Back to Blog
Cybersecurity9 min read

Cyber Insurance for Canadian SMBs in 2026: What Insurers Actually Require — and Why the Controls Matter

By Anton Kuznetsov

Cyber insurance used to be a straightforward purchase for a Canadian small business: fill out a two-page application, answer a few yes/no questions about antivirus and backups, and pay a modest premium. That era ended between 2020 and 2022, when ransomware losses pushed Canadian cyber insurers to average combined loss ratios of approximately 155% — a level that made the product unprofitable at prevailing premiums and terms, according to the Insurance Bureau of Canada.

The market response was a hard reset. Premiums spiked. Application questionnaires expanded from two pages to twenty. Underwriters started asking for evidence — screenshots, configuration exports, backup restore logs — rather than accepting attestations. And the controls that were once "recommended" became binary qualifiers: no MFA, no coverage.

By early 2026, the market has found a more sustainable equilibrium. Cyber rates fell 5% in Q1 2026 on the Marsh Global Insurance Market Index, with the seventh consecutive quarterly rate decline driven by new market entrants and increased capacity. Carriers are offering lower retentions and broader sub-limits to well-controlled insureds. But the qualification bar has not moved. If anything, it has gotten more precise about what "well controlled" means in practice.

For Canadian SMBs, this is actually an opportune moment — rates are more competitive than they were two years ago, and the controls insurers require align almost exactly with what the Canadian Centre for Cyber Security’s Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) recommends as a minimum security posture. Getting insurable and getting secure are the same project.

Why the Stakes Are High

Canadian organizations are paying a record CA$7.11 million on average per data breach, the highest level recorded since IBM began the study, according to the IBM 2026 Cost of a Data Breach Report. Canada now ranks fourth globally for average breach cost. For an SMB, even a fraction of that figure is existential: a CA$500,000 incident that includes forensic investigation, legal fees, notification costs, and lost business can end a 40-person company.

Ransomware is the highest-cost attack type. According to Coalition’s 2026 Cyber Claims Report, which analyzed claims across Coalition’s policyholders throughout 2025, initial ransom demands surged 47% year-over-year, with ransomware generating an average loss of US$269,000 per claim. The good news: 86% of businesses that experienced ransomware refused to pay — a record high that Coalition attributes to better backup hygiene and incident response planning among insured organizations.

Business email compromise and funds transfer fraud, while lower per-incident than ransomware, account for 58% of cyber claims by volume. These attacks — an attacker intercepting a payment instruction, or an employee wiring funds to a fraudulent account — frequently result in losses that standard commercial crime policies do not cover.

The Canadian Centre for Cyber Security projects ransomware will remain the leading threat to Canadian critical infrastructure through 2026, according to its National Cyber Threat Assessment. Canada’s cyber insurance market reflects this: the Insurance Bureau of Canada has warned that most Canadian SMEs remain both highly exposed and significantly underinsured, even as the overall market stabilizes.

The Five Controls Insurers Now Require

Application questionnaires across major Canadian cyber carriers have converged on a set of five non-negotiable controls. These are binary — missing any one of them will either result in a declined application, exclusion of ransomware coverage, or a substantial surcharge that eliminates the rate savings available to better-controlled peers.

1. Multi-Factor Authentication — Everywhere That Matters

MFA is the single most common reason a Canadian SMB’s cyber insurance application is declined or its claim is denied. The requirement is not "MFA is available" — it is "MFA is enforced on email, VPN, remote access, and every admin account, with no exceptions."

The City of Hamilton’s well-publicized cyber incident illustrates the risk precisely: Hamilton’s insurer denied the city’s cyber insurance claim after investigators determined that MFA was not fully implemented on the account the attacker exploited at the time of the incident. The city reportedly faced losses in excess of CA$18 million. The lesson Canadian SMBs take from Hamilton is not abstract — it is that "we had MFA deployed but not enforced on that account" is not a defence that results in a paid claim.

