Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
This is the control-by-control readiness kit for Canadian contractors facing a cyber insurance application or renewal. Every control is mapped to what underwriters actually ask, with what a defensible “yes” requires in practice and the evidence to keep on file. The download is a free PDF built for an owner or controller, not a CISO.
It exists because construction is a payment-redirection target: the Canadian Anti-Fraud Centre has flagged contracting and construction among the sectors commonly hit by payment-redirection fraud, and reported Canadian businesses losing more than $58 million to spear phishing in 2023 across all industries.
What’s in this download
- A 15-control readiness checklist in three tiers: baseline eligibility controls, submission strengtheners, and claims-survival controls, each with the underwriter’s question, what “yes” requires, and the evidence to keep.
- A job-site and multi-site hardening addendum: trailer connectivity standard, network separation, kiosk devices, and project close-out de-provisioning.
- The payment-fraud prevention runbook: verbal call-back verification for banking changes, dual authorization, and the first-hour funds-recall sequence.
- An incident readiness one-pager, plus the T-90/60/30 renewal checklist and the six questions to put to your broker.
Why insurers look harder at construction
According to the Canadian Anti-Fraud Centre, payment-redirection frauds commonly target construction, contracting, and real estate businesses. In an April 2026 case, roughly $3.5 million diverted from a Quebec business was recovered after the incident was reported quickly, allowing the CAFC and financial institutions to coordinate a response.
The construction attack surface is specific: progress payments large enough to justify patient, targeted fraud; project data (bids, drawings, schedules) that ransomware can freeze at the worst contractual moment; a rotating cast of subcontractors and suppliers whose emails are easy to spoof; and job-site connectivity stitched together trailer by trailer.
Underwriters price all of that. The applications now ask directly about multi-factor authentication (MFA), endpoint detection and response (EDR), offline or immutable backups with tested restores, patching cadence, and payment-verification procedures. An unsupported “yes” is worse than a documented “no, planned for this quarter”: misrepresented controls are a documented reason claims get denied.
This kit groups that work into three practical tiers: baseline eligibility controls, submission strengtheners, and claims-survival controls. The third tier focuses on keeping your application answers true and evidenced through the policy term. The control specifics overlap with much of the Canadian Centre for Cyber Security’s Baseline Cyber Security Controls for Small and Medium Organizations, so most of the same work serves both the insurer and your actual security.
Who is this for?
This kit is for the owner, controller, or operations lead at a Canadian construction company. That includes general contractors (GCs), trade contractors, and design-build firms buying cyber insurance, renewing coverage, or proving coverage for a bid. If your last application had a “yes” you could not evidence, this kit closes that gap before it becomes a claims problem.
It is not written for enterprise constructors with a security team, and it is not insurance advice: coverage decisions belong with your broker. The kit arms that conversation; the six broker questions in Part 6 are the ones that surface smaller limits inside the policy (sublimits) and exclusions before you need them.
Download the Contractor Cyber Insurance Readiness Kit
Fill in the three fields below. You get the PDF download link on screen as soon as you submit, and we email you a copy as a backup.
FREE DOWNLOAD
The Cyber Insurance Readiness Kit for Canadian Construction Companies (2026)
The 15-control underwriter-mapped checklist, job-site hardening addendum, payment-fraud runbook, and renewal playbook in one PDF.
Written by Mike Pearlstein, CISSP. No sales call required. Prefer to talk it through? Contact Fusion.
Form not loading? Email us directly and we’ll send the kit the same business day.
Related deep dives
- Cyber insurance requirements in Canada: the eight controls insurers now expect, and the denial mechanisms the kit’s Tier 3 defends against.
- The cyber insurance coverage checklist: first-party vs third-party coverage, sublimits, and waiting periods explained.
- The interactive cyber insurance readiness matrix: score your current posture in ten minutes before you open the kit.
- Cybersecurity for Canadian construction firms: the construction threat landscape behind the checklist.
- Top IT providers for construction firms in Canada: how to evaluate the partner who implements the controls.
Frequently Asked Questions
What’s the download?
A PDF kit: the 15-control readiness checklist in three tiers with underwriter questions and evidence lists, the job-site and multi-site hardening addendum, the payment-fraud prevention runbook with the verbal verification protocol, an incident readiness one-pager, and the renewal checklist with six broker questions. Written for a construction owner or controller, adoption-ready without our involvement.
How will my data be used?
Your name, company name, and email go into Fusion Computing’s contact system. We email you a copy as a backup. We may send occasional updates relevant to Canadian construction IT and cyber insurance, no more than once a month.
We do not sell your contact information. We use service providers, including our CRM and email systems, to process the form and deliver the kit. Every marketing email has a one-click unsubscribe.
Is this just a sales pitch?
No. The kit is the deliverable, and it works without our involvement. You do not need to speak to us to use it. If you later want help implementing the controls, MFA rollout, EDR, immutable backups, job-site network standards, that is work Fusion does for Canadian contractors, and you can reach out on your own timeline.
Will this guarantee my claim gets paid?
No document can. What the kit does is target the documented reasons claims fail: controls misrepresented on the application, controls that lapsed between renewals, and missing evidence. Tier 3 is built around keeping your answers true and provable on the day you need the policy to respond. Coverage specifics remain between you and your broker.
Can I share it with my broker or my team?
Yes, please do. The renewal section is designed to be worked through with your broker, and the checklist tiers are meant to be assigned inside your team. Attribution to Mike Pearlstein and Fusion Computing must remain on the document. No resale.
Who wrote this?
Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. The kit was written against Canadian Anti-Fraud Centre publications on payment-redirection and spear-phishing fraud, the Canadian Centre for Cyber Security’s baseline controls for small and medium organizations, and the insurer control expectations documented across Fusion’s cyber insurance guides, all verified against the primary sources in August 2026.
Bottom line
Cyber insurance readiness starts before the application and continues through the policy term. Payment-redirection fraud is a known construction risk. A written call-back rule and dual authorization reduce that risk and give your team a repeatable way to check banking changes. This kit puts the controls, evidence list, and renewal steps in one document your controller can start working through today.
If you want help implementing the controls behind the checklist, Fusion can help with multi-factor authentication, endpoint detection and response, backups, and job-site network standards.

