Five years ago, buying cyber insurance took two pages and a signature. Today your insurer asks you to prove what you have in place — and verifies it.
This shift went unnoticed by many owners. Insurers paid dearly for the ransomware waves of recent years, and they tightened up. The renewal questionnaire has effectively become a security audit in disguise.
Four requirements come up consistently. If you can't tick all four honestly, expect a sharply higher premium, an inflated deductible, exclusions — or an outright refusal.
1. Multi-factor authentication, everywhere
It's no longer "do you have MFA". It's "do you have MFA on remote access, on email, on administrator accounts and on your critical systems".
The classic trap: MFA is enabled for most employees, but not for service accounts, nor for that old administrator account nobody dares touch. That's precisely where attackers get in.
2. Endpoint detection and response (EDR), not just antivirus
Traditional antivirus compares files against a list of known threats. EDR monitors behaviour: a process that starts mass-encrypting files at 2 a.m. gets detected even if the malware is brand new.
And insurers increasingly ask not just whether you have EDR, but whether it's monitored — meaning whether someone watches the alerts outside business hours. An alert firing into an empty console on a Friday night has never stopped a ransomware attack.
3. Backups that are tested and out of reach
This is the question that catches the most SMBs. "Do you have backups?" — yes, obviously. "When did you last test a full restore?" — silence.
Three criteria matter:
- Offline or immutable. Modern ransomware actively hunts your backups and encrypts them first. A backup reachable from the network with an admin account is not a backup.
- Tested. A backup never restored is an assumption, not a protection. The real failure rate on first restore attempts always surprises people.
- Documented. If you can't show a verification log, you can't prove it.
4. A written incident response plan
Who do you call at 3 a.m.? Who decides to pull the plug? Who talks to clients? Who notifies the Commission d'accès à l'information within the timeframe Law 25 requires?
A plan fits on three or four pages. It isn't a large-enterprise document — it's a list of numbers, roles and pre-made decisions. But it has to exist before the incident, because when it happens nobody thinks clearly.
The question nobody thinks about
Here's what should worry you more than the premium: what happens if you tick a box you can't back up?
An inaccurate statement at underwriting can be used by the insurer to deny the claim when the loss occurs. You would have paid premiums for three years only to discover, on the worst day of your professional life, that you aren't covered.
We regularly see questionnaires filled in good faith by an owner who thought "yes, we have backups" was enough. That isn't dishonesty — it's an owner answering a technical question they have no way to verify themselves.
How to turn this questionnaire into a formality
A well-managed SMB ticks all four boxes effortlessly, because those controls are part of normal operations, not a special project. For our clients, insurance renewal takes thirty minutes: we hand over an annual report documenting the controls in place, and all that's left is to attach it.
If your renewal is coming up and this article made you wince, two free places to start:
- Our IT security audit — nine questions, five minutes, instant result.
- Our backup plan check — the eight criteria your insurer will look at.
And if you want the verified picture rather than the self-declared one, that's exactly what our cybersecurity + Law 25 assessment covers.
‹ Back to the blog