Practically, this means Microsoft 365 Conditional Access policies that block authentication without MFA; no bypass rules for service accounts; no "remembered device" exceptions for remote desktop or VPN access; and admin accounts that use a separate identity with Privileged Identity Management or equivalent just-in-time elevation.

2. Endpoint Detection and Response on Every Device

Signature-based antivirus — the traditional endpoint security tool that checks files against a known-bad database — does not satisfy 2026 underwriting requirements. Insurers require EDR (Endpoint Detection and Response) or XDR (Extended Detection and Response) deployed on 100% of managed endpoints, including servers.

The reason is straightforward: modern ransomware operators use living-off-the-land techniques — legitimate Windows tools like PowerShell, WMI, and PsExec — that signature antivirus cannot detect. EDR solutions identify anomalous behaviour patterns rather than known malicious files, catching attackers during the reconnaissance and lateral movement phases before they deploy the ransomware payload.

Carriers want to see EDR deployed by a managed security provider with 24/7 monitoring — not just the software installed and set to alerting mode with no one watching the dashboard. This connects directly to the Managed Detection and Response (MDR) market: an MDR contract satisfies the EDR coverage requirement while also providing the monitoring response that makes the coverage meaningful.

3. Immutable or Offline Backups with a Tested Restore

Backups are the most heavily weighted control in an underwriting assessment because they are the single largest determinant of ransomware loss size. A business with clean, restorable backups has a ransomware incident with a defined remediation cost. A business without them has an existential event.

Insurers now require that backups meet two conditions. First, they must be immutable or air-gapped — meaning ransomware cannot encrypt or delete them. A cloud backup that is accessible from the same credentials as the primary environment is not immutable in the insurer’s definition; it is a connected target. Microsoft Azure Blob Storage with immutability policies, Veeam immutable backups, or physically offline tape satisfy this requirement; a Dropbox backup connected to the network does not.

Second, the backup must have been tested within the last 90 days. "Tested" means a restore was actually executed and validated — not that the backup job completed without errors. Underwriters increasingly ask for restore test logs as part of the application. An untested backup is treated like no backup at all, because the probability of a backup that has never been restored actually being restorable under incident conditions is significantly lower than an insurer is willing to assume.

4. A Written Incident Response Plan — and a Tabletop Exercise

An incident response plan that lives as a document no one has read is not worth much in a crisis. Insurers have learned this from claims: the businesses that contain incidents quickly are the ones whose teams know what to do in the first two hours — who to call, how to isolate systems, how to preserve evidence, what the notification timeline to the OPC requires under PIPEDA, and who has authority to authorize legal and forensic spend.

The underwriting requirement is a written IR plan with named roles and a tabletop exercise conducted within the current year. A tabletop is a facilitated walk-through of a simulated incident — typically ransomware or BEC — where the team practices decision-making against the plan. Carriers know that organizations that have rehearsed their response contain incidents faster and incur lower losses, which is why they price coverage accordingly.

The plan must include a section on PIPEDA breach notification obligations: specifically, that the organization has assessed real risk of significant harm and made the determination to notify the Office of the Privacy Commissioner and affected individuals, with the 72-hour notification window to the OPC as the operative timeline after that determination.

5. Security Awareness Training — Documented and Quarterly

Phishing remains the entry point for the majority of ransomware and BEC incidents. Insurers require documented security awareness training for all employees, conducted at minimum quarterly, with records showing completion. Annual training is no longer sufficient at most carriers.

The training component that matters most to underwriters is phishing simulation — regularly sending fake phishing emails to employees and tracking click rates. Organizations with measurable, improving phishing click rates get better treatment in underwriting than organizations with the same training frequency but no measurement. The data point insurers are looking for is evidence that the training is changing behaviour, not just checking a compliance box.

