On this page
If you’ve renewed a cyber insurance policy in the last year, you’ve already seen the change. The questionnaires have grown teeth. Where 2022 applications asked vague questions about “security practices,” 2026 applications get specific — and one question shows up on the major carriers’ forms we see: do you provide regular cybersecurity awareness training to your staff?
Saying “yes” without a documented platform behind you can be how a six-figure ransomware claim gets denied at the worst possible moment. For small businesses — clinics, law firms, contractors, nonprofits — the question is no longer “should we do staff training?” It’s “can we prove we did it on the application form, in a renewal review, and during a post-incident audit?”
Here’s what the major carriers actually ask, what the Office of the Privacy Commissioner expects under PIPEDA, what Ontario’s IPC can fine you for under PHIPA, and what a defensible training programme looks like in practice.
The Question Every Cyber Insurer Now Asks
Cybersecurity awareness training has migrated from “nice to have” to a baseline underwriting question. The shift mirrors what insurers actually pay out on. Coalition’s 2024 Cyber Claims Report, which underpinned the launch of its own training platform, reported that “over half of all cyber insurance claims originate in the inbox.” Phishing, business email compromise, and the social-engineering attacks that follow are the breach vector for most SMB claims — and a workforce that doesn’t recognise the lure is an underwriting risk insurers can quantify and price.
Three carriers illustrate the spread of how this is being implemented in 2026.
What Beazley Actually Asks
Beazley’s employee cyber security training page is direct about the underwriter’s view: “Employee awareness about data security is one of the most important factors in helping reduce your organization’s risk of an incident.”
Beazley’s cyber insurance application questionnaire reflects that view operationally — it asks applicants to confirm that “you regularly provide cyber security awareness training, including anti-phishing awareness, to all users who have access to your organisation’s network or confidential information / personally identifiable information.” The questionnaire also includes an optional section of additional cybersecurity control questions — among them whether you “regularly send simulated phishing email tests to all users, and you enforce additional anti-phishing training for those who fail” — where satisfactory responses may discount the base premium offered by up to 20%.
Beazley reinforces the same expectation on the back end. The carrier states: “Beazley policyholders also enjoy discounts on anti-phishing tools and training, including simulated phishing campaigns for employee training.” That includes discounted access to KnowBe4’s anti-phishing tools for cyber and tech policyholders — 25% off for new business or up to 15% on renewals. The carrier is not just asking the question — it’s helping policyholders answer “yes” properly.
What Chubb Canada Bundles In
Chubb Canada packages its small-business cyber services under a programme called the Cyber Stack for Small Business. For policyholders with 100 employees or fewer, the first full policy year includes:
- Cyber Security Awareness Training — “Online courses arm employees with practical, actionable insights to spot and stop cyber threats like phishing.”
- Phishing Email Simulator delivered via KnowBe4 — a 100-email complimentary offering for testing staff response to simulated lures.
- Security Awareness & Anti-Phishing Training delivered via GLS — phishing prevention courses, games, and videos, plus customisable services.
- Additional services across vulnerability scanning, dark web monitoring, and incident readiness.
The total bundle is positioned as a cost savings benefit of up to $28,000 across the year, and Chubb notes the complimentary period applies to policyholders who are net-new customers of each vendor and that terms are subject to change. Chubb’s framing is that these are complimentary loss-mitigation services — but the structural implication is clear: a Canadian SMB carrying Chubb cyber coverage is expected to use the training, and a renewal that hasn’t is likely to face harder questions.
What Coalition Built
Coalition went a step further. On July 16, 2024, the carrier launched Coalition Security Awareness Training inside its Coalition Control® platform, accessible to SMBs whether or not they hold a Coalition cyber policy.
The platform includes more than 200 brief training videos, phishing exercises and simulations, automated campaign cadences with reminders, completion tracking, and reporting that Coalition says supports SOC 2, PCI DSS, and HIPAA compliance initiatives. Coalition’s own framing is direct: “Human error is one of the biggest contributors to cyber risk.”
When an underwriter builds and operates a training platform, the message to brokers and applicants is clear. Untrained staff is a known underwriting risk and the industry is willing to invest in fixing it because the alternative is paying out claims.
The Canadian Compliance Layer Most SMBs Miss
Cyber insurance is only half the story. Canadian privacy regulators treat employee training as part of the safeguards they expect — which means an undocumented training programme is a regulatory exposure even before any insurance question gets asked.
PIPEDA (Federal — applies to most Canadian businesses)
Principle 4.7 of PIPEDA requires that “personal information shall be protected by security safeguards appropriate to the sensitivity of the information.” The Office of the Privacy Commissioner of Canada describes three categories of safeguards — physical (locked filing cabinets, restricted offices, alarms), technological (passwords, encryption, firewalls, security patches), and organizational, which it illustrates with “security clearances, limiting access, staff training and agreements” — and its guidance tells organizations to “hold regular staff training on security safeguards.”
