Multi-factor authentication, endpoint detection and response (EDR), and tested, immutable backups are consistently the three controls that carry the most weight on a Canadian cyber insurance application. Underwriters have moved well past the simple "do you have antivirus?" checkbox of a few years ago — today's applications read closer to a condensed security audit, and how you answer those specific questions has a direct, sometimes dramatic, effect on the premium you're quoted, the deductible you're offered, and in some cases whether you can get coverage at all.
This guide walks through exactly what underwriters are scoring, which controls move the needle the most, realistic ranges for how much difference they can make, what those controls typically cost to implement in Canada, and a concrete plan for preparing before your next renewal conversation. It's written for the person actually responsible for making the decision — usually an owner, office manager, or controller at a small or mid-sized Canadian business — not for a security specialist who already knows this material.
It's worth being upfront about the framing here: none of this is about gaming an insurer or finding a clever loophole. The controls that move a cyber insurance quote are, almost without exception, the same controls that meaningfully reduce your actual chance of a costly incident in the first place. Insurers weight MFA, EDR, and tested backups heavily precisely because their own claims data shows these are the controls whose absence shows up over and over again in the incidents they end up paying for. Treating the insurance application as a proxy for "is our business actually protected" rather than a separate box-checking exercise tends to produce better outcomes on both fronts — a better premium and, more importantly, a lower chance you ever need to file a claim in the first place.
Not legal, financial, or insurance advice
This article is educational information based on general market patterns Canadian brokers and IT security practitioners commonly report. It isn't a substitute for reading your actual policy wording or for advice from a licensed insurance broker or lawyer about your specific situation. Every carrier's underwriting criteria and every policy's terms differ — always confirm specifics with your broker before making decisions based on this article.
What Insurers Actually Look At During Underwriting
Ten years ago, a cyber insurance application for a small business might have been two pages: general company information, an estimate of records held, and a handful of yes/no questions about antivirus and firewalls. That application no longer exists in any meaningful form. Ransomware losses across the Canadian and broader North American markets drove years of underwriting losses for carriers, and the response was a wholesale rebuild of how applications are structured. A modern application for even a 15-person company now routinely runs six to ten pages and asks pointed, specific questions rather than broad ones.
The questions that show up on nearly every current application, across nearly every carrier writing cyber business in Canada, cluster around a consistent set of themes:
- Multi-factor authentication (MFA): Is it enforced on email/M365 or Google Workspace admin accounts? On VPN and remote access? On any privileged or administrative account? Increasingly, "we have MFA available but don't require it" is scored the same as not having it at all.
- Endpoint protection type: Signature-based antivirus versus EDR or XDR (endpoint/extended detection and response) — the distinction matters because EDR can detect and often automatically contain behaviour-based threats like ransomware encryption in progress, where legacy antivirus frequently cannot.
- Backup architecture and testing: Not just "do you have backups," but whether they're immutable or air-gapped (so a ransomware attacker with network access can't encrypt or delete them too), and critically, when the last successful full restore test was performed and documented.
- Patch and vulnerability management: Is there a defined SLA for applying critical security patches, and is it actually being met?
- Email security and phishing training: Is there anti-phishing filtering beyond basic spam filtering, and does the organization run periodic phishing simulations with tracked completion rates for staff training?
- Privileged access management: Are administrative privileges limited to the people who actually need them, and are shared/generic admin accounts avoided?
- Incident response plan: Is there a written plan, and has it been tested — even informally — in the past 12 months?
- Remote access exposure: Is Remote Desktop Protocol (RDP) or similar remote access exposed directly to the internet without additional protection, which remains one of the single most common ransomware entry points investigators trace incidents back to?
Each of these questions maps to a documented, recurring root cause behind the ransomware and business email compromise claims carriers have paid out over the past several years. Underwriters aren't asking arbitrary questions — they're pricing risk against patterns their own claims data has already shown them.
📊 IT Cares field note: We regularly see business owners surprised that their broker is now asking for a screenshot of the MFA enforcement policy or a signed attestation letter from their IT provider, rather than accepting a verbal "yes, we have that." That shift — from self-attestation to requested evidence — is one of the clearest signs of how much underwriting discipline has tightened industry-wide.
