Shawn Freeman
CEO

A lot of businesses come to us the same way: they know they need IT support, they know security matters, and beyond that it's a fog. So they do one of two things. They either ask a provider to tell them what they need and hope for the best, or they shop on price and buy as little as possible.
Both approaches have the same flaw. There's no external reference point. The first leaves you trusting a vendor's opinion. The second leaves you trusting your own guess about risks you can't see. Neither is how you'd buy anything else this important.
There's a better anchor, and it already exists. Cyber insurance requirements for small business have quietly become a de facto security standard, and the CIS Controls give you an independent framework to check against. When your IT package maps to both, you know exactly what you're buying, why each piece is there, and what it doesn't cover. This post walks through how that mapping works, what insurers actually require in 2026, and how to right-size without under-buying.
If you've ever felt uncomfortable asking an IT provider what you should buy from that same IT provider, your instincts are right. It's like asking a car salesperson how much car you need. Even an honest one is guessing on your behalf, and a dishonest one has every incentive to guess high.
The reverse problem is just as common. Owners who buy the minimum aren't being cheap; they're being rational with incomplete information. Security spending feels invisible until the day it isn't, so trimming it looks like a free win. The problem is that the gap between "minimum" and "adequate" is exactly where breaches, denied insurance claims, and multi-week recoveries live.
The fix is to take the decision away from opinion entirely. Two external references do that job well: what cyber insurers require before they'll write you a good policy, and what the Center for Internet Security (CIS) defines as essential cyber hygiene. Neither one is selling you anything.
💡 Insurers have a financial incentive to require exactly the controls that prevent claims, no more and no less. That makes their requirements list one of the most honest "what do I actually need" documents in the industry.
Cyber insurance underwriting has hardened significantly. What used to be a short questionnaire is now closer to a technical audit, and the controls that appear consistently across major carriers in 2026 are: enforced multi-factor authentication (MFA) on every account that touches business data, endpoint detection and response (EDR) on all workstations and servers, immutable and restore-tested backups, advanced email security, centralized patch management, documented security awareness training, and a written, tested incident response plan.
Meeting these isn't just about eligibility. Businesses with strong controls get meaningfully better rates, while weak controls at renewal are driving steep premium increases or coverage exclusions that gut the policy's actual value. And the stakes go past pricing: if your application says MFA is enforced everywhere and an auditor finds gaps after a breach, insurers can treat that as material misrepresentation. Claims have been denied on that basis.
One item deserves special mention: managed detection and response (MDR). Some carriers still list 24/7 monitoring as recommended rather than required, which puts it in the "nice to have" column on paper. We don't treat it that way, and here's why. EDR without someone watching it is a smoke detector in an empty building. Attacks routinely start on Friday nights and long weekends precisely because attackers know nobody is looking, and an alert that sits unread until Monday morning is an alert that didn't happen. The major carriers are moving the same direction: more of them now expect EDR to come with round-the-clock monitoring through an internal security team or an MDR service, and the trend line only points one way.
The CIS Controls are a prioritized set of security actions maintained by the Center for Internet Security, built from real-world attack data. Version 8.1 organizes them into three Implementation Groups. Implementation Group 1 (IG1) is the one that matters for most small and mid-sized businesses: 56 safeguards that CIS defines as essential cyber hygiene, the minimum standard every organization should meet to defend against the most common attacks.
IG1 was specifically designed for organizations without a dedicated security team. It covers things like knowing what devices and software you actually have, controlling who has access to what, secure configurations, backups, and basic incident response. If a provider's base package can't show you how it maps to IG1, ask why.
✅ The two anchors overlap heavily on purpose. Insurers built their questionnaires from the same attack data CIS built its controls from. A package aligned to one is most of the way to the other.
Here's how the core insurer requirements line up against the CIS Controls, and what each one is actually protecting you from. This is the conversation to have with any IT provider, current or prospective.
Here's our honest position, and it cuts both ways. If a Toyota gets you where you need to go, you should buy the Toyota. A 20-person professional services firm doesn't need the security stack of a hospital, and a provider who sells you one is padding their invoice, not protecting you.
