Cyber Insurance Questionnaire Cheat Sheet (Free Download for Canadian SMBs)
The 18 CIS Controls v8.1 beside the questions Canadian cyber insurance applications ask, with the evidence to keep for each and what to do when a control is not in place.
Built by Fusion Computing’s CISSP-led team. Organised by CIS Controls v8.1, using the questions on two public Canadian application forms (Victor, 2023, and Northbridge, 2022) and Marsh’s list of twelve controls.
Toronto-based MSP since 2012
10–150 employee Canadian SMBs
Organised by CIS Controls v8.1
Reviewed by Mike Pearlstein, CISSP
Why your renewal got harder
A 2023 cyber-insurance renewal in Canada was a one-page form. A 2026 renewal is a forty-question audit. The questions in the cheat sheet come from two public Canadian application forms: the Victor Insurance Managers cyber insurance application (September 2023) and the Northbridge Cyber Risk Insurance Application (September 2022). Marsh’s list of twelve key controls sits beside them. The same controls come up under different wording, and each answer needs evidence you can produce. The same control shows up under different question phrasings, but the evidence requirement is identical: produce a date, a system, a screenshot, or a signed policy. “We have it” is no longer an acceptable answer.
For Canadian SMBs in the 10–150 employee range, the practical effect is brutal. Many firms find at least one control they cannot evidence on the day the broker sends the form. The result can be a renewal surcharge, a sub-limit on ransomware, an exclusion on social-engineering loss, or an outright declination.
The hardening you are reading about is real: According to Marsh’s 2025 Global Insurance Market Index, cyber-renewal premiums rose 6 to 12% sequentially in Canada with control-driven differentiation. Coalition’s 2025 Cyber Claims Report named MFA, EDR, immutable backups, and 24/7 monitoring as the four controls that move loss ratios most. The same controls show up on every insurer questionnaire reviewed this renewal cycle. Sources: marsh.com, coalitioninc.com, atbay.com.
What’s inside the PDF
Ten pages, formatted for partner-meeting use. Cover, how to use it, what insurers look for, the eighteen controls, payment questions, six checks before you sign and five questions for your broker. Bring it to the broker call. Bring it to the underwriter call.
Ten pages, eighteen controls, one structure per control
- Page 1, Cover and author credit
- Page 2, How to use the cheat sheet, four rules before you answer, and what happened in Travelers v. ICS
- Pages 3–8, Marsh’s twelve controls, then all eighteen CIS Controls v8.1 with what the forms ask
- Pages 9 and 10, Payment questions, six checks before you sign, five questions for your broker, and sources
Every control tells you three things
- What the forms ask, from the Victor and Northbridge application forms
- The evidence to keep, such as a dated device list, a report of accounts with and without MFA, a restore test from the last 90 days and a vendor list
- What to do next, when the control is not in place today
The eighteen controls covered
- 1. Inventory and Control of Enterprise Assets · 2. Inventory and Control of Software Assets
- 3. Data Protection · 4. Secure Configuration of Enterprise Assets and Software
- 5. Account Management · 6. Access Control Management (MFA)
- 7. Continuous Vulnerability Management · 8. Audit Log Management
- 9. Email and Web Browser Protections · 10. Malware Defenses (EDR + 24/7 SOC)
- 11. Data Recovery (immutable backups + tested restore) · 12. Network Infrastructure Management
- 13. Network Monitoring and Defense · 14. Security Awareness and Skills Training
- 15. Service Provider Management (vendor list and security evidence) · 16. Application Software Security
- 17. Incident Response Management (runbook + tabletop) · 18. Penetration Testing
Get the PDF
The download link appears on screen as soon as you submit, and we email it to you as well. Bring the questionnaire and the renewal date to a free 30-minute discovery call, and we will walk through it with you and your broker.
Who this is built for
Cyber-insurance questionnaire FAQ
What do cyber-insurance underwriters ask about most?
MFA on all remote and admin access, segregated and restore-tested backups, endpoint detection and response, email filtering and authentication, and a documented incident-response plan. A “no” on MFA or backups is the most common reason a policy is declined or surcharged.
Can a wrong answer void my cyber-insurance policy?
Yes. Insurers have denied claims where the insured attested to controls, such as MFA everywhere, that were not actually in place. The application is a representation, and a material misstatement can void coverage.
Do small Canadian businesses really need cyber insurance?
Most now do, because clients and contracts increasingly require it and the cost of an incident far exceeds the premium. The questionnaire itself also doubles as a useful security baseline.
How do I prepare for a cyber-insurance renewal?
Close the common gaps first: enforce MFA everywhere, confirm backups are segregated and restore-tested, deploy EDR, and document your incident-response plan. Walk into the renewal able to answer “yes” with evidence.
Canadian SMBs in the 10–150 employee range who have either received a 2026 renewal questionnaire and felt the temperature change, or who are coming up on a first-time cyber-insurance application and want to know what the underwriter will ask before they fill out the form.
Operating roles get the most out of the cheat sheet: founders and CEOs at firms without a dedicated IT director, CFOs and controllers handling the renewal cycle, COOs and operations leads who own the broker relationship. Internal IT leads use it as a translation layer between the underwriter’s language and their own stack. Brokers tell us they use it as the working agenda for the discovery call with the underwriter.
The mapping is industry-neutral. The same eighteen controls show up whether you are a Toronto law firm, a Hamilton manufacturer, a Vancouver accounting practice, an Ottawa wealth firm, or a Mississauga distributor. The questions adjust slightly by sector. The controls do not.
Related resources from Fusion
The cyber-insurance cheat sheet sits inside Fusion’s broader library of practitioner-built compliance and operational evidence templates for Canadian SMBs. If your firm operates inside a regulated profession, the sector-specific resources below are typically the starting point and the cyber-insurance cheat sheet is the second-pass overlay. Pair it with our cyber insurance coverage checklist, which walks through each control and the evidence Canadian carriers expect behind it.
Sector-specific evidence packets
- CPA Technology Competence Checklist, the line-by-line baseline for Canadian accounting firms covering PIPEDA, CPA Canada, CRA EFILE, and the cyber-insurance overlay
- CIRO Third-Party Risk Evidence Template, the vendor-inventory structure CIRO-registered wealth firms produce for Financial and Operations compliance examinations
- FIPPA / MFIPPA IT Controls Matrix, the controls inventory Ontario public-sector institutions use for their privacy program
Working with Fusion
- Cybersecurity services overview, the operational scope behind every line in this cheat sheet
- Managed IT services, the full stack we deploy for 10–150 employee Canadian SMBs
- IT business assessment, the 60-minute working-session pattern that produces the cyber-insurance walkthrough we offer brokers
- About Mike Pearlstein, CISSP, founder bio and credentials
We will sit with your broker to walk the questionnaire
Have the cheat sheet, the questionnaire, and a renewal date? Book the 60-minute working session and we will map your stack against the eighteen controls together. No-charge, no expectation that you move IT providers to qualify.

