Compliance

Cyber insurance: what insurers actually check before they'll pay out

A checklist document with a shield badge, representing the security controls an insurer checks on a cyber insurance proposal form

A cyber insurance proposal form is really a list of questions about your IT setup, and every answer has to be true, not just true on the day you signed up. Get a question wrong and the policy might still cost the same. Get a claim wrong, because what you told the insurer stopped being accurate somewhere along the way, and you can find out the hard way that the cover you thought you had never actually applied.

Just over half of UK small businesses now carry some form of cyber insurance. Most never read the small print on what has to stay true to keep it.

What's actually on the form

A cyber insurance proposal form isn't really about your industry or your turnover, though those show up too. It's mostly a checklist of specific technical controls, phrased as yes/no questions: is multi-factor authentication switched on across your cloud services, is there an endpoint detection and response product running, are backups tested rather than just taken, is admin access limited to the people who actually need it. Colin Fox, a cyber insurance consultant at Integrity/Hayes Parsons, names MFA, least-privilege access, EDR and privileged access management as the controls that come up first, in that rough order, in the underwriting conversations he has.

None of that is exotic. It's the same short list most managed IT providers, including us, already treat as a baseline. The difference is that an insurer isn't taking your word for it as a courtesy. It's the thing they're pricing the risk against.

Why the bar moved

A few years ago, "we run antivirus" was often enough to get a quote. It isn't any more. Selorm Kofi Domeh, a broking manager at Talbot Jones, told Insurance Business UK that a business applying without MFA now gets "probably an outright no" from most insurers, where the same gap used to mean a slightly higher premium rather than a straight decline. Colin Fox puts it more bluntly: insurers still writing cover without MFA in place are "quite a rarity" now.

The reason is unglamorous. Ransomware claims cost insurers real money for several years running, and a lot of those claims came from businesses with none of the basics in place. Underwriting tightened because paying out kept teaching the same lesson.

NCSC's seven questions, before you sign anything

NCSC's own cyber insurance guidance doesn't tell you which insurer to pick. It gives you seven questions to work through before you buy, and they're worth having in front of you at renewal too, not just at first purchase:

  • What existing cyber security defences do you already have in place?
  • How do you bring the right expertise together to assess a policy?
  • Do you fully understand the potential impact of a cyber incident on your business?
  • What does the policy actually cover, and just as importantly, what does it exclude?
  • What cyber security services come bundled with the policy, and do you need them?
  • Does it include support during or after an incident, not just a payout afterwards?
  • What has to stay true and in place for you to claim against it, or renew it?

NCSC is upfront that insurance won't instantly solve your security issues and won't prevent a breach in the first place. It's there for the financial aftermath, not as a substitute for the controls themselves.

What gets a claim refused

Two things, mainly. The first is the misrepresentation problem covered above: your answers on the form have to keep being true, and insurers reassess that picture every year, not just once. The second is coverage gaps that nobody checked for at the time. Ethan Godlieb, an associate partner at Consilium Insurance Brokers, estimates cybercrime makes up around 30% of the claims he sees, and that human error sits somewhere in the chain of roughly 95% of attacks generally. Money moved by an employee who was convinced they were paying a real supplier is a common example, and it sits closer to fraud than to a technical breach in how some policies are written. Godlieb's advice for any business that pays suppliers by invoice is a standalone crime policy with a social-engineering extension, on top of the core cyber cover, because the two aren't automatically the same thing. Our article on invoice fraud goes into how those scams actually work.

Where Cyber Essentials fits, and where it doesn't

Cyber Essentials and cyber insurance underwriting cover a lot of the same ground, but they aren't the same list. CE's five controls, firewalls, secure configuration, patch management, user access control and malware protection, overlap heavily with what a proposal form asks. Endpoint detection and response doesn't sit inside CE's scope at all, despite being one of the controls brokers describe as close to mandatory now. Some insurers do offer a premium discount for holding the certification, though it isn't universal and shouldn't be assumed. We don't hold Cyber Essentials at Alpha IT ourselves, so this is a factual note about the market, not us pointing at a badge we're wearing.