But the Toyota still needs to be a complete car. Seatbelts, brakes, airbags. The insurance-required and CIS IG1 controls are the seatbelts. They're not the premium trim; they're the parts that keep a common accident from becoming a fatal one. When a provider quotes below market, this is usually where the money came from: MFA that's available but not enforced, antivirus instead of EDR, backups that exist but have never been restore-tested.
⚠️ A cheap package that skips insurance-required controls isn't a discount. You pay the difference through higher premiums, coverage exclusions, or a denied claim after an incident, which is the most expensive way to buy security there is.
The right question isn't "what's the cheapest package" or "what's the best package." It's "which controls does my situation require, and does this package deliver every one of them properly?" Requirements come from your insurer, your industry, and frameworks like CIS. The package should follow from there.
This is where honest providers draw a clear line, and where you should push any provider to draw one. A base package aligned to insurance requirements and CIS IG1 gives you a strong security foundation. It does not automatically make you compliant with the regulations specific to your industry or the data you handle.
Every Canadian business handling personal information has obligations under PIPEDA, and businesses with customers or operations in Quebec face additional requirements under Law 25, including breach notification and privacy governance obligations. Beyond that, sector rules stack on top: health information custodians, financial services firms, legal practices, and companies handling payment card data all carry requirements that go past essential cyber hygiene.
If you're in one of those categories, the conversation changes. You may need the equivalent of CIS IG2, formal policies and evidence trails, data residency guarantees, or specific technical controls your regulator or professional body expects. That's not a base package. It's scoped work, and any provider who tells you their standard offering "covers compliance" without asking what you're required to comply with is telling you something important about how they work.
🚨 If your business faces regulatory obligations (health data, financial services, Quebec privacy law, payment card data), do not assume a base security package covers them. Ask your provider to show you specifically which obligations are met and which need additional scoping.
Whether you're evaluating a new provider or reviewing what you already pay for, the process is the same. It takes an afternoon and removes almost all of the guesswork.
📋 Keep the completed mapping document. It doubles as your evidence pack at insurance renewal time, when underwriters increasingly ask for proof rather than yes/no answers.
Yes. Carriers price directly on controls now. Strong MFA, EDR, and tested backups are the three that move underwriting decisions the most, and businesses failing renewal reviews are seeing premium increases of 40 to 100 percent, coverage exclusions, or outright denial. The controls pay for themselves twice: once in reduced breach risk, once in reduced premium.
Traditional antivirus checks files against a list of known threats. Endpoint detection and response (EDR) watches for suspicious behaviour in real time and can isolate a machine mid-attack. Insurers care because modern ransomware routinely walks past antivirus, and EDR paired with someone actually watching the alerts is what stops an intrusion from becoming a claim.
You can, but we'd tell you not to, and we'd tell you the same thing if you were buying from someone else. Managed detection and response (MDR) is the 24/7 human monitoring layer that acts on what EDR detects. Without it, an alert at midnight or on a long weekend waits until someone opens a dashboard, and that delay is often the entire difference between one isolated laptop and a full network encryption. Some carriers still call it recommended rather than required, but more expect it every renewal cycle, and in our view it stopped being optional a while ago.
No, it's a voluntary framework, and that's part of its value. Nobody is selling it to you. CIS defines IG1 as the minimum standard of security for all organizations, which makes it a neutral yardstick for judging whether a package, including ours, actually covers the fundamentals.
Ask for the mapping in writing: each insurance questionnaire item and each IG1 safeguard, with the specific service or tool that addresses it. Then ask for evidence on the three biggest ones: a screenshot or policy showing MFA is enforced (not just enabled), confirmation EDR covers every endpoint including servers, and the date and result of the last backup restore test.
That's a legitimate outcome of the mapping exercise, and a provider should welcome it. Where we'd push back is when the "part" being cut is an insurance-required or IG1 control. Those aren't options; they're the floor. Everything above the floor is a genuine business decision about your risk tolerance and budget.
Not sure what your business actually needs? Always Beyond builds its packages around cyber insurance requirements and the CIS Controls, so every line item traces back to something real. We'll map your current setup against both, show you the gaps and the extras, and give you a straight answer even if the answer is that you need less than you're paying for. Reach out to start the conversation.
See exactly how your current IT setup measures up to our Hack Free standards. Enter your business email to receive: