Download PDF (618 KB)
PDF version to print or share with your team.
Cyber insurance often gets treated like a file-and-forget policy. You buy it, file it in a drawer, and forget about it until something burns. That model is finished. In 2026, a cyber policy comes with conditions: security controls you attest to on the application and are expected to keep running.
Only 22% of Canadian businesses carried cyber insurance in 2023, which leaves roughly four in five exposed (Statistics Canada, 2024). Among small businesses the gap is wider, at about 12% holding standalone cyber coverage on Insurance Bureau of Canada figures cited by McCarthy Tétrault (2026).
For the businesses that do apply, the questionnaire has become a security audit. An inaccurate answer can lead to repricing, rescission or claim denial. The result depends on the policy wording, applicable law, materiality and the facts.
This guide covers controls carriers ask about, why each one matters, and how to compare your current evidence with the actual carrier application before you answer it. The examples below come from Canadian client renewals we have worked through since 2022.
Renewing in Q4? Use October to collect the evidence before the broker asks: training-completion records from a Cyber Security Awareness Month program, plus Entra MFA and Conditional Access exports, EDR coverage, backup configuration and a dated restore-test result. Awareness training only substantiates the training control.
Key takeaways
- Only 22% of Canadian businesses carried cyber insurance in 2023, and about 12% of small businesses hold standalone coverage (2025 figures).
- Carrier applications vary. Common questions include MFA scope, endpoint protection, backups, privileged access, incident response, email security, patching and training. Answer MFA scope for the account classes your carrier names.
- Many applications now ask about EDR rather than signature antivirus, and about immutable backups with a tested restore.
- Rates softened through 2024 and 2025 while eligibility tightened. Eligibility depends on the carrier, limits, industry, claims history, application answers and policy terms.
- Your biggest exposure is not the premium. It is a claim denied for material misrepresentation after a breach.
- Where PIPEDA applies it requires reporting of breaches posing a real risk of significant harm, as soon as feasible. Alberta, British Columbia and Quebec have substantially similar private-sector laws that may apply instead for intraprovincial activity. Insurers underwrite to whichever regime governs you.
What “cyber insurance requirements” mean in 2026
Cyber insurance requirements are the specific security controls an insurer makes you attest to before it will write or renew a policy. Treat every application answer as a material representation that must be accurate. Whether an inaccurate answer permits rescission, claim denial or another remedy depends on the policy wording, applicable provincial law, materiality and the facts. If coverage is disputed, involve the broker and legal counsel.
The policy is the floor those controls create, not a blanket you can pull over a weak setup.
The shift is visible in renewal data. Among Canadian organizations, recent insurer changes included verifying current security measures (39%), raising premiums (38%), and changing the eligibility rules to obtain or renew coverage (37%), according to the 2024 CIRA Cybersecurity Survey.
That is why the application is worth reading as one input to the security backlog. Map the gaps it exposes against CIS Controls v8.1, NIST CSF and your actual risk, because insurance questions do not replace a risk-based baseline and a control no carrier asks about can still be the one that matters. Our CISSP-led cybersecurity services team treats the questionnaire as the deploy backlog for exactly that reason.
Controls carriers commonly ask about
Underwriting varies by carrier, limit and industry, but a recognisable core set recurs. The insurer Coalition names MFA, endpoint detection and response, and secured backups as the essentials. It adds identity and access management and a tested incident response plan, and names MFA among them (Coalition, 2025). The table below shows what each control means on the form.
| Control | What applications typically ask | Why it matters |
|---|---|---|
| Multi-factor authentication | Enforced on email, VPN, remote access, and every admin account, using number-matching or phishing-resistant methods. | Blocks the stolen-credential path attackers rely on. |
| Endpoint detection and response | Behaviour-based EDR or XDR on 100% of endpoints, not signature antivirus. | Catches and isolates threats that antivirus misses. |
| Immutable and offline backups | Encrypted offline or immutable copies, plus a recent restore you actually tested. | Supports restoration without relying on a decryptor; it does not prevent data theft, extortion or every form of business interruption. |
| Identity and privileged access | Least-privilege roles, separated admin accounts, conditional access. | Limits how far an intruder can move once inside. |
| Tested incident response plan | A written plan with named roles, plus its last review date and the last tabletop or test date where the carrier asks for one. | Improves response coordination and provides evidence of preparedness. |
| Email security | DMARC enforced, advanced phishing and attachment filtering. | Reduces direct-domain spoofing; pair it with phishing controls, MFA, mailbox monitoring and payment-verification procedures. |
| Patch and vulnerability management | A defined SLA for critical patches and no exposed end-of-life systems. | Removes the known flaws attackers scan for. |
| Security awareness training | Regular phishing simulation and staff training with records. | Reduces the human-click risk that opens the door. |
None of this is arbitrary. Fusion Computing maps each of these eight controls to CIS Controls v8.1 under CISSP review. That is the same baseline we use for managed clients, so the insurer’s questions and our own security baseline are worked together, without treating the form as the standard.
Book a controls review before your next cyber insurance renewal.
Why MFA scope is the answer to get right
Multi-factor authentication is a common application question. Insurers ask whether MFA is enforced on email, VPN, remote access, and privileged accounts. A “yes” that only covers email misstates the scope, and that gap is what gets tested after a claim. Accepted authentication methods vary by carrier: some still take SMS codes, while others ask for Microsoft Entra number matching or a phishing-resistant method. Answer for the method your actual application asks about.
Key stat
Microsoft’s 2023 Azure AD study found MFA reduced account-compromise risk by 99.22% in the studied suspicious-activity population (Microsoft Entra, 2026). Phishing-resistant methods provide stronger protection than SMS.
In the Canadian renewals we have worked through since 2022, we repeatedly see gaps in MFA scope and in restore-test evidence. Both feel like a quick “yes” under time pressure. Both are easy for a forensics team to disprove later.
EDR and immutable backups: two controls to verify carefully
Applications increasingly ask about endpoint detection and response rather than signature antivirus, wanting a tool that watches behaviour in real time and can isolate a compromised device on its own (Coalition, 2025). They also want backups that are immutable or offline, with a restore you have actually tested and dated. These are two common areas to verify carefully before you answer the application.
The questions people answer wrong are specific: the percentage of endpoints actually covered by EDR, and the date of the last successful restore test. A Hamilton manufacturer we onboarded, around 120 endpoints, looked covered on paper. They had MFA on email, antivirus on most machines, and a nightly backup job.
What they did not have was EDR, MFA on the VPN or a shared admin login, or a restore test in over 14 months. That combination is a declined application.
Design practices carry an extra wrinkle here, because the seal and signing workflow is itself an insurable credential. We cover that in our guide to cybersecurity for architecture and engineering firms.
In the Canadian renewals we have worked through since 2022, moving an antivirus-only client to full EDR coverage can be substantial work. Our disaster recovery approach pairs that with immutable backups and a scheduled restore test, so the backup answer is true and provable.
The application is now a line-by-line security audit
Cyber applications have grown into detailed control questionnaires mapped to frameworks like CIS Controls and NIST CSF. An inaccurate application answer or an unmet policy condition can affect coverage. The result depends on the application and policy wording, applicable law, materiality and the facts. Keep dated evidence of what was in place, and involve the broker and legal counsel if coverage is disputed. The 10 domains below recur across the applications we see.
| Domain | What the application asks |
|---|---|
| Identity and access | MFA coverage, conditional access, privileged-account separation. |
| Endpoint security | EDR or AV vendor, version, deployment coverage percentage. |
| Email security | DMARC posture, phishing filtering, attachment sandboxing. |
| Backup and recovery | Frequency, retention, immutability, offline copy, last restore test. |
| Network security | Firewall, segmentation, remote-access controls, and how often penetration testing is done. Testing intervals vary by carrier. |
| Patch management | Critical-patch SLA, end-of-life systems, vulnerability scanning. |
| Third-party risk | Vendor access, supplier security review. |
| Incident response | Written plan, named roles, last test date. |
| Training | Awareness program, phishing simulation cadence. |
| Prior incidents | Past breaches, claims, regulatory notices. |
Reading the form this way is useful even before you buy. A Fusion Computing cybersecurity assessment against these same 10 domains tells you where you stand and what to fix first based on your risk. Then check the actual carrier application for any additional scope, method or evidence requirements before you answer it.
What changed in 2026 versus 2025, and where did the bar move?
Canadian buyers hit an odd market this year. Canadian cyber-market conditions softened through 2024 and 2025 as capacity and underwriting stabilized, though pricing varies by carrier, limits, claims history and risk profile, per Canadian Underwriter (2025). Eligibility tightened over the same stretch. Cheaper coverage is on the table for Canadian SMBs that can evidence their controls.
The underwriting bar moved because the loss data did. In CIRA’s 2025 survey of Canadian cybersecurity decision-makers, 24% said their organization had suffered ransomware in the prior 12 months, and 74% of those respondents said they paid, a pattern I unpack in the state of cybersecurity in Canada 2026 briefing.
Three shifts show up on some 2026 questionnaires that were softer in 2025. This is an illustrative underwriting trend from the applications we have worked through, not a universal carrier rule.
| Control area | 2025 expectation | 2026 expectation |
|---|---|---|
| MFA method | Some carriers accepted any second factor, including SMS codes. | Some carriers may ask for number matching or a phishing-resistant method on email, VPN, and admin accounts. |
| EDR coverage | EDR present somewhere in the fleet. | A stated coverage percentage, with every gap explained. |
| Backup proof | Backups configured and running nightly. | A dated restore-test report plus one immutable copy. |
The wording change is small and the consequence is not. In 2025 a Toronto applicant could answer “yes, we have EDR” and move on. In 2026 the form asks for a number that forensics can check after a claim. Our cyber insurance readiness matrix maps each control to the evidence Canadian underwriters accept.
How do cyber insurance claims actually get denied?
KPMG reported a 2025 Canadian claim denial in which the insurer argued that MFA required by the policy was not implemented and that the lapse contributed to the attack. That is a policy-condition example, not published proof of application misrepresentation. It is summarised by McCarthy Tétrault (2026). Years of premiums buy nothing when that happens.
Warning
The most expensive outcome is not a declined application. It is a declined claim. If you attest that MFA is on every account and forensics later finds three mailboxes without it, the insurer can rescind coverage for material misrepresentation. A US case, Travelers v. International Control Services, turned on exactly this, with the carrier moving to void a policy after finding the attested MFA was not in place.
There are quieter denial paths too. A control that lapses between renewals, a known vulnerability you left unpatched, or late or non-compliant notice under the privacy law that applies to you can all sink a claim. This is the answer to the common objection that the insurer will simply handle it.
Cyber insurance pays the claim. It does not stop the claim, and it will not pay one you cannot stand behind. A documented incident response plan, reviewed and exercised on a schedule you can evidence, is part of keeping the policy honest.
What is a cyber insurance attestation, and what does it commit you to?
An attestation is the signed statement on your application that a named control was in place on a given date. Treat it as a material representation rather than an estimate, which is why McCarthy Tétrault (2026) reports MFA, backups and staff training being written in as policy conditions.
Three things follow. The date matters, so a control switched on after you signed does not close the gap behind it. Scope matters, because “MFA enabled” and “MFA enforced on all 42 admin accounts” are different answers. Evidence matters most, since a forensics review reads logs rather than intentions.
Keep the proof with the policy. Where we run the renewal, Fusion Computing files a dated control snapshot covering MFA enrolment, EDR coverage percentage and the last restore-test result. The cyber insurance questionnaire cheat sheet lists the artifacts brokers ask for.
What does being uninsured or underinsured cost a Canadian SMB?
Going uninsured is a concrete Canadian number, not a theory. IBM put the average cost of a data breach in Canada at a record CA$7.11M in 2026, up from CA$6.98M the year before. The same report clocked detection and containment at 205 days (IBM, 2026). That is an organization-level benchmark, not an SMB loss forecast; a small business’s loss can be much lower or higher depending on the incident, downtime, records affected, response costs and coverage.
Book a controls review before your next cyber insurance renewal.
Why Canadian firms bring this work to Fusion Computing.
CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder. Securing IT for Canadian SMBs across Toronto, Hamilton, and Metro Vancouver since 2012.
Fraud is the more common hit. The Canadian Anti-Fraud Centre logged hundreds of millions in reported fraud losses in 2024, and it estimates only 5 to 10% of fraud is ever reported. Across Coalition’s global policyholder portfolio, business email compromise and funds-transfer fraud together accounted for 58% of 2025 claims (Coalition 2026 Cyber Claims Report). That is Coalition portfolio evidence, not a Canadian-market incidence rate.
Ransomware remains the headline threat. The Canadian Centre for Cyber Security recorded a 26% average yearly rise in ransomware incidents from 2021 to 2024 in its Ransomware Threat Outlook 2025-2027 (published January 2026). Recoverable backups, an insurable control, are what let a business refuse the demand. Strong data security and compliance turns those numbers into a plan.
PIPEDA, breach reporting, and why insurers care
Privacy breach duties depend on jurisdiction, and insurers underwrite to whichever regime governs you. Where PIPEDA applies, you must report any breach posing a real risk of significant harm to the Office of the Privacy Commissioner as soon as feasible. You must also notify the affected individuals and keep records of every breach for at least 24 months. Alberta, British Columbia and Quebec have substantially similar private-sector laws that may apply instead for intraprovincial activity.
Knowingly failing to report is an offence under PIPEDA s.28, carrying a fine of up to $10,000 on summary conviction or up to $100,000 on indictment (OPC, current).
Insurers read that duty as part of your risk. A business that cannot show a breach-reporting process, with a named owner and a 24-month record log, is a business that may mishandle the very incident the policy covers.
Sector matters to underwriters as well. Construction firms still face ransomware, credential and vendor-payment risks, though Statistics Canada’s 2023 survey did not place construction among the highest-incidence sectors, and our guide to cybersecurity for construction firms in Canada maps the same control list onto progress-draw and holdback workflows.
The threat backdrop reinforces it. The Canadian Centre for Cyber Security judges that ransomware will almost certainly remain the most impactful cyber threat facing Canadian organizations (CCCS, 2024). The same regulatory pressure now shapes adjacent laws, which our explainer on the Act Respecting Cyber Security (formerly Bill C-8, Royal Assent 15 June 2026) covers in more depth, and which applies to designated federally regulated critical-infrastructure sectors rather than SMBs generally.
Working through the eight controls above is easier with a scored worksheet. Our cybersecurity assessment checklist for Canadian SMBs maps each control to the evidence a Canadian underwriter asks for.
Your 2026 cyber insurance readiness checklist
Before you touch the application, score yourself honestly against the controls insurers test. A clean “yes” means you have a stronger evidence pack, not guaranteed eligibility. Compare every answer with the actual carrier application and policy wording, send the supporting evidence to your broker or insurer, and resolve anything unclear before you sign. Answering “yes” when the honest answer is “no” is how claims get refused.
Build the evidence pack from the relevant systems of record: identity exports, EDR coverage, backup and restore logs, patch and vulnerability reports, training records, incident-response documents, vendor-access reviews and any carrier-specific attestations. Network security testing supplies the scan-trend and phishing-simulation parts of that pack, not all of it.
Readiness checklist
- MFA enforced on email, VPN, remote access, and every admin account.
- EDR or XDR deployed on 100% of endpoints, not signature antivirus.
- Immutable or offline backups with a recent, dated restore test. Use the interval the carrier asks for; if none is stated, set one based on recovery risk.
- A written incident response plan with named roles, plus the date it was last reviewed and, where the carrier asks, the last tabletop or test date.
- DMARC enforced and advanced phishing filtering in place.
- A defined SLA for critical patches and no end-of-life systems exposed.
- Privileged access separated from daily-use accounts.
- Security awareness training and phishing simulation running on a schedule.
- Vendor and third-party access reviewed.
- A breach-notification process aligned to PIPEDA.
If you want the scored version, our compliance readiness assessment walks through these controls and shows where the gaps are. From there, Fusion Computing reviews each gap with a CISSP and maps it to a fix, so the next renewal is less of a scramble.
The bottom line on cyber insurance requirements
Cyber insurance in 2026 rewards businesses that can prove their controls. Treat the renewal questionnaire as your security to-do list, close the gaps before you sign, and the policy becomes a real backstop. Fusion Computing reviews these controls with Canadian SMBs and maps every gap to a fix.
Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton, and Metro Vancouver with managed IT, cybersecurity, and Microsoft 365.
Frequently asked questions
What security controls do cyber insurers require in 2026?
Carrier applications vary, so there is no single required set. The questions that recur are MFA scope, endpoint protection (EDR or XDR coverage), immutable or offline backups with a tested restore, identity and privileged access management, a tested incident response plan, DMARC and phishing filtering, patch management, and security awareness training. Check the actual application for the required scope, methods and evidence.
Is cyber insurance mandatory for businesses in Canada?
No federal law makes cyber insurance mandatory for most Canadian businesses. It can still be required by a contract, a lender, or a larger client’s vendor terms. Separately, where PIPEDA applies it requires you to report breaches posing a real risk of significant harm and to keep breach records for 24 months, and Alberta, British Columbia and Quebec have substantially similar laws that may apply instead. A legal duty exists even when the insurance itself is optional.
