Insight: What cyber insurers now require, and how to qualify
If your cyber insurance renews in the next few months, the questionnaire that lands on your desk will not look like the one you completed two years ago. It will be longer, it will ask for evidence rather than assurances, and the answers will form part of the contract.
Most firms of twenty to a hundred staff hand it to whoever looks after compliance or finance. They fill in what they can, ask IT about the rest at the last minute, and send it back. That worked when insurers accepted a tick in a box. It does not work now.
This post covers what insurers require, how Cyber Essentials Plus maps onto their questions, the answer that voids a claim, and how we handle all of it for our clients. One note before we start. We are not insurance brokers and this is not advice on what cover to buy. That is a conversation for your broker. Our job is the controls behind the answers and the evidence that proves them.
What changed
Underwriting used to run on a questionnaire. You confirmed you had a firewall and antivirus, the broker placed the cover, and nobody checked. Today underwriters want evidence: an export of the policy that enforces MFA, a device inventory showing every endpoint with EDR on it, a restore test with a date on it. Many now scan your domain and public-facing systems before quoting and compare what they find against what you declared.
Two things drove this. The first is loss experience. The US market paid out heavily through the ransomware years and tightened hard in response, with higher premiums, stricter conditions and more claims contested on the basis of what the applicant had said about their controls. The UK and Europe are far less litigious, but the direction of travel is the same and UK proposal forms now ask the same questions.
The second is the threat. AI has made attacks cheaper, faster and more convincing. Passkeys and better credential hygiene close one door, but there are plenty of others, and insurers know it. The volume of attempts against ordinary firms is rising, not falling.
The practical consequence is that answering the form is now more work, because the evidence has to be gathered, and carries more weight, because it is an attestation you are standing behind.
The controls insurers now expect
The list is consistent across UK insurers. The detail is where firms get caught, because a yes on the form means fully implemented across everything in scope, not mostly implemented.
Multi-factor authentication everywhere. Email, remote access, cloud applications holding confidential data, and every administrative account. If remote desktop is in scope, MFA on email does not cover it. SMS codes are increasingly rejected in favour of authenticator apps or hardware keys, and phishing-resistant methods on privileged accounts attract better terms.
Endpoint detection and response, not antivirus. Insurers want behaviour-based detection on every endpoint and server, with someone watching the alerts. They will ask for the product, the version and the percentage of devices covered. Laptops with EDR and servers without it is a no.
Tested backups. Backups a ransomware operator cannot reach, meaning immutable or offline, encrypted, and restored successfully on a known date. The date matters. A backup you have never restored is a hope, not a control.
A patching cadence. Critical and high-risk updates for operating systems, firmware and applications applied within fourteen days of release, with a documented process and a report to prove it.
Email filtering. Advanced phishing and malware filtering, and increasingly DMARC enforcement on your domain so that attackers cannot send email as you.
Least-privilege access. Nobody works day to day from an account with administrative rights. Admin accounts are separate, limited and reviewed. Leavers are removed promptly and provably.
A written and tested incident response plan. Who is called, in what order, with what authority, and when it was last rehearsed. This is also where your insurer's own requirements need to sit, which we come back to below.
Security awareness training. Annual at minimum, with records.
None of this is exotic. It is what a firm of twenty to a hundred staff handling client data should have regardless of insurance. The premium is the by-product.
How Cyber Essentials Plus maps onto the questionnaire
UK insurers rarely mandate Cyber Essentials by name. What they do is ask for the controls it certifies: boundary firewalls, secure configuration, access control including MFA, malware protection, and security update management. Put a proposal form next to the Cyber Essentials question set and the overlap is obvious.
The scheme tightened in April 2026. MFA is now mandatory for every cloud service where it is available, and failing to enforce it is an automatic fail. Two of the update management questions became automatic fails too: high-risk or critical updates for operating systems, router and firewall firmware, or applications that are not installed within fourteen days.
The difference between Cyber Essentials and Cyber Essentials Plus is the difference between telling and showing. Basic is a self-assessment. Plus adds an independent technical audit. An assessor tests a sample of your devices, checks the configuration, runs vulnerability scans and attempts to get malware past your defences. When you answer an insurer's questionnaire with Cyber Essentials Plus behind you, the core controls have already been verified by someone who does not work for you or for your IT partner.
Two things Cyber Essentials Plus does not cover, and insurers usually want on top: EDR and tested backups. It does not assess your incident response plan either. So the certificate gets you most of the way, and the remaining items are known and finite.
We have held Cyber Essentials Plus for over seven years and take our clients through it as standard.
The answer that voids a claim
The most useful thing to understand about a cyber insurance questionnaire is what it is in law.
