Contributed by: HUB, an Engineers Canada affinity partner 
The cyber market has softened in recent years, with cyber insurance becoming more accessible to organizations across Canada.
The real challenge today isn't in securing a cyber policy. Instead, it's understanding the gaps in cyber insurance coverage and preparing for future cyber incidents while still protecting the organization.
Cyber policies do vary, but all policies have limits. Engineering firms need to review the policies carefully to be sure those limits match with the firm's risk appetite and that leaders understand what the policies cover and what they exclude.
The top three overlooked coverage gaps include:
-
Third-party vendor incidents: Cyber policies may restrict business interruption coverage to protect only against certain partners, rather than extending broadly to all third-party vendors. For example, an attack on a sub-consultant retained for the firm's latest project may derail project deadlines - but may also be outside the scope of coverage.
-
Social engineering: Cyber policies will often include coverage for social engineering losses under a cyber-crime extension. Sub-limits of up to $250,000 are available from most carriers, but actual losses may go far beyond this threshold. AI-driven scams built on "deepfakes" are increasingly dangerous, as they often bypass even the most skeptical employees to transfer funds quickly, driving the cost of a scam higher than ever before.
-
Exclusions in business interruption coverage: Cyber policies commonly exclude infrastructure-related outages, such as disruptions in internet or electrical service. This means that a major outage that impacts the firm's ability to meet deadlines may not be covered at all.
Best practices to build cyber resilience
With these gaps leaving an organization open to many risks, engineering firms need to take proactive steps to build cyber resilience. This means acquiring a deep understanding of the different types of coverage and the limits of those policies.
Consider these best practices to protect the firm's bottom line:
-
Analyze limits. Reduce exposure by comparing sub-limits against realistic loss scenarios.
-
Confirm third-party coverage. Review parameters for business interruption coverage, especially around specific vendors.
-
Develop incident response plan. Create an incident response plan and be sure to review it annually. Test it with regular tabletop exercises and ensure notification protocols are updated.
-
Implement a secondary verification procedure for funds transfers. Establish internal protocols to verify the authenticity of funds transfer instructions
-
Consult with carrier resources. Check with the broker or advisor to see if the carrier has any resources that might be useful, including tabletop exercises, incident response plans and discounts on cybersecurity tools or coaches.
-
Gather information in a safe place. Set up a formal insurance hub with all relevant information, and make sure the information is accessible even during an incident. The hub should include information about the insurance carrier, broker, pre-approved vendors and all regulatory bodies, as well as the team members who will drive the plan.
Cyber insurance can only be effective when firms and organizations understand the limitations of coverage before an incident occurs. Firms that prepare ahead of time can ensure that their cyber coverage is just one component of true cyber resilience, rather than the entirety of the protection.
Hub International works with professional services firms and technology companies to provide risk management and insurance solutions. They provide advice and actionable insights to clients on their Professional Liability/Errors and Omissions, Cyber & Privacy Liability, Directors & Officers Liability and commercial insurance needs.