Last updated: September 23, 2026
Your cyber insurance renewal form might be the most useful IT review your business gets this year. Most businesses glance at it, forward it to whoever takes care of their IT, and sign what comes back. This year, it’s worth reading first. The questions are getting more specific, and the way you answer them matters more than most leaders realize.
Here’s what to expect on the form, why it changed, and how to prepare answers you can stand behind.
What does a cyber insurance renewal form ask in 2026?
Applications vary, but many now ask for more detail about where controls are applied and whether they have been tested. Most forms still cover the familiar ground: multi-factor authentication, antivirus, backups, employee training, and how much sensitive data you hold. What’s changed is the precision. Instead of asking whether a safeguard exists, the form increasingly asks how it’s configured, how far it reaches, and when it was last proven to work. Many forms now also ask about your incident response plan, and some newer applications and questionnaires ask about the AI tools your staff use.
If your last renewal was a page of yes-and-no boxes, expect this one to read more like a short audit. And you don’t have to take our word for that: the Insurance Bureau of Canada, the industry association for Canada’s private home, car and business insurers, publishes a plain-language guide with examples of the questions you could be asked when applying. It’s worth ten minutes before your renewal letter arrives: IBC’s Cyber Savvy insurance guide.
Why are the questions more specific?
Insurers have learned that a control listed on paper is not always a control working in practice. A business can technically have antivirus, technically have backups, and still not recover from an incident, and the difference shows up in the wording of the questions.
So, the question is less “do you have multi-factor authentication” and more “where exactly is it applied?” Small shifts in wording, but they produce very different answers and very different outcomes. Your answers become part of the record that your policy is built on.
What counts as multi-factor authentication now?
On many forms, multi-factor authentication now means it is enforced where it matters most: email, remote access, cloud applications, and especially administrator accounts, not just one of them. The old expectation might have been simply on email. Some forms go further and ask what kind, because attackers have learned to trick users into approving basic push prompts or handing over one-time codes, and insurers know it.
Before you answer, find out where multi-factor is actually enforced in your business, not just where it was intended to be. The gap between those two is one of the most common findings in any review.
How would I know if something was running that shouldn’t be?
Only if someone, or something, is watching for it. This is the modern version of the antivirus question. Having protection installed is assumed. What forms increasingly probe is detection and response.
If something started running on a laptop on a Saturday afternoon, who would notice, and what happens next?
For many small and mid-sized businesses, the honest answer is “we’d find out when something visibly broke,” and insurers take that into account. You don’t need to know the product names involved. You need to be able to say, in one sentence, how a threat on one computer gets noticed in your business.
Worth knowing: insurers didn’t dream these expectations up. The Canadian Centre for Cyber Security publishes baseline cyber security controls for small and medium organizations, and the questions on current forms often overlap with that government-published list. The form is largely checking whether you’re doing what Canada’s own cyber agency already recommends.
What do insurers want to know about backups?
They want to know whether backups exist, whether an attack could compromise them, and whether they have been restored successfully. Those three things sit in rising order of importance. The last one is the question that catches businesses most often, and it’s the one worth taking seriously. A backup that has never been restored is a hope, not a plan, and “yes, we have backups” answered from memory has a way of becoming “the restore hadn’t worked since spring” at exactly the wrong moment.
A recent successful test restore gives you a far more reliable answer than assuming backups are working.
Why is there a section about AI tools now?
Because staff started using AI tools before most businesses had decided how they should be used. Insurers aren’t asking whether you think AI is good or bad. They’re asking whether the business has visibility into how it’s being used: what information is going into which AI tools, and who has approved that use. It’s a data-handling question, the same category of risk as any other place your information travels.
If your business can answer “which tools, which versions, who decided” in a sentence, this section is easy. If nobody has ever asked those questions internally, the form is doing you a favour by asking first.
What happens if the form and the network don’t match?
If a claim is filed, the application may become an important part of the conversation. The answers you gave get compared against what was actually in place at the time of the incident, and where the two don’t line up, the claim gets harder. That is why accuracy beats optimism on every line.
The Insurance Bureau of Canada’s own guidance makes the same point from the other side of the table: your application is what the insurer uses to assess and price your risk.
That’s why the goal should not be to give impressive answers, but to give accurate ones, and then to close the gaps the accurate answers reveal, in that order.
How should we prepare our answers?
Start with one rule: don’t answer any question from memory. For each answer, ask how you know it’s true and when that was last proven. Then sit down with whoever runs your technology, internal or external, and go through the form together before your broker needs it back. If answering the form requires a long hunt for information, that is useful information in itself. It tells you how visible and well-managed those controls are today.
Anything you can’t back up with something recent, make note of it before your insurer does. That short list becomes your fall project, and it’s worth more than the premium you’re renewing.
If you’d like a dry run before the real form shows up, the Insurance Bureau of Canada offers a free cyber insurance assessment on its Cyber Savvy Canada site that walks through much of the same territory.
What if we find gaps?
Realistically, you should expect to. Almost every business finds a few, and finding them on your own schedule and terms is the whole point of reading the form early. Some gaps are worth fixing before you submit. Multi-factor coverage and tested recovery are sensible early priorities because they reduce the chance that one incident becomes much more expensive. Others, you may understand and consciously accept for now. Both can be good decisions when they’re made with accurate information, which is really what the entire exercise is for.
A renewal form answered with evidence is a boring document, and boring is the goal. In a well-run technology relationship, these answers show up all year, with proof behind them, and the insurance form becomes a summary of things you already knew. If this year’s form turns out to be full of surprises, that’s worth addressing long before next year’s arrives.
Pocket Line:
Your insurance form is only as good as the evidence behind it. Don’t answer from memory; answer from the last time it was proven.
SolutionsIT works with Manitoba businesses, municipalities, and credit unions from offices in Winkler, Portage la Prairie, Winnipeg, and surrounding communities. If your renewal is coming up and you want to review the technical questions before the form goes back to your broker, we can help you separate what is in place from what still needs attention.