Cyber insurance for Quebec small businesses: how to qualify in 2026
More and more Quebec small businesses are getting a notice from their broker: to renew the policy, they now have to tick off a long list of IT security controls. What was optional a few years ago has become a condition of eligibility. Without multi-factor authentication, tested backups and an incident response plan, plenty of companies are simply turned down.
If you run a business in Trois-Rivières, the Mauricie or elsewhere in Quebec, understanding how cyber insurance works for small companies saves you two unpleasant surprises: a premium that climbs because your file is weak, or a claim refused because a promised control was not actually in place. Here is how to qualify and negotiate from a position of strength.
Quick answer: For a Quebec small business to qualify for cyber insurance, the insurer generally requires multi-factor authentication on all access, tested offline backups, endpoint protection of the EDR type, up-to-date patching and an incident response plan. The stronger your file, the lower your premium and the broader your coverage.
1. What exactly is cyber insurance?
Cyber insurance is a policy that covers financial losses tied to an IT incident: ransomware, data theft, email fraud, service interruption or a privacy breach affecting your clients. Unlike a standard commercial policy, it targets precisely the digital risks traditional coverage often excludes.
A good policy usually covers several areas:
- Incident response costs: investigation, system restoration, crisis communication.
- Business interruption losses while your company is paralyzed.
- Legal obligations, including the notification required under Law 25 when personal information is compromised.
- Liability toward third parties (clients, partners) whose data leaked.
- Sometimes ransom payment, under strict conditions.
The important part: the insurer does not cover you on your word. It assesses your security posture before signing, and it verifies afterward that the declared controls genuinely existed at the time of the incident.
2. Why do Quebec small businesses genuinely need it?
Plenty of owners still think their company is too small to interest attackers. The opposite is true. Small businesses are prime targets because they hold sellable data while running thinner defences than large organizations. A ransomware attack can shut down a manufacturing company in the Mauricie within hours, and the recovery bill usually exceeds the annual premium.
Add to that the Quebec regulatory context. Since Law 25 came fully into force, a company that suffers a confidentiality incident involving personal information must report it to the Commission d’acces a l’information (Quebec’s privacy regulator) and, in many cases, to the people affected. Those steps cost time and money, and cyber insurance covers part of them.
A managed IT services provider can document your compliance level, which simplifies both the application and the defence of your file if you ever file a claim.
3. Which eligibility criteria do insurers require?
Underwriting questionnaires look much alike from one insurer to the next. Here are the controls that come up almost every time, the ones that swing an application between approved and refused.
Multi-factor authentication (MFA)
This is control number one. The insurer wants MFA on remote access, email, administrator accounts and ideally every cloud application. Without MFA across the board, many policies are refused outright.
Offline and tested backups
Having backups is no longer enough. The insurer asks for copies isolated from the network (immutable or offline) and proof that you regularly test restoration. A backup nobody has ever tried to restore is worth nothing on the day of a disaster.
Advanced endpoint protection (EDR)
A plain free antivirus no longer passes. Insurers want a detection and response (EDR) solution able to spot suspicious behaviour, not only known viruses.
Patch management and end-of-life systems
Systems left unpatched or past their support date, such as a workstation still running Windows 10 after updates stopped, are red flags. The insurer wants to know your updates are applied promptly.
Employee training and a response plan
Phishing awareness and a written incident response plan both weigh in the balance. A trained team lowers the risk, and a clear plan shortens recovery time.

4. How do you prepare your business before applying?
Filling out a cyber insurance questionnaire blind is risky: declaring a control you do not have can void your coverage at the worst possible moment. Here is a concrete roadmap for arriving prepared.
- Take an honest inventory. List your access points, your administrator accounts, your applications and where your sensitive data lives.
- Turn MFA on everywhere. Start with email, remote access and privileged accounts.
- Apply the 3-2-1 backup rule. Three copies, two media types, one offsite, and test restoration at least once a quarter.
- Deploy a managed EDR. Ideally monitored around the clock by a team that responds to alerts.
- Document a response plan. Who to call, in what order, how to isolate an infected machine, how to notify under Law 25.
- Train your employees. Phishing simulations a few times a year genuinely change behaviour.
Every box ticked does two things at once: it improves your eligibility and it lowers the real risk of an incident. It is rare for a security investment to serve the insurance file and daily operations equally well.

5. The role of a local IT partner in the Mauricie
Preparing a cyber insurance file calls for specific skills: configuring MFA properly, verifying backups, deploying an EDR, writing a response plan and keeping documentation current. Most small businesses do not have those resources in-house, and that is where a nearby partner makes the difference.
A provider based in Trois-Rivières knows the realities of companies in the region and can respond quickly, on site or remotely. They help you complete the questionnaire accurately, avoid false declarations, and keep your controls in place over time. When an incident happens, they also become your first line of response, which insurers value a great deal.
Frequently asked questions
Does a small company really need cyber insurance?
Yes. Small businesses are frequent targets precisely because they are less well protected. The cost of ransomware or a data leak usually exceeds the annual premium, before counting the legal obligations under Law 25.
Why is my insurer refusing cyber coverage?
A refusal almost always comes from missing controls: no MFA, untested backups, basic antivirus instead of an EDR, or end-of-life systems. Fix those points and most small businesses become eligible.
Is multi-factor authentication mandatory for coverage?
In practice, yes with nearly every insurer. MFA on email, remote access and administrator accounts has become a baseline requirement, and policies are rarely granted without it.
Prepare your file with a partner in Trois-Rivières
Cyber insurance is no longer a luxury for Quebec small businesses: it is an essential safety net, provided you genuinely qualify. Our team can audit your security posture, deploy the controls insurers require and support you through the application. Have a look at our managed IT services or get in touch to review your eligibility in the Mauricie.
Complete guide: Law 25 for Quebec small businesses
Obligations by deadline, official sources, the fines set out in the law and frequently asked questions, on one page kept up to date.
Sources: Canadian Centre for Cyber Security · Quebec.ca · OKTO Solutions
An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.