Guide

What cyber insurance asks BC small businesses in 2026

The questions on the 2026 form, what each one is really checking, and how to answer honestly.

Cyber-insurance applications used to be one page. Now they run to several, and the questions have teeth. If you renewed in the last year you probably noticed.

The change is not arbitrary. Insurers paid out a lot of claims on small businesses that had none of the basics in place, so they started asking. What follows is what actually appears on these forms, what each question is checking, and what a good answer looks like.

Why this matters more than the premium

There are two separate risks. The obvious one is cost: weak answers mean a higher premium, or no quote at all.

The less obvious one matters more. If you answer yes to something that turns out not to be true, a claim can be reduced or denied. Not because anyone is trying to trick you, but because the policy was priced on information that was wrong. Plenty of small businesses answer these forms from memory, and memory is generous.

So the useful goal is not to have perfect security. It is to know your real answers.

The questions that come up almost every time

Do you enforce multi-factor authentication?

This is the big one, and it is usually asked in parts: on email, on remote access, and on administrator accounts.

The word doing the work is enforce. Having MFA available is not the same as having it required. If three people turned it on voluntarily and nobody else did, the honest answer is no.

A good answer: MFA is required for all users on email and any remote access, with no standing exemptions.

Are backups offsite, and have you tested a restore?

Two questions in one. Most businesses have something that resembles a backup. Far fewer have tried restoring from it.

Insurers care because ransomware claims are enormously cheaper when a business can recover on its own. They also increasingly ask whether backups are separated from the main environment, because ransomware that reaches your backups is not a backup.

A good answer: Backups run daily, a copy lives offsite and is not reachable with everyday credentials, and a restore has been tested within the last few months.

A note on Microsoft 365 and Google Workspace: both keep the service running, and both have short retention windows for deleted items. Neither is a backup of your data in the sense an insurer means. This catches people out constantly.

What endpoint protection is running, and is it managed?

Again, the qualifier matters. Built-in antivirus on every machine, with nobody watching the alerts, is a different thing from managed endpoint protection where someone actually sees when something fires.

A good answer: A named endpoint protection product is deployed on all devices, centrally managed, and alerts go to someone whose job it is to look at them.

How quickly is access removed when someone leaves?

Offboarding is the question small businesses answer worst. The common reality is that accounts linger for weeks because deactivating them is nobody's task and everyone worries about losing files.

A good answer: Access is revoked the same day, using a written checklist, and it covers email, files, VPN, and any third-party systems.

Do you have a password manager, and are passwords reused?

The concern here is credential stuffing. Attackers take passwords from an unrelated breach and try them against your accounts. It works far more often than it should.

A good answer: A password manager is deployed to the whole team, and staff are not reusing personal passwords on work accounts.

Do you train staff on phishing?

Some insurers ask about frequency, some just want a yes. The honest small-business version is usually a short, occasional refresher rather than a formal programme, and that is generally acceptable if it actually happens.

Do you verify payment changes out of band?

This one shows up more each year, especially for firms that move client money. The scenario is an email that appears to be from a supplier or a client, asking to change banking details at the last minute.

A good answer: Any change to payment details is confirmed by phone using a number you already had, not a number in the email.

What to do before your next renewal

Work through the list above and write down your real answer to each one. Not the answer you would like to give. The real one.

Where the answer is no, most of these are small pieces of work. MFA enforcement, a password manager rollout, and a written offboarding checklist can usually all be done in a week or two. Backup testing takes an afternoon.

Then keep the document. Insurers ask essentially the same questions every year, and having the answers written down turns renewal into a form-filling exercise instead of a scramble.

The short version

  • MFA everywhere, enforced rather than available
  • Offsite backups you have actually restored from
  • Managed endpoint protection with someone watching alerts
  • Same-day offboarding, from a checklist
  • A password manager for the whole team
  • Out-of-band verification for payment changes

That list is not exotic. It is close to the minimum an insurer now expects, and it happens to be the same list that prevents most of what goes wrong in the first place.

If you would like a second pair of eyes on where you stand, our free IT and insurance-readiness check covers exactly this, and takes half an hour.

Related guides

Get your free check