What Claim Denials Actually Look Like

Understanding why claims are denied is the most direct way to understand what coverage actually requires. The five most common denial reasons across Canadian cyber claims in 2026 are:

  • Misrepresentation on the application — the security controls described on the application did not actually exist at the time of the incident. MFA was stated as "enforced" but bypass rules existed. Backups were stated as "immutable" but were accessible with the same admin credentials.
  • Failure to maintain stated controls — controls were present at the time of application but drifted before the incident. An employee’s laptop was removed from the EDR management console. A VPN account was added without MFA because the setup felt urgent.
  • Missing forensic evidence — the organization could not produce logs or records sufficient to substantiate the claimed loss. Insurers need to verify the scope of compromise; without logs, they cannot.
  • Late notification — the incident was reported to the insurer outside the policy’s notification window, often 72 hours from the time the organization became aware of a potential claim. Many SMBs do not know this clock starts when they suspect an incident, not when they confirm one.
  • Excluded loss types — the loss fell under a standard exclusion: an unpatched vulnerability that was publicly known for more than 30 days before exploitation, or a ransom payment to a sanctioned entity.

The Hamilton example sits squarely in the first category. The controls were stated on the application in a way that turned out not to reflect the actual configuration at incident time. That gap — between the application and operational reality — is where most claim disputes originate.

The Practical Checklist Before You Apply

Before requesting cyber insurance quotes or renewing an existing policy, a Canadian SMB should be able to answer yes to each of the following with documentation to support the answer:

ControlWhat "yes" requires
MFA enforced on emailConditional Access or equivalent blocking auth without MFA; zero bypass rules
MFA enforced on VPN / remote accessAll remote access methods require MFA; no legacy auth protocols allowed
MFA enforced on all admin accountsAdmin identities separate from daily-use accounts; MFA on every one
EDR on 100% of managed endpointsEDR software deployed and monitored; not AV; not "deployed on most"
Immutable backupsBackups cannot be deleted or encrypted from the production environment
Backup restore tested in last 90 daysA restore was executed and the result validated; logs available
Written IR plan with named rolesDocument exists; 72-hour PIPEDA notification window addressed
Tabletop exercise in the last 12 monthsFacilitated walk-through completed; participants documented
Security awareness training — quarterlyCompletion records for all employees; phishing simulation results

If any row is "no," close it before applying. A declined application or a claim denial after a major incident is a significantly worse outcome than the six to twelve weeks it takes to get the controls in place.

Coverage to Ask For — and Sub-Limits to Watch

Canadian cyber policies typically provide coverage across several categories. The ones most relevant to SMBs are:

Ransomware / cyber extortion. Covers ransom payments (where legally permissible) and the cost of recovery — forensic investigation, system restoration, business interruption. Verify that the policy does not exclude ransomware payments to entities on US OFAC or Canadian sanctions lists, which creates a coverage gap for any payment to a threat actor the government has designated.

Business interruption. Covers lost revenue during the period your systems are unavailable. This is frequently sub-limited at amounts lower than the first-party coverage maximum — watch for a $250,000 sub-limit on a $2M policy.

Data breach response. Covers forensic investigation, legal review, notification costs, credit monitoring for affected individuals, and public relations. This is where the PIPEDA notification obligation materializes as a claim cost.

Funds transfer fraud / social engineering. Covers losses from BEC attacks — an employee wiring funds to a fraudulent account based on a spoofed email. This is frequently sub-limited or requires a separate endorsement.

Regulatory defence and fines. Covers defence costs in an OPC investigation and, where insurable under applicable law, regulatory penalties. Note that some provinces limit the insurability of regulatory penalties; confirm with your broker.


Sources


Cyber insurance qualification and sound security posture are the same project — the controls insurers require are the same controls that reduce your probability of a breach in the first place. Cloud Forces helps Canadian SMBs close the gaps that stand between them and meaningful cyber coverage: MFA enforcement through Microsoft Entra ID, EDR deployment and 24/7 monitoring through our Managed Detection and Response service, immutable backup architecture, and incident response planning with tabletop facilitation. Explore our Cybersecurity services or contact us to begin with a cyber insurance readiness assessment against the five non-negotiable controls.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation