Cyber Insurance Coverage Checklist: What Canadian Businesses Need to Qualify in 2026

Tags: compliance, Cyber Insurance, cybersecurity

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Securing IT for Canadian businesses since 2012 across Toronto, Hamilton and Metro Vancouver.

Cyber insurance underwriting has tightened sharply in Canada. Premiums climbed and sub-limits shrank while carriers turned security controls into preconditions. Canadian SMBs that bought a policy on a one-page application in 2022 now answer 60-question control questionnaires.

This is the cyber insurance coverage checklist Fusion Computing uses with Canadian businesses of 10 to 150 users at renewal. It sets out what the underwriting desk expects, where claims fail and how to evidence each control before the broker calls.

What should a cyber insurance coverage checklist include?

A cyber insurance coverage checklist should include the five controls Canadian underwriters verify before binding. Those are enforced MFA on email and remote access, EDR on every endpoint, immutable backups with a tested restore, a documented incident response plan, and quarterly security awareness training. It should also map each control to the evidence your broker will request, because Canadian carriers now treat these as binary pass-or-fail items.

KEY TAKEAWAYS

  • Canadian carriers treat MFA, EDR and immutable backups as binary pass/fail items on the checklist.
  • IBM put the average Canadian data breach at a record CA$7.11M in 2026. That is the exposure your limits have to answer.
  • Most denied claims trace back to an inaccurate control attestation rather than policy wording.
  • First-party coverage funds your own recovery. Third-party answers the people a breach harmed, and Canadian SMBs underbuy it.
  • Canadian cyber rates fell 5% in Q1 2026 on the Marsh index, so a clean evidence pack now buys price too.
  • Start pre-renewal work 90 days before expiry, so the evidence pack and the MFA rollout finish before the underwriter sees them.

What is cyber insurance and what does it actually cover?

According to the Coalition 2026 Cyber Claims Report (2026), initial ransom demands jumped 47% year over year to more than US$1 million in 2025, and 86% of policyholders hit by ransomware refused to pay. The CCCS National Cyber Threat Assessment (2024) names ransomware the top cybercrime threat to Canada. Those two lines explain the current underwriting posture.

Cyber insurance is a specialty liability product covering financial losses from cybersecurity incidents. A Canadian business policy pays for these 6 things.

  • Forensic investigation and breach counsel.
  • Ransom negotiation, subject to a sub-limit.
  • Breach notification and credit monitoring.
  • Regulatory defence under PIPEDA and provincial privacy statutes.
  • Business interruption and data restoration.
  • Third-party claims tied to breached personal information.

Coverage is conditional on the controls you disclosed at application. Canadian underwriters in 2026 want documented security operations evidence, meaning monthly reporting, response logs and forensic artifacts. For the contractual model that produces it, see our guide on what an MSSP is and the 6-criterion evaluation rubric.

Canadian SMB policies in 2026 are no longer commodity products. Carriers stratify quotes by control posture, sector and revenue band. A 40-user Toronto firm with documented MFA and EDR attracts very different terms than a same-size manufacturer running a flat network. Bringing in cybersecurity services before the application closes is the cheapest place to fix a gap, and the CISSP-led team assembles the artifacts underwriters ask for.

The 8 controls Canadian cyber insurance underwriters now require.

According to Canadian Underwriter (2025), excess cyber rate factors in Canada fell by as much as 40% over two years. Carriers paid for that softening by writing multi-factor authentication and the rest of the control set into the policy as conditions. Cheaper coverage is genuinely available to Canadian SMBs that can evidence the eight controls below.

The 2026 Canadian underwriting standard has consolidated around eight controls. Beazley, Chubb, Coalition, Intact and Northbridge ask for the same core set. Failing one usually means a higher premium, a reduced ransomware sub-limit or a declination.

Control. What insurers ask. Pass threshold.
MFA Enforced on email, VPN, RDP and admin consoles? 100% of remote and privileged accounts via Microsoft Entra ID.
EDR Modern EDR with 24/7 monitoring on all endpoints? Behaviour-based endpoint detection everywhere. No signature-only antivirus.
Email security with DMARC DMARC at p=reject, with attachment sandboxing on? SPF, DKIM and DMARC p=reject on every domain.
Immutable backup with tested restore Immutable backups, restored quarterly? 3-2-1-1-0 architecture with a dated restore log inside 90 days.
IR plan with annual tabletop Written IR plan and a yearly exercise? Runbook with named roles, plus a tabletop after-action inside 12 months.
Awareness training with phishing sims Users trained and phish-tested on schedule? Quarterly phishing simulations, annual training, click-rate trend.
PAM Admin accounts separated and vaulted? Separate admin identities, vaulted credentials, just-in-time elevation.
Network segmentation User, server and OT segments isolated? Firewall VLANs separating user, server, OT, guest and management traffic.

