TL;DR: Direct answer: Canadian cyber liability underwriters (such as Lloyd's, Chubb, Travelers, and Intact) now treat MFA on all administrative access, immutable offsite backups, endpoint detection (EDR), and annual independent penetration testing as mandatory baseline requirements. Answering affirmatively without verified proof can void coverage entirely in the event of a breach.
The Hardening Canadian Cyber Insurance Market
Five years ago, securing a \$5M CAD cyber liability policy involved a straightforward, 2-page questionnaire asking about basic firewall setups and antivirus software. Today, Canadian insurers are paying out unprecedented ransomware and business email compromise (BEC) claims, leading to radical underwriting changes across Ontario, Alberta, and nationally.
Underwriters now operate with dedicated forensic technical risk engineers. When evaluating applications, they no longer take policy claims at face value. They run automated external perimeter reconnaissance, scan for exposed remote management services (RDP, SSH, Telnet), and evaluate your answers against strict contractual warranty standards.
The Four Fatal Underwriting Questions
In modern Canadian cyber underwriting applications, four questions carry automatic decline weight. A "No" on any of these four items frequently leads to immediate policy rejection or sub-limits that slash coverage for ransomware events:
- Multi-Factor Authentication (MFA): Is MFA strictly enforced for 100% of employees on email, cloud consoles (AWS, Azure, GCP), remote access (VPNs, bastion hosts), and privileged identity providers? (SMS-based verification is increasingly rejected in favour of FIDO2 WebAuthn or authenticator apps).
- Immutable Backups: Are critical data backups air-gapped or cryptographically locked with immutable object retention policies that prevent an adversary with Domain Admin credentials from deleting backup archives?
- Endpoint Detection and Response (EDR): Is a managed EDR agent (such as CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint) deployed across 100% of corporate workstations and production servers with 24/7 telemetry monitoring?
- Independent Penetration Testing: Does your organization commission at least one annual third-party penetration test executed by an accredited firm, covering internet-facing perimeter assets and web applications?
Warranty Statements: Why Guessing Voids Your Policy
The single greatest hazard for Canadian business executives completing cyber insurance renewals is treating the questionnaire as an aspirational document. Many executives answer "Yes" to questions regarding MFA enforcement or privileged access management because they intend to implement those controls in the coming quarter.
Legal Precedent: Cyber insurance applications are legally categorized as conditions precedent to coverage or warranty representations. When a ransomware incident occurs, forensic incident responders examine system logs. If they discover that MFA was not enforced on the VPN account that served as the initial breach vector, the insurer can lawfully deny the entire claim on grounds of material misrepresentation.
If a control is partially implemented, declare it honestly: "MFA is currently deployed across 95% of corporate users; production cloud migration is scheduled for completion within 45 days." This preserves policy validity and enables underwriters to issue conditional riders rather than outright claim repudiations.
Ransomware Supplemental Questionnaires Explained
Canadian brokers now routinely pair cyber applications with a 4-page "Ransomware Supplemental." This document specifically examines lateral movement defenses and Active Directory attack surfaces.
Underwriters want to know whether you have tested your internal network for Kerberoasting, LLMNR/NBT-NS broadcast poisoning, SMB signing misconfigurations, and excessive domain administrator delegation. Executing an internal network penetration test simulates these exact attacker tactics, allowing you to provide affirmative, defensible answers backed by third-party technical documentation.
Frequently Asked Questions
Almost universally, no. Insurers explicitly mandate an independent, third-party assessment to prevent conflicts of interest. Internal scans are classified as vulnerability management, not independent penetration testing.
Having critical findings is expected. What matters to underwriters is that those findings are tracked in a ticketing system, remediated promptly, and verified closed through a formal retest. An attestation letter confirming complete remediation is proof of an active, mature security program.
Yes. Every engagement includes an executive Letter of Attestation and assessment summary specifically formatted to satisfy commercial insurance underwriters, cyber risk brokers, and enterprise audit committees.
Approaching an upcoming cyber insurance renewal?
Ensure your technical controls and penetration testing documentation withstand rigorous underwriting scrutiny before you submit your application.