Cyber Insurance

What Do Canadian Cyber Insurers Actually Check Before Approving Your Policy in 2026?

When your broker submits a cyber insurance application for your law firm or accounting practice in Ontario, the underwriter’s first move is no longer a quick checklist — it’s a technical security audit. The Law Society of Ontario (LSO) now expects firms to demonstrate the same controls insurers verify, and that overlap has created a new bottleneck: from an infrastructure standpoint, many small practices discover their controls are partially implemented, not fully operational. A common finding in the PECB ISO 27001 course materials is that control documentation without active monitoring creates material misrepresentation risk. As a systems engineer, I’ve reviewed application questionnaires and noticed that firms frequently describe tools as “deployed” when they mean “installed but not monitored.” Endpoint Detection and Response (EDR) software sitting on devices but routing alerts to an unmonitored mailbox fails underwriter review every time. The application now typically includes ten specific technical controls, and a gap in any one of them can trigger a denial, a coverage exclusion, or a premium adjustment that defeats the purpose of buying insurance.

This post translates that underwriter checklist into plain language. No IT background required. If you are a managing partner at a law firm or accounting firm in Ontario, this outlines what Canadian underwriters typically review when your broker submits an application.

Why Cyber Insurance Applications Have Become Security Reviews

The Canadian cyber insurance market has tightened significantly since the early 2020s. According to Statistics Canada’s Business Enterprise Survey data, reported cyber incidents among professional services firms increased substantially, driving underwriting scrutiny across the sector. Insurers responded by replacing simple applications with technical questionnaires benchmarked against frameworks like the NIST Cybersecurity Framework and the CIS Controls — standards referenced by both the Canadian Centre for Cyber Security (CCCS) in their published guidance and provincial regulators like the Law Society of Ontario (LSO) in their 2023 cybersecurity advisory for law firms.

In 2026, Canadian underwriters verify that stated controls are actually in place and actively functioning. Answering “yes” to a control you have not implemented is a material misrepresentation — grounds for claim denial. From the PECB ISO 27001 course, this underscores why control implementation must precede documentation.

For law firms specifically, the LSO’s 2023 cybersecurity advisory noted that firms underestimating their vulnerability profile may face policy complications during underwriting review. For accounting firms, CPA Canada’s Professional Standards emphasize that PIPEDA compliance directly intersects with insurer expectations for access controls and data encryption.

The 10 Controls Canadian Insurers Typically Check

The following controls appear on questionnaires used by Canadian underwriters who work with professional services. For each one, “proven” means you can demonstrate it — not just describe it.

1. Multi-Factor Authentication (MFA) on All Remote Access and Email

MFA is a primary focus in underwriting reviews. Insurers require MFA on email, remote desktop, VPN connections, and any cloud application holding client data. From an infrastructure standpoint, having it on some systems does not satisfy the requirement. Every access point counts. If a managing partner can log into your firm’s email with only a password, you fail this control. The underwriter will ask for audit logs showing MFA enforcement — not screenshots of the configuration screen.

2. Endpoint Detection and Response (EDR) Actively Monitored

EDR software must be installed on all workstations and servers, with alerts routed to a monitored dashboard or SIEM. From an infrastructure standpoint, the software alone does not satisfy underwriters. Someone — either your internal team or a managed security service provider — must actively review and respond to alerts. Underwriters ask: “Who reviews EDR alerts daily? Show me the response log.” No response log = control not proven.

3. Automated Backup and Recovery Testing

Backups must be automated, stored off-site, and tested quarterly to confirm they restore. As a systems engineer, I’ve observed that firms often back up data but never test recovery. Ransomware incidents reveal this gap immediately. Canadian underwriters now ask for documented evidence of at least two successful restore tests within the past 12 months. The law firm or accounting firm must also verify that backups are encrypted and stored in a location physically separate from production systems.

4. Patch Management and Vulnerability Scanning

All systems — servers, workstations, network devices — must have a documented patch management process with evidence of regular application. Underwriters request a vulnerability scan report from the past 90 days and proof that critical vulnerabilities were remediated within 30 days. From an infrastructure standpoint, this means running automated scans at least monthly and maintaining a remediation log.

5. Network Segmentation and Firewall Rules

Client data networks must be logically or physically separated from general office networks. Underwriters ask for firewall configuration documentation showing that client data systems can communicate only with authorized systems. Actual segmentation requires separate VLANs, Access Control Lists (ACLs), or physical network separation with documented rules.

6. Encryption in Transit and at Rest

All data containing client personal information must be encrypted when stored and when transmitted. From an infrastructure standpoint, this means:

  • Email encryption (TLS for SMTP, S/MIME for sensitive messages)
  • VPN encryption for remote access
  • AES-256 or equivalent for stored data
  • HTTPS for all web applications

Underwriters ask where encryption keys are stored and who has access. PIPEDA compliance reinforces this: unencrypted client data is a federal violation and uninsurable.

7. Access Control and Privilege Management

Every user account must have justification for their access level, and admin accounts must be separate from daily-use accounts. Underwriters ask for a documented access matrix showing which roles can access which systems. Multi-level privilege — standard user for email, separate admin account for system changes — is required.

8. Security Awareness Training and Incident Response Plan

All staff must complete documented security training at least annually. CPA Canada’s Professional Standards and LSO advisories both emphasize that humans are the primary vulnerability. Underwriters verify training completion and ask for quiz results or training platform logs. Your firm must also have a written incident response plan — a step-by-step guide for what happens when a breach is detected.

9. Third-Party Risk Assessment and Vendor Management

If you use cloud storage, document management, email backup, or managed IT services, underwriters require proof that vendors meet the same security standards you do. From an infrastructure standpoint, this means:

  • Written Data Processing Agreements (DPAs) with vendors
  • Proof of vendor security certifications (ISO 27001, SOC 2, etc.)
  • Confirmation that vendor data centers are in Canada or jurisdictions aligned with PIPEDA

10. Logging, Monitoring, and Audit Trails

All security-relevant events — login attempts, file access, configuration changes, administrative actions — must be logged and retained for at least 90 days. Underwriters ask: “Can you show me login attempts that failed? Can you trace who accessed a specific client file and when?” If logs are not searchable and retrievable, this control is not proven.

What To Do This Week

  1. Audit Your Current Controls: Review the ten controls above against your firm’s current setup. For each one, write down: “Implemented,” “Partially Implemented,” or “Not Implemented.” Do not rely on assumptions — actually verify.
  2. Test One Critical Control: If you have EDR, run a test alert and confirm someone receives it. If you have backups, attempt a test restore of a small dataset. If you have MFA, verify it is required on all email accounts. Document the test result.
  3. Start a Vendor Checklist: If you use any third-party services (Dropbox, Microsoft 365, managed IT provider, document management system), begin collecting Data Processing Agreements and security certifications.
  4. Schedule a Mock Underwriting Call: Before your broker submits an application, simulate an underwriter’s technical interview. Have someone outside your firm ask the questions from each control section above. Record where you lack documentation.
  5. Check Your Security Baseline: Not sure where you stand overall? Take the free 7-minute cybersecurity risk scorecard to see which of these controls your firm is missing before your insurer finds them.

Note on Provincial Differences: This post reflects Ontario requirements (LSO context). Quebec firms should confirm requirements with the Barreau du Québec. Alberta law firms should check with Law Society of Alberta. Insurance oversight and regulatory expectations vary by province.

Frequently Asked Questions

Do Canadian cyber insurers actually check technical controls, or just take your word for it?

In 2026, most Canadian underwriters verify controls during the application process through technical questionnaires and sometimes external scans. Post-claim investigations are also common — insurers verify that stated controls were actually in place at the time of the incident. Material misrepresentation on an application, even unintentional, is grounds for claim denial under Canadian insurance law.

What is the most common reason a Canadian cyber insurance application gets rejected?

Missing or unmonitored MFA is the most common application blocker in 2026. Insurers also frequently flag EDR that is installed but not actively monitored, and backups that have never been tested for recovery. These three controls — MFA, EDR, and verified backups — are the baseline. Missing any one of them typically results in a higher premium or declined application.

How long does a cyber insurance application review take in Canada?

Simple applications for small businesses typically take 5–10 business days. Applications requiring a technical review — usually triggered by higher revenue, data volume, or identified control gaps — can take 3–6 weeks. Having documentation ready for all ten controls listed above significantly accelerates the process.

Can a small Ontario law firm or accounting firm actually pass these requirements?

Yes — most of these controls are implementable by any firm regardless of size. MFA on Microsoft 365 is free and takes an afternoon to configure. Tested backups require scheduling, not significant budget. EDR solutions for small firms start at $5–8/endpoint/month. The gap is not cost — it is usually awareness and documentation. Firms that work through this checklist systematically before applying almost always qualify for better terms.

What happens if my controls fail during a post-claim investigation?

If an insurer determines during a claim investigation that the controls stated on your application were not actually in place at the time of the incident, they can deny the claim entirely or reduce the payout proportionally. Under Canadian case law, this is treated as material misrepresentation. The firm bears the financial loss directly. This is why verifying that documented controls are genuinely operational — not just described in a policy — is critical before applying.


Sources

FREE RESOURCE

How Exposed Is Your Business Right Now?

Take the free 7-minute scorecard and find out exactly where your cybersecurity gaps are — before an insurer or attacker does.

Get My Free Risk Score →

No email required to start. Takes 7 minutes.

← Back to all resources

Have Questions About Your IT Setup?

Book a free 15-minute fit call. We'll help you figure out the best path forward for your business — no pressure.

Book a Free Consultation

📍 Toronto · GTA · Ontario · Across Canada  |  ⏰ 1 business day response

Discover more from Secrecy Evolution

Subscribe now to keep reading and get access to the full archive.

Continue reading