Security and cyber-insurance readiness
The protections that actually matter for a small team, plus the paperwork your insurer wants.
Small business security has a credibility problem. Half the industry sells fear, and the other half sells enterprise tooling nobody with twelve staff can operate. Neither is useful.
What actually protects a small team is a short list of controls, set up properly and kept running. That same list is what insurers now ask about, which is convenient, because doing it once solves both problems.
The controls that carry the weight
- Multi-factor authentication on every account, no exceptions
- Managed endpoint protection on every device
- Encrypted, tested, offsite backups
- A password manager the team will actually use
- Same-day offboarding when someone leaves
- Documented, so you can prove it
Why insurers changed the questions
Cyber-insurance applications used to be short. They are not anymore. Insurers now ask directly whether you enforce MFA, whether backups are offsite and tested, what endpoint protection you run, and how quickly access is revoked when staff leave. The backup question trips people up most, because platform retention is not what an insurer means by a backup. That is covered in Microsoft 365 is not a backup.
Answering those questions wrong, or guessing, is a problem in two directions. It can affect your premium, and it can affect whether a claim gets paid. Most small businesses we meet genuinely do not know their own answers.
What we do about it
We put the controls in place, then write down what is running and where. When the renewal form arrives, it becomes an hour of form-filling rather than a week of guessing. If something on the form is not in place yet, you find out from us rather than from an underwriter.
Privacy obligations, handled properly
If you hold patient records or client files, you are accountable under Canada's privacy laws: PIPEDA federally and British Columbia's PIPA provincially. That obligation is yours, not ours, but almost all of it rests on the IT layer we run for you, so we build that layer to support it.
In practice that means the safeguards these laws expect for sensitive information: access limited to who needs it, encryption, multi-factor sign-in, audit logs, and secure, tested backups. We keep your data in Canada wherever your systems and licensing allow, which matters most for health records. And if a breach ever happens, we have a plan that matches what actually applies to you. BC's PIPA requires reasonable security arrangements but does not currently mandate breach notification. PIPEDA does where it applies, along with a two-year record of every breach.
We are not lawyers, and we do not certify you as compliant. What we do is put the technical controls and documentation in place so that meeting your obligations, and proving you met them, is straightforward. For clinics that means BC PIPA and your College's expectations; for law firms, client confidentiality and the Law Society of BC's cloud due-diligence guidance.
The human parts
The most common way a small business loses money is not a sophisticated intrusion. It is someone paying a fraudulent invoice, or reusing a password that turned up in a breach. So we set up a password manager, turn on the mail rules that flag lookalike domains, and help you put a verification step in front of payment changes.
Where we stop
We are not a penetration-testing shop and we do not run SOC 2 audits. When you need that depth, we bring in specialists we have vetted and we coordinate the work, so you are not managing two vendors who blame each other. Being clear about this is deliberate. Plenty of providers will quietly say yes to everything.
What this costs
Security setup is included from $125 per user per month. Fully managed security and cyber-insurance readiness start on the Complete plan at $175. See what is in each plan.
Related services
Let’s make your tech boring. In the best way.
Get a free 30-minute insurance-readiness review. We’ll tell you what’s solid, what’s risky, and what we’d automate first. No pitch. No obligation.