A few years ago, buying cyber insurance was simple. You answered a short form, paid a modest premium, and you were covered. That has changed. After a wave of ransomware claims, UK insurers have tightened their rules sharply, and the questions on the application form now decide whether you get cover at all, what you pay, and crucially whether a future claim will actually be paid.
If you run a small business, this matters more than the headline premium. You can hold a valid-looking policy and still have a claim reduced or refused because a security control you declared was not really in place. This guide explains, in plain English, what cyber insurers now expect from a UK small business in 2026, and the practical steps to meet those requirements without turning it into a project that swallows your year.
Why cyber insurers have raised the bar
Cyber claims became expensive and frequent. Ransomware in particular can shut a small business down for days and cost far more than the premium ever brought in. Insurers responded the way any insurer does when a risk gets worse: they started pricing on the strength of your defences, not just your turnover.
The result is that cover is now conditional. Insurers ask detailed questions about specific technical controls, and your answers form part of the contract. Declare that you use multi-factor authentication everywhere when you do not, and you have handed the insurer a reason to challenge a claim. This is why getting cyber insurance and improving your security are no longer separate jobs. They are the same job.
The security controls insurers now expect
Insurer questionnaires vary, but the same core controls come up again and again. Treat the list below as the baseline most UK insurers now expect from a small business.
Multi-factor authentication (MFA)
MFA is the single most requested control. Insurers expect it on email, on remote access such as VPNs and remote desktop, on cloud administrator accounts, and increasingly on any system holding sensitive data. It is the control most likely to be checked, and the one most likely to trip up a claim if it was declared but not actually enforced everywhere.
Endpoint detection and response (EDR)
Traditional antivirus is no longer enough for many insurers. They increasingly ask for endpoint detection and response, which actively monitors devices for suspicious behaviour and can isolate a compromised machine before an attack spreads. If your questionnaire asks whether you have next-generation endpoint protection or EDR, basic free antivirus will not satisfy it.
Secure, tested backups
Backups are your insurance behind the insurance. Insurers want to see that your data is backed up regularly, that at least one copy is kept offline or otherwise isolated so ransomware cannot encrypt it, and, importantly, that you actually test your ability to restore. A backup you have never tested is a hope, not a control.
Regular patching and updates
Attackers exploit known weaknesses in software that has not been updated. Insurers expect a clear process for applying security updates promptly, especially to anything exposed to the internet, and they expect you to have retired software that no longer receives security updates.
Staff awareness training
Most breaches start with a person, not a machine, usually a convincing phishing email. Insurers increasingly ask whether you provide regular security awareness training so your team can spot and report the emails that lead to compromise.
Access control and privileged accounts
Insurers want to know that people have only the access they need, that administrator accounts are limited and protected, and that accounts are removed promptly when someone leaves. Loose access control is a common way for a small breach to become a large one.
How Cyber Essentials maps to insurer requirements
Here is the good news for a small business feeling daunted by that list. There is a UK government-backed scheme that covers almost all of it in one place: Cyber Essentials.
Cyber Essentials is built around five technical controls that map closely onto what insurers ask for: firewalls, secure configuration, access control, malware protection and patch management. Working toward certification is therefore one of the most efficient ways to get insurance-ready, because you address the underlying controls and come away with a recognised certificate you can show your broker. Many insurers now view Cyber Essentials favourably, and some price accordingly.
There is a further, genuinely useful detail. Cyber Essentials certification obtained through an IASME-accredited body can include a level of cyber liability insurance for eligible UK organisations under a turnover threshold. It is not a substitute for a full commercial policy, but for a smaller business it is a real benefit worth checking your eligibility for.
At HGC we are Cyber Essentials certified ourselves, and as a Microsoft Partner and Cloud Solution Provider we help UK small businesses put these exact controls in place. If certification is your goal, our Cyber Essentials certification service takes you from readiness through to the certificate.
What happens if you cannot show these controls
Two things, and neither is good. First, at renewal you may find cover harder to get, more expensive, or offered only with exclusions that carve out the very risks you most need covered. Second, and more serious, if you declared controls you did not truly have, an insurer can reduce or decline a claim after an incident, exactly when you can least afford it. The declaration on the form is part of the contract, so accuracy is not optional.
The practical lesson is to close the gaps before you fill in the form, not after, and to make sure the controls you declare are actually enforced across the business rather than switched on for a few accounts.
A practical path for a small business
You do not need to solve everything at once. A sensible order for most small businesses is:
- Turn on MFA everywhere it is available, starting with email, remote access and cloud admin accounts.
- Move to proper endpoint protection with detection and response, not just basic antivirus.
- Get your backups isolated and tested, so you can prove you could recover.
- Put a simple, reliable patching routine in place and retire anything unsupported.
- Run regular staff awareness training.
- Use Cyber Essentials as the framework that ties it together and gives you something to show your insurer.
If that feels like a lot to manage alongside running the business, this is precisely the kind of work a managed IT partner handles day to day. Our managed cybersecurity covers MFA, endpoint protection, patching and staff training as standard, and our secure cloud backup gives you the isolated, tested backups insurers now expect. The result is a business that is genuinely safer, and an insurance form you can complete honestly.
Frequently asked questions
What are the main requirements for cyber insurance in the UK?
Most UK insurers now expect multi-factor authentication on email, remote access and cloud admin accounts, endpoint detection and response rather than basic antivirus, regular tested backups with an isolated copy, prompt patching, staff awareness training, and controlled administrator access. The exact list varies by insurer.
Do I need multi-factor authentication for cyber insurance?
In almost all cases, yes. MFA is the most commonly required control and one insurers are most likely to check. Declaring MFA when it is not fully enforced is a common reason claims are challenged, so make sure it is genuinely in place everywhere before you apply.
Does Cyber Essentials help me get cyber insurance?
Yes. Cyber Essentials covers five technical controls that map closely onto what insurers ask for, so certification is an efficient way to become insurance-ready. Many insurers view it favourably, and certification through an IASME-accredited body can include a level of cyber liability insurance for eligible UK organisations.
What happens if I do not meet the requirements?
You may find cover harder to obtain, more expensive, or limited by exclusions. More seriously, if you declared controls you did not actually have, an insurer can reduce or decline a claim after an incident. Close the gaps before you complete the application.
Ready to get insurance-ready?
If your renewal is coming up, or a client or insurer has asked you to prove your defences, we can help you put the right controls in place and work toward Cyber Essentials certification. Book a free IT and security review with our UK-based team in Dorchester, and we will show you exactly where you stand against today's insurer requirements and what to fix first. No jargon, no obligation, just a clear picture and a practical plan.