Why Canadian Cyber Insurance Premiums Have Risen Sharply
If you renewed a cyber policy any time in the past several years and watched the premium climb even though nothing happened to your business, you're not imagining it, and it isn't specific to your company. Ransomware claim frequency and average claim severity both rose substantially across the North American market, and Canadian SMBs were not spared — mid-market and small business ransomware incidents, in particular, became a major driver of claims volume precisely because smaller organizations historically underinvested in the controls larger enterprises had already adopted.
Carriers responded in three ways that directly affect what you experience at renewal: they raised premiums broadly across the market to reflect higher expected losses; they tightened underwriting criteria, declining or non-renewing accounts that couldn't demonstrate baseline controls; and they moved from simple self-attestation toward a model that increasingly asks for supporting evidence, particularly once coverage limits climb above roughly $1 million.
The practical result is that the same set of controls that used to be "nice to have" for a modest discount are now closer to a baseline requirement just to stay insurable, while genuinely strong, well-documented security posture is what now earns the more meaningful pricing benefit. Understanding that distinction changes how you should think about this: the goal isn't just to check boxes for a discount, it's to avoid falling into the segment of applicants who get declined or hit with an unfavourable non-renewal notice altogether.
There's a compounding effect worth understanding too. A business that invests in MFA, EDR, and tested backups isn't just improving one year's premium — it's building a track record. Carriers increasingly look favourably on applicants with multiple consecutive years of clean claims history combined with demonstrated, improving security maturity, sometimes described informally as a "security trajectory." A company that could show, renewal after renewal, that it kept closing gaps rather than standing still tends to be treated differently by underwriters than one that meets the bare minimum once and never revisits it. This matters because cyber insurance underwriting in Canada, much like commercial property or auto insurance, rewards consistency over time, not just a single point-in-time snapshot.
It's also worth noting that premium size is only one part of the picture insurers adjust based on your security posture. Deductibles, sublimits on specific coverage types like ransomware extortion payments, and even whether certain exclusions apply can all shift based on the same underwriting factors discussed here. A business with strong MFA and EDR coverage might see a comparatively modest premium change but a meaningfully lower ransomware deductible, which in practice can matter just as much — or more — than the headline premium number when an actual incident occurs.
Not sure where your security posture actually stands?
IT Cares can run a practical security assessment against exactly what insurers now ask for — MFA coverage, EDR, backup testing, and more — and hand you a plain-language report before you talk to your broker.
The Controls Insurers Reward Most
Not every security investment moves an insurance quote equally. Based on what Canadian brokers commonly report seeing across renewal conversations, and what current applications weight most heavily, these seven controls consistently have the biggest effect — both on price and on insurability itself. It's worth noting upfront that these controls also tend to reinforce each other rather than work in isolation: MFA without EDR still leaves a gap if a session token is stolen through malware, and EDR without tested backups still leaves a business scrambling for a recovery path if an attack does succeed despite detection. Underwriters increasingly evaluate the combination, not just individual line items, which is part of why a business that implements all seven in a coordinated way tends to see a meaningfully better outcome than one that implements a single control in isolation and expects an outsized result from it alone.
1. Multi-factor authentication everywhere it can go
MFA is the single most heavily weighted line item on almost every current cyber insurance application, and for good reason: a very large share of the business email compromise and ransomware claims carriers pay out trace back to a compromised password with no second factor standing in the way. Brokers commonly report that missing MFA on email or remote access is now one of the single most frequent reasons an application is declined outright, which reframes the conversation — this isn't primarily about earning a discount, it's about remaining insurable in the first place. Where it does still influence price, having MFA enforced (not just available) across email, VPN, remote desktop, and any financial or administrative system is treated as a baseline expectation that unlocks better terms rather than a bonus that earns extra credit.
2. EDR or XDR replacing legacy antivirus
Traditional signature-based antivirus catches known malware by matching it against a database of known threats. Ransomware operators know this and routinely modify their tools specifically to evade signature detection. EDR and XDR instead watch for behaviour — a process rapidly encrypting files, for instance — and can often automatically isolate the affected device before an attack spreads across the network. Carriers active in the Canadian cyber market, including names like Chubb, Beazley, CFC, Definity, Travelers Canada, and AIG, have all moved their application language in recent years toward specifically asking about behaviour-based detection rather than accepting "we have antivirus" as a sufficient answer. Some carriers now list a small number of approved or preferred EDR vendors, so it's worth asking your broker directly whether your specific platform is one they recognize.
