Home Learn Cyber Insurance Requirements in 2026
Learn · North Star

Cyber Insurance Requirements in 2026

Applications that sailed through in 2021 now get declined. Here is every control on the standard Canadian questionnaire, what a truthful "yes" actually requires, and how to get there before your renewal date.

Cyber insurance underwriters have hardened their requirements dramatically since 2021, when a wave of ransomware claims made the old "sign here" approach unprofitable. Getting coverage, or renewing at a reasonable premium, now means demonstrating a specific set of technical controls on a written questionnaire. Businesses that cannot document these controls face higher premiums, reduced limits, ransomware sub-limits, or outright declines.

The part most owners miss: the questionnaire is not a formality. It is a binding representation, the same as declaring your driving record on an auto policy. If you tick "yes" to a control you do not actually have, the policy may still be issued, the premium may even look great, and the coverage can evaporate the day you file a claim. This guide walks through what insurers cover, what they now demand, and how to answer honestly, in that order.

Coverage

What cyber insurance covers, and what it excludes.

Most Canadian SMB policies cover some combination of:

  • Incident response and forensics. The specialists who figure out what happened and contain it.
  • Legal counsel and regulatory notification. Including breach notification obligations under PIPEDA and BC PIPA. Our compliance hub covers those duties in detail.
  • Business interruption. Lost income while systems are down during recovery.
  • Data restoration. The cost of rebuilding systems and recovering data.
  • Third-party liability. Claims from customers or partners whose data you exposed.
  • Cybercrime riders. Funds-transfer fraud and social engineering losses, often sub-limited and sometimes sold separately.

Common exclusions: acts of war and nation-state attacks (still being contested in courts), intentional acts by insiders, and increasingly the ransom payment itself. Paying certain ransomware groups can also violate Canadian sanctions law, which is part of why carriers pulled back. Most policies still cover the surrounding costs of a ransomware event, but confirm the current wording with your broker every year. This area moves fast.

The checklist

The eight controls on virtually every 2026 questionnaire.

For each one: what the insurer is really asking, what a truthful "yes" requires operationally, and what happens if you say yes without it being true.

01 · Hard requirement

MFA on email, remote access, and admin accounts

The real question: not "do you have MFA somewhere" but "is MFA enforced on every account that can reach email, VPN or remote desktop, and every privileged account, with zero exceptions."

A truthful yes means: MFA enforced by policy (Conditional Access in Entra ID, not user opt-in), covering executives, service accounts, and any documented break-glass account. Remote access with no second factor is a no.

If you fudge it: a compromised mailbox without MFA is the easiest misrepresentation for a carrier to prove, and MFA gaps are the most common reason cyber claims get denied.

02 · Hard requirement

EDR on every endpoint

The real question: do you run a behavioural detection and response agent, not legacy antivirus, on all workstations and servers. The difference matters; see our EDR vs antivirus guide.

A truthful yes means: the agent is deployed to 100 percent of devices, including servers and the laptop of the remote employee you forgot about, and its alerts go somewhere a human actually looks.

If you fudge it: post-incident forensics show exactly which machines had the agent installed. "All endpoints" on the form plus three unprotected servers in reality is grounds for denial.

03 · Hard requirement

Offline or immutable backups, with tested restores

The real question: can an attacker who gains admin access encrypt or delete your backups, and when did you last actually restore from them.

A truthful yes means: at least one backup copy that domain-admin credentials cannot touch (immutable storage or true offline), plus documented restore tests with dates. The 3-2-1 rule is the baseline pattern.

If you fudge it: if backups fail during a ransomware event, your business interruption claim balloons and the carrier's investigators will ask for restore logs you do not have.

04 · Standard

Patch cadence

The real question: how quickly do you apply critical security patches, typically "within 14 or 30 days," across operating systems and third-party software.

A truthful yes means: a patch management tool (Intune or an RMM) with compliance reporting, and a written note for anything you deliberately cannot patch and why.

If you fudge it: a breach traced to a six-month-old unpatched vulnerability directly contradicts a stated 30-day cadence. That contradiction is all a carrier needs.

05 · Standard

Security awareness training and phishing simulation

The real question: do staff receive recurring training with records, and do you run simulated phishing tests. One onboarding video from 2023 does not count.

A truthful yes means: an enrolment list, completion tracking, and simulation results you can export. Our managed training service produces exactly this evidence.

If you fudge it: social engineering and funds-transfer claims often hinge on this answer. No training records means the carrier can argue misrepresentation on the loss type SMBs file most.

06 · Standard

Incident response plan

The real question: is there a written plan naming who does what in an incident, and has it been tested rather than filed and forgotten.

A truthful yes means: a document with named roles, a contact tree, your carrier's breach hotline in it, and at least an annual tabletop walkthrough. See incident response for what good looks like.

If you fudge it: beyond the misrepresentation risk, hiring your own responders without carrier approval mid-incident can itself void reimbursement. The plan exists partly to stop you making that mistake at 2 a.m.

07 · Increasingly required

Logging, monitoring, or MDR

The real question: if something fires an alert at 11 p.m. on a Saturday, does anyone see it, and are logs retained long enough to investigate afterwards.

A truthful yes means: centralised logs with meaningful retention (90 days or more is a common ask) and a person or a managed detection and response service watching around the clock.

If you fudge it: carriers increasingly verify posture with external scans at underwriting and forensics after a claim. "24/7 monitoring" backed by an unwatched inbox will not survive either.

08 · Increasingly required

No end-of-life software

The real question: are you running anything the vendor no longer patches. Windows 10 after October 2025, old Windows Server versions, and aging firewalls are the usual suspects.

A truthful yes means: a current hardware and software inventory, a replacement plan with dates, and if you genuinely must keep an EOL system (a shop-floor controller, say), it is isolated from the network and disclosed on the form.

If you fudge it: an incident that enters through an undisclosed end-of-life system is about as close to an automatic denial as this industry gets.

The fine print

Only say yes when it is true.

Every answer on the application becomes part of the contract. If a claim investigation finds a control was not in place as represented, the carrier can deny that claim or void the policy from inception, meaning it behaves as if it never existed. Many policies also carry "failure to maintain" clauses: the controls must stay in place all year, not just on application day. Turning off MFA for a difficult executive in March can sink a claim in September.

The honest move when you cannot answer yes is to fix the gap before applying, or disclose it and accept the premium hit. A slightly higher premium is annoying. A denied six-figure claim is existential. We break down the actual questions carriers are asking this year, line by line, in our 2026 cyber insurance questionnaire walkthrough.

With an MSP

How these controls map to a managed IT plan.

Almost nothing on the questionnaire is a one-time purchase. MFA needs enforcement policies maintained, EDR needs someone answering alerts, backups need scheduled restore tests, training needs quarterly campaigns. That is why the practical route for most 5 to 200 user organisations is bundling the controls into a managed plan rather than buying eight products and hoping someone maintains them.

At North Star, the hard-floor items, enforced MFA, EDR on every endpoint, patch management, and image-based backup with verified restores, are built into every managed tier, because we will not run an environment without them. Moving up through our Professional and CIS-Aligned tiers adds the layers underwriters increasingly ask about next: security awareness training with phishing simulation, managed detection and response with log retention, documented incident response, and evidence packages mapped to recognised frameworks. In the BC market, managed plans typically run $100 to $250 per user per month depending on tier; our published pricing shows exactly where each control lands, with founding pricing for clients signing before December 1, 2026.

The renewal-season payoff is that the evidence already exists. When the questionnaire asks for restore test dates or training completion rates, your MSP exports a report instead of your office manager guessing. Our cybersecurity hub covers each control in more depth if you want to go service by service.

Renewal prep

What to gather 60 to 90 days before renewal.

Start well before your broker sends the forms. The package that makes underwriting painless looks like this:

  • Last year's completed application, so this year's answers stay consistent.
  • An MFA policy export showing enforcement, not just availability.
  • An EDR deployment report showing coverage across all devices.
  • Backup restore test logs with dates and outcomes.
  • A patch compliance report from your management tooling.
  • Training enrolment and phishing simulation results for the past 12 months.
  • Your incident response plan with its last revision and test date.
  • A hardware and software inventory flagging anything approaching end of life.
  • Details of any monitoring or MDR arrangement, including retention periods.
  • Honest disclosure of any incidents or near-misses since the last application.

If any line on that list makes you wince, that is the gap to close first. North Star runs a pre-application controls review that identifies the gaps, remediates them, and documents your posture accurately before you submit. A free assessment is the fastest way to find out where you stand today, or call 672-983-1174.

FAQ

Quick answers.

What does cyber insurance cover?

Most policies cover incident response, forensics, legal counsel, regulatory notification, business interruption, data restoration, and third-party liability. Coverage limits and exclusions vary widely, so read the policy wording, not just the summary page.

What controls does cyber insurance require in 2026?

The standard Canadian questionnaire asks for MFA on email, remote access, and admin accounts, EDR on every endpoint, offline or immutable backups with tested restores, a defined patch cadence, security awareness training with phishing simulation, a written incident response plan, logging and monitoring or MDR, and no end-of-life software in production.

Will cyber insurance cover ransom payments?

Most carriers have reduced or excluded ransom payment coverage. Most still cover the broader incident response and business interruption costs of a ransomware event.

How much does cyber insurance cost?

For a typical Canadian SMB, premiums run between 2,000 and 10,000 dollars per year for one to two million dollars in coverage. Premiums depend on controls in place, industry, and prior claims.

What happens if I answer the questionnaire inaccurately?

The application is a binding representation. If post-incident forensics show a control was not in place as stated, the carrier can deny the claim or void the policy entirely. This is the most common way cyber claims fail, and it surfaces at the worst possible time.

What is the single most important control for cyber insurance?

MFA. It is the gating requirement on nearly every questionnaire. No MFA on email and remote access means no coverage from most underwriters, regardless of what else you do well.

Can North Star help me meet the controls?

Yes. North Star deploys MFA, EDR, immutable backup, training, and incident response programs that satisfy the standard cyber insurance questionnaire, and we help you gather the evidence before renewal.

Want a score instead of a checklist? Take the free cyber insurance readiness scorecard: ten questions, instant fix-first list, nothing sent or stored.

Would your controls pass underwriting today?

Book a free 30-minute scoping call with a North Star engineer. We will walk through the questionnaire against your actual environment and tell you honestly what would pass, what would not, and what it costs to fix.

Get a Free Assessment More guides