
Your Cyber Insurer is Becoming Your Auditor
Category : Business | Cybersecurity | Posted : May 12, 2026
For most of the last decade, cyber insurance worked like this: you filled out an application, attested to a handful of controls, paid the premium, and filed the policy in a drawer. Renewal looked a lot like the year before. The questions were broad. “Do you have MFA?” Yes. “Do you have endpoint protection?” Yes. “Do you back up your data?” Yes. Move on. That era is ending, and some leaders haven’t caught up to what’s replacing it. Your cyber insurer is quietly becoming one of the more consequential auditors of your IT environment. Not in the traditional sense, where someone gives you a finding and a remediation date. The underwriter’s audit is the one that runs after an incident, when the question isn’t “what do we fix by Q3” but “does the policy actually pay.” Look at what’s driving the shift. The Insurance Bureau of Canada reports that Canadian cyber premiums climbed from $18 million in 2015 to $550 million in 2023. And yet from 2019 through 2023, insurers paid out roughly $1.53 in claims for every $1 they collected in premium. That’s not a sustainable book of business. It’s a market that has to tighten or collapse, and tightening is what we’re seeing. Tightening doesn’t only mean higher prices. It means underwriters are now grading deployment depth, not checkbox presence. They want to know not just whether you have MFA, but whether it’s phishing-resistant, and whether it’s deployed on the accounts that matter. They want to know not just whether you have endpoint detection and response (EDR), but what percentage of your laptops, workstations, and servers it actually covers. Marsh McLennan’s 2025 cyber risk study put numbers on it: each 25% jump in EDR coverage cut breach probability by 10%, and phishing-resistant MFA users were 9% less likely to suffer a cyber event than those on weaker MFA. Underwriters have read that study too. Then there’s the part that should make every leader pause. Coalition’s 2024 claims data found that 82% of denied cyber insurance claims involved organizations that hadn’t fully implemented the MFA they had attested to. Read that again. Most denied claims came from organizations that thought they had coverage. They paid the premium. They filed the policy. Then something went wrong, the adjuster came in, and the gap between the application and the environment was wide enough to deny the claim. For Canadian leaders the picture is sharper still. A 2025 IBC and Angus Reid survey found that only 22% of Canadian small and mid-sized organizations carry any form of cyber insurance, and just 12% hold a dedicated stand-alone policy. Meanwhile 72% of those same respondents said AI is making cyber risk harder to defend against. So most organizations are underinsured, increasingly exposed, and walking into a market that is getting pickier about who it covers and how much it pays when something goes wrong. What does this mean for the work? The renewal conversation is no longer a procurement exercise. It’s a controls conversation. And the questions worth bringing to it aren’t mostly about price. They’re about proof. Can you demonstrate, today, that the controls you attested to last year are deployed the way you described? Not in theory, in the policy document, but in the actual environment, on the actual endpoints, for the actual accounts. If a claims adjuster walked in tomorrow and pulled the configuration of your MFA, your EDR coverage, your backup retention and isolation, and your admin account hygiene, would the picture match the application? Some of the ambiguity is on the application itself. Older policies asked broad questions (“are all accounts protected by MFA?”) that were difficult to answer cleanly in a real environment with service accounts, legacy systems, and vendor exceptions. Newer applications are getting more specific (“all email accounts protected by MFA”), which helps, but the language still varies policy to policy. Part of the work at renewal is reading carefully enough to know what you’re actually attesting to. Where would an adjuster find a gap? Because there is often a gap. The acquired entity that hasn’t been fully integrated. The line-of-business system whose vendor still doesn’t support modern MFA. The shared service account everyone forgot about. The backup job that’s been failing silently for six weeks. These are the gaps that don’t matter on a normal Tuesday and matter enormously on the Tuesday something goes wrong. A useful exercise before your next renewal: take last year’s application and walk through the attested controls with your IT team or partner. For the ones that are clearly worded, ask for evidence (a configuration export, a coverage report, a screenshot) that they’re deployed the way the application described. For the ones that are ambiguous, get aligned on how you’re interpreting the question before you sign the next attestation. The deltas you find are the deltas the adjuster would find. The policy you think you have is the one that pays if those two pictures match.
Why Are We Paying Nearly the Same Money for Less Protection?
Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5,…
MFA is on. The floor for attacking it just dropped.
MFA was on. It had been on for years. The training had been done, the…