What this looks like against a real questionnaire

Set our own three support tiers against a typical proposal form and the gap is visible fast. Essential, at £50 a user a month, covers patch management and endpoint antivirus, which answers some of the form but not most of it. Professional, at £77, adds EDR, managed backup with tested restores, and email security, which is closer to what Daniel Winn, a development broker at Jensten London Markets, describes as increasingly expected for a full quote. Complete, at £108, adds SIEM and log retention, managed detection and response, compliance reporting and an annual disaster-recovery test, which is the territory Winn says starts to matter specifically for higher cover limits, the £5-10 million range he works in most.

None of that is us selling insurance. It's just what the same list looks like from the other side of the questionnaire.

Getting insurance-ready without buying anything yet

Start before you're staring at a renewal deadline. Pull together what you can currently prove, not just what you believe: when backups were last restored and tested, not just backed up; who has admin rights and why; whether MFA covers every cloud account or just some of them. A gap you find in July is a Tuesday afternoon fix. The same gap found by a claims assessor after an incident is a different conversation entirely.

We're not brokers, and picking a policy is a conversation to have with one. But if you want an honest read on where the technical gaps actually are before a proposal form finds them for you, a free IT health check covers exactly that.

Frequently asked questions

Do we need cyber insurance if our security is already good?+

Different job, not a replacement. NCSC's own guidance is direct about this: insurance will not instantly solve your cyber security issues and it will not prevent a breach. What it can do is stop a bad week becoming a bad year financially. Just over half of UK small businesses now carry some form of cyber cover, per the government's 2025/2026 breaches survey, and that's usually a decision made after doing the maths on what a fortnight of downtime or a six-figure ransom demand would actually cost against the premium.

What controls do insurers actually ask about before they'll quote?+

MFA is the one broker after broker names first. Colin Fox, a cyber insurance consultant at Integrity/Hayes Parsons, has described it as "top of the list" alongside least-privilege access, endpoint detection and response, and privileged access management, and says only a small handful of insurers will still write a policy without it. Patch management, malware protection and tested backups sit close behind. A proposal form is really that list turned into yes/no questions, and every yes has to be true, not aspirational.

Can an insurer refuse to pay out because our security wasn't what we said?+

Yes, and this is the part people skip past. NCSC's guidance flags directly that misrepresenting your security posture on a proposal form can affect whether a claim gets paid, and insurers reassess the picture at every renewal, not just when you first signed up. If MFA was switched on for the application and quietly turned off six months later because it annoyed someone in accounts, that gap is exactly the kind of thing that surfaces during a claims investigation.

Does holding Cyber Essentials get us a cheaper policy?+

Some insurers offer a discount for it, though that varies insurer to insurer and isn't universal. Worth knowing too: Cyber Essentials' five controls don't fully overlap with what a modern proposal form asks. Endpoint detection and response, for instance, sits outside CE's scope even though several of the brokers above name it as close to mandatory now. Alpha IT does not hold Cyber Essentials itself, so treat this as a factual note to check with a broker, not a pitch.

What's commonly not covered that people assume is?+

Money moved out of the business by an employee who was tricked, rather than stolen through a technical break-in, is the big one. Ethan Godlieb, an associate partner at Consilium Insurance Brokers, puts cybercrime at roughly 30% of the claims he sees and human error at the root of around 95% of attacks generally, and recommends a standalone crime policy with a social-engineering extension for any business that moves money by invoice. Our business email compromise article covers how those frauds actually work.

Is MFA really mandatory to get any cover at all?+

For a full quote at a reasonable price, it's close to it. Selorm Kofi Domeh, a broking manager at Talbot Jones, told Insurance Business UK that going without MFA now gets "probably an outright no" from most insurers he deals with, where a few years ago it might just have meant a higher premium. Cheaper micro-business policies with lighter underwriting still exist, but the direction of travel across the market is the same either way.

Can Alpha IT get us ready for an insurer's questionnaire?+

We're not brokers and we don't sell insurance, so the policy itself is a conversation for one. But the controls a questionnaire asks about, MFA, EDR, tested backups, patch cadence, are exactly what we set up and monitor day to day, and our Professional and Complete plans already cover most of that list. A free IT health check will tell you honestly where the gaps are before an insurer's questions find them for you.

Call usFree consultation