All Resources
Cybersecurity

Cyber Insurance Requirements for Ontario Small Businesses

Every insurer writes its own cyber policy and its own application questionnaire, so there is no single national checklist you can copy and paste. This article is general information, not legal or insurance advice, and it is not a guarantee that any specific control will get you coverage or a lower premium. Speak with a licensed insurance broker about your policy's actual wording. What we can do, as an IT provider that helps Ontario small businesses fill out these applications, is walk through the controls that come up again and again.

Published August 9, 2026 Updated August 9, 2026 8 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

Cyber insurance requirements differ by insurer and policy, but Ontario applications commonly ask about multi-factor authentication on email and remote access, endpoint detection and response, tested backups with an offline or immutable copy, a regular patch cadence, restricted administrative access, email filtering, an incident response plan, and staff security awareness training. This is general information, not insurance or legal advice; confirm exact requirements with your broker or insurer.

Why this is not a one-size-fits-all list

Cyber insurance underwriting has tightened considerably over the past few years. Insurers that once accepted a short questionnaire now ask detailed, sometimes technical, questions and may require evidence such as screenshots or vendor confirmation letters.

Two businesses in the same industry, applying with two different insurers, can be asked completely different questions and receive different pricing for the same risk. Broker relationships, claims history, industry, revenue, and data sensitivity all factor in. Treat every point below as "commonly asked about," not "guaranteed to be required."

Controls insurers commonly ask about

The following controls show up repeatedly on Ontario cyber insurance applications we have helped clients complete. None of them are exotic. They are the same fundamentals covered in our cybersecurity checklist for small businesses, which is a useful companion read if you are starting from scratch.

Multi-factor authentication on email and remote access

This is the single most common question on modern applications, often asked as a yes/no with no room for "partially." Insurers want MFA enforced on every mailbox, every VPN connection, and every remote desktop or remote access tool, not just for admins.

Endpoint detection and response (EDR)

Traditional antivirus is increasingly treated as insufficient on its own. Applications now frequently ask whether you run endpoint detection and response with behavioural monitoring, and whether it is centrally managed rather than left to individual users to configure.

Tested backups with an offline or immutable copy

Having backups is not the same as having backups an insurer will accept. Underwriters increasingly ask specifically whether at least one backup copy is offline, air-gapped, or immutable so ransomware cannot encrypt or delete it along with your production data, and whether restores are actually tested. See our backup and disaster recovery guide for the mechanics.

Patch cadence for operating systems and software

Expect questions about how quickly critical and high-severity patches are applied to servers, workstations, and internet-facing systems, and whether patching is centrally managed rather than dependent on individual employees clicking "remind me later."

Privileged and administrative access controls

Insurers ask how many people hold domain or global administrator rights, whether those accounts are used for day-to-day email and browsing, and whether privileged accounts also require MFA. Fewer standing admin accounts is generally viewed favourably.

Email filtering and anti-phishing controls

Because phishing remains the most common entry point for ransomware and business email compromise, applications ask whether you run advanced filtering beyond the built-in spam filter, such as email and collaboration security tooling that flags impersonation and malicious links.

A written incident response plan

Some insurers ask whether a documented plan exists describing who to call, what to isolate, and how to notify affected parties in the event of a breach. If nothing is written down, the honest answer to this question is no, and that is worth fixing before renewal, not during a live incident. Our article on what to do if your business has been hacked covers the immediate steps.

Security awareness training for staff

Applications frequently ask whether employees receive regular training and simulated phishing tests, not just a one-time onboarding video. See why employee security awareness training matters.

Logging and monitoring

Larger applications, or renewals after a claim, may ask about log retention and whether anyone is actively reviewing security alerts, which points toward managed detection and response rather than logs that sit unread.

Application-readiness table

Common cyber insurance application questions and how to prepare
ControlWhy insurers askEvidence you will likely need
MFA on email and remote accessCredential theft is the leading cause of claims insurers see across the marketScreenshot of tenant-wide MFA policy or conditional access report
EDR on servers and endpointsDetects and can contain active intrusions before they spreadVendor console showing coverage across all devices
Offline or immutable backup copyRansomware routinely targets connected backups firstBackup vendor configuration showing an air-gapped or immutable copy plus a recent restore test log
Patch management cadenceUnpatched software is a common initial access routePatch compliance report with timeframes for critical updates
Limited administrative accountsFewer privileged accounts reduce blast radius of a compromiseList of accounts with admin rights and justification for each
Email filtering and anti-phishingPhishing remains a top entry point for fraud and ransomwareConfiguration summary from your email security platform
Written incident response planFaster, coordinated response reduces claim severityA dated document naming roles and escalation contacts
Staff security awareness trainingReduces successful phishing and social engineering attemptsTraining completion records and phishing simulation results

Getting ready for a cyber insurance renewal?

We can review your current controls against common application questions and tell you plainly where the gaps are.

Book a Cybersecurity Risk Assessment

What happens if you cannot check every box

Missing a control does not automatically mean no insurer will cover you. It usually means a higher premium, a coverage sublimit for ransomware, or a requirement to implement the control within a set number of days after binding. Brokers see this constantly and can often shop your application to insurers whose risk appetite matches where you actually are today.

What we recommend to clients is treating the application as a prioritised project list rather than a pass or fail test. Start with MFA and backups, since those two controls address the largest share of claims insurers describe publicly, then work through the rest.

Where an IT provider fits in

We are not brokers and we do not sell insurance policies. What we do is implement and document the technical controls insurers ask about, and produce the evidence, such as configuration reports and training logs, that your broker needs to submit on your behalf. If you want a baseline review before your next renewal, a cybersecurity risk assessment is a practical starting point.

Sources and further reading

Frequently asked questions

Does cyber insurance require MFA in Ontario?

Most Ontario insurers now ask whether MFA is enforced on email and remote access, and many will decline or heavily restrict coverage without it, though exact requirements vary by insurer and policy.

Will I be denied coverage without EDR?

Not necessarily, but lack of EDR often results in higher premiums or exclusions for ransomware claims rather than an outright decline. Confirm with your broker.

Do backups need to be offline to qualify for cyber insurance?

Many insurers now ask specifically about an offline or immutable backup copy because ransomware often targets connected backups, but requirements differ by policy.

Is this article legal or insurance advice?

No. This is general information about controls commonly requested on Ontario cyber insurance applications. Speak with a licensed insurance broker about your specific policy.

How long does it take to become insurance-ready?

It depends on your starting point, but MFA and basic backup fixes are often achievable within days, while a full incident response plan and training program can take a few weeks to build properly.

Can an IT provider fill out the insurance application for me?

An IT provider can supply the technical answers and evidence, but the application itself should be reviewed and submitted with your insurance broker.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Need help documenting your controls for an insurer?

We will translate your application questionnaire into a technical action list and help you gather the evidence.

Keep exploring

Related services, locations, and resources

Related services

Related resources