Cyber insurance went through the same evolution as fire insurance a century earlier: first they insured anyone, then the claims arrived, and now they inspect the building. A market that once sold SME cyber policies on a company name and a turnover figure has hardened into one that asks detailed technical questionnaires, prices sharply against the answers, attaches conditions to cover, and (the part that surprises businesses at the worst moment) scrutinises those answers again when a claim lands.
That shift makes insurer requirements a de facto security standard for UK SMEs, arriving through the renewal paperwork rather than any regulator. Here is what insurers now ask for, why each item is on the list, and how to handle the questionnaire so the policy you buy is one that will actually pay.
The control checklist insurers converge on
Questionnaires vary by insurer, but the core list has standardised remarkably, because it tracks what actually drives claims:
- Multi-factor authentication, on email, remote access and admin accounts at minimum, increasingly “on all cloud services”. The single most universal question, often a binary gate: some insurers simply decline unenrolled MFA estates. The rollout guide exists for exactly this moment.
- Endpoint detection and response (EDR), asked about by name and displacing “do you have antivirus”. Monitored EDR answers both the letter and the spirit.
- Backups: offsite, offline-or-immutable, and tested, with questionnaires now probing frequency, separation from the network, and when a restore was last verified: the 3-2-1-1-0 shape, because backups determine whether ransomware claims are five-figure or six-figure events.
- Patching discipline, typically framed as critical updates within 14 days: the same clock as Cyber Essentials.
- Security awareness training, with simulated phishing programmes as the strong answer, since phishing initiates the plurality of claims.
- An incident response plan, documented, with some policies requiring the insurer’s hotline be engaged before remediation: the sequencing our IR template bakes in.
- End-of-life software absent (unsupported Windows in the estate is a common declinature or exclusion trigger; the Windows 10 arithmetic has an insurance line in it), plus payment-verification procedures where funds transfer is part of the business.
Businesses holding Cyber Essentials certification will recognise most of the list, which is why certification smooths renewals: it is pre-packaged evidence for two-thirds of the questionnaire, and basic certification through the scheme even includes a modest cyber liability element for eligible smaller firms.
How the answers price the policy
Three mechanisms translate the questionnaire into money:
Premium loading. Strong controls have moved from discount material to baseline; the pricing now works downward, with gaps loading the premium sharply or narrowing the market willing to quote at all.
Conditions and exclusions. Weak answers return as policy language: ransomware sub-limits, co-insurance percentages on cyber events, or exclusions for incidents traceable to the disclosed gap. The policy exists; the cover has holes shaped exactly like your questionnaire.
Claims scrutiny. The mechanism with teeth: answers are warranties in most policy structures, and a claim investigation that finds the declared MFA absent from the breached account, or the “tested backups” untested since purchase, gives the insurer grounds to reduce or repudiate. The market’s public disputes have overwhelmingly followed this pattern: not exotic small print but ordinary questions answered optimistically.
The practical rule that follows: the questionnaire is a compliance document, not a sales form. Answer what is true today, and where the true answer is weak, fix the control before renewal rather than gilding the form: the fix usually costs less than the loading, and infinitely less than a repudiated claim.
Handling renewal properly
The sequence we run with clients, worth adopting even unaided:
- Get the questionnaire early and treat it as an audit checklist against your actual estate, not a form-filling afternoon.
- Close the cheap gaps first: MFA completion, number-matched authenticators, backup test with a logged result, the IR plan written. Days of work, material premium difference.
- Evidence everything claimed: screenshots, reports, test logs, certification. The file that satisfies the underwriter also wins the argument if a claim is ever examined.
- Read the conditions as operational duties: notification windows, approved-responder requirements, maintenance warranties. Your incident plan must reflect them, because breaching a condition mid-incident is how valid claims die.
- Diarise the delta: anything you promised to implement gets an owner and a date, because next year’s questionnaire remembers.
Frequently asked questions
What do cyber insurers require in 2026?
The convergent list: MFA everywhere that matters, monitored EDR, offsite-and-immutable tested backups, 14-day patching, staff phishing training, a documented incident response plan, no end-of-life software, and payment-verification procedures. Gaps price in as loadings, conditions or declinature.
Does Cyber Essentials satisfy cyber insurance requirements?
It covers most of the technical checklist and serves as strong evidence, and certification through the scheme includes a modest liability element for eligible smaller organisations. Insurers typically still ask their own questions (EDR and backup testing especially), but certification converts the renewal from interrogation to confirmation.
Can an insurer refuse to pay a cyber claim?
Where investigation shows questionnaire answers were untrue when given, or policy conditions were breached (controls lapsed, notification late, unapproved remediation), yes: reductions and repudiations on exactly those grounds are the market’s recurring dispute pattern. Truthful answers and maintained controls are the entire defence.
Is cyber insurance worth it for a small business?
As risk transfer for the costs that survive good controls (forensics, notification, business interruption, liability): generally yes, priced honestly. As a substitute for the controls themselves: no, and the market has structured itself to make that substitution impossible.
Will our premium drop if we improve security?
Usually, and sometimes sharply: the market prices the questionnaire, so moving answers from no to evidenced-yes (MFA completion, EDR, tested immutable backups) routinely pays for the improvements within a renewal cycle or two, before counting the risk reduction itself.
Who should fill in the cyber insurance questionnaire?
Whoever can answer truthfully with evidence: in practice, your IT provider drafting the technical answers with the business owner reviewing and signing. The signature warrants the contents; guessing is the one approach with no upside.
Get the questionnaire answered with evidence
Bring us your renewal questionnaire (or last year’s) and the free IT health check will map every question to your actual estate: what is evidenced-true, what is aspiration, and what each gap costs to close versus carry. Get in touch before the renewal date does the scheduling for you.