WHAT INSURERS ACTUALLY ASK

What cyber insurance actually requires.

Eight controls, and the two that get applications declined most often. If a renewal questionnaire just landed on your desk, this is what it is asking about — in plain English, with no attempt to sell you a policy.

Why the questions got harder

Cyber insurance used to be a form you filled in. It is now closer to an audit. Carriers pay out on ransomware often enough that they have stopped asking whether you take security seriously and started asking which specific controls are switched on, across how many machines, and when you last tested them.

The practical consequence for a small business is that the application is answerable only if somebody actually knows the state of your systems. Guessing is worse than not applying — an answer that turns out to be wrong is grounds to deny the claim you eventually make.

What follows is the control set two independent Canadian sources agree on for 2026. Your carrier’s form may differ in wording. It will not differ much in substance.

THE EIGHT CONTROLS

What they ask, and what they mean by it

CONTROL 01

Multi-factor authentication

Enforced on email, VPN, remote access and every admin account. Some carriers now want number-matching or a phishing-resistant method rather than a code in an app.

This is the line that sinks the most applications. Not because businesses refuse it, but because it is on email and nowhere else — the VPN and the domain admin account get missed.

CONTROL 02

Threat detection on every machine (EDR)

Behaviour-based EDR or XDR on 100% of endpoints. Insurers explicitly distinguish this from signature antivirus.

The word carriers use is “percentage of endpoints”. Ninety per cent is a fail. The laptop somebody took home counts.

CONTROL 03

Backups that are immutable and tested

Offline or immutable copies, plus a dated restore you actually performed.

“We have backups” is not the question being asked. The question is when you last restored from one and whether you can produce the date.

CONTROL 04

Privileged access separation

Least-privilege roles, admin accounts separated from daily-use accounts, conditional access.

If the owner’s everyday login is also a domain admin, one phishing click is the whole company. Carriers know this and ask about it directly.

CONTROL 05

A written incident response plan

Named roles, escalation thresholds, and tested within the last twelve months.

A document nobody has read does not count as tested. A one-hour tabletop with the people named in it does.

CONTROL 06

Email security

DMARC at quarantine or reject, plus SPF and DKIM, and advanced phishing and attachment filtering.

DMARC set to p=none is monitoring, not enforcement. Plenty of businesses have it at none and believe they are covered.

CONTROL 07

Patch management with an SLA

A defined turnaround for critical patches, and no end-of-life systems anywhere on the network.

One Windows Server 2012 box in a closet can void the policy it is sitting behind. End-of-life is an explicit exclusion, not a deduction.

CONTROL 08

Security awareness training

Regular staff training and phishing simulation, with records.

The records matter as much as the training. If you cannot produce completion data, in an insurer’s eyes it did not happen.

Why applications get declined

Missing MFA is the single most common reason an application is turned down — many carriers will not quote at all without it on email and remote access. One documented case: a manufacturer declined for no EDR, no MFA on the VPN, and no restore test in over fourteen months.

Being declined is recoverable. Having a claim denied after an incident is not, and it happens for five recurring reasons:

  1. Misrepresentation. Controls you attested to were not actually in place on the day of the incident. This is the most common denial, and it is usually honest error rather than fraud — somebody ticked a box about a control they assumed was running.
  2. Control drift. It was true at renewal and had degraded by the breach. An agent stopped reporting; a new machine never got enrolled.
  3. Missing forensic evidence. Not enough logging to substantiate what was lost, so the claim cannot be quantified.
  4. Late notification. Filed outside the discovery window — often 72 hours.
  5. Excluded losses. Unpatched known vulnerabilities, and ransom payments to sanctioned entities.

Notice that three of the five are about the gap between what you said and what was true. That gap is the actual product an IT provider sells you here — not software, but the ability to answer the questions accurately.

WHERE WE FIT

Which of our tiers gets you through it

We are not insurance brokers and we do not sell policies. But since the controls map almost exactly onto what a managed IT contract does, here is the honest mapping against our three tiers:

TIERPRICECONTROLS MET
Essential$100/user/moAbout 3 of 8 — likely declined
Standard$140/user/moAbout 6 of 8
CompleteQuotedAll 8

Essential will not get you through an application. It has no backup and no threat detection, which are the two controls carriers scrutinise hardest. We would rather say that here than after your renewal comes back.

If you already have an IT provider and only want to know where you stand, we will do that as a conversation. It is free, and it does not end with a contract unless you want one.

Answered plainly.

Do I actually need cyber insurance?

That is a question for your broker, not your IT company. What we can tell you is that the application will ask about all eight controls above, and that the answers have to be true on the day of a claim, not just the day you signed.

My antivirus is fine, isn’t it?

Not for this. Carriers now ask specifically about endpoint detection and response rather than signature antivirus, because EDR watches behaviour in real time and can isolate a machine mid-incident. Traditional antivirus recognises threats it already knows about.

How do I prove my backups work?

You perform a restore, and you write down the date. That is genuinely it — but it has to have happened, and somebody has to be able to say when.

Can you help us fill in the application?

We can tell you honestly which controls are in place on your systems and which are not. We will not tell you what to write, and we would be wary of anyone who offers to.

Which of your tiers meets the requirements?

Complete meets all eight. Standard covers roughly six. Essential does not get you through an application — it has no backup and no threat detection, which are the two carriers scrutinise hardest.

Find out which controls you actually have.

Tell us what you run and we will tell you where you stand, control by control. No charge, and no obligation to change provider.

Get a free assessmentCall (587) 418-3248