Opens in a new tab

Cyber insurance in Calgary only pays if your answers were true.

We check what you told your insurer against what’s actually running on your systems, fix the gaps, and keep it that way at every renewal.

The problem

Your application is a promise about your systems.

When you apply or renew, you answer a security questionnaire: do you use MFA, how are backups kept, do you have endpoint protection, are systems patched. Often it’s filled out quickly, in good faith, by whoever has the form.

The answers get checked when you make a claim. If investigators find your systems didn’t match what you told the insurer, the insurer can deny the claim or void the policy. You’ve paid for coverage that isn’t there when you need it.

We review the technical and security requirements in your policy. We’re not an insurance broker or a lawyer, so coverage and legal questions stay with them.

A real case

The policy that was void from day one.

A US manufacturer told its insurer it used multi-factor authentication. After a ransomware attack, the insurer checked.

One answer on one form.

Travelers v. International Control Services, U.S. District Court, Central District of Illinois, 2022.

  1. The application is signed  March 2022

    The company confirms it uses MFA to protect administrator access.

  2. The policy starts  April 2022

    Coverage is bound based on the answers in the application.

  3. Ransomware hits  May 2022

    The company files a claim. The insurer investigates.

  4. MFA was only on the firewall  Finding

    Nothing else, including the servers, was protected by MFA.

  5. The policy is declared void  August 2022

    Both sides agree the policy is void from the start. No coverage for that claim, or any other.

What insurers typically require

The questions on almost every application.

Every insurer’s form is different, but the same controls come up again and again. Here’s what they mean, and how we cover them.

Multi-factor authentication (MFA)

A second check at sign-in for email, remote access and admin accounts. We configure it for every user.

Endpoint detection and response (EDR)

Security software on every computer and server that stops attacks, not just known viruses. Included in every plan.

Learn more

Backups kept separate

Copies kept away from your main systems and tested, so ransomware can’t take them too. Available as an add-on.

Learn more

Email security

Filtering for phishing and fake invoices. Check Point email security is included in every plan.

Learn more

Patching

Security updates applied on a schedule, with a record that shows it.

Training and a response plan

Many insurers also ask about staff training and an incident response plan. We’ll tell you what yours asks for.

What we do

Review. Report. Fix.

01

Review

We read your policy and your application, and list every technical and security commitment you’ve made.

02

Check

We compare each one against what’s actually running on your systems.

03

Report

A plain-language report: where you match, where you don’t, and what it takes to close each gap.

04

Fix

We close the gaps the policy actually requires, and document it so you can show it.

At renewal

Questionnaires change. Your answers should too.

Insurers update their questions, and your business changes between renewals: new staff, new systems, new ways of working. An answer that was true last year may not be true now.

Before each renewal, we go through the new questionnaire with you and confirm every answer matches what’s running. You sign knowing it’s accurate.

Your EDR, email security, MFA and patching are already managed by us on our plans, so most of the evidence is on hand when the form arrives.

Straight answer

If you already meet what your policy requires, we’ll tell you that, and stop there.

We fix what the policy actually asks for. We don’t use a review to sell you a security stack you don’t need.

Fair questions

What owners ask us about cyber insurance.

Why was my cyber insurance claim denied?

Common reasons include controls on the application that weren’t actually in place, like MFA or backups, and exclusions in the policy. We can review the technical side. Coverage questions are for your broker or lawyer.

What do cyber insurers require?

It varies, but most applications ask about MFA, endpoint protection (EDR), backups, email security, patching, and often staff training and an incident response plan.

Can an insurer void my cyber insurance policy?

Yes. If the application misstated your security and that mattered to the insurer’s decision, the policy can be voided, as it was in Travelers v. International Control Services in 2022.

Do you replace our insurance broker?

No. Your broker handles the policy and coverage. We make sure your systems match what the application says, and we’re happy to work with your broker directly.

Renewing soon?

Send us your policy and application. We’ll check them.

A short call, no sales pitch. If your systems already match what you told your insurer, you’ll hear that from us.