Always Beyond White Icon Logo Small
Is Your Business Secure?
Take our FREE 2-minute IT Security Scorecard and get instant insights—no strings attached.
👉 Start Assessment
Insights & Guides
Cybersecurity & Risk

Does Your IT Package Cover What Insurers and CIS Say You Need?

Your IT package shouldn't be your provider's opinion or your budget instinct. It should map to the standards insurers and security frameworks already agree on.
Jul 22, 2026
5 mins read

A lot of businesses come to us the same way: they know they need IT support, they know security matters, and beyond that it's a fog. So they do one of two things. They either ask a provider to tell them what they need and hope for the best, or they shop on price and buy as little as possible.

Both approaches have the same flaw. There's no external reference point. The first leaves you trusting a vendor's opinion. The second leaves you trusting your own guess about risks you can't see. Neither is how you'd buy anything else this important.

There's a better anchor, and it already exists. Cyber insurance requirements for small business have quietly become a de facto security standard, and the CIS Controls give you an independent framework to check against. When your IT package maps to both, you know exactly what you're buying, why each piece is there, and what it doesn't cover. This post walks through how that mapping works, what insurers actually require in 2026, and how to right-size without under-buying.

82%5640–100%99.9%
of MFA-related claims involved organizations without MFA (Coalition, 2024)safeguards in CIS Controls IG1, the essential cyber hygiene baseline (CIS, v8.1)premium increases seen at renewal for weak controls (industry reporting, 2026)of automated attacks blocked by MFA (CISA)

Why "just tell me what I need" is the wrong starting point

If you've ever felt uncomfortable asking an IT provider what you should buy from that same IT provider, your instincts are right. It's like asking a car salesperson how much car you need. Even an honest one is guessing on your behalf, and a dishonest one has every incentive to guess high.

The reverse problem is just as common. Owners who buy the minimum aren't being cheap; they're being rational with incomplete information. Security spending feels invisible until the day it isn't, so trimming it looks like a free win. The problem is that the gap between "minimum" and "adequate" is exactly where breaches, denied insurance claims, and multi-week recoveries live.

The fix is to take the decision away from opinion entirely. Two external references do that job well: what cyber insurers require before they'll write you a good policy, and what the Center for Internet Security (CIS) defines as essential cyber hygiene. Neither one is selling you anything.

💡  Insurers have a financial incentive to require exactly the controls that prevent claims, no more and no less. That makes their requirements list one of the most honest "what do I actually need" documents in the industry.

The two anchors: cyber insurance requirements and CIS Controls

Anchor one: what insurers require

Cyber insurance underwriting has hardened significantly. What used to be a short questionnaire is now closer to a technical audit, and the controls that appear consistently across major carriers in 2026 are: enforced multi-factor authentication (MFA) on every account that touches business data, endpoint detection and response (EDR) on all workstations and servers, immutable and restore-tested backups, advanced email security, centralized patch management, documented security awareness training, and a written, tested incident response plan.

Meeting these isn't just about eligibility. Businesses with strong controls get meaningfully better rates, while weak controls at renewal are driving steep premium increases or coverage exclusions that gut the policy's actual value. And the stakes go past pricing: if your application says MFA is enforced everywhere and an auditor finds gaps after a breach, insurers can treat that as material misrepresentation. Claims have been denied on that basis.

One item deserves special mention: managed detection and response (MDR). Some carriers still list 24/7 monitoring as recommended rather than required, which puts it in the "nice to have" column on paper. We don't treat it that way, and here's why. EDR without someone watching it is a smoke detector in an empty building. Attacks routinely start on Friday nights and long weekends precisely because attackers know nobody is looking, and an alert that sits unread until Monday morning is an alert that didn't happen. The major carriers are moving the same direction: more of them now expect EDR to come with round-the-clock monitoring through an internal security team or an MDR service, and the trend line only points one way.

Anchor two: CIS Controls IG1

The CIS Controls are a prioritized set of security actions maintained by the Center for Internet Security, built from real-world attack data. Version 8.1 organizes them into three Implementation Groups. Implementation Group 1 (IG1) is the one that matters for most small and mid-sized businesses: 56 safeguards that CIS defines as essential cyber hygiene, the minimum standard every organization should meet to defend against the most common attacks.

