Service targets: 99.9% uptime · 15-min response · 24/7 monitoringVancouver, BC · serving all of Canada · (604) 632-4959
ITIT ExpertsOPERATIONS / CANADA

INSIGHT / RISK

Cyber Insurance in Canada: The Security Controls Underwriters Now Expect

The security controls Canadian cyber insurers commonly require, how to prepare your application and why accurate answers matter.

By Ali Sedighi, MBAReviewed 2026-10-065 min read

Cyber insurance applications have grown from a few yes-or-no questions into detailed technical questionnaires. Insurers have learned that certain controls strongly predict whether a claim will occur, and they now require or price around them. Preparing in advance can lower your premium, speed approval and, most importantly, ensure the cover will respond when you need it.

01Multi-factor authentication everywhere

MFA on email, remote access and privileged accounts is the most common non-negotiable requirement. Underwriters ask whether it is enforced for all users, not merely available. Be ready to show configuration screenshots or policy exports. Gaps, such as service accounts or legacy protocols, should be documented with compensating controls.

02Endpoint detection and response

Insurers increasingly ask for modern endpoint detection and response rather than basic antivirus, and many want evidence that it is monitored around the clock. A managed detection and response service often satisfies this requirement and may lead to improved terms. Keep an inventory showing coverage across all endpoints and servers.

03Backups and recovery testing

Expect questions about frequency, offline or immutable copies, separation of credentials and restore testing. A backup that has not been tested may be treated as non-existent. Keep dated records of restore tests; they are among the most persuasive pieces of evidence you can submit.

04Patching and vulnerability management

Applications ask how quickly critical patches are applied and whether internet-facing systems are scanned. Define targets, for example critical patches within 14 days, and keep reports. Unsupported operating systems are a frequent cause of loadings or declined cover, so plan their retirement.

05Email security and training

Underwriters like to see advanced filtering, DMARC and a regular security awareness programme with simulated phishing. Completion records and click-rate trends show that the programme is real. Include a payment verification procedure to reduce social engineering losses.

06Incident response and governance

A written incident response plan, a named response lead and a tested communication path are increasingly expected. Know your insurer's breach hotline and panel vendors before an event, and understand whether you need approval before engaging your own responders. Align the plan with Canadian privacy breach reporting duties.

07Answer accurately

Misstatements on an application can give an insurer grounds to contest a claim. If a control is partly implemented, say so. Involve your IT provider in completing the questionnaire, and keep a copy of the answers along with the evidence behind each. Review them again at renewal, since environments change. We help you prepare evidence, but your broker and insurer determine cover.

08Mistakes that complicate claims

Frequent mistakes include answering from memory rather than evidence, assuming a control covers more systems than it does, failing to notify the insurer promptly, engaging unapproved responders and letting the policy renew without reviewing changes to the environment. Another is ignoring exclusions, such as war or infrastructure carve-outs and sub-limits for social engineering. Read the policy with your broker, map exclusions to your risks and keep a running record of control changes.

09A 90-day readiness plan

Begin by collecting last year's application and gaps flagged by the underwriter. In the first month, address MFA and EDR coverage. In the second, implement or verify immutable backups, restore tests and patch reporting. In the third, formalise incident response, training records and vendor contracts. Assemble an evidence pack before renewal, and meet your broker early so there is time to remediate anything that would affect pricing or eligibility.

10How underwriters view sectors

Professional services, healthcare, real estate and financial firms are viewed as holding sensitive data and valuable payment flows, so expect closer questions on email security and breach response. Manufacturers and logistics firms face questions about operational continuity and segmentation. Retailers are asked about payment-card handling. Knowing how your sector is perceived helps you anticipate the questions and prepare relevant evidence.

11Details that are easy to overlook

Check sub-limits for social engineering, funds-transfer fraud and business interruption, since these may be far below the headline limit. Understand waiting periods for interruption cover and how reputational harm is treated. Confirm whether the policy requires you to use panel vendors for forensics and legal advice. Look for conditions regarding unsupported software and unpatched vulnerabilities. Note the retroactive date and notification requirements so that an incident is reported inside the policy's timelines.

12Questions for your leadership team

What would a week of downtime cost us, and does our cover reflect that? Who completes and signs the application, and what evidence supports it? Are we comfortable that our answers are accurate today? Do we know the process for notifying the insurer and engaging responders? How will we use the underwriter's questions as a roadmap for security investment? The questionnaire is a free checklist of controls that the market considers important.

Checklist

  • MFA enforced everywhere with evidence
  • Monitored EDR across all endpoints
  • Immutable backups with dated restore tests
  • Patch reports for the last quarter
  • DMARC and email filtering in place
  • Training completion records
  • Incident plan and insurer contacts documented
  • Application answers reviewed by IT and leadership

Where this fits in your IT plan

Guidance like this works best when it is part of a coordinated programme rather than a one-off fix. These IT Experts services address the topic directly:

How IT Experts can help

IT Experts is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery. If this topic matches a situation in your organisation, book a free 30-minute consultation: call (604) 632-4959 or email info@SAZ.ca. We will give you a plain-language view of your options and, if useful, a fixed-price scope. We are an IT services and consulting firm, not a reseller, and there is no lock-in.

Frequently asked questions

Will better security reduce my premium?

It can improve eligibility and terms, though pricing depends on the insurer, sector, revenue and claims history.

Do insurers require MDR?

Not universally, but 24/7 monitoring is increasingly requested for larger or higher-risk organisations.

Can IT Experts fill in the application?

We can supply technical evidence and review answers for accuracy; your broker and leadership remain responsible for the submission.

What if we cannot meet a requirement yet?

Document the gap and a remediation timeline. Many insurers will consider a plan with dates.

Call (604) 632-4959Email info@SAZ.caBook a consultation