In our practice across Canadian SMB renewals in 2025 and 2026, MFA gaps and untested backups drive most premium increases. The fix is operational rather than technological, and it finishes inside one quarter when the work is planned alongside the broker timeline.

Cyber insurance qualification checklist: 12 controls and evidence required.

According to CIS Controls v8.1 (2024), the Implementation Group 1 baseline is the safeguard set written for organizations with limited security staff. It maps almost one for one onto what Canadian underwriters ask in 2026, which is why the matrix below pairs each control with the broker question and the artifact your evidence pack has to hold.

Fusion Computing uses this matrix during pre-renewal assessments for Canadian SMBs of 10 to 150 users. Every row is a question a Canadian broker has put in writing.

Control (CIS v8.1). What insurers ask. Evidence required.
MFA on email (CIS 6.5) Is MFA enforced on all email accounts, including shared mailboxes? Entra ID conditional access export, plus a 100% coverage report.
MFA on remote access (CIS 6.5) Is MFA enforced on VPN, RDP gateway and exposed admin consoles? VPN gateway export, conditional access policy, external scan showing no exposed admin portal.
EDR on all endpoints (CIS 10.7) Is modern EDR with 24/7 monitoring on every endpoint and server? Coverage dashboard showing every device enrolled, signed off by your detection provider.
Immutable backups (CIS 11.2) Are backups immutable, offsite and outside the production domain? 3-2-1-1-0 diagram, immutability attestation, offsite copy confirmation.
Backup restore testing (CIS 11.5) When was the last documented restore test, and did it succeed? Dated restore log inside 90 days, named tester, recorded recovery time.
Incident response plan (CIS 17.1) Is there a written IR plan with named roles and timelines? IR plan PDF with version date, named officer signature, insurer contact line.
Annual tabletop exercise (CIS 17.7) Has a tabletop run in 12 months with an after-action report? After-action document, participant list, lessons learned with close dates.
Security awareness training (CIS 14.1) Are staff trained at hire and on a cadence, with phishing sims? Phishing simulation reports, annual completion export, click-rate trend.
Patch management SLA (CIS 7.3) What is your SLA for critical and high-severity patches? Documented SLA, commonly 14 days critical and 30 days high, plus a Microsoft Intune compliance report.
Network segmentation (CIS 12.2) Are user, server and OT segments separated by firewall policy? Firewall config showing VLAN separation, plus a topology diagram.
Privileged access management (CIS 6.8) Are admin accounts separate from daily accounts and vaulted? Vault report, admin identity naming convention, just-in-time elevation log.
Email security and DMARC (CIS 9.5) Is DMARC at p=reject with SPF and DKIM on every sending domain? DMARC aggregate report, SPF and DKIM DNS records, sandboxing config.

Talk to Fusion

Source: IBM put the average Canadian data breach at a record CA$7.11M in 2026, up from CA$6.98M a year earlier, with the full breach lifecycle running 205 days. (IBM Cost of a Data Breach Report (2026).)

First-party vs third-party coverage.

According to the NetDiligence Cyber Claims Study (2025), 98% of the 10,402 claims it analysed came from organizations under US$2B in revenue, and the five-year average incident cost for that group was US$246,000. Those are the numbers your first-party and third-party limits have to answer. Canadian SMBs usually size only the first one.

Cyber policies bundle two products. First-party covers the insured business’s own losses. Third-party covers claims brought by the people a breach harmed, including complaints to the Office of the Privacy Commissioner. Canadian SMBs buy enough first-party and underbuy third-party, then discover the shortfall during a class action.

First-party (your costs). Third-party (others’ claims).
Forensic investigation and incident response. Privacy regulator investigations and PIPEDA defence.
Ransomware payment and recovery costs. Class action defence after a personal-data breach.
Business interruption and lost revenue. Vendor liability for downstream impact.
Breach notification and credit monitoring. Media liability and reputational claims.
Data restoration and system rebuild. Regulatory fines where insurable.

Size third-party limits against the worst-case notification population rather than IT spend. The Office of the Privacy Commissioner, the provincial regulators and the courts treat record counts as the unit of harm, and a 30,000-record incident escalates fast. For the regulatory mechanics, see PIPEDA breach reporting and notification obligations.

Working through this for your business?

Mike Pearlstein, CISSP, and the Fusion Computing team support Canadian SMBs with getting cyber-insurance-ready or closing the control weaknesses your insurer asks about. Free 30-minute consult, we will tell you what we would do.

Book a consult →

Why do cyber insurance claims get denied?

According to the Coalition 2026 Cyber Claims Report (2026), dual-extortion incidents made up 70% of ransomware claims in 2025 and averaged US$302,000, roughly twice the cost of an encryption-only event. Those are the claims a carrier examines hardest, and a control you overstated on the application is what turns a payable claim into a denial.

The policy almost always pays when the application was honest and the controls were genuinely running. In the files Fusion Computing has reviewed, the painful denials come from misstated controls and lapsed evidence.

In our practice the five most common denial reasons look like this.

  • MFA was not enforced on the account the attacker actually used.
  • EDR was never deployed on the affected server. Our managed detection and response review covers the monitoring layer underwriters accept.
  • Backups existed, but no restore test had run inside 12 months.
  • The incident response plan claimed on the form did not exist in writing.
  • A privileged credential had been reused on a personal service.

Each one is a yes on the form that should have been a no.

Social engineering and funds-transfer fraud sub-limits are a separate failure mode. Coalition (2026) found 39% of funds-transfer-fraud events happened with no confirmed email compromise. Those claims pay at a fraction of policy limit, because the sub-limit sits buried in the schedule. Reading that page is the highest-yield 30 minutes at renewal.

A Hamilton client renewed in early 2026 thinking their ransomware sub-limit was their full policy limit. It was not. The schedule capped ransomware at 25% of the aggregate. We restructured with a different carrier the next quarter, kept premium nearly flat and doubled the practical recovery ceiling. The certificate is marketing. The schedule is the policy.

Field note from Mike Pearlstein, CISSP, CEO of Fusion Computing.

Qualification for Canadian SMBs in 2026 is binary on five controls. Enforced MFA, EDR everywhere, immutable backups with a recent restore log, a written IR plan with a tabletop, and quarterly awareness training. Roughly half of new prospects fail one of those five during the application. Closing that with documented evidence shifts the quote category.

How does the cyber insurance application process work?

According to Canadian Underwriter (2026), cyber rates in Canada fell 5% in the first quarter of 2026 on the Marsh index as capacity expanded across primary and excess layers. More competition has not shortened the questionnaire. It moved the pricing spread onto how well you evidence each answer.

The application is a structured questionnaire, often 40 to 80 questions across identity, endpoint, network, data, vendor and governance. Underwriters score the answers, scan your public-facing footprint and price against carrier minimums. The cycle takes two to six weeks for a clean Canadian SMB account.

The work itself falls into three buckets.

  • Evidence. MFA screenshots, EDR coverage reports, dated restore logs, training exports, IR plan PDF.
  • Attestation. A named officer signs each answer as true on a specific date.
  • External posture. The carrier scans your public IPs and DNS. What it sees has to match what you attested.

Need this prepared for an upcoming renewal? Get in touch and walk into the broker meeting with all 12 artifacts already assembled.

What is changing in the Canadian cyber insurance market in 2026?

According to the Office of the Superintendent of Financial Institutions (2024), federally regulated financial institutions must reach full adherence with Guideline E-21 on operational risk and resilience by September 1, 2026. That deadline is now flowing down into the vendor questionnaires Canadian SMBs receive from their bank, insurer and pension-fund clients.

For the wider 2026 threat picture behind these underwriting changes, see my state of cybersecurity in Canada 2026 briefing, which sources the CA$6.98 million average Canadian breach cost and CIRA’s 74% ransom payment rate.

Three shifts matter for Canadian SMBs in 2026.

  • Bill C-8 flow-down. The Critical Cyber Systems Protection Act received royal assent on June 15, 2026 (Public Safety Canada (2026)). Designated operators in telecom, banking, energy and transportation now carry cyber-program duties, and their suppliers face the same review.
  • OSFI E-21 in financial services. Operational-resilience expectations are landing in questionnaires sent to any firm serving a federally regulated institution.
  • Provincial privacy pressure. British Columbia’s PIPA, Quebec’s Law 25 and Ontario’s PHIPA enforcement are pushing third-party limits up.