The OPC’s interpretation is operational, not theoretical. In its 2025 investigation of Staples Canada’s Openbox programme (PIPEDA Findings #2025-004), the OPC found deficiencies in Staples’ policies, procedures and training for wiping returned devices, and one of the published takeaways is that “organizations must provide their staff with training to equip them to complete technical tasks related to removing any personal information from returned electronic devices.” Training was not optional advice — it was part of the corrective action Staples agreed to.
For most businesses, PIPEDA is the floor. PHIPA raises it considerably.
PHIPA (Ontario healthcare custodians)
Effective January 1, 2024, Ontario’s Information and Privacy Commissioner has discretion to issue administrative monetary penalties (AMPs) for contraventions of PHIPA. Maximums are $50,000 for individuals and $500,000 for organizations, and a penalty can also be set to strip out any economic benefit a person derived from the contravention.
The penalty factors set out in Ontario Regulation 329/23 are equally specific. The Commissioner must consider, among other factors:
- The extent to which the contraventions deviate from PHIPA requirements
- The extent to which the person could have taken steps to prevent the contraventions
- The extent of the harm or potential harm to others
- The number of individuals affected
- Whether the custodian notified the IPC and affected individuals
The second factor is where missing or undocumented training cuts the deepest. A clinic that did not train its staff on phishing recognition, lost patient records to a phishable account, and cannot produce training records is sitting in front of an IPC determining whether the contravention “could have been prevented.” The answer is likely to be yes — and any penalty may reflect it.
What “Documented Training” Actually Looks Like
A defensible training programme has four components, in roughly this order of importance:
1. A real platform with completion records. Spreadsheets and email reminders are not evidence. A modern security awareness platform tracks completion per user, per module, per date. When the insurance broker asks for evidence at renewal, when the OPC asks during an investigation, when the IPC asks during a PHIPA breach review — the export takes thirty seconds.
2. A baseline curriculum every staff member completes annually. Phishing recognition, password and MFA hygiene, safe handling of personal information under PIPEDA / PHIPA, social engineering awareness, secure remote work. Cadence matters. Annual is the common baseline on the forms we see, with refreshers when a major threat or platform shift occurs (the 2026 NCSC passkeys recommendation is a current example — staff need to know what’s changing in their Microsoft 365 sign-in flow).
3. Simulated phishing tests with remediation, not gotcha. Beazley’s optional questionnaire items reward applicants who run simulated phishing programmes. The point is not to embarrass staff who click — it’s to identify training gaps and route those users to focused refresher modules. A phishing simulation programme without remediation is bullying with a logo.
4. Productivity training that lowers the support burden in parallel. This is the part most cybersecurity-only platforms miss. Staff who don’t know how to use Microsoft 365, Teams, OneDrive, or Copilot generate helpdesk tickets, save files in the wrong place, and create the conditions phishing attacks exploit. Combining productivity and security training in one platform reduces both ticket volume and breach risk on the same monthly subscription.
Platforms in this category include BiggerBrains (productivity + cybersecurity combined, 225+ courses per the vendor, channel-priced with no user minimum), KnowBe4 (the cybersecurity-awareness gorilla, deepest phishing-simulation library, but its MSP partner programme carries a reported 101-user minimum per client as of May 2026, which prices many SMBs out), Hook Security, Phin Security, and the bundled training inside Coalition Control. DVG Systems deploys BiggerBrains for SMB engagements specifically because the productivity-plus-security combination addresses both the cyber-insurance question and the helpdesk-ticket reduction in one subscription — which is unusual in the category.
How DVG Systems Builds the Stack
We operate a managed training stack as part of every full managed IT engagement. The stack covers:
- Productivity training for the Microsoft 365 environment we already manage on your behalf — Outlook, Excel, Teams, SharePoint, OneDrive, and Copilot tracks built into the same platform staff already log into.
- Cybersecurity awareness training with annual baseline curriculum, role-based modules for healthcare and legal practices, and updated content as threats evolve.
- Documented completion records ready to export for insurance applications, OPC investigations, IPC reviews, or auditor requests.
- Conditional Access integration so non-completion of mandatory training can be tied to authentication policy where the client wants strict enforcement.
- Reporting cadence that matches the rest of your managed IT review — quarterly summaries, completion percentages by department, and high-risk user identification.