IG1 was specifically designed for organizations without a dedicated security team. It covers things like knowing what devices and software you actually have, controlling who has access to what, secure configurations, backups, and basic incident response. If a provider's base package can't show you how it maps to IG1, ask why.

✅  The two anchors overlap heavily on purpose. Insurers built their questionnaires from the same attack data CIS built its controls from. A package aligned to one is most of the way to the other.

Mapping the controls: what insurers want, where CIS covers it

Here's how the core insurer requirements line up against the CIS Controls, and what each one is actually protecting you from. This is the conversation to have with any IT provider, current or prospective.

ControlWhy insurers require itCIS ControlWhat to ask your provider
MFA everywhereCompromised passwords drive most breaches; MFA blocks nearly all automated attacksControl 6: Access Control ManagementIs MFA enforced by policy on email, remote access, and admin accounts, or just available?
EDR on every endpointLegacy antivirus misses modern attacks; EDR detects and responds to behaviour in real timeControl 10: Malware DefensesDoes coverage include servers and remote laptops, and who watches the alerts after hours?
MDR (24/7 monitoring)Listed as recommended by some carriers, expected by more each year; unwatched EDR can't stop a weekend attackService layer supporting Controls 8, 10, and 17Who responds to an alert at 2 a.m. on a Saturday, and how quickly can they isolate a machine?
Immutable, tested backupsRansomware hunts backups; insurers want copies that can't be altered and proof they restoreControl 11: Data RecoveryWhen was the last documented restore test, and can I see the result?
Email securityPhishing and business email compromise are the top entry points for fraud and ransomwareControl 9: Email and Browser ProtectionsIs there advanced filtering beyond what's built into Microsoft 365, and are SPF, DKIM, and DMARC enforced?
Patch managementUnpatched systems are the easiest attack vector; carriers now expect defined patching timelinesControl 7: Continuous Vulnerability ManagementWhat's the standard timeline for patching workstations vs. internet-facing systems?
Security awareness trainingHuman error is behind the vast majority of successful attacks; insurers want documented completionControl 14: Security Awareness TrainingIs training ongoing with phishing simulations, or a once-a-year video?
Incident response planA written, tested plan shortens recovery and is now a standard underwriting questionControl 17: Incident Response ManagementDo we have a written plan, and when was it last walked through?

The Toyota and the Cadillac: right-sizing without under-buying

Here's our honest position, and it cuts both ways. If a Toyota gets you where you need to go, you should buy the Toyota. A 20-person professional services firm doesn't need the security stack of a hospital, and a provider who sells you one is padding their invoice, not protecting you.

But the Toyota still needs to be a complete car. Seatbelts, brakes, airbags. The insurance-required and CIS IG1 controls are the seatbelts. They're not the premium trim; they're the parts that keep a common accident from becoming a fatal one. When a provider quotes below market, this is usually where the money came from: MFA that's available but not enforced, antivirus instead of EDR, backups that exist but have never been restore-tested.

⚠️  A cheap package that skips insurance-required controls isn't a discount. You pay the difference through higher premiums, coverage exclusions, or a denied claim after an incident, which is the most expensive way to buy security there is.

The right question isn't "what's the cheapest package" or "what's the best package." It's "which controls does my situation require, and does this package deliver every one of them properly?" Requirements come from your insurer, your industry, and frameworks like CIS. The package should follow from there.

What a base package doesn't cover: regulatory and compliance needs

This is where honest providers draw a clear line, and where you should push any provider to draw one. A base package aligned to insurance requirements and CIS IG1 gives you a strong security foundation. It does not automatically make you compliant with the regulations specific to your industry or the data you handle.

Every Canadian business handling personal information has obligations under PIPEDA, and businesses with customers or operations in Quebec face additional requirements under Law 25, including breach notification and privacy governance obligations. Beyond that, sector rules stack on top: health information custodians, financial services firms, legal practices, and companies handling payment card data all carry requirements that go past essential cyber hygiene.

If you're in one of those categories, the conversation changes. You may need the equivalent of CIS IG2, formal policies and evidence trails, data residency guarantees, or specific technical controls your regulator or professional body expects. That's not a base package. It's scoped work, and any provider who tells you their standard offering "covers compliance" without asking what you're required to comply with is telling you something important about how they work.

