The 10 questions your cyber insurer, your biggest clients, and your auditors are asking in 2026. Pulled from real Canadian renewal questionnaires and the Canadian Centre for Cyber Security's baseline controls.
Cyber insurance renewal in 2026 doesn't look like it did in 2022. Coalition's 2026 Cyber Claims Report calls it the "Year of Technical Validation": insurers no longer ask "do you have these controls?" They ask "can you prove these controls were enforced at the time of the incident?"
Chubb, Beazley, and Travelers 2026 policies now include Condition Precedent clauses — coverage is void if a forensic audit shows controls lapsed. At the same time, your enterprise and public-sector clients are asking the same questions through their vendor-risk questionnaires, and Canada's federal cyber agency has formalised a baseline of controls your organization should meet.
Use this checklist to prepare for every conversation in that list — before you get blindsided on renewal day.
What they'll ask
"Is MFA enforced on all email, remote access, admin accounts, cloud backup consoles, and financial systems — including for service accounts and legacy protocols?"
What "good" looks like
MFA is enforced by policy, not left to users to enable. Microsoft 365: Security Defaults or a Conditional Access policy requiring MFA for all users, with break-glass accounts excluded and monitored. Legacy authentication (SMTP AUTH, POP, IMAP) is blocked. Phishing-resistant methods (passkeys, FIDO2, Microsoft Authenticator number-matching) are preferred over SMS.
What they'll ask
"Do all endpoints, including servers and remote laptops, run an EDR or XDR product with 24/7 monitoring and automated response?"
What "good" looks like
A managed EDR (Microsoft Defender for Business, SentinelOne, CrowdStrike, Huntress) deployed to 100% of endpoints and servers, with a SOC or MSP actively investigating alerts. Signature-based antivirus alone (Norton, McAfee, built-in Defender without plan 1/2) no longer qualifies on most renewal forms.
What they'll ask
"Does your sending domain publish SPF, DKIM, and DMARC records, and is DMARC at least p=quarantine?"
What "good" looks like
All three records published and passing. DMARC is moving from p=none to at least p=quarantine with aggregate reporting (RUA) so you can see who spoofs your domain. As of May 5, 2025, Microsoft began rejecting mail from non-compliant senders of 5,000+ messages/day to Outlook, Hotmail, and Live recipients — Google and Yahoo did the same in February 2024.
What they'll ask
"Is DNS-layer filtering deployed on internal networks and remote endpoints to block connections to known-malicious domains?"
What "good" looks like
A cloud DNS filter (Cisco Umbrella, DNSFilter, Cloudflare Gateway) that covers office networks AND remote users via endpoint agent. Category policies block newly-registered domains, C2 infrastructure, and known phishing hosts. Log retention supports post-incident review.
What they'll ask
"Are backups automated, stored immutably offsite, and have you performed a documented restore test in the last 12 months?"
What "good" looks like
A 3-2-1 architecture (3 copies, 2 media, 1 offsite) with at least one copy that is immutable — can't be deleted or encrypted by an attacker with domain admin. Microsoft 365 backups (Dropsuite, Afi, Keepit) for mailboxes, SharePoint, OneDrive, and Teams are separately covered. Restore tests are logged — screenshots, dates, file counts.
What they'll ask
"Are passwords generated and stored in a business-grade password manager, with sharing governance and offboarding workflows?"
What "good" looks like
1Password Business, Bitwarden Enterprise, Keeper, or equivalent, with staff trained on capture-and-save. Shared vaults replace shared spreadsheets. Offboarding revokes vault access in minutes, not weeks.
What they'll ask
"Do you have a signed IT/AUP on file for every active employee and contractor, including AI-tool and personal-device use?"
What "good" looks like
A short, plain-English policy signed on hire and reviewed annually. In 2026 the policy needs to cover generative AI use (see our AI Policy Toolkit), personal-device access, and social-engineering reporting. Signatures stored with HR records, not loose PDFs.
What they'll ask
"Do all staff complete security awareness training at hire and at least annually, with simulated phishing results tracked?"
What "good" looks like
A platform-based programme (KnowBe4, Hoxhunt, Microsoft Defender Attack Simulator, Proofpoint) with completion reports. Simulated phishing monthly or quarterly. Staff who fail get remediation, not shame. Records retained for at least 2 years.
What they'll ask
"Are privileged accounts separated from daily-use accounts, with just-in-time access where possible and MFA on every admin action?"
What "good" looks like
Every admin has a named privileged account separate from their daily account. Shared "administrator" or "office@" admin logins are retired. Cloud admin roles use Privileged Identity Management (PIM) or equivalent just-in-time elevation. Break-glass accounts are documented, MFA-enforced, and alerted on use.
What they'll ask
"Do you have a documented incident response plan, and when did you last test it?"
What "good" looks like
A plan that fits on 4–6 pages, names real people and real phone numbers, covers ransomware / email compromise / M365 outage / vendor outage, and lists your insurer's hotline as step one. Tested via tabletop exercise at least annually, with action items logged and closed.
Score each of the 10 above: 2 points if you can prove it with evidence dated before today, 1 point if you can describe it but not prove it, 0 points if it's a gap.
DVG Systems runs a free 45-minute Cyber Insurance Readiness Review for Northern Ontario businesses. We walk the 10 questions with you, flag the evidence gaps, and hand back a one-page summary you can share with your broker.