A DVG Systems Guide  ·  Edition 2026

The Cyber Insurance Readiness Checklist

The 10 questions your cyber insurer, your biggest clients, and your auditors are asking in 2026. Pulled from real Canadian renewal questionnaires and the Canadian Centre for Cyber Security's baseline controls.

www.dvgsystems.com   ·   (807) 700-0061
v2026.04

Why a checklist — and why now

Cyber insurance renewal in 2026 doesn't look like it did in 2022. Coalition's 2026 Cyber Claims Report calls it the "Year of Technical Validation": insurers no longer ask "do you have these controls?" They ask "can you prove these controls were enforced at the time of the incident?"

Chubb, Beazley, and Travelers 2026 policies now include Condition Precedent clauses — coverage is void if a forensic audit shows controls lapsed. At the same time, your enterprise and public-sector clients are asking the same questions through their vendor-risk questionnaires, and Canada's federal cyber agency has formalised a baseline of controls your organization should meet.

Use this checklist to prepare for every conversation in that list — before you get blindsided on renewal day.

1Multi-Factor Authentication on every account that touches data

What they'll ask

"Is MFA enforced on all email, remote access, admin accounts, cloud backup consoles, and financial systems — including for service accounts and legacy protocols?"

What "good" looks like

MFA is enforced by policy, not left to users to enable. Microsoft 365: Security Defaults or a Conditional Access policy requiring MFA for all users, with break-glass accounts excluded and monitored. Legacy authentication (SMTP AUTH, POP, IMAP) is blocked. Phishing-resistant methods (passkeys, FIDO2, Microsoft Authenticator number-matching) are preferred over SMS.

How to prove it: A Conditional Access policy export dated well before the incident. "We turned on MFA last week" won't pass a forensic audit.

2Endpoint Detection & Response — not just antivirus

What they'll ask

"Do all endpoints, including servers and remote laptops, run an EDR or XDR product with 24/7 monitoring and automated response?"

What "good" looks like

A managed EDR (Microsoft Defender for Business, SentinelOne, CrowdStrike, Huntress) deployed to 100% of endpoints and servers, with a SOC or MSP actively investigating alerts. Signature-based antivirus alone (Norton, McAfee, built-in Defender without plan 1/2) no longer qualifies on most renewal forms.

Common gap: One uncovered server or one remote laptop outside the console is enough to fail the question. Run a device-reconciliation report before filling in any questionnaire.

3Email authentication — SPF, DKIM, and DMARC

What they'll ask

"Does your sending domain publish SPF, DKIM, and DMARC records, and is DMARC at least p=quarantine?"

What "good" looks like

All three records published and passing. DMARC is moving from p=none to at least p=quarantine with aggregate reporting (RUA) so you can see who spoofs your domain. As of May 5, 2025, Microsoft began rejecting mail from non-compliant senders of 5,000+ messages/day to Outlook, Hotmail, and Live recipients — Google and Yahoo did the same in February 2024.

If you're below the 5,000/day threshold: you're still being judged. Client spam filters, Microsoft's reputation engine, and Gmail's "Show Details" expose your posture to every recipient. This is no longer a big-sender-only issue.

4DNS filtering on every network your staff touches

What they'll ask

"Is DNS-layer filtering deployed on internal networks and remote endpoints to block connections to known-malicious domains?"

What "good" looks like

A cloud DNS filter (Cisco Umbrella, DNSFilter, Cloudflare Gateway) that covers office networks AND remote users via endpoint agent. Category policies block newly-registered domains, C2 infrastructure, and known phishing hosts. Log retention supports post-incident review.

5Backups that are automated, immutable, and tested

What they'll ask

"Are backups automated, stored immutably offsite, and have you performed a documented restore test in the last 12 months?"

What "good" looks like

A 3-2-1 architecture (3 copies, 2 media, 1 offsite) with at least one copy that is immutable — can't be deleted or encrypted by an attacker with domain admin. Microsoft 365 backups (Dropsuite, Afi, Keepit) for mailboxes, SharePoint, OneDrive, and Teams are separately covered. Restore tests are logged — screenshots, dates, file counts.

The single most common claim denial: backups that existed but weren't recoverable. Untested is unproven.

6A password manager for the whole team

What they'll ask

"Are passwords generated and stored in a business-grade password manager, with sharing governance and offboarding workflows?"

What "good" looks like

1Password Business, Bitwarden Enterprise, Keeper, or equivalent, with staff trained on capture-and-save. Shared vaults replace shared spreadsheets. Offboarding revokes vault access in minutes, not weeks.

7Acceptable Use Policy signed by every employee

What they'll ask

"Do you have a signed IT/AUP on file for every active employee and contractor, including AI-tool and personal-device use?"

What "good" looks like

A short, plain-English policy signed on hire and reviewed annually. In 2026 the policy needs to cover generative AI use (see our AI Policy Toolkit), personal-device access, and social-engineering reporting. Signatures stored with HR records, not loose PDFs.

8Security awareness training — at least annual, documented

What they'll ask

"Do all staff complete security awareness training at hire and at least annually, with simulated phishing results tracked?"

What "good" looks like

A platform-based programme (KnowBe4, Hoxhunt, Microsoft Defender Attack Simulator, Proofpoint) with completion reports. Simulated phishing monthly or quarterly. Staff who fail get remediation, not shame. Records retained for at least 2 years.

9Privileged access — no shared admin accounts

What they'll ask

"Are privileged accounts separated from daily-use accounts, with just-in-time access where possible and MFA on every admin action?"

What "good" looks like

Every admin has a named privileged account separate from their daily account. Shared "administrator" or "office@" admin logins are retired. Cloud admin roles use Privileged Identity Management (PIM) or equivalent just-in-time elevation. Break-glass accounts are documented, MFA-enforced, and alerted on use.

10Incident response plan — written AND tested

What they'll ask

"Do you have a documented incident response plan, and when did you last test it?"

What "good" looks like

A plan that fits on 4–6 pages, names real people and real phone numbers, covers ransomware / email compromise / M365 outage / vendor outage, and lists your insurer's hotline as step one. Tested via tabletop exercise at least annually, with action items logged and closed.

Practical test: can your office manager reach your cyber insurer at 3 AM on a Saturday without opening the filing cabinet? If not, the plan isn't deployed yet.

The 15-minute self-scoring exercise

Score each of the 10 above: 2 points if you can prove it with evidence dated before today, 1 point if you can describe it but not prove it, 0 points if it's a gap.

Sources
  1. Coalition, 2026 Cyber Claims Report — coalitioninc.com/claims-report/2026
  2. Microsoft, "Strengthening the Email Ecosystem: Outlook's New Requirements for High-Volume Senders" — techcommunity.microsoft.com
  3. Canadian Centre for Cyber Security, "Baseline cyber security controls for small and medium organizations" — cyber.gc.ca
  4. Canadian Centre for Cyber Security, ITSAP.10.035 "Top measures to enhance cyber security for small and medium organizations" — cyber.gc.ca
  5. Beazley Cyber Insurance Application (sub-$20M) — beazley.com

Want a second pair of eyes before renewal?

DVG Systems runs a free 45-minute Cyber Insurance Readiness Review for Northern Ontario businesses. We walk the 10 questions with you, flag the evidence gaps, and hand back a one-page summary you can share with your broker.

Talk to us
(807) 700-0061
Email
solutions@dvgsystems.com
Book online
www.dvgsystems.com/contact