CONTACT

What Security Controls Do Cyber Insurers Require

cyber insurance requirements

If your cyber insurance is up for renewal, the proposal form will ask detailed questions about your security. This guide explains what insurers ask for and what evidence you need.

Cyber insurance requirements now cover specific security controls. Underwriters ask for evidence of multi-factor authentication, endpoint detection, tested backups and regular patching, and weak answers can cost you cover or better terms.

Most cyber insurance requirements come down to a short list: MFA on remote and privileged access, endpoint detection and response, backups you’ve tested by restoring, documented patching and an incident response plan. Each honest “no” on the proposal form is work you need to do.

What Are the Cyber Insurance Requirements Underwriters Ask About?

Underwriters ask about the controls you actually have in place. The NCSC says buying a policy “might require providing information about your security controls”, covering technical, procedural and human measures. Your answers can also be checked when you make a claim, not just when you get a quote.

In the forms clients send to Transputec, the same six areas come up almost every time. So it’s worth treating the form as a working document, not a box-ticking exercise.

Why Does the Proposal Form Matter More Than the Policy?

Because it’s often the only time you have to describe your security honestly, in writing, with money depending on the answers. Many organisations have never been asked by a third party whether MFA covers every remote user, or whether a backup has actually been restored. The proposal form asks both.

Use the answers to plan your work. If you treat your cyber insurance requirements as a to-do list, you’ll have fewer surprises at renewal.

Renewing Your Cyber Insurance?

Transputec's cyber security services cover the MFA, endpoint detection, patching and backup work that insurers ask about. Talk to our team about the security work behind your next renewal.

Get a Strategic Consultation

What Security Controls Do Cyber Insurers Require in the UK?

The cyber insurance requirements on almost every UK proposal form fall into six areas: identity, endpoint, backup, patching, email and response. Insurers word them differently, but they’re asking the same questions, and for each one you either have the evidence or you don’t.

What the insurer asksWhat actually evidences it
Is MFA enforced on remote access, email and admin accounts?Conditional access policies, with per-user enforcement reporting
Do you run endpoint detection and response?EDR or MDR console coverage report across all endpoints
Are backups tested and isolated from production credentials?A dated restore test, not a backup job success log
How quickly are critical patches applied?Patch compliance reporting against a stated cadence
Is email filtered for phishing and malware?Gateway configuration and quarantine reporting
Do you have an incident response plan?A written plan with named roles, and evidence it has been exercised

The right-hand column is where most organisations struggle. These cyber insurance security controls are rarely missing completely. More often they’re in place but can’t be proven.

Do Cyber Insurers Require MFA?

In practice, yes. Insurers now expect multi-factor authentication as standard, and an insurer MFA requirement usually covers remote access, webmail and privileged accounts, not only administrators. The common failure is partial rollout: MFA for head office staff but not contractors, or on email but not the VPN.

Of all the cyber insurance requirements, this is the one underwriters are least willing to negotiate on. Gaps usually sit in service accounts and older protocols that are hard to change. If you’re not sure where yours are, our guide to why multi-factor authentication matters covers how to enforce it, and identity work is part of our Microsoft 365 services.

Does Cyber Essentials Reduce Cyber Insurance Premiums?

Not automatically. The NCSC says “some insurers offer discounts if your organisation already has recognised cyber security defences in place (such as those certified by Cyber Essentials, or Cyber Essentials Plus)”. That means some insurers, not all, and there’s no set percentage.

The more reliable benefit is different. Cyber Essentials covers firewalls, secure configuration, security update management, user access control and malware protection, which is most of what the proposal form asks about. Certification may not make your policy cheaper, but it means you can answer the questions. That’s why cyber essentials for insurance is worth doing anyway, and our breakdown of the five Cyber Essentials controls explains each one.

One thing to know: the current Danzell question set and Requirements v3.3 made 14-day patching for high-risk and critical updates an automatic fail. Insurers ask about the same cadence. If you’re working to a renewal date, our guide to how long Cyber Essentials takes sets out the realistic timeline.

What Does the Free Cyber Essentials Insurance Actually Cover?

A UK-domiciled organisation with turnover under £20m that certifies its whole organisation to Cyber Essentials by self-assessment can opt in to cyber liability insurance included with certification. It is underwritten by American International Group UK Limited and administered through Sutcliffe & Co Insurance Brokers.

Check the limits before you rely on it:

  • £25,000 total limit of indemnity, covering legal, IT, data recovery, notification, reputation and first response costs
  • A 24 hour incident helpline, with crisis management and incident response counting against that same £25,000
  • A £1,000 excess, rising to £5,000 for claims arising from activities in the USA or Canada
  • A six hour network interruption retention
  • No cover for money stolen electronically or for cyber fraud

IASME itself says £25,000 “might be sufficient for a small breach or incident but inadequate for a serious problem”, and advises organisations to get guidance from their own broker. Transputec doesn’t give that advice. We make sure the security controls behind the policy are in place.

Which Cyber Insurance Requirements Do Businesses Most Often Fail?

Three: backups that have never been restored, patching without reporting, and gaps in endpoint coverage. A successful backup job doesn’t prove you can recover. A patching routine with no reports can’t be evidenced. And endpoint gaps look like EDR on laptops but not servers, or missing from machines that came with an acquisition.

These are common problems, usually because the IT grew faster than the documentation. Transputec’s managed SOC services and managed detection and response cover the endpoint and response questions, vulnerability management covers patching, and tested recovery through disaster recovery as a service covers backups.

The Cyber Security Breaches Survey 2025/2026 found that 47% of UK businesses have cyber cover in some form, but only 10% have a specific cyber policy. Most cover is an add-on to a broader policy, which often gives less protection than people expect and may come with its own control conditions.

Your Cyber Insurance Requirements Checklist

Work through these cyber insurance requirements and start with anything you can’t evidence.

  1. Get the proposal form early, before renewal week, and use it to spot gaps.
  2. Confirm MFA is enforced on remote access, webmail and every privileged account, including contractors and service accounts.
  3. Check EDR or MDR covers servers as well as laptops, and keep the coverage report.
  4. Restore something from backup and record the date. A backup job log isn’t enough evidence.
  5. Write down how often you patch and keep compliance reports that show it.
  6. Confirm email filtering is configured and quarantine reporting is available.
  7. Write down your incident response plan, name the people responsible, and test it at least once.
  8. Remove unsupported software from scope. It’s a problem for underwriting and an automatic fail for Cyber Essentials.
  9. Answer the form honestly. An inaccurate answer can affect whether a claim is paid.

Conclusion

Meeting cyber insurance requirements doesn’t make you secure on its own. The NCSC advises against limiting yourself to an insurer’s minimum, and says a policy “will not prevent a cyber breach”. Treat the form as a starting point. It’s still useful, because it’s one set of security questions a business has to answer truthfully every year.

Transputec holds Cyber Essentials Plus and ISO/IEC 27001, so we’ve answered these questions about our own IT as well as for our clients. We don’t sell insurance or advise on cover. We do the security work the questions are about: identity and access, endpoint detection, patching, backup and recovery, and monitoring, delivered through our cyber security services.

If your renewal is coming up, talk to us about the security work behind your answers.

FAQs

Most UK proposal forms ask about six areas: multi-factor authentication on remote and privileged access, endpoint detection and response, tested and isolated backups, documented patching, email filtering and an incident response plan. The wording varies between insurers, but the underlying cyber insurance requirements are the same.

In practice, yes, and it’s now the most common condition. Insurers usually expect MFA on remote access, webmail and admin accounts, not only on administrators. The usual problem is partial rollout, especially for contractors, service accounts and older protocols that bypass modern authentication.

Not automatically. The NCSC says some insurers offer discounts where recognised defences such as Cyber Essentials or Cyber Essentials Plus are in place, but that isn’t a guaranteed reduction. The more practical benefit is that certification helps you answer most of the proposal form.

It gives a £25,000 total limit of indemnity to UK-domiciled organisations under £20m turnover that certify the whole organisation and opt in. IASME says that may not be enough for a serious incident, and it doesn’t cover electronically stolen money or cyber fraud. Transputec doesn’t advise on cover levels, so talk to your broker about those.

An inaccurate answer can affect whether a claim is paid, so treat the form as an evidence exercise. If you can’t produce the reports behind an answer, fix that gap first instead of wording around it.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation
Sonny Sehgal

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch