October 6, 2026
Paris Evangelou

Your Cyber Insurance Renewal Is Coming Up. Is Your IT Ready for the Questionnaire?

The riskiest word on your cyber insurance questionnaire might be "Yes."

The renewal usually starts with an email from your broker and a PDF to return by month-end. Somebody forwards it to whoever handles IT, which in a lot of Montreal offices means the office manager, the controller, or the one person who knows where the router is.

Question 14 asks whether multi-factor authentication is required for remote access and administrative accounts. MFA is definitely on for Microsoft 365, because everyone grumbled about the Authenticator app for a week when it went live. So the box gets a confident tick.

That tick has a history. In 2022, Travelers asked a U.S. federal court to rescind a cyber policy issued to International Control Services (ICS), whose application had answered Yes to MFA for email, remote access and administrative access. After a ransomware attack, Travelers alleged it found MFA protecting only the firewall. The two sides then agreed to void the policy, so no court ever ruled on whether ICS had misrepresented anything. It's a U.S. case with no bearing on Quebec law. It does show what can happen when the form and the environment behind it drift apart.

Your cyber insurance questionnaire is a terrible place to discover what your IT actually looks like. The rest of this article is about finding out before the form arrives.

Why Insurers Ask IT Questions

An insurer pricing a cyber policy can't send someone to walk through your server room, so the questionnaire does the walking. It's trying to establish whether a handful of basic controls are actually in place, such as MFA, endpoint protection, backups and limits on administrative access.

Your answers also become part of what the insurer relies on when it issues the policy, which is why this article treats the questionnaire as an IT exercise. (Coverage and pricing belong to your broker. None of this is insurance or legal advice.)

MFA: Does It Protect the Accounts That Matter?

The form says: "Is MFA enforced for all remote access, email, and privileged or administrative accounts?"

What they're really asking: If someone buys one of your employees' passwords on a forum tonight, what stops them from logging in tomorrow?

The trap is the word "all." Plenty of businesses have MFA on their Microsoft 365 mailboxes and nothing on the VPN, the remote desktop gateway the accountant uses at tax time, the firewall's admin page or the backup console. Emergency "break-glass" admin accounts are often excluded on purpose and then forgotten. Some forms may also ask what kind of MFA you use. SMS-based authentication does not provide the same phishing resistance as passkeys and hardware security keys. We covered that shift in Microsoft Is Moving to Passkeys. What Does That Mean for Your Business?

Who should know: your IT provider or internal IT team, who can pull the sign-in policies and the list of excluded accounts.

What proof looks like: an export or screenshot of your MFA and conditional access policies, a list of exceptions with a reason beside each one, and confirmation for any remote access tools that sit outside Microsoft 365.

Endpoint Security: What's Actually Protecting Every Device?

The form says: "Is endpoint protection or EDR deployed on 100% of endpoints and servers? Is it monitored?"

What they're really asking: What is protecting every computer in the company, and does anyone notice when it raises an alarm?

Traditional antivirus looks for known bad files. EDR (endpoint detection and response) watches behaviour, such as a spreadsheet suddenly launching PowerShell, and can cut a machine off from the network. Insurer wording varies, so answer the question your form actually asks.

The harder word is "100%." Think of the reception PC running the door buzzer software, the owner's personal laptop that also opens the company inbox, the old server nobody touches because the accounting software lives on it, or the remote employee's desktop in Laval that hasn't checked in since spring. Each one counts, and each tends to be missing from the dashboard.

Coverage is only half the question. If the platform raises an alert, someone needs to be responsible for seeing it and responding.

Who should know: IT, through the security console. Management should know who responds after hours.

What proof looks like: a device report from the security console checked against your actual asset list (that comparison is where the surprises turn up), plus the name of whoever watches alerts.

Backups: Could You Restore If the Attacker Found Them First?

The form says: "Are backups segregated from the network and tested regularly? Do you keep offline or immutable copies?"

What they're really asking: If ransomware took your whole network tonight, could you get the business running again without paying?

Attackers know backups stand between them and a payment, so they go looking. A USB drive that stays plugged into the server, or a backup system that signs in with the same domain admin password as everything else, can be compromised along with the systems it's supposed to help recover. "Immutable" means a copy that can't be changed or deleted for a set period, even by an administrator. "Offline" means disconnected entirely.

Then comes testing. A backup you've never restored is a hope with a nightly schedule attached. Ask when someone last restored a full server or a real mailbox, and how long it took.

Microsoft 365 deserves its own line on your list. Microsoft provides substantial built-in resiliency and recovery capabilities, but those aren't the same thing as having a backup strategy designed around your own recovery requirements. We'll tackle that question separately in an upcoming article.

Who should know: whoever operates the backups, whether that's your IT provider or someone in-house.

What proof looks like: backup job reports, a plain description of where copies live and how they're separated, and a dated record of the last restore test.

Admin Accounts: Who Holds the Keys?

The form says: "Do you restrict and monitor privileged access? Are administrative accounts separate from standard user accounts?"

What they're really asking: If one powerful account were compromised, how much of your business could someone control?

Access sprawl builds up quietly. The owner was made a Global Admin in 2019 "just in case." The former IT coordinator's Microsoft 365 account was disabled, but an old local administrator account they used still works on the firewall. A software vendor left a permanent remote-access tool on the accounting server during an install three years ago. The phone system provider and the website developer each have a login somewhere too, and so, oddly often, does the copier company.

A good answer starts with a list: every account with admin rights, internal or external, and the reason it needs them. People who do admin work should use a separate account for it and a normal one for email and browsing, so a phishing click lands on the weaker account.

Who should know: IT for the technical inventory; management for deciding which vendors should still have access.

What proof looks like: a current list of admin accounts, the number of Global Admins in Microsoft 365, and a vendor access list with the date it was last reviewed.

Employee Training: Can You Show Who Was Trained and When?

The form says: "Do all employees complete security awareness training at least annually? Do you run phishing simulations?"

What they're really asking: Would your staff spot a fake invoice or a spoofed email from the boss, and can you show you've prepared them?

Forms differ here: some ask about simulations, others only about training. The answer that holds up is a record of what training you provide, who completed it and when, and who hasn't. The June new hire who skipped the onboarding module counts.

Who should know: HR usually owns the records, and IT usually runs the training platform.

What proof looks like: dated completion reports, and simulation results if you run them.

Incident Response: Who Calls Whom?

The form says: "Do you have a written incident response plan? Has it been tested?"

What they're really asking: When something goes wrong at 7:40 on a Tuesday morning, does anyone know what to do first?

A usable plan fits on a few pages. It names who declares an incident, who calls whom, how you reach people if email is down, and where those contact details are stored if your normal systems aren't available. It should also note who your policy requires you to contact after an incident, and whether the policy specifies or provides breach-response, legal or forensic resources.

Quebec adds its own layer. Under the province's private-sector privacy law, as amended by Law 25, businesses must keep a register of confidentiality incidents. When an incident involving personal information presents a risk of serious injury, they must promptly notify the Commission d'accès à l'information and the people affected (LégisQuébec, P-39.1, ss. 3.5 and 3.8). Your plan should name who handles that.

Who should know: management, IT, the person in charge of the protection of personal information, and your broker.

What proof looks like: the written plan, a contact sheet, your incident register, and notes from a tabletop exercise if you've run one.

Why You Shouldn't Guess

Whatever the full facts were in the ICS case, the dispute centred on a gap between the application and what the environment looked like after an attack. That gap is where guessed answers live.

Most people filling out these forms are honest, but they're relying on reassurance. A colleague saying "yes, we have MFA" is reassurance. A sign-in policy showing which accounts it covers, and which it quietly skips, is evidence. The questionnaire deserves the second kind.

If a control is only partially implemented, don't turn that into a Yes or No on your own. Establish exactly what is in place and ask your broker how the question should be answered.

Your 60–90 Day Pre-Renewal IT Checklist

Start before the broker's email lands. Three months is enough time to fix small gaps and document the bigger ones.

90 days out

  • Find last year's questionnaire and your broker's contact details. Last year's answers are this year's starting point.
  • Assign an owner to each area: MFA, endpoints, backups, admin access, training and incident response.

60 days out

  • Pull your MFA and sign-in policies, and list every exception.
  • Compare the endpoint security console against your real device list.
  • Run a test restore and write down the date and how long it took.
  • Inventory admin accounts and vendor access, and remove what's no longer needed.

30 days out

  • Export training completion records and follow up with anyone who hasn't finished.
  • Update the incident response plan and contact sheet, and confirm your confidentiality-incident register is current.
  • Close the quick gaps. For the rest, write a remediation plan with dates and owners.

Before you sign

  • Review every answer with IT and your broker, attach evidence where the form asks for it, and keep a copy of exactly what you submitted.

Know the Answers Before the Questionnaire Arrives

A cyber insurance questionnaire can expose gaps, but it shouldn't be the first time your business discovers them.

If you can verify where MFA is enforced, which devices are protected, whether backups can be restored and who has administrative access, the questionnaire becomes much easier to answer accurately.

More importantly, you have a clearer picture of the IT environment your business relies on every day.

If you'd like a second set of eyes before your next renewal, Syslogic can go through the questionnaire with you and check each answer against what's actually running in your environment. Talk to Syslogic about a pre-renewal IT review.

homeuserphone-handsetcalendar-fullclockarrow-right linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram