Cyber Insurance Requirements for SMBs: Pass the Questionnaire
Insurers now demand MFA, EDR and tested backups before they'll cover you. Here's how to satisfy each control with the Microsoft stack, honestly.
Five years ago, buying cyber liability insurance in Canada took a short phone call and a signature. Today the application arrives with a security questionnaire that reads like an audit, and one wrong answer can mean a declined application, an exclusion buried in the fine print, or a renewal premium that makes you wince. Cyber insurance requirements for SMBs have tightened to the point where many Quebec businesses discover, mid-renewal, that they can't honestly answer yes to half the questions.
Here's what most brokers won't spell out: the controls insurers demand map almost one to one onto Microsoft 365 Business Premium, a licence plenty of SMBs already pay for. This guide walks through the six questions that appear on nearly every questionnaire, explains why underwriters ask them, and shows how Defender for Business, Intune, Conditional Access and Dropsuite satisfy each one. The goal is simple: pass the questionnaire honestly, with evidence behind every checkbox.
Key Takeaways
- Insurers now expect MFA, EDR, offsite backups, patching discipline, an incident response plan and separated admin accounts.
- Answering yes to a half-deployed control can void your coverage when you file a claim.
- Microsoft 365 Business Premium plus Dropsuite answers most questionnaire items without new purchases.
- Based on field observations, declined applications usually trace back to MFA gaps and untested backups.
- Keep evidence as you deploy: policy exports and reports speed underwriting and protect future claims.
Why Cyber Insurance Requirements for SMBs Got Strict
Underwriters spent 2019-2021 paying ransomware claims that dwarfed the premiums they collected, and the correction was predictable. Carriers now underwrite cyber risk the way they underwrite fire: no sprinklers, no policy. The questionnaire is their sprinkler inspection.
Quebec businesses carry a second layer of exposure. Law 25 makes breach notification mandatory and adds real penalties, which raises the cost of every incident an insurer might end up covering. Underwriters price that in. Based on field observations, renewal questionnaires that ran two pages in 2021 now run ten or more, and quotes increasingly arrive conditional on specific controls being live before the policy binds.
None of this is bad news if you flip your perspective. Every control on the questionnaire is one you'd want anyway, and the insurer just handed you the priority list for free.
The Six Controls on Every Cyber Insurance Questionnaire
The wording varies from carrier to carrier, but the substance doesn't. For each control, here's what insurers ask, why they ask it, and how the Microsoft stack answers.
MFA everywhere, not just somewhere
What insurers ask: whether multi-factor authentication protects email, remote access, administrative accounts and any system holding sensitive data. The cyber insurance MFA requirement usually sits at question one, and "partially deployed" counts as no.
Why: compromised credentials remain the most common entry point in the claims carriers actually pay. A password alone, anywhere, is an open door.
How the stack answers: Entra ID Conditional Access enforces MFA for every user on every cloud app and blocks the legacy authentication protocols that sneak around it. For a tested starting point, our free Conditional Access baseline covers the exact policies underwriters expect to see.
EDR on every endpoint
What insurers ask: whether you run endpoint detection and response, sometimes phrased as "next-generation antivirus with behavioural detection", on all workstations and servers.
Why: EDR is often the difference between a ransomware attempt and a ransomware claim. Signature-based antivirus misses the hands-on-keyboard techniques behind six-figure losses.
How the stack answers: Defender for Business, included in Business Premium, delivers full EDR with automated investigation and attack surface reduction rules. Deployed through Intune, it reaches every enrolled device, and the portal produces the coverage report that proves it. Pair the tooling with someone who actually reviews alerts; that's the core of our managed cybersecurity service.
Offsite and immutable backups
What insurers ask: whether backups exist, whether a copy lives offsite or offline, whether an attacker with admin rights could alter them, and when you last tested a restore.
Why: ransomware crews hunt backups first. The carrier wants a clean recovery path to exist so the claim stays a restoration bill instead of a ransom negotiation.
How the stack answers: Dropsuite backs up Exchange, OneDrive, SharePoint and Teams to independent storage outside your tenant, with retention a compromised admin account can't shorten. We compared the options in Microsoft 365 Backup vs Dropsuite. For servers and file data, add an offsite copy through our backup and recovery service. Then run a test restore each quarter and keep the ticket. That ticket is your evidence.
A patching cadence you can prove
What insurers ask: how quickly you apply critical security updates, often against a stated window such as 14 or 30 days.
Why: a large share of claims begin with an unpatched, internet-facing system whose fix had been available for weeks.
How the stack answers: Intune update rings push Windows updates on a defined schedule, with deadlines and grace periods that make the cadence enforceable instead of aspirational. Compliance reporting shows patch status across the fleet, exactly the artifact to attach when the questionnaire asks for proof.