3. Tested, immutable, offline or air-gapped backups (the 3-2-1 rule)
A backup that ransomware can also encrypt or delete isn't much of a backup at all, and attackers specifically target connected backup systems as part of a modern ransomware attack sequence. The 3-2-1 rule — three copies of your data, on two different types of media, with one copy offline or otherwise isolated from the production network — remains the standard underwriters are effectively asking about when they inquire about backup architecture. Just as important as having the backups is proving they work: a growing number of applications now specifically ask for the date of your last successful full restore test, not just whether backups run on schedule. A backup nobody has ever tried to restore is a theoretical control, not a demonstrated one.
4. Patch management with a defined SLA
Many of the highest-profile ransomware incidents of recent years traced back to a known, publicly disclosed vulnerability that had a patch available for weeks or months before the attacker exploited it. A documented patch management process — critical vulnerabilities patched within a defined window, typically 72 hours to two weeks depending on severity and system exposure — signals to an underwriter that a known window of exposure isn't sitting open indefinitely.
5. Phishing simulation and security awareness training with tracked completion
Since business email compromise and credential theft overwhelmingly start with a phishing email, carriers increasingly ask not just whether security awareness training exists, but what percentage of staff have actually completed it, and whether the organization runs periodic simulated phishing tests to measure real-world click rates over time. A program that exists on paper but that half the staff never completed doesn't carry much weight compared to one with documented completion above roughly 90%.
6. A documented, tested incident response plan
Having a one-page document that names who makes which decisions during an incident — who calls the insurer's breach hotline, who can authorize a system shutdown, who handles client communication — measurably shortens response time during a real event, and underwriters know it. A short annual tabletop exercise, even a 30-minute walkthrough rather than a full simulation, is often enough to answer this question favourably on an application.
7. Privileged access management and least-privilege access
Limiting administrative rights to only the accounts that genuinely need them, retiring shared or generic admin logins, and reviewing access permissions periodically all reduce how far an attacker who does get in can actually reach. This control shows up less prominently than MFA or EDR on shorter applications, but becomes a more detailed line of questioning as coverage limits and company size increase. A practical starting point most SMBs can implement without new tooling is a quarterly access review: pull a list of every account with administrative rights across email, finance systems, and core business applications, and confirm each one is still needed, still tied to a current employee, and still scoped no more broadly than their role requires. Businesses that formalize even this simple quarterly habit typically find, the first time they do it, several stale accounts that should have been removed months earlier.
Common Mistakes That Undo a Security Investment's Premium Impact
Implementing the right controls is necessary but not sufficient — we regularly see Canadian businesses spend real money on security improvements and then see little or no change in their renewal quote, usually for one of the following avoidable reasons.
- Enabling a control without enforcing it. MFA that's "available" but not required across every account behaves, from an underwriting standpoint, almost the same as no MFA at all — a single unenrolled admin account is often enough for an underwriter to flag the whole application as incomplete.
- Deploying a tool but never documenting it. An EDR platform installed on every endpoint doesn't help your application if nobody can produce a vendor confirmation letter, a deployment report, or even a simple exported device list showing 100% coverage when the underwriter asks.
- Confusing backup frequency with backup reliability. Backups that run every night on schedule but have never been restore-tested answer a different question than the one increasingly being asked. "We back up daily" and "we know our backup restores correctly" are not the same claim, and underwriters are getting better at telling the two apart.
- Letting the application answers go stale. Many businesses copy last year's answers forward at renewal without re-verifying them. If an employee left and their access wasn't revoked, or a new branch office was opened without the same controls rolled out, the application no longer reflects reality — and a claim investigation after an incident will surface that gap at the worst possible time.
- Treating the broker as a form-filler rather than an advisor. Brokers who specialize in cyber insurance typically know which carriers currently value which specific controls most and can help you sequence a limited security budget for maximum underwriting impact — that guidance is wasted if you only hand them completed forms rather than involving them earlier in the planning process.
