Array of Networking Equipment and Cabling

For years, getting cyber insurance meant filling out form, checking off some boxes, and paying a premium. Most Ontario business owners assumed that if they had antivirus software and a backup running somewhere, they were covered. Unfortunately, that assumption no longer holds. Cyber insurance in 2026 has shifted from a paperwork exercise into something closer to a technical audit, and businesses that haven't kept pace are finding out the hard way when they try to file a claim. The problem is not that coverage has disappeared. It's that the bar for qualifying has moved.

Why "We Have MFA" Isn't Good Enough Anymore

A few years ago, insurers took businesses at their word. If you said you had multi-factor authentication, that was typically enough to get a policy. Nowadays, insurers expect proof that security features like MFA were actually enforced, controlled, and active across every account at the time of the loss. This distinction matters more than most business owners realize. If MFA is turned on for email but not for VPN, RDP, or admin accounts, and an attacker gets in through one of those gaps, insurers can treat the original application as a misrepresentation.

What Insurers Are Actually Looking For

Requirements vary slightly by carrier, but the core expectations are consistent across the market:

  1. Multi-factor authentication enforced across every access point. Not just M365, but VPN, remote desktop, cloud platforms, and admin accounts.
  2. Endpoint detection and response (EDR) on every device. Traditional antivirus no longer meets the bar, since it only catches known threats rather than actively monitoring for suspicious behaviour.
  3. Backups that are offsite, isolated from the primary environment, and immutable, meaning they can't be altered or deleted even if an attacker gains access. Just as important, backups need to be tested on a regular schedule.
  4. A written incident/disaster response plan that spells out roles, containment steps, and who to contact when something goes wrong.
  5. Email security controls like SPF, DKIM, and DMARC properly configured and enforced, since email compromise remains the most common entry point for attackers.
  6. Security awareness training completed on a recurring basis, not once a year, with records to prove it happened.

None of these controls are out of reach for a small or mid-sized business, and getting them in order does more than satisfy an insurance agency- It closes the same gaps attackers are actively looking for, which means better coverage and a lower chance you ever need to use it.

If you're not sure where your business stands against these requirements, or you have a renewal coming up and want to know what an insurer will actually ask, Keystone Technologies can help you find out. We'll walk through your current controls, flag the gaps, and get you documented and ready before the questionnaire lands.

To learn more or book an assessment, visit keystonetech.ca, call 519-451-1793, or email info@keystonetech.ca.

Need help with what you just read about?

Talk to a senior engineer, no sales script.