Cyber insurance underwriting has tightened dramatically over the past several years, and the days of a simple one-page application with light security questions are largely over. Rising ransomware claims industry-wide pushed insurers to start requiring baseline security controls before even offering coverage, not just to price risk after the fact — which means a business that hasn't touched its security posture in a while may find itself surprised by how much the underwriting questionnaire now asks, or worse, declined outright on a first application.
The good news: getting genuinely "insurance-ready" rarely requires an enterprise security budget. It requires working through a specific, well-defined list of technical controls, documentation, and process items — most of which are affordable and achievable for a small business within a matter of weeks. This guide is that list, organized so you can work through it methodically rather than guessing at what an underwriter might ask.
One more framing point before diving in: this guide is organized around three categories that tend to get evaluated somewhat separately during underwriting even though they overlap in practice — the purely technical controls (MFA, EDR, backups, patching), the documentation and compliance items (privacy policy, data inventory, incident response plan), and the people-and-process side (training, access revocation, ownership of the renewal process itself). Working through all three, rather than focusing heavily on one while neglecting the others, is what tends to produce both a smoother underwriting experience and a genuinely lower-risk business, independent of the insurance conversation entirely.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians who regularly help Canadian small and mid-sized businesses prepare for cyber insurance underwriting from the IT security side — MFA rollout, EDR deployment, backup configuration, incident response planning. IT Cares is an IT company, not an insurance broker; for policy structure, pricing, and coverage interpretation, always work with a licensed broker. What we bring is direct, practical experience with the technical side of what gets asked, and what actually needs to be true, not just written down.
Why Underwriting Tightened So Much
It's worth understanding the "why" behind the current state of cyber insurance underwriting, because it explains why the questionnaire looks the way it does rather than feeling like arbitrary bureaucracy. Ransomware claims in particular grew sharply in both frequency and average payout size over the past several years, and insurers — who ultimately have to make their loss ratios work — responded the way any insurance market responds to a sustained rise in claims costs: by tightening underwriting standards, adding specific control requirements as conditions of coverage, and in some cases exiting segments of the market they found too costly to insure profitably at previous pricing.
The practical result for a small business today is that "do you have antivirus" — a question that might have been sufficient a decade ago — has been replaced by much more specific, control-by-control questions: is MFA enforced, is there EDR or just legacy antivirus, are backups offline or immutable, is there a documented incident response plan, has staff completed security awareness training. None of these questions are arbitrary; each one maps directly to a specific pattern insurers have observed repeatedly in the claims that cost them the most to pay out.
It's also worth understanding that this tightening happened alongside a broader restructuring of how cyber insurance itself is priced and offered. Several years ago, it was common for a small business to obtain a policy with relatively light underwriting scrutiny and a fairly low premium, largely because the market hadn't yet accumulated enough claims data to price the risk accurately. As claims data accumulated — and as ransomware in particular proved to be both more frequent and more expensive than early pricing models assumed — insurers recalibrated in two directions simultaneously: premiums rose across the board, and coverage became conditional on specific, verifiable controls rather than general assurances. A business shopping for its first policy today, or renewing a policy it first purchased years ago under the old, looser standards, should expect a meaningfully different, more detailed process than what "cyber insurance" used to mean.
Want a clear picture of your gaps before you apply?
Our certified technicians benchmark your setup against what insurers actually ask — from $119.99.
The Technical Baseline Controls Insurers Expect in 2026
The following controls appear, in some form, on nearly every current Canadian cyber insurance underwriting questionnaire we've seen work through for clients. None of them are exotic, and most small businesses already have partial access to several through software they already pay for — the gap is usually turning them on and enforcing them consistently, not purchasing something entirely new.
Multi-factor authentication (MFA)
MFA on email, remote access, and administrative accounts has become close to a universal baseline expectation, and for a growing number of insurers it functions as a gating question — a "no" can mean an application is declined outright rather than simply priced higher. Most business email and cloud platforms (Microsoft 365, Google Workspace) already include MFA at no extra cost; the gap is almost always that it's available but not enforced account-wide.
