Cyber Insurance Requirements vs. Your Current Controls: A Side-by-Side Checklist for Nonprofit Associations

Csae LogoCypher 30yrs logo

The renewal application asks whether multi-factor authentication is enforced for every user who accesses email. Your executive director checks "Yes," because MFA was turned on when the office moved to Microsoft 365 a few years ago. Nobody remembers that the shared membership inbox was exempted so part-time staff could sign in easily, that two board members never finished enrolling, or that an old event-registration integration still signs in with only a password.

If an attacker gets into that inbox, the insurer's claim review will not start with the attacker. It will start with the application you signed.

That gap, between what an association attests to and what its systems actually do, is where most problems with cyber insurance for nonprofits begin. This checklist puts the two side by side: what carriers now expect Canadian organizations to prove, and what that looks like inside a typical association running Microsoft 365, an association management system (AMS), a small staff, and a board and committees that all need some level of access.

Associations Are Buying Coverage Without Knowing What They've Promised

Cyber coverage is still uncommon among smaller Canadian organizations. In an Insurance Bureau of Canada survey from 2025, fewer than half of respondents had put any form of cyber defence in place, 22% had cyber insurance, and just 12% held a standalone cyber policy.

The organizations that do carry coverage are finding that the application has changed. A few years ago it was a short form. Today it runs many pages and asks detailed technical questions, and carriers increasingly want screenshots, configuration exports, and reports to back up each answer. Your answers effectively become the security conditions of your policy. If a claim investigation shows those controls were not in place, the insurer may have grounds to dispute or limit what it pays. Your broker can tell you exactly how your policy wording treats misstatements, and it is worth asking before renewal rather than after an incident.

Many associations also assume their mission protects them. The Canadian Centre for Cyber Security addresses this directly in its Ransomware Threat Outlook 2025-2027: some ransomware groups claim to avoid charities and similar organizations, but others will go after anyone, and the Cyber Centre assesses that every Canadian organization, whatever its size or sector, is at risk of being targeted.

Association Environments Have Gaps Insurance Questionnaires Don't Anticipate

Insurance applications assume a conventional business: employees, company-owned laptops, one IT administrator. Associations rarely look like that. A typical setup includes:

  • Board and committee members who need access to documents and Teams channels but aren't staff, and who often use personal devices
  • Shared mailboxes such as info@, membership@ and events@ that several people access
  • An AMS and event platforms holding member records, and sometimes payment details, managed by outside vendors
  • Part-time staff and contractors who come and go, sometimes faster than their accounts are shut off
  • No dedicated IT role, so security settings drift over time without anyone noticing

The exposure is real. In CIRA's 2025 Cybersecurity Survey, 42 per cent of Canadian organizations reported a breach of customer or employee data in the previous 12 months, compared with 29 per cent in 2022. For an association, "customer data" is member data, and member trust is the whole business model.

The Side-by-Side Checklist

Work through each table with whoever manages your IT. Mark a row as met only if you could produce the proof today. "I think so" counts as not met.

Identity and Access

What insurers ask What "yes" actually has to mean Where associations commonly fall short Your status
MFA enforced on all email accounts Enforced through Conditional Access or equivalent, with no exclusions and legacy sign-in methods blocked Shared mailboxes with direct sign-in, board accounts never enrolled, exemptions made "temporarily" years ago ☐
MFA on remote access and cloud apps Every system reachable from the internet requires MFA: VPN, AMS, finance, payroll, banking AMS or payment portal still using a password only ☐
Privileged accounts protected Separate admin accounts, used only for admin work, held by as few people as possible Executive director's everyday account is a global admin; a former contractor still has admin rights ☐
Access removed promptly Accounts disabled the day someone leaves, with regular access reviews Past staff, former board members and volunteers still active in Microsoft 365 ☐

Devices, Email and Network

What insurers ask What "yes" actually has to mean Where associations commonly fall short Your status
EDR on all endpoints Endpoint detection and response (not basic antivirus) on 100% of laptops, desktops and servers, with active monitoring Part-time staff on personal laptops; an old front-desk PC nobody manages ☐
Patch management Critical updates applied within a defined timeframe, with a report to prove it Devices that haven't checked in for months; firewall firmware never updated ☐
Email security Filtering plus SPF, DKIM and DMARC, with DMARC set to enforce Executive director's name spoofed in payment requests; DMARC left on monitor-only ☐
Secure remote access and firewall No exposed Remote Desktop, a managed firewall, and no stray open ports A port opened during the pandemic that nobody closed ☐
Mobile devices Phones and tablets that access organizational data are managed and can be wiped Staff reading member records on unmanaged personal phones ☐

Recovery, People and Response

What insurers ask What "yes" actually has to mean Where associations commonly fall short Your status
Secure backups Backups that can't be deleted or encrypted from the production environment, using separate credentials, and including Microsoft 365 data Relying on the OneDrive recycle bin; backup console uses the same admin login ☐
Tested restores A documented, dated restore test within the last 12 months Backups exist but have never been restored ☐
Security awareness training All staff trained at least annually, ideally with phishing simulations, and completion records kept Board and volunteers left out; no records of who completed it ☐
Incident response plan A written plan, tested through a tabletop exercise, listing who calls the insurer's breach hotline first No plan, or a plan that doesn't mention the insurer; board unclear on its role ☐
Vendor risk A list of vendors that hold member data, with security terms reviewed Nobody knows how the AMS or event platform protects data or handles a breach ☐
AI use A policy governing which AI tools staff can use and with what data (a newer question on some applications) Staff pasting member information into free AI tools ☐

A "Yes" on the Application Needs a File Behind It

Underwriters are moving from trusting answers to checking them. Before your next renewal, assemble an evidence folder so every "yes" is backed by something dated:

  1. MFA report from Microsoft 365 showing enrolment for every user, plus your Conditional Access policies
  2. EDR coverage report from your endpoint console listing every protected device
  3. Patch compliance report showing update status across devices
  4. Backup restore log with the date, what was restored and how long it took
  5. Training records showing who completed security training and when
  6. Incident response plan plus notes from your most recent tabletop exercise
  7. Vendor list covering every third party that stores member or donor data
  8. External exposure results from a scan of what an attacker can see from outside your network

This folder does double duty. It speeds up the renewal, and if you ever file a claim, it shows the insurer that the controls you attested to were actually running.

Close the Gaps in the Order Underwriters Weigh Them

Most associations won't fix everything in one budget cycle, and they don't need to. Prioritize based on what carriers scrutinize most and what attackers actually exploit:

First, lock down identity. Enforce MFA with no exceptions, block legacy sign-in, separate admin accounts and clean out old ones. This is inexpensive in Microsoft 365 and closes the most common path into association inboxes.

Second, secure devices and backups. Get EDR onto every endpoint that touches organizational data, and confirm that at least one backup copy is protected from deletion and has actually been restored in a test.

Third, address email and people. Move DMARC to enforcement and put everyone, including the board, through phishing training. Associations are frequent targets for invoice and payment fraud because their leadership is publicly listed.

Fourth, write down the response. An incident response plan that names the insurer's breach hotline as an early call can protect your coverage, since many policies expect you to use approved responders.

If a control won't be in place by renewal, be honest on the application and tell your broker what's underway and when it will be finished. An accurate "in progress" answer is far safer than an optimistic "yes."

Where Cypher Systems Fits

For more than 30 years, Cypher Systems has supported Ottawa organizations, and a large part of that work today is with nonprofit associations. We know how associations actually operate, board members and shared inboxes included, and we build security around that reality instead of a corporate template.

Our Cyber Insurance Support service helps associations answer applications accurately and assemble the evidence behind each answer. That work draws on the rest of our cybersecurity services:

For a deeper look at the threats associations face, see our Cybersecurity Risk Guide for Associations, and for how we protect member data day to day, visit Cybersecurity for Associations.

If your renewal is coming up and you aren't sure every "yes" on your application would hold up, talk to Cypher Systems or call 1-800-864-2797. We'll walk through this checklist with you and show you exactly what to fix first.

Gabriel Rapacz

Gabriel Rapacz

Vice President and Co-Owner, Cypher Systems
Gabriel Rapacz has been working in IT since 2013, starting during university before joining Cypher Systems full-time in 2017. He brings a well-rounded, hands-on approach with experience across support, infrastructure, and cybersecurity.

He believes IT is ultimately about supporting people, not just technology. Gabriel focuses on making systems approachable and effective for each client and their team, adapting to different levels of comfort and experience.

With a strong interest in cybersecurity, Gabriel stays current on emerging threats and attacker tactics, helping clients stay protected in an evolving landscape.
Connect with Gabriel on Linkedin
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram