L’Assomption
IT services in L’Assomption: the cyber insurance questionnaire, with proof behind it
The policy is up for renewal and the form no longer asks whether you run antivirus. It asks whether specific measures are in place, and the insurer may want to verify that on the day of a claim. OKTO Solutions offers its services to SMBs in L’Assomption so they can answer with facts, from Trois-Rivières, about 100 km away.
In L’Assomption, an SMB renewing its cyber insurance is usually asked about six points: multi-factor authentication, monitored protection on workstations, tracked patching, tested off-site backups, staff training and an incident procedure. OKTO Solutions checks the real state of the environment, puts the missing measures in place and keeps dated proof of each. No policy and no premium is promised.
How does an SMB in L’Assomption answer a cyber insurance questionnaire?
An SMB in L’Assomption answers a cyber insurance questionnaire by first checking what truly exists in its environment, then backing every answer with a dated document. OKTO Solutions offers its services to SMBs in L’Assomption from its office in Trois-Rivières, about 100 km away, with no premises and no technician in the city. At renewal, insurers come back to the same subjects: a second factor on email and remote access, advanced protection on workstations that somebody monitors, patches that are applied and tracked, off-site backups whose restore has been tested, staff training, and a written procedure for incidents. OKTO puts those measures in place, watches them and records each change with its date. Management then fills in the form from those documents instead of from memory. OKTO promises neither that a policy will be accepted nor that a premium will drop: that decision belongs to the insurer.
The form
What does the insurer ask when the policy comes up for renewal?
Not much about antivirus anymore. The form wants to know whether the second factor is switched on for email and for remote access, whether workstations carry advanced protection that a person keeps an eye on, whether patches are applied and tracked, and whether a copy of the data sits off site, with a restore already attempted. Two more questions close the list: are employees trained, and is there a written plan for the day things go wrong?
From one insurer to the next, the questions look alike. Work done for one renewal carries over to the following one, provided the documents were kept.
What matters is the date. Saying yes is not enough: at claim time, the insurer will want proof that the measure was really there on the day of the incident. A screenshot taken the week after says nothing about March.
In an environment we look after, every change is documented, dated and kept. The answers come out of the console with the document beside them, not out of somebody’s recollection of the last meeting.
Sample screen, with a fictional form: each answer rests on a document pulled from the console. The stamp is part of the illustration; the decision remains the insurer’s.
What is in it
The six points that show up on form after form
For each one, here is what the question is really trying to find out, and where the measure sits in our services.
| Point on the form | What the question checks | What covers it at OKTO |
|---|---|---|
| Multi-factor authentication | Active on email and on remote access, administrator accounts included | Included in the Base, Standard and Complet plans |
| Workstation protection | Advanced protection whose alerts somebody reads, not an antivirus left on its own | Managed EDR on workstations and servers, in all three plans |
| Patching | Applied and tracked, on Windows and on third-party applications | Patch management included in all three plans |
| Backups | A copy off site, and a restore that has already been tried | Backup in all three plans, with a restore test twice yearly starting at Standard |
| Staff training | Do people recognize a phishing email? | Phishing simulations, four a year, in the vCIO module, which is added to a plan |
| Incident procedure | A written plan that exists before the day it is needed | Written response plan, prepared before the incident |
Managed detection, central logging and vulnerability management are added in the Complet plan. The three levels, Base, Standard and Complet, are compared line by line on the plans page, and the simulations are described on the vCIO module page; the module is a paid add-on that requires at least ten workstations or servers.
The bad morning
What do you need on hand the day you file a claim?
The form gets signed on a quiet day. The claim comes when nothing responds anymore. Here is what is useful then, in order.
- The policy conditions. Several policies require the insurer to be notified before anyone intervenes. Find the insurer’s number before an incident, not during one.
- The date of each measure. Second factor, workstation protection, patching: you have to show they were in place that day, with a document that says so.
- The logs. They establish what was viewed, copied or changed, and since when. Without them, you are guessing. Central logging is part of the Complet plan.
- A clean copy. Recovery starts from a verified, isolated backup, never from a system that is still compromised.
- The written report. The cause is fixed, the missing measure is added, and the report stays on file with the documents for the next renewal.
Six areas reviewed, then findings ranked by likelihood and impact.
Before you sign
Why have the environment checked before ticking the first box?
Because memory and the console do not always tell the same story. The person filling in the form answers in good faith, going by what was said at installation. Since then, a remote access was left open after a project, a former employee’s account still works, and the backup has been running for years without anyone attempting a restore.
The check takes a few days, depending on the size of the environment. It is done read-only, with nothing modified and no system stopped. Six areas are examined in the real environment: who has access to what, the state of workstations and servers, what the network lets in from outside, the backups, the email configuration and the company’s practices.
You receive a report of findings, with what it takes to answer an insurer’s form. Many gaps close with a setting instead of a purchase: turning on the second factor, removing inactive accounts, applying overdue patches. The remainder gets scheduled.
This engagement stands alone. You do not need to be an OKTO client, and the report is yours. It is our cybersecurity audit for SMBs.
The ground
L’Assomption, about 100 km from our office
L’Assomption is the seat of the regional county municipality of the same name, in Lanaudière. The Institut de la statistique du Québec put its population at 25,126 in 2025, a provisional figure.
Autoroute 40 crosses the city’s territory. For the work described here, the road matters little: reading a console, pulling a patch status or checking a policy in Microsoft 365 does not require being on site. That is how the service is offered in L’Assomption, where we have neither premises nor a technician stationed. A trip starts from Trois-Rivières, by appointment.
Our support team works weekdays, from 8 a.m. until 5 p.m. An outage that stops the business in the evening or on the weekend goes through the emergency line, which is included in the Complet plan. The list of territories is on the service areas page. If your renewal is coming up, write to us through the contact page and give the policy’s expiry date.
Questions and answers
Your questions about cyber insurance in L’Assomption
Do you have an office in L’Assomption?
Can you guarantee our cyber insurance will be renewed?
What do we answer when a required measure is not in place yet?
The insurer asks whether our backups are tested. What counts as a test?
Do we have to be an OKTO client to have our environment checked before renewal?
Who signs the insurer’s questionnaire?
Is your policy up for renewal soon?
Give us the expiry date and send the form. We tell you which answers already stand on proof, and which ones need work before anyone signs.
Reviewed by Antonio Pazzi, president of OKTO Solutions · updated