Analysis · Cyber insurance
Cyber insurance: what insurers require
MFA, backups, EDR, patching, a response plan, suppliers: what a cyber insurance application has you declare, and how to build the evidence once and reuse it.
By Sentrix · Published 2026-10-01
The renewal is six weeks away and the broker has just sent a form. The one an insurer publishes on ransomware, as a supplement to its application, runs to forty-six questions over five pages and ends with a signature: that of an authorized person who declares the answers true. Who in the organization can answer without guessing, and with what evidence?
What the sources say
The Insurance Bureau of Canada (IBC) sets the frame in its cyber insurance checklist: insurers use the application to assess the risks to the organization and to price the policy. The sample questions cover the business, the records it retains (card numbers, government identification, health information), the written security plan, the last audit and any recommendation left uncompleted, staff training, then the controls: encryption, authentication, antivirus, firewall, annual budget, and what will be improved in the next six months.
An insurer's questionnaire goes deeper. The ransomware supplemental application published by one insurer (May 2022 edition), cited here as one insurer's questionnaire and not as the market standard, asks among other things:
- Multi-factor authentication (MFA): is it enforced for all user accounts for remote access to the network, for web-based email, and for all domain administrator accounts?
- Backups: are there offline, encrypted, immutable copies, and how often is a restoration tested?
- Detection: which solutions are in place (endpoint protection, endpoint detection and response or EDR, MDR, NDR, SIEM), and can the security operations center isolate an endpoint remotely?
- Patching: what percentage of the enterprise is covered by vulnerability scans, and what has been, over two years, the average time to remediate critical CVEs (CVSS score 9.0 to 10.0), from "under 48 hours" to "over two weeks" or "unknown"?
- Plan: was the business continuity or disaster recovery plan that covers cyber threats created or updated within the past two years, and has a tabletop exercise included ransomware?
Suppliers appear in the IBC guide: have them complete a security practice questionnaire, request supporting documentation, reassess them from time to time, integrate them into the incident response plan and remove all their access when the contract ends.
None of these questions is specific to insurance. The Canadian Centre for Cyber Security's baseline controls, written for organizations with fewer than 500 employees, already recommend a written incident response plan (BC.1.2), automatic patching or full vulnerability and patch management (BC.2.1), up-to-date anti-malware (BC.3.1), two-factor authentication wherever possible (BC.5.1), encrypted backups with long-term copies stored offline (BC.7.1 and BC.7.2) and a SOC 3 report requested from cloud service providers (BC.10.1).
Why it matters
Because the form is not a survey. The closing declaration of that questionnaire says what becomes of the answers: they are the basis of the contract should a policy be issued, the insurer has relied on them, and the application is deemed attached to the policy. The answers must be accurate as of the date of signature, and if the information changes before the effective date, the applicant must immediately notify the insurer, which may then withdraw or modify its quotation.
A "yes" ticked on the question about MFA for administrators is therefore a dated, signed statement. If it rests on a memory, on a policy nobody verified or on "nearly all accounts", it is fragile. The form itself provides the honest way out: it asks for exceptions to be noted in a dedicated section. A written exception is worth more than an approximate yes.
IBC also reminds readers that cyber insurance is only one component of a broader risk mitigation strategy: it replaces none of the controls it asks about.
What we think at Sentrix
The questionnaire changes from one year and one insurer to the next; the evidence changes little. Better to build it once, per control, then keep it current. In order:
- Name an owner per family of questions: identity, backups, detection, patching, plan, suppliers. The signatory signs only what an owner has confirmed in writing.
- Attach a dated exhibit to every answer: a directory export showing the MFA method per account, the report of the last restoration test, EDR coverage compared with the inventory, the minutes of the last tabletop exercise.
- Write the exceptions before anyone asks: the service account without MFA, the end-of-life software segregated from the network, each with its compensating measure and its end date.
- Measure what the form measures. If the question is the average time to remediate critical CVEs, that figure must exist before the renewal, not be estimated the night before.
- Reuse. The same exhibit answers a customer's security questionnaire, an audit and next year's application: one file per control, not one file per requester.
- Reread the file between signature and effective date, since the declaration requires reporting what has changed.
The next step
Take the last signed application and, for every "yes", look for the exhibit that proves it today. Every "yes" without an exhibit becomes a line in the work plan between now and the renewal. A cybersecurity posture assessment gives that starting point, control by control.
Sources
Frequently asked questions
- What does a cyber insurance application ask?
- According to the Insurance Bureau of Canada's checklist, it describes the business, the information it keeps, the security plan, the last audit, staff training and the controls in place. The one insurer's questionnaire we cite goes further: multi-factor authentication (MFA) by account type, offline backups and restoration tests, detection tools, time to remediate critical vulnerabilities, tabletop exercises.
- Why do insurers ask these questions?
- The Insurance Bureau of Canada puts it simply: insurers use the application to assess the risks to the organization and to price the policy. In the one insurer's questionnaire we cite, the signed declaration adds that the answers are the basis of the contract should a policy be issued. Each answer is therefore a dated statement, not a formality.
- Where do you start if the organization has no cyber insurance yet?
- With the controls themselves. The Canadian Centre for Cyber Security's baseline controls, written for organizations with fewer than 500 employees, cover the incident response plan, patching, two-factor authentication and backups, and recommend considering a policy that covers incident response and recovery, or providing a rationale for not purchasing one.
Let's talk about your compliance program.
Last updated: 2026-10-01