Comparison: Premium Impact, Cost, and Time to Implement
| Security Control | Typical Premium Impact* | Typical Implementation Cost (CAD) | Typical Time to Implement |
|---|---|---|---|
| MFA on email, VPN, admin accounts | Difference between insurable and declined in many cases; otherwise a meaningful factor in the quote | $0–$8/user/month (often included in existing M365/Google Workspace business plans) | 1–2 weeks |
| EDR/XDR replacing legacy AV | Moderate-to-significant, frequently cited among the top 3 factors | $4–$12/endpoint/month | 2–4 weeks for full fleet rollout |
| Tested immutable backups | Moderate-to-significant, especially for ransomware/extortion sublimits | $150–$1,200/month depending on data volume and retention | 2–6 weeks including first restore test |
| Patch management SLA | Modest to moderate | $3–$8/endpoint/month if using a managed RMM tool | 2–4 weeks to establish process |
| Phishing simulation + training | Modest to moderate | $2–$6/user/month | Ongoing; first cycle in 30 days |
| Documented, tested IR plan | Modest, but closes a commonly under-scored gap | $0–$3,000 one-time if built with a consultant | 1–3 weeks to draft and tabletop |
| Privileged access management | Modest, larger impact at higher coverage limits | Mostly internal process/time; $0–$500/month for tooling at SMB scale | 2–4 weeks |
*Ranges reflect patterns commonly reported by Canadian cyber insurance brokers across multiple carriers and are illustrative, not a quote or guarantee from any specific insurer. Your actual premium impact depends on your carrier, industry, revenue, claims history, and overall application.
How the Renewal Underwriting Conversation Actually Goes
Most owners picture the renewal process as filling out a form and waiting for a number. In practice, for anything beyond the smallest micro-business policies, it's closer to a structured conversation, usually mediated by your broker, where specific answers trigger specific follow-up questions.
A typical sequence looks something like this: the broker sends the current carrier's renewal application, which restates last year's answers and asks you to confirm or update them. If you answer "yes" to MFA, don't be surprised if the underwriter — sometimes directly, sometimes through the broker — comes back asking which accounts specifically, whether it's enforced or optional, and occasionally for a screenshot of the enforcement policy from your identity provider's admin console. The same pattern increasingly applies to backups: "yes, we have backups" now often triggers a follow-up asking for the date of the last successful restore test.
Where this matters practically: if you go into the renewal conversation with documentation already prepared — screenshots, a vendor attestation letter, a dated restore-test log — you shorten the underwriting cycle and remove friction that can otherwise turn into either a delay or a more conservative quote issued out of caution because the underwriter couldn't fully verify your answers. Brokers who work with cyber insurance regularly will often tell you this directly: the applicants who show up with evidence tend to get faster, more favourable responses than the ones who show up with verbal assurances.
There's also a timing dimension that catches businesses off guard. Underwriting reviews for anything beyond the smallest micro-business policies can take anywhere from a few days to several weeks, particularly if a follow-up request for evidence goes back and forth more than once. Starting the renewal conversation at the last minute — a week or two before the policy expires — leaves little room to correct a gap the underwriter flags, which sometimes forces a choice between accepting unfavourable terms or having a coverage gap while a new application is processed. Businesses that start 60-90 days out, by contrast, generally have enough runway to close any gap that surfaces mid-process rather than being stuck reacting to it under time pressure.
It's also common for the underwriter's follow-up questions to reveal something the business itself didn't fully know about its own environment — a legacy VPN appliance nobody had gotten around to decommissioning, a branch office running on a different, less-managed network than head office, or a third-party vendor with standing remote access that was never revisited after a project ended. Part of the practical value of the renewal process, beyond the premium itself, is that it forces a periodic outside-in review of your environment that many SMBs otherwise don't get around to doing on their own schedule.
Three Canadian SMB Case Studies
Case Study 1 — Law Firm, Calgary, Alberta
A 22-person boutique litigation firm in Calgary was quoted a renewal premium of $6,400 CAD for $2 million in coverage, up from $4,100 the year before, with the increase attributed largely to the firm's continued use of standalone antivirus and optional (not enforced) MFA. Over eight weeks, the firm's IT provider enforced MFA across all M365 accounts, deployed EDR to all 26 endpoints, and documented a successful full backup restore test. At renewal, the firm's broker re-shopped the policy across three carriers and returned a quote of $4,800 CAD — a roughly 25% reduction from the prior renewal quote — alongside a lower deductible on the ransomware sublimit.
