Service desk: 778-321-2372 Existing clients: contact@brevitytech.ca
Guide

What cyber insurance asks BC small businesses in 2026

The questions on the 2026 form, what each one is really checking, and how to answer honestly.

Cyber-insurance applications used to be one page. Now they run to several, and the questions have teeth. If you renewed in the last year you probably noticed.

The change is not arbitrary. Insurers paid out a lot of claims on small businesses that had none of the basics in place, so they started asking. What follows is what appears on these forms, what each question is checking, and what a good answer looks like.

Why this matters more than the premium

There are two separate risks. The obvious one is cost: weak answers mean a higher premium, or no quote at all.

The less obvious one is worse. Answer yes to something that turns out not to be true and a claim can be reduced or denied. Not because anyone is trying to trick you, but because the policy was priced on information that was wrong. Plenty of small businesses fill these forms in from memory, and memory is generous.

Perfect security is not the goal here. Knowing your real answers is.

The questions that come up almost every time

Do you enforce multi-factor authentication?

The big one, usually asked in parts: on email, on remote access, and on administrator accounts.

The word doing the work is enforce. Having MFA available is not the same as having it required. If three people turned it on voluntarily and nobody else did, the honest answer is no.

A good answer: MFA is required for all users on email and any remote access, with no standing exemptions.

Are backups offsite, and have you tested a restore?

Two questions wearing one coat. Most businesses have something that resembles a backup. Far fewer have tried restoring from it.

Insurers care because ransomware claims cost them enormously less when a business can recover on its own. They also increasingly ask whether backups sit apart from the main environment, since ransomware that reaches your backups has not left you with backups.

A good answer: Backups run daily, a copy lives offsite and is not reachable with everyday credentials, and a restore has been tested within the last few months.

One trap worth naming. Microsoft 365 and Google Workspace both keep the service running, and both have short retention windows for deleted items. Neither is a backup in the sense an insurer means, and this catches people out constantly.

What endpoint protection is running, and is it managed?

Again the qualifier carries the weight. Built-in antivirus on every machine with nobody watching the alerts is a different animal from managed endpoint protection where someone sees what fires.

A good answer: A named endpoint protection product is deployed on all devices, centrally managed, and alerts go to someone whose job it is to look at them.

How quickly is access removed when someone leaves?

Small businesses answer this one worst. The common reality is that accounts linger for weeks because deactivating them is nobody's task and everyone worries about losing files.

A good answer: Access is revoked the same day, using a written checklist, covering email, files, VPN, and any third-party systems.

Do you have a password manager, and are passwords reused?

The concern is credential stuffing. Attackers take passwords from an unrelated breach and try them against your accounts, and it works far more often than it should. What the insurer wants to hear is that a password manager is deployed across the team and that nobody is reusing personal passwords on work accounts.

Do you train staff on phishing?

Some insurers ask about frequency, some just want a yes. The honest small-business version is usually a short refresher a couple of times a year rather than a formal programme, and that generally passes if it genuinely happens.

Do you verify payment changes out of band?

This shows up more each year, especially for firms that move client money. The scenario is an email that appears to be from a supplier or a client asking to change banking details at the last minute.

A good answer: Any change to payment details is confirmed by phone, using a number you already had rather than a number in the email.

Before your next renewal

Work through the list above and write down your real answer to each one. Not the answer you would like to give. The real one.

Where the answer is no, most of these are small pieces of work. MFA enforcement, a password manager rollout and a written offboarding checklist can usually all be done inside a fortnight. Backup testing takes an afternoon.

Then keep the document. Insurers ask much the same questions every year, so having the answers written down turns renewal into form-filling rather than a scramble.

None of it is exotic. It is close to the minimum an insurer now expects, and it happens to be the same list that prevents most of what goes wrong in the first place.

Not sure where you stand against the list? The free insurance-readiness review walks it with you in half an hour.

Related guides

Request a readiness review