Cyber Insurance Renewal: 8 Security Controls Your Business Should Prepare
Cyber insurance requirements for small business vary by insurer, policy and renewal application. A useful starting point is to check what your business actually operates—and collect evidence before answering questions about security controls. This checklist helps Metro Vancouver businesses prepare for that technical review. It does not guarantee eligibility, coverage, pricing or payment of a claim; confirm policy-specific requirements with your broker or insurer.
1. Keep an accurate inventory
List business computers, servers, cloud services, remote-access tools and internet-facing systems. Record who owns each system, who administers it and whether it is still supported. Include vendor-managed applications and backup platforms. An incomplete inventory makes statements such as “all devices are protected” difficult to verify.
Keep a dated inventory and note any exceptions with an owner and a remediation date. The Canadian Centre for Cyber Security’s baseline controls for small and medium organizations provide a useful starting point for broader security planning.
2. Verify multi-factor authentication coverage
Check MFA on business email, remote access, cloud administration, backup consoles and other critical accounts. Review actual enforcement and exceptions, rather than assuming that making MFA available means everyone uses it. Privileged accounts and third-party access deserve particular attention.
Keep a dated coverage report and an approved process for emergency access. For Microsoft 365, review identity settings alongside email and sharing controls; our Microsoft 365 security hardening guide explains the wider review.
3. Separate administrator access from everyday work
Use separate administrator accounts where appropriate and give staff only the access required for their work. Remove unused accounts, review vendor permissions and document how access changes when someone joins, changes roles or leaves. Shared privileged accounts can make accountability harder.
Useful evidence includes a dated access review, the list of authorized administrators and a record of completed offboarding checks. Record unresolved exceptions honestly.
4. Make patching measurable
Define how quickly updates are assessed and applied, who responds to urgent vulnerabilities and how failed installations are handled. Include operating systems, applications, firewalls and other business devices. Unsupported products need a replacement or documented risk-treatment plan.
Collect a recent compliance report that shows missing updates and exceptions, not just a screenshot showing that automatic updates are enabled. Match any application answer to the systems and timeframes it actually asks about.
5. Confirm endpoint protection is monitored
Installing a security agent is only part of the job. Check device coverage, agent health, alert review, escalation and authority to contain an affected device. Clarify who responds outside business hours and what records are retained.
EDR, XDR and MDR describe different technologies and service arrangements. Verify the capabilities your business has rather than relying on a product label. Our cybersecurity services can help assess protection and response responsibilities.
6. Review email protection and staff reporting
Review anti-phishing settings, suspicious forwarding rules, older authentication methods and the process employees use to report suspicious messages. Check SPF, DKIM and DMARC with the people responsible for your legitimate email senders; changes need to account for every authorized sending service.
Keep records of staff awareness activities and a simple reporting route. Training supports technical controls, but it does not replace them. Test whether a reported message reaches someone who can investigate and act.
7. Test recovery from protected backups
Identify the systems and data that must be recoverable, the acceptable downtime and the acceptable amount of lost work. Review backup isolation, encryption, access controls and protection against deletion. A successful backup job does not prove that a business process can be restored.
Run a documented restore test and record the result, elapsed time and follow-up actions. Evaluate Microsoft 365 recovery needs separately from retention settings. Our backup and recovery services can help connect the technical setup to business recovery priorities.
8. Prepare and exercise an incident-response plan
Document who can declare an incident, isolate systems and approve recovery actions. Keep current contacts for technical support, leadership, your broker or insurer and appropriate legal advisers. Identify evidence-preservation needs and where an offline copy of the plan is available.
Run a short tabletop exercise using a realistic scenario, such as a compromised email account or ransomware affecting a shared drive. Record decisions and gaps. The NIST Cybersecurity Framework 2.0 organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover; it can help structure ongoing improvement.
Build a renewal evidence folder
Before completing an application, gather a dated system inventory, MFA coverage report, access review, patching report, endpoint coverage and monitoring summary, email-security review, restore-test record and incident-response plan. Give each item an owner and note open exceptions. Share sensitive technical records only through a channel agreed with the intended recipient.
Read questions literally. Words such as “all,” “every,” “24/7” and “tested” can require more evidence than a general security summary provides. If a control is only partly deployed, describe the actual state and ask your broker or insurer how to record it accurately. Do not represent planned work as completed.
Turn the checklist into a practical improvement plan
Start with a baseline review, rank the gaps by business impact and assign owners and dates. Recheck the evidence after changes are made. A regular review through managed IT services helps keep the information current between renewals.
SOS Computer Experts supports businesses in Vancouver, North Vancouver, Burnaby, Richmond, Coquitlam, Surrey and Langley. Book a 15-minute IT baseline conversation to discuss your security controls and next steps, or call 778-262-2133. We provide technical readiness support; your broker, insurer and legal advisers determine policy and legal requirements.