Case Study 2 — Precision Parts Manufacturer, Windsor, Ontario
A 60-employee automotive parts manufacturer in Windsor had been declined by two carriers at its prior renewal specifically due to internet-exposed RDP used by a remote maintenance vendor and a lack of documented backup testing. After closing the exposed RDP behind a VPN with MFA, deploying EDR across the plant floor and office network (48 endpoints), and running and documenting two consecutive successful backup restore tests, the company secured coverage from a carrier that had previously declined it, at an annual premium of $11,200 CAD for $3 million in coverage — where the year prior, the best available offer in the market (from a non-standard/excess carrier) had been $17,500 CAD for the same limit due to the exposure.
Case Study 3 — Regional Nonprofit, Halifax, Nova Scotia
A 15-person nonprofit serving Nova Scotia communities operated on a tight annual IT budget and had never carried standalone cyber coverage, self-insuring informally. After a phishing-driven near-miss (an employee caught a fraudulent wire transfer request before it was processed), the board approved a modest security budget: MFA (no additional cost, already included in their existing Microsoft 365 Business Premium plan), a $6/user/month phishing simulation and training platform, and a $300/month managed backup service with quarterly restore testing. With those controls documented, the organization secured its first cyber policy at $2,150 CAD/year for $1 million in coverage — a rate its broker described as meaningfully below the typical range for nonprofits without prior documented controls, largely because the application went in already showing MFA, training completion records, and a tested backup process from day one.
How to Prepare for a Lower-Premium Renewal — Step by Step
Most brokers recommend starting this process 60-90 days before your renewal date, since implementing and documenting controls properly takes real time, not a weekend.
Pull your current policy and last application
Get the exact questionnaire submitted last time, so you know precisely which specific controls the underwriter scored you against and where the gaps were.
Deploy MFA on every account that can support it
Prioritize email/M365 or Google Workspace admin accounts, VPN, remote desktop, and any privileged or financial system first.
Replace legacy antivirus with EDR or XDR
Confirm with your broker whether your specific EDR vendor is one the carriers they work with specifically recognize.
Run and document a real backup restore test
Run a full restore test, save the results, and note the date — increasingly, applications ask for this specific date, not just whether backups exist.
Push phishing simulation completion above 90%
Track and document actual completion percentage, not just whether a training program exists on paper.
Write down your incident response plan and test it once
A short tabletop exercise, even 30 minutes, answers one of the most commonly under-scored questions on modern applications.
Gather proof before you re-shop the policy
Screenshots of MFA enforcement, an EDR vendor letter, and your restore-test log turn a verbal "yes" into evidence an underwriter can actually price against.
Quick Checklist: Pre-Renewal Security Readiness
- ☐ MFA enforced (not just enabled) on all email/admin accounts
- ☐ MFA enforced on VPN and remote access
- ☐ EDR/XDR deployed on 100% of endpoints, with vendor attestation letter on file
- ☐ Backups follow the 3-2-1 rule with at least one immutable/offline copy
- ☐ Full backup restore test completed and dated within the last 90 days
- ☐ Critical patch SLA defined and being met (documented)
- ☐ Phishing simulation program running with completion rate tracked and above 90%
- ☐ Written incident response plan, reviewed/tabletopped in the last 12 months
- ☐ No RDP or remote admin ports exposed directly to the internet
- ☐ Privileged/admin accounts limited and reviewed in the last 6 months
- ☐ Renewal application answers cross-checked against actual current state (not last year's answers copy-pasted)
Budget & Pricing: What These Controls Actually Cost in Canada
One of the more reassuring realities in this space is that the highest-impact controls are frequently not the most expensive ones. Here's a realistic budget range for a Canadian SMB with roughly 15-75 employees looking to implement the full set of controls covered above:
- MFA: $0-$8 CAD per user/month — often already included in Microsoft 365 Business Premium or Google Workspace Business Plus, meaning the real cost for many businesses is the time to configure and enforce it, not a new subscription.
- EDR/XDR: $4-$12 CAD per endpoint/month depending on vendor and whether it's bundled with managed detection and response (MDR) monitoring.
- Managed, tested backup: $150-$1,200 CAD/month for an SMB, scaling with data volume, retention period, and how frequently restore tests are performed.
- Patch management (via RMM tooling): $3-$8 CAD per endpoint/month if bundled into a managed IT services agreement.
- Phishing simulation and awareness training: $2-$6 CAD per user/month for a mid-tier platform with tracked completion reporting.