Endpoint detection and response (EDR)
Legacy antivirus, which relies heavily on recognizing known malware signatures, is increasingly viewed by insurers as insufficient on its own against modern threats that are specifically designed to evade signature-based detection. EDR (and related terms like managed detection and response, or MDR) monitors endpoint behaviour for suspicious activity rather than only checking against a list of known threats, and is increasingly named specifically on underwriting questionnaires rather than being covered by a generic "do you have antivirus" question.
Offline or immutable backups
Backups that stay continuously connected to the network they're protecting are vulnerable to the same ransomware that encrypts or deletes the primary data, since well-designed ransomware specifically searches for and targets connected backup systems. Insurers increasingly ask specifically whether at least one backup copy is offline, air-gapped, or immutable (meaning it cannot be altered or deleted even by an attacker with administrative access) rather than simply asking "do you have backups."
Patch management
A regular, documented process for applying security patches — to operating systems, business applications, and network equipment — addresses one of the most consistently exploited categories of vulnerability. Ad hoc, "we get to it when we remember" patching is a common gap insurers now ask about directly, sometimes requesting a specific maximum timeframe (e.g., critical patches applied within a set number of days).
Privileged access management
Limiting who has administrative access to systems, and ensuring admin accounts are used only when actually needed rather than for daily work, reduces how much damage a single compromised account can cause. This overlaps directly with the least-privilege principle covered in broader zero-trust and access-control guidance, and increasingly appears as its own specific underwriting question.
Email filtering and anti-phishing controls
Given how many incidents originate through phishing, insurers increasingly ask about email filtering and anti-phishing tooling as a distinct control category, separate from general endpoint protection.
Network segmentation
Separating critical systems from general business network traffic — so a compromised guest device or a less-critical system can't directly reach financial or client data systems — is a control insurers increasingly ask about for businesses with more complex network environments, though it's typically a lower-priority item for the smallest businesses relative to the controls above.
| Control | Why insurers ask | Typical minimum expected | Rough cost to implement (CAD) |
|---|---|---|---|
| MFA | Directly addresses stolen/weak credentials, involved in a large share of breaches | Enforced on email, remote access, admin accounts | $0 – $500 (often already included) |
| EDR | Legacy antivirus misses modern, signature-evading threats | Deployed on all business endpoints | $40 – $120 / device / year |
| Offline/immutable backups | Ransomware specifically targets connected backups | At least one offline or immutable copy, tested periodically | $500 – $3,000 setup + ongoing storage |
| Patch management | Unpatched known vulnerabilities are a top exploited category | Documented process, critical patches within days | $0 – $1,500 (tooling + process time) |
| Incident response plan | Faster containment reduces claim severity | Written, with clear roles and escalation steps | $1,000 – $3,000 to develop |
| Employee training | Phishing remains a top initial-access method | Baseline training with completion records | $500 – $2,000 / year for a small team |
| Privileged access management | Limits blast radius of a compromised admin account | Admin access limited and reviewed regularly | Mostly time investment, minimal direct cost |
The Compliance and Documentation Side of Underwriting
Beyond the purely technical controls, a growing share of underwriting questionnaires touch on compliance and documentation items that overlap directly with Canadian privacy law obligations, whether or not the insurer frames them that way explicitly.
- A documented privacy policy. Insurers want to see that a business has a real, current privacy policy reflecting its actual data practices, not a generic template that doesn't match reality.
- Law 25 / PIPEDA compliance posture. For Quebec businesses especially, questions about privacy officer designation, consent practices, and PIA processes increasingly appear alongside purely technical security questions — see our Law 25 vs PIPEDA guide for the underlying legal framework these questions are drawing from.
- A data inventory. Knowing what personal and sensitive information you hold, where it's stored, and who can access it is both a privacy law expectation and something underwriters increasingly ask about directly, since it affects how severe a potential incident could be.