The training platform sits alongside the rest of the security stack: endpoint detection and response (EDR), Conditional Access, DNS filtering, mailbox and Microsoft 365 backup, identity threat detection and response (ITDR), and an incident response playbook that your team has actually rehearsed. Each layer cuts a known underwriting risk. Together they produce a renewal conversation where your broker has good news.
The Bottom Line
Cyber insurance carriers are not asking about staff training as a courtesy. They are asking because their claims data points to the inbox — and the people reading it — as the most common way a paid claim starts. Beazley, Chubb, and Coalition have all moved the question into application questionnaires, premium calculations, and bundled services. Canadian privacy regulators have moved in the same direction — the OPC lists training among PIPEDA’s organizational safeguards, and PHIPA can now be enforced with penalties of up to $500,000 that explicitly weigh whether a custodian could have prevented the breach.
The businesses that handle this well are likely to see lower premiums, smoother claims, and a meaningfully smaller chance of being the breach in the first place. The businesses that drift through the question will find out what “satisfactory response” really meant when their renewal premium jumps or their claim is denied.
We’d rather you be in the first group.
If your team’s training programme is informal, undocumented, or non-existent, get in touch with DVG Systems or run our free pricing assessment to see what a managed training stack would look like alongside your existing Microsoft 365 environment. We support clinics, law firms, contractors, and nonprofits across Thunder Bay, Marathon, Geraldton, Timmins, and surrounding communities — and the conversation usually starts with the broker question that’s already on your desk.
Frequently Asked Questions
Does my Canadian cyber insurance application actually ask about staff training?
Beazley’s does. Its cyber insurance questionnaire asks you to confirm that you regularly provide cybersecurity awareness training, including anti-phishing awareness, to all users with access to your network or confidential data. Optional questions on simulated phishing testing can affect premium pricing. Other major carriers including Chubb and Coalition have moved in the same direction.
Is annual security awareness training required by Canadian privacy law?
PIPEDA does not name a specific training cadence in the statute. However, the Office of the Privacy Commissioner of Canada lists staff training among the organizational safeguards it expects under Principle 4.7 and tells organizations to hold regular staff training. The practitioner standard, and the standard reflected in OPC investigations like PIPEDA Findings #2025-004 (Staples Canada), is an annual minimum with role-specific refreshers.
What’s the maximum fine my Ontario clinic could face under PHIPA?
Up to $50,000 for an individual and $500,000 for an organization, and the IPC can also set a penalty to remove any economic benefit derived from the contravention. Administrative monetary penalty authority took effect on January 1, 2024.
Will training reduce my cyber insurance premium?
It can. Beazley’s questionnaire treats simulated phishing testing as an optional item where satisfactory responses may discount the base premium by up to 20%. Chubb Canada bundles up to $28,000 of training and security services into the first year of cyber coverage for SMBs with 100 employees or fewer. Coalition policyholders get integrated training inside Coalition Control. Quantifying the discount requires your broker to compare quotes side by side — but the direction is consistent: documented training lowers risk and price.
Can DVG Systems set up a training platform for our team?
Yes. We deploy a managed training stack as part of full managed IT engagements — productivity training for Microsoft 365 and Copilot alongside cybersecurity awareness modules, with documented completion records ready for insurance applications, OPC investigations, or auditor requests. Get in touch or run our free pricing assessment for a transparent estimate.
Sources and last verified
Last verified 11 September 2026. Insurer application forms, bundled-service offers and discount percentages are revised by each carrier without notice, and vendor programme minimums change.
- Beazley cyber insurance application (short form, sub-$20M), Beazley: the training question, the optional simulated-phishing question, and the up-to-20% premium discount.
- Employee cyber security training, Beazley: the “employee awareness” quote and the policyholder discount statement.
- KnowBe4 Anti-Phishing Training, Beazley: the 25% new-business / up-to-15% renewal discount.
- User Security and Education Solutions (Cyber Stack for Small Business), Chubb Canada: the 100-employee threshold, the up-to-$28,000 figure, the KnowBe4 and GLS components, and the terms.
- Introducing Coalition Security Awareness Training, Coalition: the July 16, 2024 launch, the “over half” claims statistic, the 200+ videos, and the compliance reporting claims.
- PIPEDA Fair Information Principle 7 — Safeguards, Office of the Privacy Commissioner of Canada: the three safeguard categories and the “regular staff training” guidance.
- PIPEDA Findings #2025-004 (Staples Canada Openbox programme), Office of the Privacy Commissioner of Canada: the training deficiencies and the training takeaway.
- Administrative monetary penalties under PHIPA (notice), Information and Privacy Commissioner of Ontario: the effective date, maximums and economic-benefit provision.
- O. Reg. 329/23 (Administrative Penalties) under PHIPA, Government of Ontario: the penalty factors.