Cyber insurance IT requirements Canada

The MSP that meets your cyber insurance checklist

MFA on every login, managed EDR on every endpoint, immutable backups, a documented incident response plan, and evidence a Canadian cyber liability underwriter will actually accept. Everything on the checklist, run by one team, verified quarterly.

100%
MFA coverage
Managed EDR
Every endpoint
Immutable
Canadian backups
Written IR
Plan and runbook

Every Canadian cyber liability control, run by one team

Renewal questionnaires from Chubb, Zurich, Beazley, CFC, Cansure, Northbridge, Intact, and BFL all ask the same 20-odd questions. Here is how NFD answers each of them for you, verified quarterly, evidence ready when your broker asks.

MFA everywhere, verified
Microsoft 365 conditional access, VPN, remote access, admin consoles, cloud dashboards. Number-matching preferred, hardware keys for privileged accounts. Monthly evidence report.
Managed EDR on every endpoint
SentinelOne, CrowdStrike, or Microsoft Defender for Business (your choice). 24/7 monitored, quarterly attack surface report, ransomware rollback tested annually.
Managed email security
Advanced anti-phishing, safe links, safe attachments, DMARC/DKIM/SPF alignment, quarterly phishing simulations with awareness training for repeat clickers.
Immutable backups in Canada
Servers, Microsoft 365 mailboxes and SharePoint, cloud databases. Air-gapped from production credentials. Restore drills every 90 days. Written restore report each quarter.
Documented incident response plan
Written IR plan naming decision-makers, external counsel, breach coach, and forensics partner. Tabletop exercise once a year. Ready to hand your broker or auditor.
Vulnerability and patch management
Patch SLA under 14 days for critical CVEs on servers and endpoints. Monthly external vulnerability scan. Annual internal scan. Reports retained for your broker.

What we deliver during your renewal

  • Filled-in cyber questionnaire. Pre-populated answers for every question your broker's underwriter asks - MFA coverage, EDR product, backup strategy, IR plan, awareness training.
  • SOC 2 Type II bridge letter. Our own third-party attestation, showing your underwriter that the MSP behind your controls is itself audited.
  • Evidence pack. MFA coverage report, EDR install report, backup success + last restore report, IR plan PDF, awareness training completion, patch report - assembled as one document.
  • Broker briefing call. A 30-minute call with your broker (with you) to walk through the evidence pack and answer underwriter follow-ups.
  • Post-renewal action plan. Any gap the underwriter flagged is turned into a scoped project with a fixed close-out date, so next renewal is quieter.
  • Ongoing quarterly proof. Once you renew, quarterly reports keep the control set verified. No scramble the week before next year's renewal.

FAQ for CFOs and risk managers

Do you actually improve premium rates?

Yes, in most cases. A full evidence pack with SOC 2 attestation typically moves a renewal from "declined or heavily rated" to "quoted at market". We do not sell insurance, so this is your broker's outcome, not ours - but our clients see it consistently.

Can you work alongside our existing insurance broker?

Yes. We are broker-agnostic. We commonly work with Aon, Marsh, HUB, BFL Canada, Gallagher, and independent Ontario brokers.

What if we have already had an incident?

We can rebuild the control set post-incident, which is often a condition of continued coverage. We coordinate with your appointed forensics partner and breach coach and hand back a written remediation report.

Is this only for large companies?

No. Small-business cyber liability policies now require MFA, EDR, backup, and awareness training too. We deliver the same evidence pack scaled to 10-user firms.

Where is our data physically stored?

Canada. Backups in Canadian regions, log storage in Canada, all admin access via Canadian identity infrastructure. Compliant with PIPEDA and provincial privacy regimes.

Renewal season is coming - is your checklist ready

Book a 20-minute review. We compare your current state to what your underwriter will ask, and give you a written gap report within five business days.