1. Multi-factor authentication (MFA), everywhere that matters
MFA is the single highest-value control on this list. It requires a second proof of identity — usually a phone prompt or code — so a stolen password on its own is worthless to an attacker.
Insurers typically expect MFA on email, remote access (VPN or remote desktop), and administrative accounts at minimum. Applying it to email alone closes the most common path into a business.
2. Endpoint detection and response (EDR)
Traditional antivirus matches known malware signatures. EDR watches how software behaves, catches threats nobody has seen before, and can automatically isolate a compromised machine within seconds — before ransomware spreads across the network.
This is now a baseline requirement on most policies. If your renewal questionnaire asks whether you run "EDR" or "next-generation endpoint protection," plain antivirus is not a yes.
3. Backups that are tested — and can't be encrypted
Ransomware crews look for your backups first. Immutable backups can't be altered or deleted once written, which is what keeps a bad week from becoming an extinction event.
The other half is testing. A backup you have never restored is a hypothesis, not a safety net. Restores should be tested at least quarterly and the recovery time written down.
Rule of thumb: three copies of your data, on two different media, with one off-site and immutable — the 3-2-1 rule, updated for the ransomware era.
4. Security awareness training and phishing simulations
Over 90% of breaches start with a person clicking something. Ongoing micro-training paired with realistic phishing simulations measurably lowers click rates over time, and insurers increasingly ask for documented proof that a program exists.
5. Email protection beyond the built-in filter
Advanced filtering, impersonation protection, and correctly configured DMARC, SPF, and DKIM records stop most phishing and business email compromise before anyone has to make a judgment call. Misconfigured DNS records are one of the most common gaps we find in Ontario businesses.
6. Least privilege and offboarding
Everyone should have exactly the access their job requires — no more. Just as important: access must actually be removed when someone leaves. Dormant accounts with live credentials are a favourite way in.
7. Patching, on a schedule you can prove
Most successful attacks exploit vulnerabilities that were patched months earlier. Automated patching for operating systems and third-party software, with reporting that shows compliance, closes the window.
Where Ontario businesses usually fall short
- MFA on email but not on remote access or admin accounts
- Backups running, but never test-restored
- Antivirus mistaken for EDR on the insurance questionnaire
- Training done once at onboarding and never again
- No documentation — the controls exist, but nothing proves it at claim time
The documentation trap
Having the controls is only half the requirement. When you attest to them on an application, you are making a statement your insurer can test after an incident. Keep evidence: policy exports, training completion records, patch reports, restore-test results.
Borg ITS implements each control on this list and documents it, so the answers on your renewal are accurate and defensible.
Want a second opinion on your setup?
A senior Borg ITS engineer will review your environment and tell you plainly where you stand — no obligation.
