Skip to main content
Dig IT Solutions logo

Cyber Security

Cyber insurance IT requirements: what UK insurers now ask for

What UK cyber insurers now require before covering a small business: MFA, EDR, backups, patching and an incident plan, and how to answer honestly.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

UK cyber insurers now expect multi-factor authentication on email, remote access and admin accounts, endpoint detection and response on every device, backups that are offline or immutable and tested, patching within a defined window, no unsupported software, and a written incident response plan. Answer the proposal form accurately, because a misstatement can void the policy when you claim.

Cyber insurance proposal forms have changed from a page of tick boxes to detailed questionnaires about specific technical controls. Insurers have paid out heavily on ransomware and email fraud, and they now set conditions before they will cover a business of any size. This guide explains what they ask for, why, and how to answer without creating a problem at claim time.

Why insurers ask what they ask

Every question on a cyber proposal form corresponds to a type of claim the insurer has paid. Business email compromise and payment diversion fraud drive the questions about MFA and email security. Ransomware drives the questions about endpoint detection, backups and patching. Long recovery times drive the questions about incident plans and tested restores.

The GOV.UK Cyber Security Breaches Survey shows that around four in ten UK businesses identify an attack or breach each year and that phishing is the most common type, which matches what insurers see in their claims data. The NCSC publishes guidance on cyber insurance that is worth reading before you buy.

The controls insurers now expect

The table below reflects what UK proposal forms for businesses of 10 to 250 people typically ask. Individual insurers vary, but the pattern is consistent.

ControlWhat the form asksWhat insurers usually expect
Multi-factor authenticationIs MFA enforced on email, remote access, admin accounts and cloud services?Enforced for every user, no exceptions, including shared mailboxes and directors
Endpoint detection and responseWhich EDR product runs on servers and workstations, and is it monitored?A named EDR product on every device, with someone watching alerts
BackupsFrequency, offline or immutable copy, last tested restore, Microsoft 365 backupDaily backups, at least one copy ransomware cannot reach, restore tested within the year
PatchingHow quickly are critical patches applied to operating systems and applications?Critical patches within 14 days, all others within a month, managed centrally
Unsupported softwareAny end-of-life operating systems or applications in use?None, or isolated from the network with a documented plan
Email securityFiltering, SPF, DKIM, DMARC, impersonation protectionAll in place, with DMARC at least in monitoring mode
Privileged accessAre admin accounts separate from daily accounts, and how many admins?Named admin accounts, few of them, used only for admin
Remote accessHow do staff connect remotely?VPN or cloud access protected by MFA, no exposed remote desktop
Incident response planIs there a written plan, and has it been tested?A short written plan naming who does what, reviewed annually
Staff trainingHow often, and is phishing simulation used?At least annually, with evidence
Funds transfer controlsAre bank detail changes verified out of band?A written process with a phone call on a known number

Businesses that already meet Cyber Essentials cover a large part of this list. Certification through IASME also comes with included cyber liability insurance for organisations with turnover under £20 million, at a modest limit, which is not a substitute for a full policy but does show insurers the basics are in place.

The four controls that decide most applications

MFA everywhere. The most common reason for a declined application or an excluded claim is MFA that is "on" but not enforced. Microsoft 365 tenants often have MFA enabled for most users while a director, a scanner mailbox or a legacy protocol slips through. Insurers ask about enforcement, and a claim investigation will check the sign-in logs.

EDR, not antivirus. Insurers want to know that an attack on a laptop at 2am will be detected and the machine isolated. Traditional antivirus does not do that. Ask your provider which EDR product runs on every device, whether servers are covered, and who receives the alerts. Our endpoint security page explains the difference.

Backups ransomware cannot reach. A backup on a drive that is always connected, or a cloud sync that mirrors deletions, is encrypted along with everything else. Insurers ask for an offline or immutable copy and for evidence of a tested restore. Microsoft 365 data needs its own backup, because the platform does not provide one in the sense the form means.

Patching with a number attached. "We keep things up to date" is not an answer. Insurers want a window, typically 14 days for critical patches, and a mechanism, typically remote monitoring and management that applies updates centrally and reports on what is missing.

How to answer the questionnaire honestly

The Insurance Act 2015 places a duty of fair presentation on commercial policyholders. If a claim reveals that a control described on the form was not actually in place, the insurer can reduce the payout or void the policy. Deliberate misstatements void it entirely. Careless ones can still cost the claim.

Practical rules:

  1. Answer from evidence, not memory. Before ticking "MFA enforced", get a report from the tenant showing every user's status. Before ticking "backups tested", find the date and the result of the last restore.
  2. Involve your IT provider. They should complete the technical sections with you and be able to produce the reports behind each answer. A provider who cannot do this is telling you something.
  3. Say no where the answer is no. A "no" with a date by which the control will be in place usually leads to a condition or a slightly higher premium. A wrong "yes" leads to no cover.
  4. Keep the evidence. Save the reports you used to answer, dated, with the policy documents. At claim time you will be asked to show that the position on the form was true on the day.
  5. Read the conditions. Some policies make cover conditional on specific controls remaining in place through the year. If EDR lapses or MFA is switched off for a user, the condition is breached.

Preparing for renewal

Renewal is easier if the review happens two months before the form arrives. A short process:

  • Pull the MFA, patching and EDR coverage reports and fix the exceptions.
  • Test a restore and record the result.
  • Check for end-of-life software and either remove it or isolate it with a plan.
  • Review admin accounts and remove any that are not needed.
  • Update the incident response plan and walk through it with the people named in it.
  • Run a phishing awareness session and keep the attendance record.

Each of these is routine for a business on a managed contract with monitoring and patching in place. For a business without one, it is a useful list of what a provider should be doing. Our cyber security services cover the controls above, and the review itself is what our IT health check is designed to produce.

What insurance does not replace

Cover pays for recovery, legal costs and some losses. It does not restore client confidence, recover a completion payment that has already left the country, or shorten the days a business spends without its systems. The controls insurers ask for are the ones that prevent most incidents in the first place, which is why the application process, done honestly, is worth more than the policy.

What to do next

If you are unsure whether MFA is enforced for every user, which EDR product runs on your devices, or when a restore was last tested, find out before the proposal form arrives rather than after. Book an IT health check and we will report against the insurers' typical requirements, with the evidence you need to answer each question accurately.

Frequently asked questions

Is MFA mandatory for cyber insurance in the UK?
Most UK cyber insurers now treat multi-factor authentication on email, remote access and privileged accounts as a condition of cover for businesses of any size. Some will decline to quote without it, others exclude claims arising from accounts that lacked it. If your proposal form says MFA is enforced, it must be enforced for every user, including directors and shared mailboxes, not just switched on for most.
What counts as EDR for insurance purposes?
Endpoint detection and response is security software that monitors behaviour on each device and can isolate a machine when it detects an attack, rather than simply scanning files for known malware. Insurers distinguish it from traditional antivirus and ask which product you run and whether it is monitored. Built-in antivirus on its own is usually not accepted as EDR.
What backup requirements do cyber insurers set?
Insurers typically ask whether backups exist for all critical data, whether at least one copy is offline, immutable or otherwise separated from the main network so ransomware cannot encrypt it, how often backups run, and when a restore was last tested. Cloud backups of Microsoft 365 count only if they are independent of the Microsoft tenant.
What happens if we answer the cyber insurance questionnaire wrongly?
Under the Insurance Act 2015, businesses owe a duty of fair presentation to insurers. If a claim reveals that a control described in the proposal form was not in place, the insurer may reduce the payout or void the policy, depending on whether the misstatement was careless or deliberate. Honest answers that show gaps lead to conditions or a higher premium. Wrong answers lead to no cover when you need it most.
Does Cyber Essentials help with cyber insurance?
Yes. Cyber Essentials certification covers many of the controls insurers ask about, and UK organisations with turnover under £20 million that certify receive included cyber liability insurance with a modest limit from IASME. Insurers also treat certification as evidence that the basics are in place, which can simplify the questionnaire and improve the premium, though it does not replace the proposal form.
How often do insurers reassess IT requirements?
Annually at renewal, and the questions get more detailed each year. Businesses that were accepted with basic antivirus a few years ago are now being asked for EDR, immutable backups and privileged access management. Reviewing your controls a couple of months before renewal, rather than the week the form arrives, gives time to close gaps and answer accurately.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us