- Vendor and third-party risk management. Questions about whether you've reviewed the security practices of key vendors and cloud providers you rely on are becoming more common, reflecting how many real incidents originate through a compromised third party rather than a direct attack.
- A written incident response plan. Covered in more technical depth below, but worth flagging here too: this is as much a documentation/process item as a technical one, and it's one of the most commonly requested items on current questionnaires.
- Evidence of employee security awareness training. Not just "do you train staff" but increasingly "can you show records of when and what training was completed."
📊 IT Cares field note: A pattern worth highlighting: businesses that had already done privacy compliance work — a Law 25 privacy officer designation, a proper PIA process, a real privacy policy — consistently found the cyber insurance underwriting questionnaire noticeably less painful, because so many of the questions overlapped with work they'd already done. Treating compliance and insurance readiness as one combined project, rather than two separate to-do lists, saves real time.
The Underwriting Questionnaire Itself: What to Expect and How to Answer It Well
The application process for cyber insurance today typically involves a detailed questionnaire — sometimes dozens of questions — covering the technical and compliance categories above, plus general business information (revenue, industry, data volumes) that affects risk pricing. A few practical points about navigating it well:
Answer accurately, not optimistically
This is the single most important piece of guidance in this entire article. If a question asks "is MFA enforced on all remote access" and the honest answer is "it's available but about a third of the team hasn't turned it on," the accurate answer is closer to "no" or "partial" than "yes." Answering "yes" because MFA exists somewhere in your environment, when it isn't actually enforced, creates a misrepresentation problem that can surface at the worst possible time: during a claim, when an insurer's investigation reveals the gap between what was represented and what was actually true.
Document before you apply, not during the questionnaire
Trying to figure out your actual security posture for the first time while filling out the application form leads to rushed, inaccurate answers. Doing a deliberate review beforehand — ideally with IT support — means you walk into the questionnaire already knowing your real answers, and with time to fix the most glaring gaps before they become part of a formal application record.
Understand what "misrepresentation" actually risks
Insurance policies generally give insurers the right to deny a claim, or in more serious cases void the policy entirely, if material misrepresentations were made on the application. This isn't insurers looking for excuses — it's a standard feature of how insurance contracts work across essentially every type of insurance, and it exists precisely because premiums are priced based on the risk represented on the application. A business that materially misrepresents its security posture is, in effect, paying a premium priced for a lower-risk profile than it actually has.
Expect follow-up questions and possibly a call
For larger policies or higher-risk industries, it's increasingly common for an insurer or their security assessment partner to follow up with additional technical questions, or occasionally request a light external scan of your systems, before finalizing terms. This isn't a sign of unusual scrutiny — it reflects the same broader industry tightening discussed earlier in this guide.
Common Mistakes Businesses Make When Preparing
Beyond simply not having the controls in place, several recurring patterns tend to complicate the underwriting process even for businesses genuinely trying to do things right.
Treating MFA as "done" once it's technically available
The most common gap isn't a total absence of MFA — most businesses using Microsoft 365 or Google Workspace already have it available. The gap is enforcement: MFA is turned on for some users but not others, or it's technically required but employees have found workarounds, or it was rolled out once and quietly lapsed as new employees joined without it being applied consistently to their accounts. "Available" and "enforced" are different facts, and only the second one is what an insurer is really asking about.
Confusing legacy antivirus with modern endpoint protection
Many businesses genuinely believe they have adequate endpoint protection because they've had antivirus software installed for years, without realizing that legacy, signature-based antivirus is a meaningfully different category of protection from EDR in the eyes of a 2026 underwriting questionnaire. This isn't a matter of one being better-branded than the other — the detection approach is fundamentally different, and insurers have specifically adjusted their questions to distinguish between the two categories rather than accepting "we have antivirus" as sufficient.
