifically for Canadian businesses. Their guidance aligns with what MSPs have been recommending for years:
- Implement MFA on all remote access, email, and cloud services before applying for coverage — most insurers now require it.
- Maintain regular, tested backups stored in a location separate from your primary environment (not on the same network).
- Train employees to recognize phishing, social engineering, and suspicious activity.
- Have an incident response plan documented before you need it.
- Work with professionals — both an insurance broker who understands cyber coverage and an IT partner who can implement and maintain the required controls.
The IBC is explicit: cyber insurance is a complement to active security investment, not a substitute for it.
Where Your MSP Fits In
An MSP’s role in your cybersecurity posture isn’t limited to keeping your systems running. A capable MSP should be actively reducing your risk profile — which directly affects your insurance eligibility, your premium costs, and your likelihood of surviving a serious incident.
At DVG Systems, our security work for SMB clients includes:
- Deploying and managing MFA across Microsoft 365, remote access, and cloud platforms — meeting insurer requirements and closing the most common attack vector
- Endpoint detection and response (EDR) that monitors behaviour in real time, catching attacks that traditional antivirus misses
- Managed backup with offsite, immutable copies designed so ransomware cannot alter or delete them during their retention window — tested regularly, not assumed to work
- Security awareness training that runs continuously, not just at onboarding, so staff recognize evolving phishing tactics and credential theft attempts
- Dark web monitoring to identify when your credentials have been exposed before attackers use them
- Incident response planning so that when — not if — something happens, you know exactly what to do in the first hour
We also work with clients to document their security posture for insurance applications. The controls you implement don’t just reduce risk — they can lower your premiums, support higher coverage limits, and give you the documented evidence a claim depends on. Whether a claim is paid is the insurer’s decision under the policy wording; what we can do is make sure the controls the policy requires are in place and provable.
Why DVG Systems Requires Cyber Insurance From Every Client
This is a policy, not a suggestion: DVG Systems requires all managed services clients to maintain their own cyber liability insurance. This requirement is written into our Master Service Agreement before work begins.
Here’s why — and why you should care.
The MSP Liability Problem
When an SMB client is breached, the question investigators and lawyers ask is: who had privileged access to these systems? The answer is almost always the MSP. This creates a liability exposure that most SMBs don’t think about when they hire a managed services provider.
MSPs operate with elevated credentials across client environments. RMM (Remote Monitoring and Management) and PSA tools provide deep access to workstations, servers, and cloud accounts. Threat actors know this. In documented incidents — most notably the Kaseya VSA attack in 2021, which affected roughly 1,500 businesses across 17 countries — attackers compromised MSP management platforms specifically to deploy ransomware across every downstream client simultaneously. The security industry calls this a “keys to the kingdom” scenario, and CISA has issued formal guidance on it.
The liability exposure flows both ways:
- If your business is breached and you have no insurance, your legal counsel may pursue the MSP for negligence — even if the breach originated from unpatched client hardware or a staff member clicking a phishing link.
- If your MSP is compromised and used as a vector to breach you, recovery falls to whoever has coverage. If neither party does, litigation determines who pays.
- Even when the breach is clearly the client’s fault — a user sharing their password, a server left unpatched despite our documented recommendation — MSPs have been found liable when security measures were deemed insufficient relative to the scope of access granted.
This isn’t hypothetical. It’s the documented pattern in MSP liability cases across North America, and it’s why cybersecurity law firms and MSP industry groups consistently advise MSPs to mandate client-side insurance as a contractual requirement.
What Our Contract Requires
Our Master Service Agreement includes:
- Mandatory cyber liability insurance of appropriate coverage for the client’s size and data classification. We verify this at onboarding and annually.
- Documented declinations. If a client declines a security service — MDR, phishing training, MFA enforcement — they sign a waiver acknowledging the recommendation and the associated risk. This protects both parties.
- Defined scope of work. Our agreements clearly specify what is and is not included. Scope creep in security work is how MSPs get held responsible for incidents on systems they never managed.
- Limit of liability clauses. Our liability is capped relative to the service fees paid — a standard MSP industry practice that prevents disproportionate claims from a single incident.
Why This Is Good for Your Business
Clients sometimes push back on the insurance requirement. Our answer is straightforward: if your business can’t obtain cyber insurance at a reasonable premium, that’s important information. It tells you that underwriters — professionals whose job is assessing risk — have evaluated your security posture and decided it represents too much exposure.
An MSP-managed security baseline makes your business easier to insure, helps keep premiums manageable, and removes the most common reasons a claim is disputed. The alternative is discovering after an incident that your policy excluded the attack type, or that your coverage lapsed, or that coverage was denied because controls weren’t in place — including the staff-training control that your insurer’s application form already asks about.
A cyber policy is a real line item, but it is small next to an uninsured incident. Working with an MSP who mandates insurance is how you build a business that can survive what’s coming.
The Bottom Line
Cybersecurity for SMBs in 2026 is not optional. It is not a cost you can defer until the business is larger. And it is not satisfied by an antivirus subscription and good intentions.
The combination of active security controls, proper cyber insurance, and an MSP partner who manages both is what keeps a ransomware attack from becoming a business-ending event. Businesses that take this seriously survive incidents. Those that don’t are the ones paying ransoms and rebuilding from scratch.
DVG Systems provides managed IT and cybersecurity services to small and mid-sized businesses across Thunder Bay and Northern Ontario. If you’d like to assess your current security posture or understand your cyber insurance readiness, book a free assessment.