act360 Web & IT
Blog

Cybersecurity Insurance Requirements in Ontario (2026)

Cyber insurance applications have turned into technical audits. Here’s what underwriters are actually checking for in 2026, and what happens if you can’t demonstrate it.

Close-up of a hand signing a document with a pen, representing signing off on a cyber insurance policy application

QUICK ANSWER

Quick answer

In 2026, most Canadian cyber insurers require multi-factor authentication on every account, modern endpoint detection and response instead of basic antivirus, immutable or offline backups with a tested restore, a documented incident response plan, and regular security awareness training. Missing any of these can mean a declined application or a sub-limited policy.

KEY TAKEAWAYS

What to remember

  • Cyber insurance is not legally mandatory in Canada, but contracts, lenders, and larger clients increasingly require it.
  • MFA and the date of the last tested backup restore are the two answers that most often fail an application.
  • Signature-based antivirus is treated as legacy technology by most 2026 underwriters.
  • A documented, tested incident response plan is now a standard requirement, not an advanced one.
  • Applications commonly run to dozens of questions across identity, endpoint, backup, network, and vendor risk.
  • PIPEDA's breach reporting requirements apply regardless of whether a business carries cyber insurance.
In this article
  1. Multi-Factor Authentication on Every Account
  2. Endpoint Protection Beyond Basic Antivirus
  3. Backups That Have Actually Been Tested
  4. A Documented, Tested Incident Response Plan
  5. Security Awareness Training
  6. Why This Matters Even Without a Policy
  7. What This Looks Like at ACT360
  8. Final Thought

Cyber insurance applications used to be a short questionnaire. In 2026, they're closer to a technical audit, and the controls insurers now expect are worth knowing before you apply.

Cyber insurance is not required by law for most Ontario businesses. It is, however, showing up more frequently as a condition in vendor contracts, lender agreements, and larger client relationships, which means more businesses are applying for it whether or not they’d choose to on their own.

Cybersecurity insurance requirements refer to the specific security controls a business has to demonstrate, with evidence, before an insurer will offer coverage or renew an existing policy.

The bar for what counts as adequate has moved considerably in the last few years. What used to satisfy an underwriter in 2022 often doesn’t in 2026, and businesses applying or renewing without knowing that tend to be surprised by the questions they can’t answer.

Multi-Factor Authentication on Every Account

Close-up of a hand signing a document with a pen, representing signing off on a cyber insurance policy application

MFA is the most scrutinized line item on most applications, and the specific gap that trips up applicants isn’t usually the absence of MFA entirely, it’s inconsistent coverage. Email and general staff accounts have it, but an administrator or privileged account was set up before the policy existed and never updated. Insurers ask specifically about coverage on email, remote access, cloud consoles, and privileged accounts, and partial coverage tends to be treated as a fail on the whole line item.

Endpoint Protection Beyond Basic Antivirus

Traditional signature-based antivirus, the kind that only catches known threats it has a signature for, is treated as outdated by most Canadian underwriters now. What insurers look for instead is endpoint detection and response (EDR) or extended detection and response (XDR): tools that watch for suspicious behaviour in real time and can isolate a compromised device automatically, rather than only scanning files against a known list.

Backups That Have Actually Been Tested

A backup job completing successfully and a backup that’s actually recoverable are two different things, and insurers increasingly ask for proof of the second one specifically. What matters on an application isn’t just whether backups run, but whether they’re immutable or kept offline where ransomware can’t reach them, and whether a restore has been tested and dated recently. “We have backups” and “we tested a restore three weeks ago and it worked” are very different answers on the same question.

A Documented, Tested Incident Response Plan

Having a plan written down is the starting point. Insurers increasingly want to know it’s been tested, typically through a tabletop exercise where the response team walks through a simulated incident rather than just reading a document that’s never been rehearsed. A plan nobody has practiced tends to fall apart under real conditions in ways a tested one doesn’t.

Security Awareness Training

Regular training, not a one-time onboarding session years ago, rounds out the standard control set most Canadian underwriters now check for. The reasoning tracks with how most breaches actually start: a person clicking a link or approving a fraudulent request, not a technical failure in the network itself.

Why This Matters Even Without a Policy

Separate from insurance entirely, PIPEDA requires Canadian businesses to report breaches of security safeguards that create a real risk of significant harm, and to keep records of every breach for at least 24 months, whether or not the business carries cyber insurance. The overlap is worth noting: the controls insurers now expect largely track the baseline the Canadian Centre for Cyber Security already recommends for small and medium organizations, so building toward one tends to move a business toward the other.

What This Looks Like at ACT360

Jeffrey Bowles, Partner and Director of IT Services at ACT360, puts it this way when clients ask why security reviews happen on a set schedule rather than only after something goes wrong:

“I’d rather we catch this now, in a review, than have it show up as an incident in six months.”

— Jeffrey Bowles, Partner & Director of IT Services, ACT360

Quarterly business reviews under ACT360’s vCIO service cover exactly the controls insurers now check for: MFA coverage, endpoint protection status, backup testing dates, and incident response readiness, reviewed on a schedule rather than discovered for the first time on an application. The costs of getting this wrong are real: average ransomware recovery runs around $200,000 and average data loss around $180,000, based on ACT360’s own published figures, well above the cost of building the right controls before an insurer, or an attacker, asks.

Final Thought

Cyber insurance underwriting in 2026 rewards businesses that can show their work: real evidence of MFA coverage, real dates on backup tests, a plan that’s actually been rehearsed. None of it requires exotic technology. Most of it is configuration and process that a lot of businesses already have partial pieces of, just not documented or consistent enough to survive a questionnaire.

T: 705-739-2281 E: [email protected]

FAQ

Frequently asked questions

Is cyber insurance mandatory for businesses in Ontario?

No federal or provincial law makes cyber insurance mandatory for most Ontario businesses. It’s increasingly required by contract, though: lenders, larger clients, and vendor agreements are asking for it more often as a condition of doing business.

What's the single most common reason applications get declined?

Incomplete multi-factor authentication is the most frequent issue, particularly gaps on administrator or privileged accounts even when MFA is enforced everywhere else. A close second is not having a recently tested backup restore to point to.

Does basic antivirus still meet insurer requirements?

Generally not in 2026. Most carriers now expect endpoint detection and response (EDR) or extended detection and response (XDR), which monitors behaviour in real time rather than just scanning for known threats. Traditional signature-based antivirus alone is treated as outdated by most underwriters.

What counts as a tested backup for insurance purposes?

A backup that has had an actual restore performed and dated, not just a backup job that completed successfully. Insurers distinguish between a backup existing and a backup being proven to work, and ask for the date of the most recent test.

Do I need cyber insurance if I already have good security in place?

Good security reduces the likelihood of a claim, but it doesn’t replace the financial protection insurance provides if a breach happens anyway. The two work together: strong controls make a business easier to insure and reduce the chance a policy is ever needed.

KEEP READING

Related Posts