Never actually testing backup restoration
A backup that has never been tested for restoration is, in a meaningful practical sense, an unverified claim rather than a working safety net. It's common for a business to discover, only during an actual incident, that a backup was incomplete, corrupted, or configured incorrectly months earlier without anyone noticing — precisely the scenario a periodic restoration test is meant to catch before it matters.
Waiting until the renewal deadline to start preparing
Underwriting readiness work — MFA rollout, EDR deployment, policy documentation — takes real time to do properly, and rushing it in the final two weeks before a renewal deadline tends to produce exactly the kind of "technically true but not really" answers that create problems later. Starting the process 60 to 90 days ahead of a renewal date gives enough runway to close gaps properly rather than scrambling.
Not involving IT and the broker in the same conversation
Some businesses complete the underwriting questionnaire with input only from whoever handles insurance administratively, without checking the technical answers against what IT actually knows to be true. Others rely entirely on IT to assess risk without factoring in how a broker would frame or negotiate specific answers. The businesses that navigate this most smoothly tend to loop in both perspectives before finalizing an application.
Getting Insurance-Ready: A Step-by-Step Plan
Inventory your data and systems
Map what personal and sensitive data you hold, where it lives, and which systems would need to be part of an underwriting conversation. This is foundational — you can't accurately answer questionnaire questions about data protection without first knowing what data you actually have.
Implement MFA everywhere
Enforce multi-factor authentication on email, remote access, admin accounts, and any system holding sensitive data. This is the highest-priority, typically lowest-cost item on this entire list, and often already available in software you're already paying for.
Deploy endpoint detection and response (EDR)
Move beyond legacy antivirus to EDR or an equivalent modern endpoint protection platform on all business devices, including any BYOD devices accessing business systems.
Set up offline or immutable backups
Ensure at least one backup copy is offline or immutable, specifically resistant to ransomware that targets connected backup systems, and test restoration periodically rather than assuming backups work until you actually need one.
Establish a patch management routine
Put a regular, documented process in place for applying security patches across operating systems and business software, with a clear target timeframe for critical patches specifically.
Write an incident response plan
Document who does what during a security incident — detection, containment, notification, recovery — even in a fairly simple form. Having something documented and followable matters more initially than having something exhaustive.
Complete employee security awareness training
Provide baseline training on phishing recognition and safe data handling, with records kept as evidence of completion — this is both a genuine risk reducer and increasingly a documented underwriting requirement.
Review your privacy policy and Law 25/PIPEDA compliance posture
Confirm your privacy documentation and practices reflect applicable provincial and federal privacy law before an underwriter asks — this overlaps directly with legal compliance obligations that exist independent of insurance.
The Complete Pre-Application Checklist
This is the core deliverable of this guide — a comprehensive, organized checklist to work through before applying for or renewing cyber insurance. Nothing here requires an enterprise budget, but working through the full list typically benefits from IT support to execute cleanly.
