Canadian cyber rates are falling and only 22% of SMEs have cover
It’s a combination that should alarm every insurance broker
Canadian cyber rates are falling and only 22% of SMEs have cover
CYBER
By Paul Lucas
29 Sep 2026

Canadian cyber insurance rates fell 6% in both Q1 and Q2 of 2026, with new market entrants adding capacity across primary and excess layers and driving competition to levels the market has not seen since before the 2020-2022 hard cycle. On the surface, those are benign conditions. Cheaper cover, more capacity, better terms.

Underneath them, something is wrong.

Despite the softening, IBC-commissioned survey data published in 2026 found that just 22% of Canadian SMEs carry cyber insurance - and only 12% hold a standalone policy. The Business Development Bank of Canada's own data shows that 73% of small businesses have experienced a cybersecurity incident. The gap between those two figures - between exposure and protection - is not narrowing as rates fall. It is persisting.

Derek May, VP cyber & technology and Canadian cyber product co-leader at Hub, described the rate environment at a recent Insurance Business Canada cyber power panel. "It's certainly been a race to the bottom over the last couple of years, not even just the last few quarters. And this is all despite claims still persisting out there."

A rate correction is coming - here is what signals it

The direction of travel is not in doubt. May noted that larger Canadian cyber insurers - those carrying the bulk of the national portfolio - are beginning to signal that rates will change. The US market is already moving, with carriers pushing 5-10% rate increases. May expects Canada to follow within 12 to 18 months.

Joseph Hines, AVP commercial sales - Nova Scotia and national practice leader - cyber at Gallagher, identified the specific tension that makes that timeline feel optimistic rather than reassuring. "I think underwriters and the underwriting community think that their rates are potentially in the right spot right now, but at the same time, claims frequency is certainly not declining."

That gap - between underwriters' confidence in current pricing and a frequency environment that keeps rising - is exactly where prior market corrections have originated.

IBC data from its Canadian Cyber Insurance Market report recorded a combined ratio averaging 153% from 2019 to 2023, meaning that for every dollar of premium earned during that period, $1.53 was paid out in claims and operating expenses. The hard market of 2020-2022 corrected that. The subsequent softening has been steadily rebuilding the conditions that produced it.

Coalition data from 2025 adds a Canada-specific dimension that rarely gets enough attention: Canadian cyber insurance claims average US$226,000 per incident - more than double the US average of US$108,000 for the same period. Canadian losses are materially more expensive to resolve. That differential makes the rate reduction trajectory in this country particularly difficult to justify against the underlying loss data.

Hines identified the trigger that could accelerate a reversal sharply. "A quick uptick in the severity and the frequency of claims, or a large systemic loss, will certainly put that to the test very quickly."

That scenario has a recent precedent. The CrowdStrike software update failure in July 2024 triggered simultaneous claims across thousands of policyholders globally from a single vendor event. The American Academy of Actuaries flagged in its February 2026 report, Cyber Insurance Inflection Point, that reinsurers remain cautious about systemic risk, with approximately 50% of cyber premiums currently ceded to reinsurers - meaning that a concentrated correlated loss event could propagate through the market faster than frequency trends alone would suggest.

Why 78% of SMEs still have no cover

The more pressing question for Canadian brokers is not when the market turns. It is why falling rates have failed to move the SME penetration needle at all.

The IBC data is unambiguous on the diagnosis. Only 48% of SME respondents believe their business is vulnerable to a cyberattack or data breach. Just 6% strongly agree there is any chance they could be targeted. Statistics Canada data shows that 26% of Canadian businesses had a written cybersecurity policy in 2023 - a figure unchanged from 2021 despite years of high-profile incidents.

Hines put the problem squarely. "I think the issue is less about the cost and more about the perception and awareness that these SMEs have. Many SMEs still believe that they're too small to be targeted despite the evidence that cyber incidents increasingly affect smaller organizations. To me, the low penetration rate represents a significant market opportunity driven by education rather than pricing."

May's description of how threat actors actually operate cuts through the perception problem directly. "We give the example that they're going down Main Street, they're jiggling door handles, and if you're the unfortunate one that's left them in that day, then unfortunately you're gonna be targeted."

That analogy reflects documented reality. Automated scanning tools probe entire IP address ranges for vulnerabilities without any selection by company size or sector. An SME running unpatched software is as discoverable as a large enterprise - and typically has fewer resources to detect, contain, and recover from an incident once it begins.

The relative cost problem - and how to reframe it

May identified a practical hurdle that brokers working in the SME segment encounter routinely and need a clear answer to.

For a small business already paying for property and general liability, adding a cyber policy - even at $1,000 to $2,000 annually - can feel like doubling the insurance bill. In absolute terms, those premiums are modest. But for an owner comparing the cost of insuring a building they can see against the cost of insuring a digital risk they do not fully understand, the comparison is weighted against cyber from the start.

The reframe that moves that conversation is not a features walkthrough or a policy comparison. It is a direct, specific account of what an uninsured cyber incident costs a business of that size in practice. A data breach requiring breach notification, forensic investigation, and legal counsel runs well above any premium paid. A ransomware attack that shuts operations for two weeks may not be survivable without the incident response infrastructure that a cyber policy brings.

CFC's head of cyber for Canada made the same point in April 2026 from a market perspective: "Too often cyber is discussed as a tick-box discussion rather than advised. The services wrapped around the wording - such as proactive and incident response - are under-sold, and client misperceptions go unchallenged."

That observation goes to the heart of the penetration problem. The broker who presents cyber insurance as another line item on a policy schedule is making the same mistake as the SME owner who sees it as optional cover for a risk they do not think applies to them. Hines framed the conversation that actually works: "The problem's not affordability, it's that many organizations haven't connected cyber insurance to business survival."

That connection - made concretely, with real incident costs and real recovery timelines - is the conversation that closes business the rate environment has so far failed to generate.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.