A few years ago a cyber-insurance application was a page long. Today it is a technical questionnaire, and the answers decide whether you are covered, what you pay, and — after an incident — whether the claim is honoured. Businesses across the GTA are finding this out at renewal time, usually with two weeks to respond.
The questions that matter
Multi-factor authentication (MFA)
Almost every insurer now requires MFA on email, remote access and administrator accounts. "Some users have it" is not a yes. It needs to be enforced by policy across the organisation.
Endpoint detection and response (EDR)
Traditional antivirus looks for known bad files. EDR watches behaviour — a legitimate tool being used to encrypt files at 2 a.m., for example — and can isolate the machine automatically. Insurers ask for it by name.
Backups that are offline or immutable, and tested
The question is usually phrased as "Are backups separated from the production network, and when did you last test a restore?" Both halves need a real answer.
Patching cadence
How quickly are critical updates applied to servers, workstations and — often forgotten — firewalls and network equipment? A documented schedule with evidence is what they want to see.
Email security and staff training
Filtering for phishing and malicious attachments, plus periodic awareness training with simulated phishing, are increasingly standard.
Privileged access and remote access
Are there shared admin accounts? Is remote desktop exposed to the internet? A yes to either can be a decline.
How to prepare without a scramble
Treat the questionnaire as a checklist, not a form. Each item maps to a control that a managed security service should already be running, with evidence kept continuously: MFA reports, EDR coverage, backup test logs, patch reports. When the renewal arrives, the answers are a report rather than a project.
If your renewal is coming up, send us the questionnaire. We will go through it line by line and tell you what is already in place, what is missing, and what it would take to close the gap — before the insurer asks.