Technical controls
- ☐ MFA enforced on all email accounts
- ☐ MFA enforced on all remote access (VPN, remote desktop, cloud admin portals)
- ☐ MFA enforced on all administrative/privileged accounts
- ☐ EDR (not just legacy antivirus) deployed on all business devices, including BYOD accessing business systems
- ☐ At least one backup copy stored offline or immutable
- ☐ Backup restoration tested within the past 12 months
- ☐ Documented patch management process with a target timeframe for critical patches
- ☐ Email filtering / anti-phishing tooling in place
- ☐ Privileged/admin access reviewed and limited to those who genuinely need it
- ☐ Network segmentation reviewed for businesses with more complex environments
Documentation & policy
- ☐ Current, accurate privacy policy reflecting actual data practices
- ☐ Privacy officer formally designated (particularly relevant for Quebec businesses under Law 25)
- ☐ Data inventory documenting what personal/sensitive information is held and where
- ☐ Written incident response plan with clear roles and escalation steps
- ☐ Vendor/third-party risk review completed for key service providers
- ☐ Prior-incident history documented and ready to disclose accurately if asked
People & process
- ☐ Employee security awareness training completed, with dated records kept
- ☐ Process in place for immediately revoking access when an employee departs
- ☐ Underwriting questionnaire draft answers cross-checked against what's actually true and enforced, not just theoretically available
- ☐ Internal owner identified for the underwriting/renewal process, so it doesn't fall through the cracks
- ☐ Broker consulted on how specific answers may affect pricing or eligibility before finalizing the application
Real-World-Style Canadian Case Studies
Case study: Quebec manufacturing SMB, declined then approved
A 35-person Quebec manufacturing business applied for its first cyber policy and was declined outright by its first-choice insurer, primarily citing the absence of MFA on remote access and reliance on legacy antivirus rather than EDR. The rejection came as a genuine surprise to ownership, who had assumed their existing IT setup — antivirus on every machine, a firewall at the office, and a password policy requiring changes every 90 days — represented reasonably solid security, since it had been sufficient for a policy renewal only three years earlier. Rather than simply shopping for a more lenient insurer that might ask fewer questions, the business worked with an IT provider over roughly 60 days to enforce MFA account-wide, deploy EDR across its roughly 40 devices, and document a basic incident response plan covering its production floor systems as well as its office network. On reapplication, it was approved, with a premium of approximately $5,400 CAD annually for a $1 million limit — a figure the broker described as favourable given the company's industry and size, directly attributable to the improved application answers and the documentation package prepared alongside them.
Case study: professional services firm, a misrepresentation complication
A mid-sized professional services firm represented on its application that MFA was enforced organization-wide. In practice, MFA had been rolled out for most staff but several long-tenured employees had been granted informal exceptions for convenience — a legacy accommodation from years earlier that had simply never been revisited — a detail the person completing the application wasn't aware of, since it predated their time managing the file. When a phishing-driven breach occurred and one of the exempted accounts was the entry point, the insurer's investigation surfaced the discrepancy fairly quickly, since access logs showed the compromised account had never once completed an MFA challenge. The claim was ultimately paid, but only after weeks of additional review and negotiation between the firm's legal counsel and the insurer, and the policy was renewed the following year with additional monitoring conditions attached — an outcome the firm's leadership described as an avoidable, stressful complication that a more careful pre-application review, specifically checking application answers against actual configuration rather than institutional assumption, would have caught well before it mattered.
Case study: Ontario retailer, a pre-application audit pays off
A 15-person Ontario retailer with an e-commerce operation commissioned a security audit specifically ahead of its first cyber insurance application, at a cost of approximately $2,200 CAD, after a peer in the same industry association mentioned having gone through a difficult, drawn-out application process the previous year. The audit identified that backups, while regular, were not offline or immutable, and that no written incident response plan existed — two gaps the owner hadn't previously considered, since "we do backups every night" had always seemed sufficient. Both gaps were closed within three weeks at a combined cost of roughly $1,800 CAD, with the incident response plan built around the retailer's actual small team structure rather than a generic enterprise template. The retailer's application went smoothly, and the broker specifically noted that having a completed audit report to reference — rather than the retailer trying to describe its own security posture from memory during the underwriting call — sped up the underwriting conversation considerably compared to a typical first-time application in the same industry.
Budget: Getting Insurance-Ready (CAD)
| Item | Typical cost range (CAD) |
|---|---|
| MFA rollout (often already included in existing subscriptions) | $0 – $500 one-time setup effort |
| EDR licensing (per device, annual) | $40 – $120 / device / year |
| Backup solution with offline/immutable copy | $500 – $3,000 setup + ongoing storage costs |
| Incident response plan development | $1,000 – $3,000 one-time |
| Security awareness training platform (per year, small team) | $500 – $2,000 / year |
| Pre-application security audit | $1,500 – $4,000 for a small business |
| Full insurance-readiness program (all of the above, small business) | $5,000 – $12,000, often offset partly by premium reductions |
Canadian Government Resources
- Canadian Centre for Cyber Security (cyber.gc.ca): Publishes the well-known Baseline Cyber Security Controls for Small and Medium Organizations, a genuinely useful, free reference that maps closely to what insurers now expect as baseline controls.
