A cyber insurance application looks like a checklist. It is not. It is a factual declaration that gets read twice: once when you buy the policy, and once by somebody deciding whether to pay a claim.
That second reading is the one worth writing for.
Below are the questions that appear on almost every small business application in 2026, what each one is actually testing, and the answer patterns that fail. None of this is complicated. Most of it is a twenty minute conversation that nobody has until the form arrives.
"Do you enforce multi-factor authentication on all remote access and email?"
The word doing the work is all. Not most, not where practical.
Almost every small business we look at has multi-factor authentication switched on for the bulk of accounts and one exception somewhere. It is usually an owner who found it irritating, a shared mailbox that several people sign into, or a service account nobody wants to touch because something might break.
One exception makes the honest answer no.
The reason underwriters care is straightforward. The overwhelming majority of small business compromise starts with a valid credential rather than an exploit. Multi-factor authentication is the single control that breaks that chain, which is why it has moved from a discount to a precondition. Increasingly, an application that answers no here does not get a loaded premium. It gets declined.
What passes: enforced by policy for every account, including administrators and shared mailboxes, with conditional access blocking anything that bypasses it, and a short list of documented exceptions if any exist.
"Are backups stored offline, immutable, or in a separate account?"
This is not asking whether you have backups. It is asking whether ransomware can reach them.
The failure here is almost always the same. A business has cloud file sync and believes it is backed up. Sync is not backup. When files are encrypted, the sync client does exactly what it was built to do and faithfully replicates the encryption to every device and to the cloud copy.
The second failure is a backup that lives inside the same identity as everything else. If one compromised administrator account can delete both your data and your backups, you have one copy, not two.
What passes: backups held in a separate security boundary, either offline, immutable, or in an account with its own credentials that the production administrators cannot reach.
"When was your last tested restore?"
The quiet one. Almost nobody has a date.
A backup that has never been restored is a hope with a schedule attached. Backup jobs report success while silently skipping a folder. Retention gets shortened by a setting nobody reviewed. Restores turn out to take four days when the business assumed four hours.
You cannot find any of that out except by doing it.
What passes: a date, what was restored, and how long it took. If you cannot produce those three facts, that is the finding, and it is worth acting on regardless of the insurance question.
"How quickly is access revoked when an employee leaves?"
This tests whether you have a procedure or a habit.
Offboarding is the most commonly failed control at small scale, for structural reasons rather than careless ones. Nobody is waiting on it. The departure has already happened, and a late revocation breaks nothing anyone can see.
So accounts stay live. Weeks, often months. The risk is rarely the former employee, who has moved on. The risk is a dormant credential nobody is watching, protected by a password that was reused on a service that has since been breached.
What passes: a written checklist, a named owner, and a stated timeframe, usually same day. If the answer depends on who remembered to tell IT, it is a habit.
"Do you run managed endpoint protection?"
The word here is managed. Built-in antivirus on every machine is a reasonable baseline in 2026, and it is not what the question is asking.
Managed means somebody receives the alert. An endpoint tool that detects something at two in the morning and reports it into a console nobody opens has done half a job. Underwriters have learned to ask this distinction because the difference in claims outcomes is large.
What passes: a managed detection product deployed to every device including personal machines that touch company data, with alerts going somewhere a human reviews.
"Do you have email authentication configured?"
SPF, DKIM and DMARC. This one is asked less often at the smallest end and is spreading quickly.
It matters because the most expensive small business losses are usually not intrusions at all. They are fraudulent invoices and payment redirections, which work by impersonating a domain that never told the world how to detect impersonation. Email authentication is how you make that harder, and it costs nothing but an afternoon of DNS work.
What passes: all three records published, DMARC moved past monitoring into a policy that actually rejects, and someone reading the reports.
"Do you provide security awareness training?"
The honest answer for most small businesses is no, and the honest reason is that the available training is tedious and nobody finishes it.
Underwriters are not looking for a certificate. They are looking for evidence that staff have been told what an invoice fraud attempt looks like and what to do when they see one.
Something regular, short and documented will clear the bar. A quarterly fifteen minute conversation with a written record beats an annual video nobody watched.
"Do you have an incident response plan?"
For a small business this does not need to be a document with a cover page. It needs to answer four things: who gets called first, who can authorise taking systems offline, where the contact list lives if email is down, and who notifies whom.
That last part depends on which law reaches you, and it is widely misunderstood. BC's PIPA requires reasonable security arrangements but does not currently require you to report a breach or keep a breach record. The BC Privacy Commissioner recommends voluntary reporting and has asked government to make it mandatory. The mandatory regime people are usually thinking of is FIPPA, which covers public bodies rather than private businesses.
PIPEDA is different. Where it applies, which is federally regulated businesses and personal information crossing provincial or national borders, breaches posing a real risk of significant harm must be reported to the Privacy Commissioner of Canada and to affected individuals, and a record of every breach must be kept for two years.
Your professional body, your insurer and your client contracts may require more than either statute. Keep a record regardless, because it is the only way to reconstruct what happened.
One page, printed, with phone numbers on it, and somebody who has read it.
The gap that actually decides claims
Every question above has two versions of yes. The first is "yes, we do that." The second is "yes, and here is the evidence, dated."
The gap between them is not a paperwork problem. Insurers can and do deny claims for material misrepresentation on an application, and the application is the document that gets pulled first. Nobody is trying to catch you out. They are checking whether what you declared was accurate, and "we thought it was on" is not a defence.
This is also the part that takes the longest. Turning multi-factor authentication on across a small business is an afternoon. Being able to produce a report showing it was enforced on every account on a specific date is a different task, and it is the one people start too late.
What to do about it
Start eight weeks before renewal, not two. Most of the controls take days. The evidence takes weeks, mostly because it involves finding out that something you assumed was true is not.
Answer the form honestly even where the answer is embarrassing. A no with a remediation date attached is a normal conversation with an underwriter. A yes that turns out to be a no is a different conversation entirely, held at the worst possible moment.
And do the restore test this week regardless of when your renewal is. Pick a file from three months ago, ask for it back, and time it. It is five minutes and it is the single most useful thing on this page.
If you want a second pair of eyes on any of this, our free insurance-readiness review covers the same ground: what is solid, what is risky, and what an underwriter would make of your current answers. You keep the findings either way.
Related reading: what cyber insurance asks BC small businesses in 2026, the offboarding checklist most small businesses skip, and our security and insurance readiness service.
Related guides
- The IT checklist accounting firms should finish before tax seasonThe work to finish in the quiet months, so nothing breaks between February and April 30.
- Payment redirection fraud, and why construction gets hit firstHow the scam works on a progress draw, the controls that stop it, and the first hour if it lands.
- Windows 10, a year after support ended: the October decisionWhat year two of Extended Security Updates costs, and how to decide machine by machine.