Cyber Security
Cyber insurance IT requirements: what UK insurers now ask for
What UK cyber insurers now require before covering a small business: MFA, EDR, backups, patching and an incident plan, and how to answer honestly.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
UK cyber insurers now expect multi-factor authentication on email, remote access and admin accounts, endpoint detection and response on every device, backups that are offline or immutable and tested, patching within a defined window, no unsupported software, and a written incident response plan. Answer the proposal form accurately, because a misstatement can void the policy when you claim.
Cyber insurance proposal forms have changed from a page of tick boxes to detailed questionnaires about specific technical controls. Insurers have paid out heavily on ransomware and email fraud, and they now set conditions before they will cover a business of any size. This guide explains what they ask for, why, and how to answer without creating a problem at claim time.
Why insurers ask what they ask
Every question on a cyber proposal form corresponds to a type of claim the insurer has paid. Business email compromise and payment diversion fraud drive the questions about MFA and email security. Ransomware drives the questions about endpoint detection, backups and patching. Long recovery times drive the questions about incident plans and tested restores.
The GOV.UK Cyber Security Breaches Survey shows that around four in ten UK businesses identify an attack or breach each year and that phishing is the most common type, which matches what insurers see in their claims data. The NCSC publishes guidance on cyber insurance that is worth reading before you buy.
The controls insurers now expect
The table below reflects what UK proposal forms for businesses of 10 to 250 people typically ask. Individual insurers vary, but the pattern is consistent.
| Control | What the form asks | What insurers usually expect |
|---|---|---|
| Multi-factor authentication | Is MFA enforced on email, remote access, admin accounts and cloud services? | Enforced for every user, no exceptions, including shared mailboxes and directors |
| Endpoint detection and response | Which EDR product runs on servers and workstations, and is it monitored? | A named EDR product on every device, with someone watching alerts |
| Backups | Frequency, offline or immutable copy, last tested restore, Microsoft 365 backup | Daily backups, at least one copy ransomware cannot reach, restore tested within the year |
| Patching | How quickly are critical patches applied to operating systems and applications? | Critical patches within 14 days, all others within a month, managed centrally |
| Unsupported software | Any end-of-life operating systems or applications in use? | None, or isolated from the network with a documented plan |
| Email security | Filtering, SPF, DKIM, DMARC, impersonation protection | All in place, with DMARC at least in monitoring mode |
| Privileged access | Are admin accounts separate from daily accounts, and how many admins? | Named admin accounts, few of them, used only for admin |
| Remote access | How do staff connect remotely? | VPN or cloud access protected by MFA, no exposed remote desktop |
| Incident response plan | Is there a written plan, and has it been tested? | A short written plan naming who does what, reviewed annually |
| Staff training | How often, and is phishing simulation used? | At least annually, with evidence |
| Funds transfer controls | Are bank detail changes verified out of band? | A written process with a phone call on a known number |
Businesses that already meet Cyber Essentials cover a large part of this list. Certification through IASME also comes with included cyber liability insurance for organisations with turnover under £20 million, at a modest limit, which is not a substitute for a full policy but does show insurers the basics are in place.
The four controls that decide most applications
MFA everywhere. The most common reason for a declined application or an excluded claim is MFA that is "on" but not enforced. Microsoft 365 tenants often have MFA enabled for most users while a director, a scanner mailbox or a legacy protocol slips through. Insurers ask about enforcement, and a claim investigation will check the sign-in logs.
EDR, not antivirus. Insurers want to know that an attack on a laptop at 2am will be detected and the machine isolated. Traditional antivirus does not do that. Ask your provider which EDR product runs on every device, whether servers are covered, and who receives the alerts. Our endpoint security page explains the difference.
Backups ransomware cannot reach. A backup on a drive that is always connected, or a cloud sync that mirrors deletions, is encrypted along with everything else. Insurers ask for an offline or immutable copy and for evidence of a tested restore. Microsoft 365 data needs its own backup, because the platform does not provide one in the sense the form means.
Patching with a number attached. "We keep things up to date" is not an answer. Insurers want a window, typically 14 days for critical patches, and a mechanism, typically remote monitoring and management that applies updates centrally and reports on what is missing.
How to answer the questionnaire honestly
The Insurance Act 2015 places a duty of fair presentation on commercial policyholders. If a claim reveals that a control described on the form was not actually in place, the insurer can reduce the payout or void the policy. Deliberate misstatements void it entirely. Careless ones can still cost the claim.
Practical rules:
- Answer from evidence, not memory. Before ticking "MFA enforced", get a report from the tenant showing every user's status. Before ticking "backups tested", find the date and the result of the last restore.
- Involve your IT provider. They should complete the technical sections with you and be able to produce the reports behind each answer. A provider who cannot do this is telling you something.
- Say no where the answer is no. A "no" with a date by which the control will be in place usually leads to a condition or a slightly higher premium. A wrong "yes" leads to no cover.
- Keep the evidence. Save the reports you used to answer, dated, with the policy documents. At claim time you will be asked to show that the position on the form was true on the day.
- Read the conditions. Some policies make cover conditional on specific controls remaining in place through the year. If EDR lapses or MFA is switched off for a user, the condition is breached.
Preparing for renewal
Renewal is easier if the review happens two months before the form arrives. A short process:
- Pull the MFA, patching and EDR coverage reports and fix the exceptions.
- Test a restore and record the result.
- Check for end-of-life software and either remove it or isolate it with a plan.
- Review admin accounts and remove any that are not needed.
- Update the incident response plan and walk through it with the people named in it.
- Run a phishing awareness session and keep the attendance record.
Each of these is routine for a business on a managed contract with monitoring and patching in place. For a business without one, it is a useful list of what a provider should be doing. Our cyber security services cover the controls above, and the review itself is what our IT health check is designed to produce.
What insurance does not replace
Cover pays for recovery, legal costs and some losses. It does not restore client confidence, recover a completion payment that has already left the country, or shorten the days a business spends without its systems. The controls insurers ask for are the ones that prevent most incidents in the first place, which is why the application process, done honestly, is worth more than the policy.
What to do next
If you are unsure whether MFA is enforced for every user, which EDR product runs on your devices, or when a restore was last tested, find out before the proposal form arrives rather than after. Book an IT health check and we will report against the insurers' typical requirements, with the evidence you need to answer each question accurately.