- BDC — Business Development Bank of Canada (bdc.ca): Offers SMB advisory support, including financing options for security upgrades that support both real risk reduction and insurability.
- ISED — Innovation, Science and Economic Development Canada (ised-isde.canada.ca): Provides general SMB digital and cybersecurity resources useful for businesses building a readiness program from scratch.
- OPC — Office of the Privacy Commissioner of Canada (opc.gc.ca): Offers PIPEDA compliance guidance relevant to the documentation side of underwriting covered above.
For the broader cyber insurance picture, see our cyber insurance guide for small business, our guide on lowering your premium through IT security, our IT security audit checklist, and our explainer on what ransomware coverage actually includes — all of which connect directly to the readiness work covered in this guide.
Renewal Is Not a One-Time Event
None of the resources or checklists above replace direct conversation with your broker about your specific policy wording, and none of the technical guidance replaces a genuine, hands-on review of your specific environment by someone who can actually verify what's configured versus what's assumed. This guide is meant to make that conversation more productive on both fronts — arriving at a broker meeting or an IT review already knowing roughly what to expect tends to produce a faster, less stressful process than starting from a blank page.
It's worth closing on a point that's easy to lose sight of once an application has been approved: cyber insurance readiness isn't a project with a finish line so much as an ongoing posture that needs periodic attention. Underwriting standards continue to evolve as insurers accumulate more claims data and as the threat landscape itself shifts, which means a set of controls that satisfied an insurer two years ago may not fully satisfy the same insurer at the next renewal without some additional documentation or a control that's since become standard expectation.
Practically, this means treating the checklist in this guide as something to revisit on a recurring basis — ideally annually, ahead of each renewal cycle, rather than only the first time a business seeks coverage. Businesses that build a light annual review into their calendar (confirming MFA enforcement hasn't quietly lapsed for new hires, verifying backup restoration still works, refreshing the incident response plan if team structure has changed) tend to find each subsequent renewal noticeably smoother than the last, rather than facing a fresh scramble every time a policy comes up for renewal.
This is also where the relationship between IT support and insurance readiness becomes most valuable on an ongoing basis rather than as a one-time project. A managed IT provider that already monitors MFA enforcement, patches systems on a schedule, and tests backups periodically as part of normal operations is, in effect, keeping a business insurance-ready continuously rather than needing a dedicated push before each renewal — which is often the more efficient way to think about this whole category of work for a business that would rather not revisit it from scratch every twelve months.
Ultimately, the underlying goal of every item in this checklist is the same, whether or not insurance is even part of the conversation: reducing the real chance and real cost of a security incident. Cyber insurance readiness and genuine cybersecurity maturity point in the same direction so consistently that treating the underwriting questionnaire as an unwelcome hoop to jump through misses the more useful framing — it's a fairly reliable, externally validated checklist of the controls most likely to actually prevent or contain the incident a business hopes never happens in the first place.
Want an honest, prioritized pre-application punch list?
IT Cares' security audits benchmark your actual setup against exactly the controls insurers ask about, and translate the gaps into a concrete, appropriately scaled action plan. If ongoing management makes sense for your business, our managed IT services can maintain these controls over time so your posture doesn't quietly drift out of date before your next renewal, whether that renewal is three months away or a year out.
Frequently Asked Questions
Want a Prioritized Punch List Before You Apply?
IT Cares benchmarks your actual security setup against what insurers ask for and gives you a right-sized readiness plan.
Comments (3)
The checklist alone was worth bookmarking. We were declined once already and this explained exactly why — no EDR, just old antivirus.
Really appreciated the section on answering the questionnaire honestly. We almost overstated our MFA coverage without realizing the risk.
Got a security audit done first like the Ontario case study suggests. Made the whole insurance process much less stressful.
Leave a Comment