Ransomware or a breach right now? Don't wait. Call our incident line.+1 587 208 3742What to do first →

Insurance & compliance

Answer the insurance form honestly, and still get covered.

Cyber insurers and enterprise clients now ask detailed security questions before they will cover you or sign a contract. An inaccurate "yes" can put a future claim at risk. We help you put the controls in place, so the honest answer is the good answer.

What insurers commonly ask

The controls behind the questions.

Wording varies by insurer, but most applications and renewals focus on the same core controls.

Typical requirementHow we cover it
Multi-factor authentication on email, remote access and admin accountsManaged IT
Endpoint detection and response (EDR) or 24/7 monitoringManaged Detection & Response
Backups that are offline or immutable, and regularly testedBackup & Disaster Recovery
Timely patching of critical vulnerabilitiesManaged IT / Vulnerability Management
Annual security awareness and phishing trainingSecurity Awareness Training
A documented incident response planvCISO / Incident Response

Canadian privacy law

If personal information is breached, the clock starts.

Canadian organizations have legal duties to protect personal information and to report certain breaches. Our investigation and documentation give you and your counsel the facts needed to meet them.

PIPEDA (federal)

Private-sector organizations must report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner of Canada, notify affected individuals, and keep records of every breach for 24 months.

Alberta PIPA

Organizations subject to Alberta’s Personal Information Protection Act must notify the Information and Privacy Commissioner, without unreasonable delay, of incidents where there is a real risk of significant harm to individuals.

Alberta Health Information Act

Custodians of health information, including clinics and dental offices, have their own duty to notify the Commissioner, the Minister of Health and affected individuals when unauthorized access or disclosure creates a risk of harm.

This page is general information, not legal advice. Talk to your legal counsel about your specific obligations.

How we help

From questionnaire to evidence.

  1. 01
    Gap review

    We go through your insurer or client questionnaire with you and check each answer against what is actually configured.

  2. 02
    Close the gaps

    We deploy the missing controls, such as MFA, EDR or MDR, tested backups and training, in priority order.

  3. 03
    Keep the evidence

    Reports, test results and training records are kept ready for renewals and audits, so next year is easier.

Renewal coming up?

Send us the questionnaire. We will tell you which answers are solid, which are at risk, and what it takes to fix them.