Across the Canadian carrier questionnaires Fusion Computing reviewed in the first half of 2026, nine of eleven now include an AI governance attestation. They ask whether production data can be pasted into consumer LLMs and whether vendor reviews reach GenAI subprocessors.

Carrier. 2026 emphasis.
Beazley EDR plus 24/7 monitoring. Tighter ransomware sub-limits without managed detection.
Chubb Privileged access management. Immutability evidenced via vendor reports.
Coalition External attack surface scoring in pricing. Rewards a documented patch SLA.
Intact Canadian SMB focus, PIPEDA alignment and IR plan attestation.
Northbridge Sector underwriting for healthcare, professional services and manufacturing OT.
What actually happened to cyber claims in 2025.Four outcome percentages from the Coalition 2026 Cyber Claims Report, shown as horizontal bars.What happened to cyber claims in 2025.Coalition policyholder claims, 2025 claim year.Refused to pay ransom.Dual-extortion ransomware.Closed at zero cost to insured.Fraud with no email breach.86%70%64%39%Recoverable backups and evidenced controls are what let a business refuse.Source: Coalition 2026 Cyber Claims Report. fusioncomputing.ca
Most policyholders now refuse the ransom, and most closed claims cost the insured nothing. Both outcomes depend on controls evidenced before the incident. Source: Coalition (2026).

Source: Statistics Canada found 16% of Canadian businesses were impacted by a cyber security incident in 2023, and that recovery spending doubled to CA$1.2B over two years. (Statistics Canada (2024). The 2025 cycle of the survey closed in March 2026 and has not been published yet.)

How does an MSP help you qualify and stay compliant?

According to the Canadian Centre for Cyber Security (version 1.2, 2020), its baseline controls are written for organizations under 499 employees and assume most will not run security operations in-house. A CISSP-led MSP is how a 40-person Canadian firm gets that baseline running, monitored and evidenced without hiring a security team for it.

A CISSP-led MSP changes the renewal in three places. It runs the controls so the attestation matches reality. It builds the evidence pack. It stays present after binding, so a midterm change does not silently void your coverage.

Fusion Computing standardizes Canadian SMBs on Microsoft Entra ID for identity, Microsoft Defender for Endpoint plus a managed detection service on the endpoint, and Microsoft Intune for device compliance. A next-generation firewall and a password vault hold the network and privileged-access answers. Managed detection and response maps directly to what insurers ask about 24/7 monitoring, dwell time and escalation.

Before the renewal call, run the controls through our cybersecurity assessment checklist for Canadian SMBs, which pairs each of the 8 categories with the evidence a Canadian underwriter asks to see.

Pre-renewal checklist: review 90 days before expiry.

According to Coalition (2026), 64% of closed claims in 2025 resolved with zero out-of-pocket loss to the policyholder. That outcome belongs to businesses whose controls held up under review, which is exactly what the 90-day run-up below is designed to produce for a Canadian SMB.

Renewals fail when the work starts three weeks before expiry. Starting 90 days out lets a Canadian SMB close MFA gaps, run a tabletop and assemble an evidence pack that lands with the broker call.

  1. Day 90: pull the prior application. Validate every yes against reality.
  2. Day 80: run an MFA coverage report. Close every uncovered account on email, VPN and privileged consoles.
  3. Day 70: verify EDR on every endpoint. Remove signature-only antivirus remnants.
  4. Day 60: execute a restore test from immutable backup. Save the dated log.
  5. Day 45: hold the IR tabletop. Document the after-action, refresh the plan PDF.
  6. Day 30: run a phishing simulation. Export training completion and DMARC reports.
  7. Day 15: assemble the evidence pack. Brief the named officer, pre-read sub-limits.
  8. Day 0: sign the application with the evidence in hand.

Book a Consultation

Book a consultation with a CISSP-led team and get a renewal-ready cyber insurance coverage checklist tailored to your environment.

Frequently asked questions

Is cyber insurance mandatory for Canadian businesses?

Cyber insurance is not legally mandatory for most Canadian businesses. Enterprise customer contracts, federal procurement and regulated-sector vendor terms increasingly require it anyway. Many large Canadian buyers require suppliers to carry cyber liability with minimum limits and named ransomware coverage. Most Canadian SMBs now buy coverage to keep customers.

How much cyber insurance does a Canadian SMB need?