🚨  If your business faces regulatory obligations (health data, financial services, Quebec privacy law, payment card data), do not assume a base security package covers them. Ask your provider to show you specifically which obligations are met and which need additional scoping.

How to map your needs before you buy (or renew)

Whether you're evaluating a new provider or reviewing what you already pay for, the process is the same. It takes an afternoon and removes almost all of the guesswork.

  1. Pull your cyber insurance application or renewal questionnaire. It's a ready-made requirements list. Every question is a control your insurer believes prevents claims. If you don't have coverage yet, ask a broker for a sample application from a major carrier.
  2. Download the CIS Controls IG1 list. It's free from the Center for Internet Security. You don't need to understand all 56 safeguards; you need your provider to show you where each one is handled.
  3. Ask your provider to map their package against both. Line by line. A good provider can do this quickly because they built their package this way. Hesitation or vagueness here is data.
  4. Identify your regulatory layer. PIPEDA applies broadly; Law 25 if you touch Quebec; sector rules if you're in health, finance, legal, or handle card payments. Flag anything the base package doesn't cover and scope it separately.
  5. Cut what doesn't map. Anything in a quote that doesn't trace back to an insurance requirement, a CIS safeguard, a regulatory obligation, or a genuine business need is a candidate for removal. This is how you avoid the Cadillac.
📋  Keep the completed mapping document. It doubles as your evidence pack at insurance renewal time, when underwriters increasingly ask for proof rather than yes/no answers.

Frequently asked questions

Do cyber insurance requirements really affect my premium that much?

Yes. Carriers price directly on controls now. Strong MFA, EDR, and tested backups are the three that move underwriting decisions the most, and businesses failing renewal reviews are seeing premium increases of 40 to 100 percent, coverage exclusions, or outright denial. The controls pay for themselves twice: once in reduced breach risk, once in reduced premium.

What's the difference between antivirus and EDR, and why do insurers care?

Traditional antivirus checks files against a list of known threats. Endpoint detection and response (EDR) watches for suspicious behaviour in real time and can isolate a machine mid-attack. Insurers care because modern ransomware routinely walks past antivirus, and EDR paired with someone actually watching the alerts is what stops an intrusion from becoming a claim.

My quote lists MDR as an optional add-on. Can I skip it?

You can, but we'd tell you not to, and we'd tell you the same thing if you were buying from someone else. Managed detection and response (MDR) is the 24/7 human monitoring layer that acts on what EDR detects. Without it, an alert at midnight or on a long weekend waits until someone opens a dashboard, and that delay is often the entire difference between one isolated laptop and a full network encryption. Some carriers still call it recommended rather than required, but more expect it every renewal cycle, and in our view it stopped being optional a while ago.

Is CIS IG1 mandatory for my business?

No, it's a voluntary framework, and that's part of its value. Nobody is selling it to you. CIS defines IG1 as the minimum standard of security for all organizations, which makes it a neutral yardstick for judging whether a package, including ours, actually covers the fundamentals.

My provider says everything is covered. How do I verify that?

Ask for the mapping in writing: each insurance questionnaire item and each IG1 safeguard, with the specific service or tool that addresses it. Then ask for evidence on the three biggest ones: a screenshot or policy showing MFA is enforced (not just enabled), confirmation EDR covers every endpoint including servers, and the date and result of the last backup restore test.

What if I only need part of a package?

That's a legitimate outcome of the mapping exercise, and a provider should welcome it. Where we'd push back is when the "part" being cut is an insurance-required or IG1 control. Those aren't options; they're the floor. Everything above the floor is a genuine business decision about your risk tolerance and budget.

Not sure what your business actually needs? Always Beyond builds its packages around cyber insurance requirements and the CIS Controls, so every line item traces back to something real. We'll map your current setup against both, show you the gaps and the extras, and give you a straight answer even if the answer is that you need less than you're paying for. Reach out to start the conversation.
On this page

Ready to Make IT One Less Thing to Worry About?

Book a no-pressure consultation to see how Always Beyond can help you simplify, secure, and future-proof your IT.

See exactly how your current IT setup measures up to our Hack Free standards. Enter your business email to receive:

  • Free 10-point security scorecard for your business
  • Complete Hack Free Guarantee eligibility checklist
  • Exclusive case studies from our protected clients