Logo AgtechnoAGTECHNOManaged IT services — Montreal

Your cyber insurance questionnaire: why you may be about to fail it

Cyber insurance · 5 min read

Five years ago, buying cyber insurance took two pages and a signature. Today your insurer asks you to prove what you have in place — and verifies it.

This shift went unnoticed by many owners. Insurers paid dearly for the ransomware waves of recent years, and they tightened up. The renewal questionnaire has effectively become a security audit in disguise.

Four requirements come up consistently. If you can't tick all four honestly, expect a sharply higher premium, an inflated deductible, exclusions — or an outright refusal.

1. Multi-factor authentication, everywhere

It's no longer "do you have MFA". It's "do you have MFA on remote access, on email, on administrator accounts and on your critical systems".

The classic trap: MFA is enabled for most employees, but not for service accounts, nor for that old administrator account nobody dares touch. That's precisely where attackers get in.

2. Endpoint detection and response (EDR), not just antivirus

Traditional antivirus compares files against a list of known threats. EDR monitors behaviour: a process that starts mass-encrypting files at 2 a.m. gets detected even if the malware is brand new.

And insurers increasingly ask not just whether you have EDR, but whether it's monitored — meaning whether someone watches the alerts outside business hours. An alert firing into an empty console on a Friday night has never stopped a ransomware attack.

3. Backups that are tested and out of reach

This is the question that catches the most SMBs. "Do you have backups?" — yes, obviously. "When did you last test a full restore?" — silence.

Three criteria matter:

4. A written incident response plan

Who do you call at 3 a.m.? Who decides to pull the plug? Who talks to clients? Who notifies the Commission d'accès à l'information within the timeframe Law 25 requires?

A plan fits on three or four pages. It isn't a large-enterprise document — it's a list of numbers, roles and pre-made decisions. But it has to exist before the incident, because when it happens nobody thinks clearly.

The question nobody thinks about

Here's what should worry you more than the premium: what happens if you tick a box you can't back up?

An inaccurate statement at underwriting can be used by the insurer to deny the claim when the loss occurs. You would have paid premiums for three years only to discover, on the worst day of your professional life, that you aren't covered.

We regularly see questionnaires filled in good faith by an owner who thought "yes, we have backups" was enough. That isn't dishonesty — it's an owner answering a technical question they have no way to verify themselves.

How to turn this questionnaire into a formality

A well-managed SMB ticks all four boxes effortlessly, because those controls are part of normal operations, not a special project. For our clients, insurance renewal takes thirty minutes: we hand over an annual report documenting the controls in place, and all that's left is to attach it.

If your renewal is coming up and this article made you wince, two free places to start:

And if you want the verified picture rather than the self-declared one, that's exactly what our cybersecurity + Law 25 assessment covers.

‹ Back to the blog

Is your renewal coming up?

The assessment gives you the real state of your controls — and the plan to close the gaps before the date.

Book my assessment