Under the Insurance Act 2015, a business taking out or renewing commercial insurance owes the insurer a duty of fair presentation. In plain terms: disclose every material circumstance you know or ought to know, present it clearly, and make a reasonable search of the information held inside your own organisation before you do. A material circumstance is anything that would influence a prudent insurer in deciding whether to take the risk and on what terms. Whether MFA is enforced is material by any measure.
If the duty is breached and the insurer can show it would not have written the policy, or would have written it on different terms, it has remedies. Where the breach was deliberate or reckless, the insurer can avoid the policy from the start, refuse every claim and keep the premium. Where it was careless rather than reckless, the remedy is proportionate, which can still mean a reduced payout or different terms applied after the fact.
Two cases show how this plays out. In the US, a manufacturer called International Control Services told its insurer it used multi-factor authentication for administrative and privileged access. After a ransomware attack, the insurer found MFA was deployed on the firewall and nowhere else. The application had been signed by the CEO and by the person responsible for network security. The policy was declared void from inception in 2022 and the claim, around a million dollars, was never paid. Nobody suggested fraud. Someone ticked a box they did not fully understand.
Closer to home, in Berkshire Assets (West London) v AXA the High Court upheld an insurer's right to avoid a policy for breach of the duty of fair presentation. Different facts, same principle. A material circumstance was not disclosed, the insurer showed it would not have written the risk, and the policy fell away. Avoidance is a live remedy in English courts, not an American curiosity.
Now consider how the form usually gets filled in. Someone in compliance completes what they can. They guess at a few. They ask IT about the rest at the last minute and it goes back in a hurry. The box for MFA enforced by policy is ticked because there is a policy document that says so. Nobody has opened the tenant and checked the conditional access rule. The policy exists on paper. The control does not exist in the environment.
That is the gap that voids claims: the distance between the questionnaire and the configuration. And the person signing the form usually cannot close it personally, because the systems being described are administered by their IT provider. Our IT company said it was fine is not a reasonable search.
When you find a gap you cannot close before the deadline, there are three honest options. Close the control now. Disclose the gap with a dated remediation plan. Or renegotiate the term with your broker. The fourth option, answer yes and hope nobody checks, is the one that produced a void policy in Illinois.
Your IT provider is on the form too
Look closely at a current UK proposal form and you will find a section on third parties. CFC's asks whether any of your IT infrastructure is outsourced and, if so, to list your critical technology providers with a summary of what each does for you. It asks who monitors your EDR, an internal team or an outsourced one. Chubb's UK form has a third-party risk management section and asks about incidents affecting a provider of yours.
Insurers ask because an IT provider is a concentration risk. One compromise of a provider's remote management platform or privileged credentials can hit every client at once. So the underwriter is assessing your IT partner whether or not you have.
Three questions are worth putting to your provider before you sign your own form. What professional indemnity and cyber cover do they hold, and are the limits per claim or in the aggregate across all their clients. What does the liability cap in your contract with them say, because a two million pound insurance limit means little if the agreement caps recovery at three months of fees. And are their own controls externally certified, or self-declared.
We are increasingly seeing well-advised clients write minimum insurance levels into their IT contracts. That is a sensible development and we will cover it properly in a separate post on what insurance your IT provider should carry.
How we handle this for our clients
Completing these forms is part of our cyber security service, not an extra. At least once a year we expect to sit down with each client and work through their cyber insurance renewal, often their wider business insurance too, and the due diligence questionnaires that arrive from prospective clients, business partners, lenders and regulators. Regulated or not, every firm we work with gets these, and they come at inconvenient times.
The first pass is the hard one. After that the client holds a library of stock answers with the evidence behind each, and understands what the questions are really asking. The next questionnaire takes an hour rather than a week.
Before anything is signed, we verify each answer against what is actually configured. Not the policy document, the tenant. If the form says MFA is enforced, we produce the conditional access export that shows it. If it says backups are tested, we produce the restore report with the date on it. Where the answer would be no, we say so, and the client decides between fixing it, disclosing it or renegotiating.
Every questionnaire finds something. Sometimes it is a quick fix. Sometimes it pulls a thread and turns into a project that surfaces other issues. Either way it feeds a rhythm of steady improvement around privacy, confidentiality and security, which is what resilient systems look like in practice.
At onboarding, and again at regular planning meetings, we take a copy of the client's cyber policy. Most policies set out who must be notified in an incident, how quickly, and which incident response firms may be used. Call the wrong people first and you can breach a policy condition before the incident is an hour old. So the insurer's hotline and notification requirements go into the incident response plan alongside ours, and the whole thing folds into business continuity planning.
Before your next renewal
Ask your IT partner for the evidence behind every answer on the form before you sign it: the MFA policy export, the EDR device inventory including servers, the dated restore test, the patch compliance report, the incident response plan with a rehearsal date. If they can produce it in a day, your renewal will be straightforward. If they cannot, you have learned something more important than your premium.
If you would rather talk it through, book a no-strings discovery call.

