Enquiries: +44 (0) 20 8584 1400

CONTACT

What Security Controls Do Cyber Insurers Require

cyber insurance requirements

The renewal form lands in February. Twelve questions, most of them technical, and the person filling it in is usually the one who knows least about the estate. Answer optimistically and you risk the claim. Answer honestly and you find out what you have been deferring.

Cyber insurance requirements are no longer a formality. Underwriters now ask for evidence of multi-factor authentication, endpoint detection, tested backups and a patching cadence, and a weak answer costs you cover, terms, or both.

Cyber insurance requirements have converged on a short list: MFA on remote and privileged access, endpoint detection and response, backups that have been restored from, documented patching, and an incident response plan. The proposal form is the audit. Every honest “no” on it is a piece of work waiting to be scoped.

What Are the Cyber Insurance Requirements Underwriters Ask About?

Underwriters ask about controls, not intentions. The NCSC puts it plainly: buying a policy “might require providing information about your security controls”, covering technical, procedural and human measures. What has changed is that those answers are now verified at claim time, not just at quote time.

In the forms clients forward to Transputec, the same six areas come up almost every time. So the form is worth treating as a live document rather than a box-ticking exercise.

Why Does the Proposal Form Matter More Than the Policy?

Because the form is the only moment anyone forces you to describe your estate honestly, in writing, with money attached. Most organisations have never had a third party ask whether MFA covers every remote user or whether a backup has actually been restored. The proposal form asks both, and it does not accept “mostly”.

That makes it the most useful free assessment a business gets all year. Treat it that way and your cyber insurance requirements become a project plan. Treat it as paperwork and they become a surprise in renewal week.

Got a Renewal Form on Your Desk?

Send the questionnaire your insurer sent you to the Transputec team and we will tell you which answers you cannot currently evidence. No obligation, no jargon.

Get a Strategic Consultation

What Security Controls Do Cyber Insurers Require in the UK?

The cyber insurance requirements that appear on almost every UK proposal form fall into six areas: identity, endpoint, backup, patching, email and response. Insurers word them differently, but they are asking the same questions, and each one has an evidence trail you either have or do not.

What the insurer asksWhat actually evidences it
Is MFA enforced on remote access, email and admin accounts?Conditional access policies, with per-user enforcement reporting
Do you run endpoint detection and response?EDR or MDR console coverage report across all endpoints
Are backups tested and isolated from production credentials?A dated restore test, not a backup job success log
How quickly are critical patches applied?Patch compliance reporting against a stated cadence
Is email filtered for phishing and malware?Gateway configuration and quarantine reporting
Do you have an incident response plan?A written plan with named roles, and evidence it has been exercised

The right-hand column is where most organisations come unstuck. These cyber insurance security controls are rarely missing altogether. They are usually present but unprovable, and having the control is not the same as being able to prove it.

Do Cyber Insurers Require MFA?

In practice, yes. Multi-factor authentication is the one control that has moved from desirable to assumed, and an insurer MFA requirement now routinely covers remote access, webmail and privileged accounts rather than just administrators. Partial deployment is the common failure: MFA on head office staff but not contractors, or on email but not the VPN.

Of all the cyber insurance requirements, this is the one underwriters are least willing to negotiate on. The gap is usually the service accounts and the legacy protocols nobody wants to touch. If you are unsure where yours sit, our guide to why multi-factor authentication matters covers the practical enforcement problem, and identity work sits inside our Microsoft 365 services.

Does Cyber Essentials Reduce Cyber Insurance Premiums?

Not automatically, and anyone promising otherwise is guessing. What the NCSC actually says is that “some insurers offer discounts if your organisation already has recognised cyber security defences in place (such as those certified by Cyber Essentials, or Cyber Essentials Plus)”. Some, not all, and a discount is not a stated percentage.

The stronger argument is different. Cyber Essentials asks for firewalls, secure configuration, security update management, user access control and malware protection, which is most of the proposal form already. Certifying does not buy you a cheaper policy so much as it means you can answer the questions. That is why cyber essentials for insurance is worth doing on its own terms, and our breakdown of the five Cyber Essentials controls maps them one by one.

Worth knowing before you plan around it: the current Danzell question set and Requirements v3.3 made 14-day patching for high-risk and critical updates an automatic fail. Insurers ask about the same cadence. If you are working to a renewal date, our guide to how long Cyber Essentials takes sets out the realistic timeline.

What Does the Free Cyber Essentials Insurance Actually Cover?

A UK-domiciled organisation with turnover under £20m that certifies its whole organisation to Cyber Essentials by self-assessment can opt in to cyber liability insurance included with certification. It is underwritten by American International Group UK Limited and administered through Sutcliffe & Co Insurance Brokers.

Read the limits before you rely on it:

  • £25,000 total limit of indemnity, covering legal, IT, data recovery, notification, reputation and first response costs
  • A 24 hour incident helpline, with crisis management and incident response counting against that same £25,000
  • A £1,000 excess, rising to £5,000 for claims arising from activities in the USA or Canada
  • A six hour network interruption retention
  • No cover for money stolen electronically or for cyber fraud

IASME itself notes that £25,000 “might be sufficient for a small breach or incident but inadequate for a serious problem”, and advises organisations to seek guidance from their own broker. That is the right advice, and it is not advice Transputec gives. What we do is make sure the controls behind the policy are real.

Which Cyber Insurance Requirements Do Businesses Most Often Fail?

Three, consistently. Backups that have never been restored, because a successful backup job is not a successful recovery. Patching without reporting, where the cadence exists in someone’s head but cannot be evidenced. And endpoint coverage gaps, where EDR is deployed to laptops but not servers, or not to the machines a recent acquisition brought with it.

None of these are exotic. They are the ordinary consequence of an estate that grew faster than its documentation. Continuous monitoring through Transputec’s managed SOC services and managed detection and response closes the endpoint and response questions, vulnerability management answers the patching one, and tested recovery through disaster recovery as a service answers the backup one.

There is a wider point in the national data. The Cyber Security Breaches Survey 2025/2026 found 47% of UK businesses hold cyber cover in some form, but only 10% hold a specific cyber policy. Most cover is a bolt-on to a broader policy, which is thinner than people assume and often carries its own control conditions.

Your Cyber Insurance Requirements Checklist

Work through the cyber insurance requirements below and treat anything you cannot evidence as the priority.

  1. Get the proposal form early, before renewal week, and read it as a gap list.
  2. Confirm MFA is enforced on remote access, webmail and every privileged account, including contractors and service accounts.
  3. Check EDR or MDR coverage across servers as well as laptops, and produce the coverage report.
  4. Restore something from backup and record the date. A job log is not evidence.
  5. State your patching cadence and produce compliance reporting against it.
  6. Confirm email filtering is configured and quarantine reporting is available.
  7. Write down the incident response plan, name the roles, and exercise it once.
  8. Remove unsupported software from scope, since it fails both underwriting and Cyber Essentials.
  9. Answer the form honestly. An inaccurate answer is a repudiated claim later.

Conclusion

Meeting cyber insurance requirements and being secure are not the same thing, and the NCSC is blunt about it: do not limit yourself to an insurer’s minimum, and remember that a policy “will not prevent a cyber breach”. The form is a floor, not a target. But it is a useful floor, because it is the one set of questions a business is obliged to answer truthfully once a year.

Transputec holds Cyber Essentials Plus and ISO/IEC 27001, so we have answered these questions about our own estate as well as our clients’. We do not sell insurance and we do not advise on cover. We do the estate work the questions are really asking about: identity and access, endpoint detection, patching, backup and recovery, and monitoring, delivered through our cyber security services.

If your renewal is coming up, send us the questionnaire and we will tell you which answers you can evidence today and which you cannot.

FAQs

Most UK proposal forms ask about six areas: multi-factor authentication on remote and privileged access, endpoint detection and response, tested and isolated backups, a documented patching cadence, email filtering, and an incident response plan. Wording varies between insurers, but the underlying cyber insurance requirements are consistent.

In practice yes, and it is now the single most common condition. Insurers typically expect MFA on remote access, webmail and administrative accounts rather than administrators alone. Partial deployment is the usual problem, particularly contractors, service accounts and legacy protocols that bypass modern authentication.

Not automatically. The NCSC says some insurers offer discounts where recognised defences such as Cyber Essentials or Cyber Essentials Plus are in place, which is not the same as a guaranteed reduction. The practical benefit is that certification means you can answer most of the proposal form.

It provides a £25,000 total limit of indemnity for UK-domiciled organisations under £20m turnover that certify the whole organisation and opt in. IASME itself says that may be inadequate for a serious incident, and it excludes electronically stolen money and cyber fraud. Transputec does not advise on cover levels, so discuss those with your broker.

An inaccurate answer can affect whether a claim is paid, which is why the form is worth treating as an evidence exercise rather than an administrative one. If you cannot produce the reporting behind an answer, treat that gap as the priority rather than wording around it.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his “straight-talking” approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch