What cyber insurance actually requires from your IT, and what happens at claim time if it isn't there
Cyber insurance has stopped being a form-filling exercise. As of August 2026, most UK insurers won’t quote, or won’t quote affordably, without evidence of specific security controls in place, and overstating them on the proposal form can void the policy exactly when you need it. Here’s what they’re actually asking for, and how to get there without drama.
Why the questions got harder
A few years of heavy ransomware losses taught insurers which controls actually separate the businesses that survive an attack from the ones that make headline claims. So the proposal forms grew from a page of tick-boxes into detailed technical questionnaires, and the answers now directly determine whether you get cover, what it costs, and what’s excluded.
That’s uncomfortable, but it’s also useful: the insurers’ list is effectively a free, market-tested definition of “reasonable security” for an SME.
What most insurers now ask for
The exact wording varies by insurer, but the core list is remarkably consistent:
- MFA everywhere that matters. Multi-factor authentication on email, remote access, cloud services and especially admin accounts. This is the closest thing to a hard gate: many insurers simply won’t bind a policy without it.
- EDR, not just antivirus. Endpoint detection and response on every device and server, ideally monitored around the clock. Traditional antivirus alone increasingly doesn’t satisfy the question. This is exactly what managed detection and response provides: the tooling plus a 24/7 team acting on what it finds.
- Backups that would survive an attack. Separated or immutable copies that ransomware can’t reach, and evidence of test restores, because attackers target backups first. Our backup and disaster recovery service is built around precisely this standard.
- Patching and supported systems. A routine cadence for security updates, and no unsupported operating systems quietly running in the corner.
- Staff training. Regular security awareness training, because most claims still start with a person clicking something.
- Email security. Filtering, impersonation protection and authentication that blunt phishing before it reaches an inbox, the sort of layered defence our email and endpoint security service puts in place.
Some insurers go further, asking about incident response plans, privileged access management and network segmentation. But the list above is the consistent core, and a business that can honestly tick all of it is insurable at sensible rates.
Where Cyber Essentials fits
Cyber Essentials is the UK government-backed certification covering five core controls: firewalls, secure configuration, access control, malware protection and security update management. For insurance purposes it does two things.
First, it’s evidence. A current certificate answers a chunk of the proposal form in one line, and it’s independently verified rather than self-declared to the insurer.
Second, it includes cover. Organisations certifying through the self-assessment route with a turnover under £20m are eligible for included cyber liability insurance, currently up to £25,000. That’s a real benefit for smaller businesses, though it’s a baseline: most should still hold a full cyber policy on top, because £25,000 doesn’t go far against a serious incident’s true cost.
What Cyber Essentials doesn’t do is cover everything insurers ask about. It says nothing about tested backups or 24/7 detection and response, which is why we describe it as a floor, not a ceiling.
The claim-time problem nobody plans for
Here’s the part that deserves more attention than it gets. The proposal form isn’t marketing paperwork; it’s the foundation of the insurance contract. If your form says MFA is enforced on all accounts and the post-incident investigation finds three shared mailboxes and a domain admin account without it, the insurer has grounds to reduce the payout or refuse the claim.
This isn’t hypothetical meanness. Insurers investigate significant claims forensically, and the gap between “what we said” and “what was actually configured” is one of the first things they look for. The businesses that get burned are rarely lying deliberately; they’re answering optimistically about an environment nobody has actually audited.
The fix is boring and effective: verify before you attest. Have someone technical confirm each answer against the real environment, and where the honest answer is “not yet”, fix it before renewal rather than rounding up.
Getting insurable, in the right order
- MFA first. Highest impact, usually fastest to close.
- EDR or MDR on every endpoint and server.
- Backups separated, immutable and test-restored, with the test documented.
- Patching routine confirmed, unsupported systems retired.
- Training running on a schedule, not a one-off.
- Then certify. With the above in place, Cyber Essentials is straightforward, and the proposal form becomes a form rather than a risk.
For businesses we manage, most of this is how the environment runs by default, and we complete the technical sections of proposal forms with clients, honestly. If your renewal is approaching and you’re not certain the answers would survive an investigation, book a consultation and we’ll review your position against what insurers actually check, before they do.