Cyber Insurance Requirements in Canada: The Controls Insurers Now Expect
In This Article
Cyber insurance used to be a form you filled in and a premium you paid. That has changed. Coverage is no longer automatic, and the deciding factor is usually not the size of your business but the state of your security controls. If you want to qualify at a reasonable premium, the controls below are the practical gate. For the broader picture of what a policy covers and whether you need one, start with our guide to business cyber insurance in Canada.
Why Requirements Tightened
The tightening traces back to the ransomware wave of the early 2020s. Insurers paid out heavily on incidents that shared a pattern: no multi-factor authentication on remote access, flat networks with no segmentation, and backups that were encrypted alongside production. Carriers responded by rewriting their underwriting. Instead of pricing a broad category of risk, they now ask pointed questions about specific controls and decline or surcharge the applicants who cannot answer them.
The result for a Canadian business is straightforward. Coverage is available, but it is conditional. An insurer wants evidence that you have made the incidents they pay for less likely and less severe. The controls that do that are the ones that show up on every application, and the businesses that have them in place before they apply have a far easier renewal conversation.
The Controls Insurers Require
Requirements differ from one carrier to the next, and no single list is universal. That said, the following controls appear on nearly every Canadian cyber insurance application, and missing any of them tends to trigger follow-up questions or a higher premium.
- Multi-factor authentication (MFA): Enforced on remote access, email, administrative accounts, and any VPN. This is the single most common requirement, and insurers increasingly want it on every account rather than most.
- Endpoint detection and response (EDR): Modern detection that can spot, investigate, and contain threats on every device, going beyond traditional antivirus. See our primer on EDR for Ontario SMBs.
- Tested backups that are offline or immutable: Backups stored separately from production, protected so attackers cannot encrypt them, and restored on a schedule so you know they work.
- Email security and filtering: Anti-phishing, anti-spoofing (such as DMARC), and link protection, since email remains the most common entry point for both ransomware and invoice fraud.
- Timely patching and vulnerability management: A repeatable process for applying updates, with critical vulnerabilities addressed quickly rather than left open.
- An incident response plan: A documented plan covering who to call, how to contain an incident, and how to meet notification duties, ideally rehearsed at least once.
- Security awareness training: Regular training for staff, including phishing awareness, so the people using the systems are part of the defense.
- Least-privilege access: Users and administrators hold only the access they need, which limits how far an attacker can move after a single account is compromised.
See where you stand against these requirements
Score your controls against what Canadian cyber insurers ask about, including MFA, EDR, backups, and training, and see the gaps that could block coverage or raise your premium. No email required, results are immediate.
Check your readiness against insurer requirementsHere is how the core controls line up with the reason insurers ask about them and what a strong answer looks like.
| Control | Why insurers require it | What "good" looks like |
|---|---|---|
| MFA | Stolen passwords are the most common way in, and MFA blocks most account takeovers. | Enforced on all users for email, admin, remote access, and VPN, with no unprotected exceptions. |
| EDR / managed detection | It shortens the time between compromise and containment, which limits loss. | Deployed on every endpoint, monitored, and able to isolate a device automatically. |
| Tested backups | Recoverable backups are what let a business refuse a ransom and restore instead. | Offline or immutable copies, separated from production, with restores tested on a schedule. |
| Email security | Email is the primary channel for phishing, ransomware delivery, and invoice fraud. | Anti-phishing and anti-spoofing controls plus link protection across the whole tenant. |
| Patching | Unpatched, known vulnerabilities are a frequent entry point for attackers. | A repeatable process with critical fixes applied quickly and a tracked exception list. |
| Incident response plan | A prepared response reduces the cost and duration of an incident. | A documented, dated plan with clear roles and contacts, rehearsed at least once. |
| Security awareness training | People are the target of phishing, so trained staff lower the odds of a successful attack. | Regular training and phishing simulations with records you can show, at least annually. |
CIS Controls and Frameworks
Insurers rarely require a named framework, but their questionnaires map closely onto recognized ones, and the most common reference point is the CIS Controls. The CIS Controls are a prioritized set of security actions maintained by the Center for Internet Security, organized into Implementation Groups so a smaller business can start with the essentials rather than the full catalog.
For a Canadian business, the practical value is alignment. When you work toward CIS Controls Implementation Group 1, which covers items like asset and software inventories, MFA, secured backups, patching, and awareness training, you end up able to answer nearly every underwriting question honestly. You are not adopting the framework to satisfy the insurer so much as using it as a checklist that happens to match what the insurer asks. Other frameworks, such as the NIST Cybersecurity Framework, serve a similar purpose. The point is a recognized baseline, not any one badge.
How Controls Affect Eligibility and Premium
Controls influence coverage in two distinct ways, and it helps to keep them separate. The first is eligibility. Some carriers now treat certain controls, MFA on remote access in particular, as a hard gate. Without them, the answer is not a higher price; it is no quote at all, or a policy with a ransomware sub-limit so low it offers little real protection.
The second is price. Among businesses that do qualify, the ones who can demonstrate a fuller set of controls generally see better terms, because they represent lower and more predictable risk. The reverse is also true. Gaps that stop short of an outright decline still tend to push the premium up or narrow the coverage. None of this is a guarantee, and outcomes depend on your carrier, industry, and claims history, but the direction is consistent: present controls lower risk and cost, and missing controls raise both.
Application and Documentation
Having the controls in place is the first half of the job. The second is proving it. Once your controls are operating, insurers ask you to document and attest to them, and the evidence they expect has become more specific and more demanding at renewal. That is a separate topic with its own detail, so rather than repeat it here, see our companion post on what insurers ask for for the questionnaires, evidence categories, and attestation expectations.
How to Get Ready
The most reliable path is to treat the application as the last step, not the first. A practical sequence looks like this:
- Assess your current controls: Map what you have against the list above, honestly, and note where coverage is partial rather than complete.
- Close the highest-risk gaps first: Prioritize the controls that act as hard gates, starting with MFA on remote access, EDR on every device, and backups you can actually restore.
- Document as you go: Capture configuration, policies, and training records while you implement, so the evidence exists when the questionnaire arrives.
- Then apply or renew: Go to the insurer or broker from a position of evidence, and give yourself lead time before the policy date rather than scrambling at the deadline.
This is exactly the work a managed IT partner does day to day. Through our managed IT services and cybersecurity support, ClayGen implements MFA, EDR, backup, email security, patching, and training as an ongoing program, so the controls are real and maintained rather than assembled in a rush before a renewal.
Get Help
Meeting cyber insurance requirements is less about buying one product and more about running a consistent set of controls and keeping the evidence current. ClayGen puts those controls in place and documents them as part of managed IT, so when the application or renewal lands, you can answer every question accurately and back it up.
If you are not sure where your business stands, start with the free cyber insurance readiness check, then get in touch and we will help you close the gaps that matter most before your next policy date.
Cyber Insurance Requirements FAQ
What security controls do cyber insurers require in Canada?
Is MFA required for cyber insurance?
Do insurers require EDR?
What are the CIS Controls and why do insurers ask about them?
Can we be denied coverage for missing controls?
Last updated . New article.
See where your security actually stands
Score your controls against what Canadian cyber insurers require in 2026, and see the gaps that block coverage or inflate premiums. 15 questions, immediate results, no email.