Most Canadian SMBs of 10 to 150 users land between CA$1M and CA$5M in aggregate coverage, with sub-limits sized against record counts and downtime cost. Healthcare, financial services and any business holding large volumes of personal information needs higher third-party limits, because exposure scales with record count. Size it from a written exposure analysis rather than the cheapest quote.

Which sub-limits should I check on a Canadian cyber policy?

Check four schedule lines before you sign. Ransomware and cyber extortion is often capped at 10% to 25% of the aggregate limit. Social engineering and funds-transfer fraud frequently sits between CA$100,000 and CA$1M. Business interruption carries a waiting period, commonly 8 to 12 hours, and dependent business interruption for a cloud outage is often excluded. The schedule is authoritative, not the certificate.

Does cyber insurance cover ransomware payments?

Most Canadian cyber policies cover ransomware payments under an extortion clause, subject to a sub-limit and pre-approval by the carrier’s breach coach. Payments to OFAC-sanctioned groups are excluded, and several carriers require evidence of immutable backups first. The sub-limit often sits well below the headline policy limit.

What is the difference between cyber liability and tech E&O?

Cyber liability covers losses from cybersecurity incidents that affect the insured business or its customers. Tech errors and omissions covers professional liability for technology services delivered to clients, such as a coding error or a missed SLA. Most Canadian technology firms need both, and the right structure depends on revenue mix and contract requirements.

Will cyber insurance pay if MFA was not enabled?

If the application attested that MFA was enforced and the breach traces to an account without it, most Canadian carriers will deny on misrepresentation. If partial MFA was disclosed and the breach hit that known gap, payment is more likely, though premium and sub-limits will reflect that posture. Attest accurately, then remediate before the next renewal.

Can I use a SOC 2 report or CyberSecure Canada certification as evidence?

They help, and neither replaces the artifacts. A SOC 2 Type 2 report or a CyberSecure Canada certification tells the underwriter an independent party reviewed your programme, which can shorten the review and improve terms. Canadian brokers still ask for the same 12 dated artifacts, because a certification issued 10 months ago says nothing about MFA coverage this morning.

How long does the cyber insurance application process take?

A clean Canadian SMB application takes two to four weeks from questionnaire to bound policy if the evidence pack is ready. Accounts with control gaps or a recent incident take longer, because underwriters request remediation evidence. Starting 90 days before expiry leaves room to fix what the questionnaire surfaces.

Are regulatory fines covered by Canadian cyber insurance?

Cyber policies cover regulatory investigation defence under PIPEDA, British Columbia’s PIPA, Quebec’s Law 25 or Ontario’s PHIPA, plus fines where insurable by law. Some statutory penalties are not insurable in certain provinces, and wording varies. Federally regulated entities should confirm how Bill C-8 and OSFI E-21 duties interact with the regulatory defence section.

How do Bill C-8 and OSFI E-21 reach a small Canadian supplier?

Neither one regulates a 40-person firm directly. Both reach you through your customers. A designated operator under Bill C-8, which received royal assent on June 15, 2026, has to manage supply-chain cyber risk, and an OSFI-regulated institution must reach full E-21 adherence by September 1, 2026. Expect their procurement teams to pass the same control questions down.

What is a cyber insurance evidence pack and why does it matter?

An evidence pack is the bundle of screenshots, exports and PDFs that proves each yes answer. It typically holds 8 artifacts: MFA coverage reports, endpoint detection dashboards, dated restore logs, the IR plan PDF, the latest tabletop after-action, training exports, DMARC reports and a segmentation diagram. A well-built pack defends the policy if a claim is ever contested.

Can a Canadian SMB get cyber insurance after a breach?

Yes, though the application is harder and several carriers will decline new business for 12 to 24 months after a material incident. The pathway is documented remediation, a forensic report, evidence the root cause is closed and a higher retention. A CISSP-led MSP building that post-incident control story shortens time to bindable coverage.

Underwriters ask for the register before they ask for anything else. Our guide to how to conduct a cybersecurity risk assessment shows how to produce one in two to four weeks.

Carriers now ask for 24/7 monitoring by name, which is the single most common reason a Canadian SMB moves to a co-managed MSSP model rather than hiring a second IT generalist.

Related Resources

Renewal timings and control-gap patterns here come from anonymized client data, an FC internal benchmark from Q2 2026 and first-person field observation. Fusion Computing is a CISSP-led Microsoft Solutions Partner.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 10 to 150 employees across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611