Free guide · SMB
12 controls your insurer will require
Insurers and Law 25 demand concrete proof. Verify, point by point, whether your business already ticks the expected boxes.
Multi-factor authentication (MFA) on email and all remote access.
Isolated, encrypted, regularly tested backups.
Endpoint detection and response (EDR).
Patches applied quickly, workstations, servers and applications.
Email filtering and anti-phishing protection.
Privileged access management on a least-privilege basis.
A written, tested incident response plan.
Documented employee awareness training.
Logging and monitoring of security events.
Encryption of sensitive data, at rest and in transit.
An inventory of assets and personal information held.
An incident log and notification procedure (Law 25).
Need help checking all these boxes? Book a free 30-minute call with a Quebec-based expert.
Book a call