A few years ago, cyber insurance applications were mostly a short questionnaire. Following a wave of ransomware payouts, Canadian insurers tightened underwriting significantly — and started requiring proof of specific technical controls before they'll issue a policy, and sometimes before they'll pay out on a claim. Businesses that assumed they were covered have discovered mid-claim that a missing control voided the policy entirely.

Why insurers changed the rules

Ransomware claims became the largest and least predictable category of cyber insurance losses. Insurers responded the way any insurer responds to a costly, hard-to-model risk: by requiring the policyholder to reduce it first. The controls now commonly required aren't arbitrary — they map directly to the entry points and failure modes insurers saw repeatedly in claims.

What's commonly required now

Multi-factor authentication, especially for remote access and email

This is close to universal on current applications. Several major insurers will decline or heavily surcharge an application without MFA enforced on email, VPN, and any remote administrative access.

Endpoint Detection and Response (EDR), not just antivirus

Basic antivirus is increasingly treated as insufficient on its own. Insurers want evidence of behavioural detection capable of catching ransomware and fileless attacks that signature-based tools miss.

Immutable, offline, or air-gapped backups

Because ransomware groups specifically target and destroy connected backups, insurers now frequently ask whether backups are immutable (cannot be altered or deleted, even by an attacker with admin credentials) and how quickly you could actually restore from them.

Email filtering and phishing protection

Given how many claims originate from a single phished credential, insurers want evidence of active email security — not just spam filtering, but protection against business email compromise and malicious attachments.

A documented incident response plan

Some applications now ask directly whether you have a written incident response plan and who is responsible for executing it. 'We'll figure it out if it happens' is increasingly treated as a red flag.

What happens if you don't have these controls

Three outcomes are common: the application is declined outright, the premium is priced dramatically higher to offset the risk, or — the outcome that causes the most damage — the policy is issued, an incident happens, and the insurer denies the claim during investigation because a required control (often MFA) wasn't actually in place as represented on the application.

The practical takeaway

Treat the cyber insurance application as a security audit, not paperwork. Walking through it honestly, before you apply, usually surfaces the exact gaps worth closing regardless of whether you end up insured — they're the same gaps that lead to real incidents.

Need help closing the gap between what you have and what insurers require? Find your plan or book a free 15-minute call.