INSIGHT / RISK
Cyber Insurance in Canada: The Security Controls Underwriters Now Expect
The security controls Canadian cyber insurers commonly require, how to prepare your application and why accurate answers matter.
Cyber insurance applications have grown from a few yes-or-no questions into detailed technical questionnaires. Insurers have learned that certain controls strongly predict whether a claim will occur, and they now require or price around them. Preparing in advance can lower your premium, speed approval and, most importantly, ensure the cover will respond when you need it.
01Multi-factor authentication everywhere
MFA on email, remote access and privileged accounts is the most common non-negotiable requirement. Underwriters ask whether it is enforced for all users, not merely available. Be ready to show configuration screenshots or policy exports. Gaps, such as service accounts or legacy protocols, should be documented with compensating controls.
02Endpoint detection and response
Insurers increasingly ask for modern endpoint detection and response rather than basic antivirus, and many want evidence that it is monitored around the clock. A managed detection and response service often satisfies this requirement and may lead to improved terms. Keep an inventory showing coverage across all endpoints and servers.
03Backups and recovery testing
Expect questions about frequency, offline or immutable copies, separation of credentials and restore testing. A backup that has not been tested may be treated as non-existent. Keep dated records of restore tests; they are among the most persuasive pieces of evidence you can submit.
04Patching and vulnerability management
Applications ask how quickly critical patches are applied and whether internet-facing systems are scanned. Define targets, for example critical patches within 14 days, and keep reports. Unsupported operating systems are a frequent cause of loadings or declined cover, so plan their retirement.
05Email security and training
Underwriters like to see advanced filtering, DMARC and a regular security awareness programme with simulated phishing. Completion records and click-rate trends show that the programme is real. Include a payment verification procedure to reduce social engineering losses.
06Incident response and governance
A written incident response plan, a named response lead and a tested communication path are increasingly expected. Know your insurer's breach hotline and panel vendors before an event, and understand whether you need approval before engaging your own responders. Align the plan with Canadian privacy breach reporting duties.
07Answer accurately
Misstatements on an application can give an insurer grounds to contest a claim. If a control is partly implemented, say so. Involve your IT provider in completing the questionnaire, and keep a copy of the answers along with the evidence behind each. Review them again at renewal, since environments change. We help you prepare evidence, but your broker and insurer determine cover.
08Mistakes that complicate claims
Frequent mistakes include answering from memory rather than evidence, assuming a control covers more systems than it does, failing to notify the insurer promptly, engaging unapproved responders and letting the policy renew without reviewing changes to the environment. Another is ignoring exclusions, such as war or infrastructure carve-outs and sub-limits for social engineering. Read the policy with your broker, map exclusions to your risks and keep a running record of control changes.
09A 90-day readiness plan
Begin by collecting last year's application and gaps flagged by the underwriter. In the first month, address MFA and EDR coverage. In the second, implement or verify immutable backups, restore tests and patch reporting. In the third, formalise incident response, training records and vendor contracts. Assemble an evidence pack before renewal, and meet your broker early so there is time to remediate anything that would affect pricing or eligibility.
10How underwriters view sectors
Professional services, healthcare, real estate and financial firms are viewed as holding sensitive data and valuable payment flows, so expect closer questions on email security and breach response. Manufacturers and logistics firms face questions about operational continuity and segmentation. Retailers are asked about payment-card handling. Knowing how your sector is perceived helps you anticipate the questions and prepare relevant evidence.
11Details that are easy to overlook
Check sub-limits for social engineering, funds-transfer fraud and business interruption, since these may be far below the headline limit. Understand waiting periods for interruption cover and how reputational harm is treated. Confirm whether the policy requires you to use panel vendors for forensics and legal advice. Look for conditions regarding unsupported software and unpatched vulnerabilities. Note the retroactive date and notification requirements so that an incident is reported inside the policy's timelines.
12Questions for your leadership team
What would a week of downtime cost us, and does our cover reflect that? Who completes and signs the application, and what evidence supports it? Are we comfortable that our answers are accurate today? Do we know the process for notifying the insurer and engaging responders? How will we use the underwriter's questions as a roadmap for security investment? The questionnaire is a free checklist of controls that the market considers important.
Checklist
- MFA enforced everywhere with evidence
- Monitored EDR across all endpoints
- Immutable backups with dated restore tests
- Patch reports for the last quarter
- DMARC and email filtering in place
- Training completion records
- Incident plan and insurer contacts documented
- Application answers reviewed by IT and leadership
Where this fits in your IT plan
Guidance like this works best when it is part of a coordinated programme rather than a one-off fix. These IT Experts services address the topic directly:
Hardware Procurement & Lifecycle
We standardise on a short list of business-grade devices, procure them, pre-configure them with zero-touch provisioning and track every asset through to secure retirement.
SVC / BUILDAzure & AWS
Our Azure and AWS service covers architecture, deployment and ongoing operation of cloud workloads, from virtual desktops and line-of-business servers to storage, networking and identity integration.
SVC / OPERATECo-Managed IT
Co-managed IT pairs your internal IT staff with our engineers and tooling. You keep the people who understand your business; we add monitoring, security operations, escalation expertise and surge capacity.
How IT Experts can help
IT Experts is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery. If this topic matches a situation in your organisation, book a free 30-minute consultation: call (604) 632-4959 or email info@SAZ.ca. We will give you a plain-language view of your options and, if useful, a fixed-price scope. We are an IT services and consulting firm, not a reseller, and there is no lock-in.
Frequently asked questions
Will better security reduce my premium?
It can improve eligibility and terms, though pricing depends on the insurer, sector, revenue and claims history.
Do insurers require MDR?
Not universally, but 24/7 monitoring is increasingly requested for larger or higher-risk organisations.
Can IT Experts fill in the application?
We can supply technical evidence and review answers for accuracy; your broker and leadership remain responsible for the submission.
What if we cannot meet a requirement yet?
Document the gap and a remediation timeline. Many insurers will consider a plan with dates.