Cyber Security

What cyber insurance actually requires from your IT, and what happens at claim time if it isn't there

Cyber insurance has stopped being a form-filling exercise. As of August 2026, most UK insurers won’t quote, or won’t quote affordably, without evidence of specific security controls in place, and overstating them on the proposal form can void the policy exactly when you need it. Here’s what they’re actually asking for, and how to get there without drama.

Why the questions got harder

A few years of heavy ransomware losses taught insurers which controls actually separate the businesses that survive an attack from the ones that make headline claims. So the proposal forms grew from a page of tick-boxes into detailed technical questionnaires, and the answers now directly determine whether you get cover, what it costs, and what’s excluded.

That’s uncomfortable, but it’s also useful: the insurers’ list is effectively a free, market-tested definition of “reasonable security” for an SME.

What most insurers now ask for

The exact wording varies by insurer, but the core list is remarkably consistent:

  • MFA everywhere that matters. Multi-factor authentication on email, remote access, cloud services and especially admin accounts. This is the closest thing to a hard gate: many insurers simply won’t bind a policy without it.
  • EDR, not just antivirus. Endpoint detection and response on every device and server, ideally monitored around the clock. Traditional antivirus alone increasingly doesn’t satisfy the question. This is exactly what managed detection and response provides: the tooling plus a 24/7 team acting on what it finds.
  • Backups that would survive an attack. Separated or immutable copies that ransomware can’t reach, and evidence of test restores, because attackers target backups first. Our backup and disaster recovery service is built around precisely this standard.
  • Patching and supported systems. A routine cadence for security updates, and no unsupported operating systems quietly running in the corner.
  • Staff training. Regular security awareness training, because most claims still start with a person clicking something.
  • Email security. Filtering, impersonation protection and authentication that blunt phishing before it reaches an inbox, the sort of layered defence our email and endpoint security service puts in place.

Some insurers go further, asking about incident response plans, privileged access management and network segmentation. But the list above is the consistent core, and a business that can honestly tick all of it is insurable at sensible rates.

Where Cyber Essentials fits

Cyber Essentials is the UK government-backed certification covering five core controls: firewalls, secure configuration, access control, malware protection and security update management. For insurance purposes it does two things.

First, it’s evidence. A current certificate answers a chunk of the proposal form in one line, and it’s independently verified rather than self-declared to the insurer.

Second, it includes cover. Organisations certifying through the self-assessment route with a turnover under £20m are eligible for included cyber liability insurance, currently up to £25,000. That’s a real benefit for smaller businesses, though it’s a baseline: most should still hold a full cyber policy on top, because £25,000 doesn’t go far against a serious incident’s true cost.

What Cyber Essentials doesn’t do is cover everything insurers ask about. It says nothing about tested backups or 24/7 detection and response, which is why we describe it as a floor, not a ceiling.

The claim-time problem nobody plans for

Here’s the part that deserves more attention than it gets. The proposal form isn’t marketing paperwork; it’s the foundation of the insurance contract. If your form says MFA is enforced on all accounts and the post-incident investigation finds three shared mailboxes and a domain admin account without it, the insurer has grounds to reduce the payout or refuse the claim.

This isn’t hypothetical meanness. Insurers investigate significant claims forensically, and the gap between “what we said” and “what was actually configured” is one of the first things they look for. The businesses that get burned are rarely lying deliberately; they’re answering optimistically about an environment nobody has actually audited.

The fix is boring and effective: verify before you attest. Have someone technical confirm each answer against the real environment, and where the honest answer is “not yet”, fix it before renewal rather than rounding up.

Getting insurable, in the right order

  1. MFA first. Highest impact, usually fastest to close.
  2. EDR or MDR on every endpoint and server.
  3. Backups separated, immutable and test-restored, with the test documented.
  4. Patching routine confirmed, unsupported systems retired.
  5. Training running on a schedule, not a one-off.
  6. Then certify. With the above in place, Cyber Essentials is straightforward, and the proposal form becomes a form rather than a risk.

For businesses we manage, most of this is how the environment runs by default, and we complete the technical sections of proposal forms with clients, honestly. If your renewal is approaching and you’re not certain the answers would survive an investigation, book a consultation and we’ll review your position against what insurers actually check, before they do.

FAQs

Frequently asked questions

What security controls do cyber insurers require?

As of 2026, most UK insurers expect multi-factor authentication on email, remote access and admin accounts, endpoint detection and response (EDR) on every device rather than plain antivirus, backups that are separated from the live network and actually tested, a patching routine that keeps systems supported and up to date, and staff security awareness training. Weak answers on these either push the premium up sharply or mean no quote at all.

Does Cyber Essentials include cyber insurance?

Yes, for eligible organisations. UK businesses that certify through the Cyber Essentials self-assessment route and have a turnover under £20m get included cyber liability insurance, currently up to £25,000 of cover. It's a genuinely useful baseline, but it isn't a substitute for a full cyber policy: £25,000 rarely covers the real cost of a serious incident.

What happens if we claimed security controls on the proposal form that we don't actually have?

You risk the policy not paying out when you need it most. Cyber proposal forms are the basis of the contract, and under the Insurance Act 2015 a business must make a fair presentation of its risk. If an insurer investigating a claim finds that MFA wasn't actually enforced everywhere, or backups were never tested, they may reduce the payout or decline the claim entirely. Answer honestly, then fix the gaps before renewal.

Is Cyber Essentials enough to get cyber insurance?

It helps significantly, and some insurers offer better terms for certified businesses, but most treat it as a starting point rather than the finish line. Cyber Essentials covers five core controls; insurers increasingly also want EDR or managed detection and response, tested backup and recovery, and evidence that it's all maintained, not just switched on once.

Ready to work smarter, act faster?

Book a free, no-obligation consultation. We’ll review your IT, security and print, and show you exactly where we can help.