Cyber insurance applications used to be a short questionnaire. In 2026, they're closer to a technical audit, and the controls insurers now expect are worth knowing before you apply.
Cyber insurance is not required by law for most Ontario businesses. It is, however, showing up more frequently as a condition in vendor contracts, lender agreements, and larger client relationships, which means more businesses are applying for it whether or not they’d choose to on their own.
Cybersecurity insurance requirements refer to the specific security controls a business has to demonstrate, with evidence, before an insurer will offer coverage or renew an existing policy.
The bar for what counts as adequate has moved considerably in the last few years. What used to satisfy an underwriter in 2022 often doesn’t in 2026, and businesses applying or renewing without knowing that tend to be surprised by the questions they can’t answer.
Multi-Factor Authentication on Every Account

MFA is the most scrutinized line item on most applications, and the specific gap that trips up applicants isn’t usually the absence of MFA entirely, it’s inconsistent coverage. Email and general staff accounts have it, but an administrator or privileged account was set up before the policy existed and never updated. Insurers ask specifically about coverage on email, remote access, cloud consoles, and privileged accounts, and partial coverage tends to be treated as a fail on the whole line item.
Endpoint Protection Beyond Basic Antivirus
Traditional signature-based antivirus, the kind that only catches known threats it has a signature for, is treated as outdated by most Canadian underwriters now. What insurers look for instead is endpoint detection and response (EDR) or extended detection and response (XDR): tools that watch for suspicious behaviour in real time and can isolate a compromised device automatically, rather than only scanning files against a known list.
Backups That Have Actually Been Tested
A backup job completing successfully and a backup that’s actually recoverable are two different things, and insurers increasingly ask for proof of the second one specifically. What matters on an application isn’t just whether backups run, but whether they’re immutable or kept offline where ransomware can’t reach them, and whether a restore has been tested and dated recently. “We have backups” and “we tested a restore three weeks ago and it worked” are very different answers on the same question.
A Documented, Tested Incident Response Plan
Having a plan written down is the starting point. Insurers increasingly want to know it’s been tested, typically through a tabletop exercise where the response team walks through a simulated incident rather than just reading a document that’s never been rehearsed. A plan nobody has practiced tends to fall apart under real conditions in ways a tested one doesn’t.
Security Awareness Training
Regular training, not a one-time onboarding session years ago, rounds out the standard control set most Canadian underwriters now check for. The reasoning tracks with how most breaches actually start: a person clicking a link or approving a fraudulent request, not a technical failure in the network itself.
Why This Matters Even Without a Policy
Separate from insurance entirely, PIPEDA requires Canadian businesses to report breaches of security safeguards that create a real risk of significant harm, and to keep records of every breach for at least 24 months, whether or not the business carries cyber insurance. The overlap is worth noting: the controls insurers now expect largely track the baseline the Canadian Centre for Cyber Security already recommends for small and medium organizations, so building toward one tends to move a business toward the other.
What This Looks Like at ACT360
Jeffrey Bowles, Partner and Director of IT Services at ACT360, puts it this way when clients ask why security reviews happen on a set schedule rather than only after something goes wrong:
“I’d rather we catch this now, in a review, than have it show up as an incident in six months.”
— Jeffrey Bowles, Partner & Director of IT Services, ACT360
Quarterly business reviews under ACT360’s vCIO service cover exactly the controls insurers now check for: MFA coverage, endpoint protection status, backup testing dates, and incident response readiness, reviewed on a schedule rather than discovered for the first time on an application. The costs of getting this wrong are real: average ransomware recovery runs around $200,000 and average data loss around $180,000, based on ACT360’s own published figures, well above the cost of building the right controls before an insurer, or an attacker, asks.
Final Thought
Cyber insurance underwriting in 2026 rewards businesses that can show their work: real evidence of MFA coverage, real dates on backup tests, a plan that’s actually been rehearsed. None of it requires exotic technology. Most of it is configuration and process that a lot of businesses already have partial pieces of, just not documented or consistent enough to survive a questionnaire.
T: 705-739-2281 E: [email protected]