What your cyber insurance renewal actually asks, taken from the real forms
Search for cyber insurance requirements and you will find dozens of IT companies telling you that insurers now demand endpoint detection, immutable backups and 24/7 monitoring. Almost none of them cite a form.
About this piece
- Article
- Managed IT
- Written by Nicholas Backwell · Founder, Redsilicon
- Updated 2026-08-24
I went looking for the actual Canadian application documents. Two are public. What they ask is narrower than the marketing suggests, and more specific.
The short version
- Multi-factor authentication is the question that appears everywhere, and it is asked in three separate places, not one.
- Offline or separated backups is the other consistent question. “We back up to the cloud” is not the same answer.
- Claims that insurers require EDR, immutable backups or a security operations centre could not be verified against any public Canadian form.
- Canadian cyber rates fell about 5% in the first quarter of 2026. The market is soft, not hardening.
- The cautionary tale is local: Hamilton lost $5 million of an $18.3 million claim after missing MFA was found to be the root cause.
The MFA question is three questions
Coalition’s Canadian cyber questionnaire, version 202205, asks: “For which of the following services do you enforce Multi-Factor Authentication (MFA)?” and then splits it into three:
- Virtual Private Network (VPN), Remote Desktop Protocol (RDP), RDWeb, RD Gateway, or other remote access
- Network/cloud administration or other privileged user accounts
Most owners answer that question in their head as one item and think of Microsoft 365 email. Email is the one businesses usually have covered, because Microsoft nags until it is on.
The other two are where the gaps sit. Remote access is a common miss: a Remote Desktop connection left open so someone can get at the accounting machine from home, no second factor on it. Privileged accounts is the more dangerous one. The global admin account in Microsoft 365, the firewall admin login, the account your IT provider uses. These get exempted from MFA precisely because they are inconvenient, and they are the accounts an attacker wants.
CFC’s Canadian private enterprise application asks the same thing more tersely: “Please confirm whether multi-factor authentication is always enabled on all email accounts.”
Note the word “always.” Not available. Not enabled for most people. Always.
Backups: the word doing the work is "offline"
Coalition asks whether you maintain “at least weekly backups of all sensitive or otherwise critical data and all critical business systems offline or on a separate network.”
CFC asks whether you maintain “daily offline back-ups of all critical data.”
Two different insurers, two different frequencies, same load-bearing word. Offline, or on a separate network.
This trips up a lot of businesses that genuinely do back up. If your backup runs to a network drive that your servers can reach, or to a cloud folder that syncs from a mapped drive, ransomware that reaches the server reaches the backup. That is not a hypothetical failure mode. It is the normal one.
The honest test is simple. If an attacker had domain admin on your network right now, could they delete or encrypt your backups? If yes, you do not have the thing the form is asking about, regardless of what your backup software costs.
Worth pairing this with a second question nobody asks on a form: when did you last restore something from it? An untested backup is a belief, not a control.
What CFC asks that Coalition does not
CFC’s form runs longer and reaches into how the business is actually run:
- “Is any part of your IT infrastructure outsourced to third party technology providers?”
- “How many full-time employees do you have in your IT department?”
- “Who is responsible for IT security within your organisation (by job title)?”
- “Please describe your process for patching all operating systems and applications”
- “If your organization uses Remote Desktop Protocol (RDP) to allow remote access to your network, please describe the measures you adopt”
- “How often do you conduct vulnerability scanning of your network perimeter?”
Those middle two are free-text. An underwriter reads what you write. “We update when prompted” and “workstations patch monthly on a managed schedule, servers are patched in a maintenance window with a tested rollback” describe two different businesses, and the difference is visible on the page.
CFC also runs a tick-box checklist that includes advanced endpoint protection, employee awareness training, an incident response plan and two-factor authentication. Ticking a box is not the same as being asked to prove it, which is why I would not describe those as requirements.
What I could not verify, and why that matters
I went looking for public Canadian evidence that insurers require endpoint detection and response, immutable backups, a 24/7 security operations centre, or privileged access management. I did not find any. Every source asserting it was an IT provider’s blog with nothing behind it.
That does not mean no insurer asks. It means nobody selling you the control has shown you the form. If someone tells you your policy requires a product they happen to sell, ask them which insurer and which question. It is a fair question and it takes ten seconds to answer if the claim is real.
The Insurance Bureau of Canada does publish a cyber insurance checklist, dated 30 September 2025, telling owners to be ready to describe a written information security plan, whether anyone holds a privacy or IT leadership role, recent audits, staff training, access controls, encryption, firewalls, backups, software updates, spam filtering, MFA, data retention and destruction policies, and a device inventory. That is an industry body’s preparation list rather than an underwriting form, but it is Canadian and it is dated, which puts it ahead of most of what circulates.
Prices are falling, not rising
Nearly every article on this subject opens with premiums soaring. That was true a few years ago. It is not true now.
Canadian cyber insurance rates fell about 5% in the first quarter of 2026, with capacity expanding as new insurers entered the market, according to Marsh’s Global Insurance Market Index as reported by Canadian Underwriter on 23 April 2026.
The background to that: Canadian cyber insurers ran a combined loss ratio of roughly 155% between 2019 and 2023, per the Insurance Bureau of Canada. They lost a great deal of money, tightened underwriting hard, and the tightening worked. Prices came down afterward.
Two things follow. Renewal scrutiny is real even though price pressure has eased, so the questions still matter. And if your broker is telling you rates are climbing, that is worth a second opinion.
Take-up remains low. Statistics Canada reported on 21 October 2024 that 22% of Canadian businesses carried cyber insurance in 2023, up six points year over year. The same release found 16% of Canadian businesses experienced a cyber security incident in 2023.
The Hamilton case, and how to read it
In 2024 the City of Hamilton was hit by ransomware. Its insurance claim came to $18.3 million. It recovered $13.3 million. Global News reported on 31 July 2025 that the absence of multi-factor authentication was found to be the root cause of the breach, and $5 million of the claim went unpaid.
Read that carefully, because it gets misquoted in both directions.
Hamilton is a municipality, not a small business, with a much larger attack surface and a much larger claim. It is not a case study for a 40-person company in Ajax. And the reporting describes a policy condition tied to MFA, not a finding that the city lied on its application. Some commentary has speculated about misrepresentation without confirming it.
What the case does establish, close to home, is that a single missing control can cost a specific and very large amount of money at claim time. Whitby to Hamilton is about an hour.
What this means for your building
A 30-person clinic in Oshawa and a 30-person contractor in Uxbridge fill in the same form and fail it in different places.
The clinic usually has Microsoft 365 with MFA on email, because the practice management vendor insisted. Where it falls down is the shared front-desk login that four people use, and the backup that runs to a NAS in the same server cupboard as everything else.
The contractor usually has the opposite shape. Everyone works off phones and laptops from job sites, remote access into an office machine was set up years ago by someone who has left, and nobody is certain whether that connection needs a second factor. That is the Coalition question 5b gap, and it is the one that gets exploited.
Neither of those is expensive to fix. Both take a couple of hours and a decision.
What to do about it
The first four cost nothing but time.
- Pull your last application or renewal questionnaire out of your email and read your own answers. Most owners have never re-read what was submitted on their behalf. If a broker filled it in from a phone call, check that what it says is still true.
- Check MFA in all three places, separately. Email. Any remote access into your network. Every administrator account, including the ones your IT provider uses. Write down which of the three you cannot confirm.
- Ask the offline backup question honestly. If someone with full access to your network could delete the backups, they are not offline. Microsoft 365 is not a backup of Microsoft 365, which is its own subject.
- Email your broker one question in writing: does this policy have any condition or exclusion tied to unsupported software, MFA, or backup practice? Keep the reply. That answer is about your actual policy, which beats any general article including this one.
- Write down your patching process in three sentences, because a form is going to ask you to. If you cannot write it, that is the finding.
- Fix the gaps before renewal, not at renewal. Turning MFA on the week before is fine. Turning it on the week after a claim is not.
If you want the MFA and backup pieces handled properly rather than half-enabled, that is what our cybersecurity work covers, and Microsoft 365 tenant work is usually where it starts.
Want this scoped for your site?
Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.
Before you call
Do we even need cyber insurance?
That is a question for your broker and your accountant, not your IT company, and anyone in my trade who answers it confidently is out of their lane. What I would say is that the controls on the form are worth having whether or not you buy the policy. They are the same controls that stop the incident.
Our insurer never asked us any of this.
Then either the policy is older than the current underwriting cycle, or the coverage is a small endorsement on a broader business policy rather than standalone cyber cover. Both are common. Worth knowing which you have before you need it.
If we tick the boxes, are we covered?
Nobody in IT can tell you that. Ticking a box on an application is a representation you are making to an insurer. If it turns out not to be accurate, that is a problem at claim time. Which is the actual reason to check MFA in all three places rather than assume.
We are ten people. Is this overkill?
The Coalition and CFC forms make no allowance for size. A ten-person business filling in the same application answers the same MFA question. The good news is that at ten people the work is genuinely small.