- Incident response plan development: $0 if built internally using free templates from the Canadian Centre for Cyber Security, up to roughly $1,500-$3,000 CAD one-time if developed with an outside consultant including a tabletop exercise.
For a 30-person business, the full package above typically lands somewhere between $800 and $2,500 CAD/month depending on vendor choices and how much is bundled into an existing managed IT services agreement versus purchased as standalone tools. Against that, a premium reduction in the range case studies above illustrate — anywhere from several hundred to several thousand dollars annually, plus the value of remaining insurable at all — often produces a payback period measured in months rather than years, especially once you account for the cost avoidance of a ransomware incident that these same controls are specifically designed to prevent or contain.
It's worth sizing that cost-avoidance side of the equation explicitly, because it's usually the bigger number by far. Incident response, forensics, legal counsel, notification costs, and business interruption from even a moderate ransomware incident at a Canadian SMB commonly run into six figures once every cost category is added up, before factoring in reputational damage or lost clients. Against that backdrop, a monthly security spend in the range described above — often a few hundred to a couple thousand dollars a month depending on company size — is a modest insurance policy of its own, layered underneath the actual insurance policy. Many brokers frame it exactly this way to clients who are hesitant about the upfront spend: the security investment and the insurance policy aren't competing for budget, they're two halves of the same risk management strategy, and carriers price the insurance half more favourably specifically because the security half reduces how often they expect to pay out.
One more budgeting note that's easy to miss: many of these tools are priced per user or per endpoint, which means the monthly cost scales roughly linearly with headcount rather than being a fixed overhead. A 10-person business implementing the full package might realistically land closer to $400-$900 CAD/month, while a 100-person company could reasonably see $3,000-$6,000 CAD/month for the equivalent coverage across a larger fleet — in both cases representing a similar percentage of revenue for a well-run small or mid-sized business, even though the absolute dollar figures differ substantially.
Canadian Government & Regulatory Resources
Several federal programs and regulators are directly relevant to this topic and worth knowing about, whether you're building your security program or preparing documentation for an insurance application:
- BDC (Business Development Bank of Canada): Offers financing and advisory services that can support cybersecurity investments for Canadian SMBs, including guidance on prioritizing security spending as part of broader business risk management.
- ISED (Innovation, Science and Economic Development Canada): Runs the CyberSecure Canada certification program, a baseline cybersecurity standard for small and medium organizations that overlaps significantly with what cyber insurance underwriters ask about. Some brokers and carriers give the certificate meaningful weight during underwriting, so it's worth asking directly whether the carriers you're working with recognize it.
- OPC (Office of the Privacy Commissioner of Canada): Publishes guidance on breach notification obligations under PIPEDA (the federal privacy law). Understanding your notification obligations matters directly for cyber insurance, since most policies include notification cost coverage and expect you to follow the legally required reporting timeline as part of a compliant claim.
Provincial programs are worth checking too, since they change more frequently than federal ones and vary by where your business is registered. Quebec businesses can look at Investissement Québec's digital transformation and cybersecurity advisory programs, Ontario businesses have historically had access to Digital Main Street funding streams that include a security component for smaller retail and service businesses, and several provinces run their own small business advisory services through their economic development ministries that can point you toward matching funding for security upgrades. A quick call to your provincial economic development office alongside your BDC advisor is often worth the 20 minutes it takes, since program availability shifts year to year and a program that didn't exist at your last renewal may exist now.
If you'd like a professional assessment of where your current security posture stands against what insurers are now asking for, our security audit service is built specifically around this kind of gap analysis, and our cybersecurity services page covers ongoing MFA, EDR, and backup management for Canadian businesses. You don't need to figure this out alone or guess at what to prioritize first.
Frequently Asked Questions
Want a Clear Picture of Where You Stand Before Renewal?
IT Cares can assess your current MFA coverage, endpoint protection, and backup testing against what Canadian cyber insurers now ask for, and help you close the gaps before your next renewal conversation.
Comments (3)
Went through almost exactly this renewal process this spring at our firm. The restore-test date question caught us off guard — glad this article flags it specifically.
Didn't realize an exposed RDP port could get us declined outright. Had our IT provider lock that down within a week after reading something similar to this.
Appreciate the budget numbers being realistic rather than vague. Our nonprofit board needed actual dollar ranges to approve the spend, not just "it's worth it."
Leave a Comment