Cyber insurance requirements have hardened faster than almost any other part of UK business insurance. Five years ago a proposal form asked whether you had antivirus and a firewall; today underwriters want evidence of multi-factor authentication on every remote entry point, endpoint detection on every device, and backups that a ransomware operator cannot reach. Answer those questions wrongly and the consequences arrive at the worst possible moment — as a reduced payout, or no payout at all, after an incident. The NCSC’s own cyber insurance guidance tells buyers to ask what must be in place before a claim or renewal, because insurers increasingly check.
This guide sets out the cyber insurance requirements UK underwriters actually apply in 2026: the IT controls that appear on almost every proposal form, the statistics behind them, what the Insurance Act 2015 does to a careless answer, how Cyber Essentials fits in, what premiums look like for SMEs, and a 90-day plan to become insurable at a sensible price. It complements our earlier guide to cyber insurance red flags, which looked at the warning signs insurers hunt for; here the focus is the cyber insurance requirements themselves and how to meet them.
Table of contents
- What Cyber Insurance Requirements UK Insurers Set in 2026
- What Cyber Insurance Covers — and What It Does Not
- The 10 IT Controls Behind Most Cyber Insurance Requirements
- Inside the Big Five Cyber Insurance Requirements
- What Happens If Your Proposal Form Is Wrong
- Cyber Insurance Requirements and Cyber Essentials
- How Cyber Insurance Requirements Affect Your Premium
- Meeting Cyber Insurance Requirements: A 90-Day Plan
- Cyber Insurance Requirements UK: FAQ
- References
What Cyber Insurance Requirements UK Insurers Set in 2026
A cyber insurance requirement is no longer a box-ticking exercise. Underwriters have a decade of claims data, and it tells them exactly which missing controls turn into losses. Marsh McLennan’s research across thousands of policyholders identified twelve key control categories commonly required by cyber insurers, and found the three most frequently demanded are endpoint detection and response (EDR), multi-factor authentication (MFA) and privileged access management (PAM).
The claims data behind the questions
The same research quantified why. Organisations that patch high-severity vulnerabilities within seven days halve their probability of a cyber event — yet only 24% actually do it. Broad MFA, covering all remote access, critical data and administrator accounts, makes a successful attack 1.4 times less likely. Automated hardening techniques were associated with roughly six times fewer incidents. Coalition’s claims data adds two more: firms still running end-of-life software are three times more likely to suffer an incident, and a single unresolved critical vulnerability makes a claim 33% more likely. Every one of those figures now resurfaces as a cyber insurance requirement on somebody’s proposal form.
The UK threat picture
The government’s Cyber Security Breaches Survey 2026 found 43% of UK businesses identified a breach or attack in the previous twelve months, with phishing by far the most common vector at 38% of businesses. Exposure climbs sharply with size, which is exactly how underwriters price it.
Despite that, only 10% of UK businesses hold a specific cyber security insurance policy. A further 37% have some cyber cover folded into a broader policy, taking total insurance against cyber risk to 47% — but bundled cover usually carries low sub-limits and none of the incident response services a dedicated policy provides.
What Cyber Insurance Covers — and What It Does Not
A dedicated policy typically covers incident response and forensics, data restoration, business interruption, cyber extortion, liability for compromised data, and regulatory defence costs. The word “typically” is doing a lot of work: the details vary by insurer, and three mechanisms quietly shrink the headline limit.
Sub-limits and co-insurance
A £1 million policy rarely pays £1 million for every loss type. Sub-limits cap specific categories — ransomware, social engineering fraud, business interruption — at a fraction of the headline figure, and co-insurance clauses make you carry part of the loss yourself. As Corvus, the Travelers-owned cyber underwriter, explains in its coverage guide, one major insurer introduced ransomware co-insurance requiring policyholders to bear 50% of digital extortion losses. Missing cyber insurance requirements do not always mean a declined quote; sometimes they mean quietly savage terms.
War exclusions and systemic events
After Merck’s $1.4 billion NotPetya dispute — settled in January 2024 after US courts rejected the insurer’s “hostile or warlike acts” defence — the market rewrote its war exclusions. Modern UK wordings exclude state-backed and systemic events in far more precise language. If your business depends on one cloud provider or one software vendor, read this clause before signing, because a mass event affecting thousands of firms at once is exactly where insurers now draw boundaries.
The 10 IT Controls Behind Most Cyber Insurance Requirements
Proposal forms differ, but the underlying checklist barely does. These ten controls are the cyber insurance requirements UK underwriters ask about, in roughly the order they ask. Treat every row as a question you will have to answer in writing — and evidence later if you claim.
| Control | What the proposal form asks | Why insurers demand it |
|---|---|---|
| Multi-factor authentication | Is MFA enforced for all remote access, email and privileged accounts? | Broad MFA makes a successful attack 1.4x less likely (Marsh McLennan) |
| Endpoint detection and response | Is EDR or MDR deployed on all endpoints and servers? | One of the three controls insurers most frequently require |
| Tested offline backups | Are backups offline or immutable, separated from the network, and restore-tested? | Decides whether ransomware is an inconvenience or a payout |
| Patch management | Are critical patches applied within 14 days, high-severity faster? | 7-day patching of high-severity flaws halves event probability; only 24% of firms do it |
| No end-of-life software | Do you run unsupported operating systems or applications? | EOL software means a firm is 3x more likely to suffer an incident (Coalition) |
| Privileged access management | Are admin rights restricted, separated and logged? | Top-three required control; admin accounts are the attacker’s target |
| Remote access exposure | Is RDP or any remote admin service exposed to the internet? | Coalition rates internet-exposed RDP the strongest predictor of ransomware claims |
| Email security | Do you filter inbound mail and verify payment-change requests? | Email compromise plus funds-transfer fraud drove 58% of claims in 2025 (Coalition) |
| Security awareness training | Is phishing training run at least annually, with simulations? | Phishing touches 38% of UK businesses a year |
| Incident response plan | Is there a written, tested plan with named roles? | Only 25% of UK businesses have one — a fast differentiator |
The pattern across all ten is the same: each control either shrinks the chance of a claim or shrinks its size. That is the entire logic of every cyber insurance requirement — underwriters are not auditing your IT for fun, they are pricing the probability that they will be writing you a six-figure cheque.
Inside the Big Five Cyber Insurance Requirements
Five cyber insurance requirements dominate underwriting decisions, and they deserve a closer look because “yes” on the form has a precise technical meaning.
MFA everywhere that matters
“Do you use MFA?” does not mean the VPN alone. Insurers expect it on all remote access, all email accounts, and every administrator or privileged account — cloud consoles, firewalls and hypervisors included. A typical UK form asks exactly that in one compound question, and a “yes” that is only true for one of the three categories is the classic misrepresentation that unravels claims.
Backups a ransomware operator cannot delete
Connected backups get encrypted along with everything else. The cyber insurance requirement is offline or immutable copies, logically separated from production credentials, with restore tests you can evidence. Our guide to the immutable backup 3-2-1-1-0 strategy maps directly onto what underwriters want to see. The payoff is real: Coalition reports that 100% of its UK ransomware clients in 2025 recovered without paying a ransom — backups are the single biggest reason that number is possible.
EDR, not just antivirus
Signature antivirus satisfies Cyber Essentials; it no longer satisfies most underwriters, and EDR has moved from differentiator to standing cyber insurance requirement in about three years. EDR watches behaviour, isolates infected machines and gives responders the telemetry to reconstruct an attack. For firms without a security team, the managed variant (MDR) answers the follow-up question insurers increasingly add: who is watching the alerts at 2am?
Patching and end-of-life software
The 14-day patching window mirrors Cyber Essentials, but claims data pushes insurers towards seven days for high-severity flaws. Unsupported software is the harder problem — a Windows Server 2012 box or an out-of-support firewall is a standing “no” on the form. If that is your situation, our guide to unsupported software and certification covers the remediation routes.
Privileged access and exposed remote services
Day-to-day accounts with permanent admin rights, shared administrator passwords and internet-facing RDP are the three findings that most reliably sour an underwriter. 73% of UK businesses already restrict admin rights in some form; the cyber insurance requirement is stricter — separate admin accounts, unique credentials, and remote administration only behind a VPN with MFA.
What Happens If Your Proposal Form Is Wrong
The controls are half the story. The other half is the legal machinery that connects your answers to your payout — and it is sharper than most buyers realise.
The duty of fair presentation
Under the Insurance Act 2015, a business buying insurance owes a duty of fair presentation: disclose every material circumstance you know or ought to know, and make sure representations of fact are substantially correct. “Ought to know” matters — it covers what a reasonable search of your own organisation would have revealed. Signing the form without asking your IT provider whether MFA genuinely covers everything is precisely the failure the Act contemplates — the duty reaches every cyber insurance requirement you attest to.
Travelers v ICS: the MFA case
The cautionary tale is American but the lesson travels. In 2022, US insurer Travelers asked a court to rescind a $1 million cyber policy after its policyholder, International Control Services, stated on its application that MFA protected email, remote access and servers — when in reality it protected only the firewall. Attackers came in through an unprotected admin account weeks after the policy began; the court entered judgment declaring the policy void from inception. The insured ended up with a ransomware bill and no insurance at all.
Why UK answers are representations, not warranties
English law is more proportionate, but not forgiving. Section 9 of the Insurance Act 2015 abolished basis-of-contract clauses, so your form answers cannot be silently converted into strict warranties. Instead the remedies scale with the breach: a deliberate or reckless misstatement about cybersecurity controls lets the insurer avoid the policy entirely and keep the premium; a careless one lets it reduce the claim proportionately or apply the terms it would have imposed. A firm that carelessly overstated its MFA coverage could see a £200,000 ransomware claim cut dramatically — legally, and with no regulator to appeal to.
Cyber Insurance Requirements and Cyber Essentials
Cyber Essentials is the natural starting point for meeting cyber insurance requirements, and insurers treat it as a meaningful signal. The NCSC notes that some insurers offer discounts for certified organisations, and its 2024 Annual Review reported a striking figure: organisations implementing the Cyber Essentials controls are 92% less likely to make a claim on their cyber insurance than those without. Yet only 5% of UK businesses hold the certification — one of the cheapest differentiators available.
| Area | Cyber Essentials requires | Insurers increasingly expect |
|---|---|---|
| Access control | User access control, MFA on cloud services | MFA on all remote access, email and admin accounts, plus PAM |
| Malware defence | Malware protection on devices | EDR or MDR with someone monitoring it |
| Updates | Security updates within 14 days | 7-day high-severity patching, no end-of-life systems |
| Backups | Not assessed | Offline or immutable copies with evidenced restore tests |
| Incident readiness | Not assessed | Written, rehearsed incident response plan |
The insurance included with certification
Any UK organisation with turnover under £20 million that certifies its whole organisation is automatically entitled to Cyber Liability Insurance arranged through the NCSC’s delivery partner IASME — a £25,000 limit of indemnity including a 24-hour incident helpline, crisis management and legal support. Certification itself starts at £320 plus VAT. The £25,000 will not survive a serious incident, but as a free floor under a £320 certificate it is remarkable value, and the certification also strengthens your answer to every cyber insurance requirement on a full proposal form.
Where Cyber Essentials stops
The table shows the gap. Backups, EDR and incident response — the three controls underwriters weight most heavily for ransomware — sit outside the certification entirely. Treat Cyber Essentials as the entry ticket, and the comparison in our Cyber Essentials Plus vs ISO 27001 guide as the map for what comes after it.
How Cyber Insurance Requirements Affect Your Premium
Here is the good news: you are buying in a falling market. Marsh’s Global Insurance Market Index recorded cyber rates down 4% in Q2 2026 — the twelfth consecutive quarterly decline — with UK composite rates down 8%. UK cyber claims fell 20% in 2024, and ransomware claims fell 31%. Insurers are competing for well-controlled risks, which means the controls in this guide convert directly into premium leverage.
| Business profile | Turnover | Cover limit | Indicative annual premium |
|---|---|---|---|
| Consultancy | £500k | £1m | £500–£750 |
| Building contractor | £1m | £1m | £500–£750 |
| Hotel | £5m | £2m | £3,000–£5,000 |
| Law firm | £2m | £5m | £7,500–£10,000 |
| Hardware assembly firm | £12m | £5m | £10,000–£12,500 |
Benchmarks from UK broker Get Indemnity’s 2026 tables. Taking the midpoint of each range — £625, £4,000, £8,750 and £11,250 for the four distinct profiles — shows how steeply price scales with data sensitivity and turnover rather than headcount.
What actually moves the price
Get Indemnity names the premium-reducing controls explicitly: MFA, immutable backups, EDR, patch management, encryption and privileged access controls — the same list as the cyber insurance requirements above, because they are the same calculation. The stakes on the claims side are equally concrete: Insurance Times reporting of Coalition’s 2026 claims report puts average claim severity at roughly £87,000, with ransomware incidents averaging about £202,000, and initial ransom demands up 47% in 2025 to over £1 million. Meanwhile 86% of businesses refused to pay — and well-backed-up firms could afford to refuse.
Meeting Cyber Insurance Requirements: A 90-Day Plan
Ninety days is enough to move from “declined or loaded premium” to “clean submission”, because most of the work is configuration and evidence rather than capital spend.
Days 1–30: find the gaps before the insurer does
Inventory every remote entry point, admin account, unsupported system and backup job, then score yourself honestly against the ten cyber insurance requirements above. An independent review pays for itself here — our breakdown of cyber security audit costs in the UK shows what that costs an SME. The audit output doubles as your disclosure record, which is exactly what the duty of fair presentation asks for.
Days 31–60: close the big five
Enforce MFA across remote access, email and admin accounts; deploy EDR to every endpoint; move backups to an immutable or offline pattern and run a restore test; patch or isolate anything end-of-life; strip standing admin rights and shut internet-facing RDP. A capable managed IT services provider can implement this set inside the window for a typical SME estate, and each item maps to a specific cyber insurance requirement you can now answer “yes” to truthfully.
Days 61–90: certify, document, rehearse
Take Cyber Essentials certification for the discount signal and the included £25,000 cover. Write the incident response plan and rehearse it once — a cyber tabletop exercise takes an afternoon and turns “do you have a tested plan?” into a documented yes. Then gather the evidence pack: MFA policy exports, EDR deployment reports, backup test logs, patching reports. Brokers confirm that submissions arriving with evidence attached get better terms than bare yes/no forms.
Cyber Insurance Requirements UK: FAQ
Will insurers refuse to quote without MFA?
Increasingly, yes — MFA on remote access, email and privileged accounts is the closest thing the market has to a universal cyber insurance requirement. Some insurers will still quote with exclusions or heavy co-insurance, but the pricing gap between “MFA everywhere” and “MFA partially” is now wide enough that fixing it first is almost always cheaper than insuring around it.
Is Cyber Essentials enough to satisfy cyber insurance requirements?
It satisfies some of them and signals seriousness — with a 92% lower likelihood of claiming, per the NCSC — but it does not cover backups, EDR or incident response, which underwriters weight heavily. Treat it as necessary rather than sufficient.
How much does cyber insurance cost a small UK business?
Benchmark data puts a £500k-turnover consultancy at £500–£750 a year for £1 million of cover, rising with turnover and data sensitivity. Rates fell through 2025 and 2026, so firms quoted harshly two years ago should re-approach the market with their improved controls.
What if we discover an answer on our form was wrong?
Tell your broker now, not at claim time. Under the Insurance Act 2015 remedies scale with culpability: corrected promptly, a mistake usually means adjusted terms; discovered during a claim, a careless answer can cut the payout proportionately and a reckless one can void the policy from inception, as the Travelers v ICS rescission showed.
We have some cyber cover in our office policy — is that enough?
Check the sub-limit and the services. Bundled cyber cover is commonly capped at a small fraction of the headline limit and includes no incident response retainer, no forensics and no negotiators. Given that 47% of UK businesses have some cover but only 10% hold a specific policy, this gap is the most common false sense of security in UK SME insurance.
References
Cyber Security Breaches Survey 2026 — GOV.UK
NCSC Cyber Essentials Overview
NCSC Annual Review 2024, Chapter 2
IASME Cyber Liability Insurance
Marsh McLennan Research: Cybersecurity Controls and Cyber Risk
Marsh Global Insurance Market Index Q2 2026
Marsh UK Cyber Insurance Claims Trend Report
Coalition 2026 Cyber Claims Report
Insurance Times: Initial Cyber Ransom Demands Grew 47% in 2025