A written incident response plan
What insurers ask: whether a documented plan exists, who sits on the response team, and whether you've ever exercised it.
Why: incidents contained in hours cost carriers far less than incidents discovered after weeks. A business that knows who to call at 2 a.m. loses less.
How the stack answers: this control is paper and practice, not licences. Name the internal lead, your IT provider, your broker and the carrier's breach hotline, and note where the technical runbooks live. Then run one tabletop exercise a year, even 90 minutes over lunch, and record the date. That turns "we have a plan" into a defensible yes.
Separate admin accounts
What insurers ask: whether administrators use dedicated accounts for privileged work, distinct from the identity that reads email and browses the web all day.
Why: when the mailbox account is also Global Administrator, a single phishing click hands over the entire tenant.
How the stack answers: Entra ID makes separation cheap. Create dedicated admin accounts with no mailbox, protect them with phishing-resistant MFA, and use Conditional Access to restrict where they sign in. Assign granular roles so nobody holds Global Administrator for work that needs far less privilege.
How to Pass the Cyber Insurance Questionnaire Honestly
The temptation is real: check yes everywhere and fix things later. Resist it. Misrepresentation on an application is one of the few reliable ways to lose a claim, and carriers audit the state of controls after an incident, when the logs tell the whole story.
A sequence that works better:
- Fill out a draft honestly and flag every no or partial answer.
- Prioritize the flags. MFA and backup gaps sink more applications than everything else combined.
- Close the gaps before submitting. Most Microsoft 365 controls deploy in days or weeks, not months.
- Capture evidence as you go: Conditional Access policy exports, Defender coverage reports, Dropsuite retention settings, restore test tickets.
- Submit with dates and specifics.
Underwriters respond to precision. "MFA enforced tenant-wide through Conditional Access since March 2026, legacy authentication blocked" reads very differently from a bare checkbox, and it can shorten the back-and-forth by weeks.
Denied Coverage or Facing a Hike? Read It as a Roadmap
A declined application feels like a verdict. Treat it as a gap list with a deadline instead. In our field observations, most refusals trace back to a short list of fixable items, and businesses that close their MFA, EDR and backup gaps generally obtain coverage at the next application window.
The same logic applies to painful renewals. Before accepting a higher premium or a stripped-down policy, have someone map your Microsoft 365 tenant against the questionnaire line by line. Several no answers may be configuration work away from becoming yes answers, on licences you already own. Keeping those controls running year-round is the quiet argument for managed IT: next year's renewal becomes an afternoon of exporting reports rather than a scramble.
FAQ
Is MFA required for cyber insurance?
In practice, yes. Nearly every carrier writing cyber liability insurance in Canada now requires multi-factor authentication on email, remote access and administrative accounts before quoting. A few will quote without it, but with ransomware exclusions or a materially higher premium. Treat MFA as the entry ticket, not a bonus point.
Does Defender for Business count as EDR for insurance purposes?
Generally, yes. Defender for Business is a true endpoint detection and response product with behavioural detection and automated response, and it satisfies the EDR question on standard questionnaires. Plain Windows antivirus on its own usually doesn't. What matters to the insurer is that EDR covers every endpoint and someone reviews what it finds.
What happens if I answer the cyber insurance questionnaire wrong?
If a misstatement is material, the carrier can deny the claim or void the policy outright, even when the error was honest. Insurers investigate the real state of controls after an incident, and logs make that easy. Answer accurately, mark in-progress items with target dates, and tell your broker when controls change.
Do I need immutable backups to get cyber insurance?
More questionnaires now ask for backups an attacker can't encrypt or delete, which in practice means offsite copies with enforced retention and separate credentials. Backups stored inside the same tenant or on the same network often don't qualify. A cloud-to-cloud backup with independent storage and fixed retention answers the question cleanly.
The questionnaire is coming at your next renewal whether you're ready or not, and every control on it makes your business harder to breach regardless of what your insurer thinks. For a straight answer on which questions you can already say yes to, our IT assessment maps your tenant against the standard insurer checklist and hands you the gap list before your broker asks for it.
Related Articles

Sentinel 50 Go + Defender Business: SOC for SMBs
Microsoft Sentinel 50 GB free ingestion and Defender for Business Premium bring true SOC capabilities to Quebec SMBs. Learn how to deploy it step by step.
Back to Work: The 10-Point Post-Vacation Security Checklist
Quebec offices are back from the construction holiday. Learn how a 10-point post-vacation security checklist blocks the attacks that target week one.
Patch Tuesday July 2026: 570 Flaws, What SMBs Must Patch First
Microsoft's Patch Tuesday July 2026 fixed a record 570 flaws and 3 zero-days. Learn how your SMB should prioritize patching this month.