What does an insurer actually verify before covering a cyber risk in Quebec?
Short answer: a cyber insurer doesn't verify a company's technological maturity, it verifies documented proof of a few specific controls. Cyber insurance in Quebec rests on a simple logic: whatever isn't disclosed, or is disclosed inaccurately, can void coverage at the exact moment it's needed. Denial almost never happens at underwriting, it happens at claims settlement.
For a broker, this is a delicate exercise. Cyber risk doesn't read like property damage risk. You can't inspect the premises. You depend entirely on what the client discloses, often without the client fully understanding it themselves. And yet that disclosure binds the entire policy.
The criteria that show up in almost every proposal form
Regardless of the insurer, the proposal form asks roughly the same questions. They fall into four categories:
- multi-factor authentication on remote access and privileged accounts
- an endpoint detection and response (EDR) solution in place
- backup copies isolated from the main network and recently tested
- a formalized incident response plan, with named roles
These aren't arbitrary requirements. They're the four controls that, in practice, determine whether an intrusion stays a minor incident or turns into a prolonged operational shutdown. A broker who understands why these four points come up everywhere can explain the policy to their client instead of simply having them check boxes.
Where the insurer's doubt stops
An insurer almost never declines an SME over an insufficient security score. As far as we know, there's no published, uniform threshold across insurers. What tips a file over is the absence of proof on a specific point that was already disclosed:
- a box checked "MFA enabled on all administrator access" when that's only true for part of the fleet
- a backup that exists but has never been restored to confirm it actually works
- an incident response plan that exists on paper, but that no employee has ever seen
The insurer's doubt ends when documented proof exists. Until it does, the insurer treats the gap as a misrepresentation or a material omission, with the consequences that follow for the validity of coverage. This is a point we see come up often in our discussions with insurers and brokers: the dispute is almost never about the technology itself, it's about the gap between what was disclosed and what actually existed at the time of the incident.
Cyber insurance Quebec: pre-contractual disclosure and Law 25
The Civil Code of Québec, in force since 1994, imposes on the insured an obligation to accurately disclose the risk at the outset (articles 2408 to 2411) and an obligation to report any material increase in risk during the term of the contract (article 2466). This is the legal foundation for everything above: it's not the insurer inventing a requirement for proof, it's the Quebec civil law regime that makes it necessary.
Law 25, assented to on September 22, 2021 and phased in through September 2023, adds a layer specific to Quebec. It requires a designated person in charge of the protection of personal information, an up-to-date incident register, and notification to the Commission d'accès à l'information in the event of an incident presenting a risk of serious injury. These three elements don't always appear on the cyber proposal form, but they become central as soon as an incident involves personal information, which is the case in the large majority of files. A client who can't produce this register runs into trouble twice: with the CAI, and with their insurer.
Questions to ask your client before submitting the risk
Before filling out a proposal form, a broker benefits from asking five concrete questions, not generic ones:
- Is MFA active on all administrator accounts and on remote access, with no undocumented exceptions?
- When was the last backup restoration test performed from an isolated copy?
- Who, specifically, is responsible for the protection of personal information under Law 25, and does that name appear in an official document?
- Does the confidentiality incident register exist, and has it ever been used?
- Has the incident response plan been tested, and is a breach coach identified in advance?
If the client answers with an intention rather than a fact, that's where the risk of a future dispute lives. This isn't a matter of good faith. It's a matter of proof.
Conclusion
A broker who places a cyber risk without having asked these questions transfers the doubt to their client, at the worst possible moment: the moment of the claim. The difference between coverage that holds and coverage that gets disputed doesn't come down to the technology deployed, it comes down to what can be documented at the time of disclosure.
Groupe ITCS carries out audits, assessments and action plans to durably close the gap between what a client discloses and what they can actually demonstrate. Once an incident is confirmed at an insured's or a broker's client's organization, Groupe ITCS coordinates a response around the clock: forensics, containment and secure resumption of operations.
Before your next renewal, have the coverage reviewed by Groupe ITCS, or keep our emergency line on hand for the day a case comes up.
Sources
- Civil Code of Québec, articles 2408 to 2411 and 2466, in force since 1994 (LégisQuébec)
- Act to modernize legislative provisions as regards the protection of personal information (Law 25), assented to on September 22, 2021, phased into force through September 2023