Does cyber insurance require multi-factor authentication?
It depends on the carrier and application. MFA scope is a common application question. Check whether your application requires MFA on email, VPN, remote access and admin accounts, and which methods it accepts. Some carriers still take SMS codes, others ask for number-matching or phishing-resistant MFA, because Microsoft’s 2023 Azure AD study found MFA reduced account-compromise risk by 99.22% in the studied suspicious-activity population.
Worried about a denied claim? Talk through your coverage gaps with us.
Can an insurer deny my cyber insurance claim?
Yes. Material misrepresentation is one reason a claim may be denied, where you attested to a control on the application and a forensics review later found a gap. Claims can also be denied when a control lapses between renewals, a known vulnerability went unpatched, or notice under the applicable privacy law was late or non-compliant. Keep dated evidence of what was actually in place.
What is material misrepresentation on a cyber insurance application?
Material misrepresentation means an answer on your application was inaccurate in a way that affected the insurer’s decision to cover you. If you stated MFA was on every account and an investigation found 3 mailboxes without it, the carrier can rescind the policy and refuse the claim. Application answers are material representations, not estimates, and their effect depends on the policy wording and applicable provincial law.
Is antivirus enough, or do I need EDR for cyber insurance?
Many applications now ask about endpoint detection and response rather than signature antivirus. EDR or XDR watches behaviour in real time and can isolate a compromised device automatically, which is what the question is usually getting at. Check what your actual application asks for. Expect the application to ask for your EDR vendor, version and actual coverage figure. Report the real number and explain any excluded or unsupported endpoints; internally, target complete coverage where technically feasible.
What kind of backups do cyber insurers require?
Applications typically ask for backups that ransomware cannot reach or encrypt, which means immutable or offline copies kept separate from production, and for the date of your last successful restore test, and use whatever interval the carrier asks for. A backup you have never restored does not count as a working recovery control on the form.
How much does a data breach cost a Canadian business?
IBM put the average cost of a data breach in Canada at a record CA$7.11 million in 2026, up from CA$6.98 million the year before. The average breach also took 205 days to detect and contain. That is an organization-level average rather than an SMB forecast, but it is the core reason cyber insurance and strong controls matter together.
How do I prepare for a cyber insurance application or renewal?
Treat the questionnaire as a security checklist and close the gaps before you sign. Confirm each of the eight controls above, starting with MFA on every account, EDR on all endpoints, and immutable backups with a recent tested restore. A readiness assessment scores each control so your answers are accurate and provable.
Does PIPEDA require me to report a data breach?
Where PIPEDA applies, yes. You must report any breach posing a real risk of significant harm to the Office of the Privacy Commissioner as soon as feasible. You must also notify the affected individuals and keep records of every breach for at least 24 months. Alberta, British Columbia and Quebec have substantially similar private-sector laws that may apply instead for intraprovincial activity. Knowingly failing to report is an offence under PIPEDA s.28, carrying a fine of up to $10,000 on summary conviction or up to $100,000 on indictment.
How long does it take to get cyber insurance ready in Canada?
For a Canadian SMB under 100 seats with a working Microsoft 365 tenant, remediation time depends on the gaps, the endpoint estate, identity design, third-party access and the carrier’s evidence requests. Fusion scopes the effort after reviewing the actual application and environment. In our experience MFA enforcement, EDR enrolment and the first documented restore test can each take real work. Start with the actual gaps before the broker asks.
What evidence do Canadian underwriters accept as proof of a control?
Brokers ask for artifacts with dates on them. In practice that means an MFA enrolment export from Entra ID and an EDR console report showing coverage percentage. Add the latest dated restore-test log and an incident response plan with its last review date, plus the last tabletop or test date where the carrier asks for one. In our experience undated screenshots usually get sent back.
Cyber insurance reviews at Fusion Computing are run by a CISSP-led team at a Microsoft Solutions Partner. The renewal examples above are first-person field observations from client engagements, anonymized. They are illustrative, not a measured benchmark.
Part of the Canadian IT Compliance Hub: PIPEDA, PHIPA, OSFI B-13, the Act Respecting Cyber Security (formerly Bill C-8), CyberSecure Canada and cyber-insurance guidance for Canadian SMBs, in one place.

