Renewal season used to be a formality. You filled in a short form, the premium ticked up a little, and the policy landed in your inbox for another year. That is no longer how it goes. A professional services firm in the GTA sitting down to renew its cyber policy in 2026 is far more likely to face a multi-page technical questionnaire, a request for evidence, and a broker who quietly warns that coverage could shrink or vanish if the answers come back thin.
The reason is not a mystery. Insurers paid out heavily on ransomware and business email compromise over the last few years, and they responded the way any business would after a run of losses. They tightened who they will cover and on what terms. For a small firm in Oakville or Toronto, that shift has turned the renewal form into a de facto security audit, and the controls it asks about happen to be the same ones that keep you out of trouble in the first place.
The questionnaire became an audit
A cyber application five years ago asked whether you had antivirus and a firewall. Today the same form runs several pages and reads like a controls checklist. Carriers want to know whether multi-factor authentication protects email, remote access, and administrator accounts. They ask how you back up, whether those backups sit offline, and when you last restored from one. They ask about endpoint detection, email filtering, how quickly you patch, whether anyone still runs software that has reached end of life, who holds administrator rights, and whether staff get security training. Some go further and ask for a written incident response plan.
Here is what catches firms off guard. The answers are not just informational. In many policies they are representations you are legally making to the insurer, and a claim can be reduced or denied if the reality does not match what you wrote. Answering "yes, we have MFA everywhere" when a couple of service accounts or a legacy mail protocol slipped through the cracks is the kind of gap an adjuster will find after a breach, at the worst possible moment. The renewal form is not paperwork to rush through. It is a description of your actual security posture, and it needs to be true.
MFA is table stakes, and they check the details
Multi-factor authentication is the single control carriers care about most, because it stops the largest category of claims: an attacker with a stolen password walking into an inbox. So the question is no longer whether you have MFA. It is where you have it and how strong it is.
Underwriters now distinguish between MFA on user email and MFA on the accounts that matter most, meaning administrator logins, remote desktop, and VPN access. They increasingly ask whether legacy authentication, the older mail protocols that ignore MFA entirely, has been switched off. In Microsoft 365 that door is often still propped open on tenants set up years ago. And a growing number of applications ask about the strength of the second factor, because a code sent by text or a simple approve-or-deny prompt can be defeated by a determined attacker. I wrote about exactly how that happens, and why number-matching prompts and passkeys hold up where basic ones fail, in the MFA prompt you approved too fast. If your renewal asks about phishing-resistant authentication and you are not sure what you have, that is the first thing worth checking.
They want backups you have actually restored
The second control insurers press on is backups, and they have learned to ask the sharper question. It is not whether backups run. It is whether they are isolated from your live environment and whether you have ever recovered from them.
That precision exists because ransomware crews go looking for backups first. If your only copies live in the same Microsoft 365 tenant or on a network share the attacker can reach, they get encrypted alongside everything else, and your recovery plan evaporates. Carriers now want to see offline or immutable copies and, more and more, evidence of a tested restore with a realistic recovery time. A backup job reporting green for months is not proof of anything, a point I made at length in backups only count if you test them. Walk into a renewal able to say you restored a full mailbox and a critical file share last quarter, and you have answered one of the toughest questions on the form.
Detection matters as much as prevention now
The third theme is a shift in what insurers expect you to do once something gets in. Prevention alone stopped satisfying them, because attackers who slip past the front door can sit quietly for weeks. Applications now ask about endpoint detection and response, and many mid-market policies effectively require managed detection with round-the-clock monitoring rather than a tool nobody is watching.
For a firm without a security team of its own, that expectation is where a managed service earns its place. Continuous monitoring turns a quiet intrusion into an alert someone acts on, which is the whole argument I laid out for monitoring over reactive support. If the terms managed detection and response are new to you, my primer on what MDR actually is covers what carriers mean when they ask.
The paperwork behind the answers
One more thing separates a smooth renewal from a painful one, and it is the ability to prove what you claim. The Canadian Centre for Cyber Security has flagged ransomware as a top threat to Canadian organizations year after year, and insurers read the same reports. When they ask for an incident response plan or logging that shows who accessed what, they want a document, not a verbal assurance.
This is the same evidence problem that surfaces when a client's legal team asks how you handle their data, which is the ground I covered in PIPEDA and SOC 2 for growing firms. Firms that already write down their controls find the cyber questionnaire far less painful, because the answers are documented rather than reconstructed from memory the night before the deadline. For regulated verticals like financial services firms in the GTA, that documentation does double duty across insurance, client due diligence, and privacy obligations.
Start before the deadline, not on it
The trap most small firms fall into is treating the renewal as a form to fill out rather than a standard to meet. By the time the questionnaire arrives, there is rarely enough runway to turn on phishing-resistant MFA, isolate backups, and stand up monitoring before the answers are due. So the honest answers come back weak, the premium jumps, the coverage narrows, or the application is declined outright.
Firms that renew cleanly treat the controls as the goal and the paperwork as a byproduct. Close the legacy authentication gap, get real MFA on every account that matters, prove you can restore, and put eyes on your environment around the clock. Those measures lower your premium and your actual risk at the same time, which is the only version of a security spend that pays for itself twice. That combination is exactly what our managed security and compliance work is built to deliver, and if you want a second set of eyes on your posture before your next renewal, reach out any time.