A policy is not the same as being covered
Cyber insurance has become something most businesses have rather than something most businesses understand. The certificate goes in the folder, the premium leaves by direct debit, and everyone gets on with their day assuming the worst case is now somebody else's problem.
Then something happens, a claim goes in, and the amount that comes back is nothing like what anyone expected. The reason is rarely an argument about the incident itself. It is usually about a form somebody filled in months earlier.
What insurers now expect you to have
Underwriting has tightened a long way. A few years ago a cyber policy asked a handful of general questions. Now most UK insurers treat a specific set of controls as the price of entry, and missing one of them either prices you out or writes you out.
- Multi-factor authentication a second check on top of the password, usually a code or a prompt on a phone, covering email, any remote access into your systems and every administrator account
- Endpoint protection that responds software on every laptop, desktop and server that spots suspicious behaviour and acts on it, rather than an old-style virus scanner that only recognises threats it has seen before
- Backups an attacker cannot reach at least one copy held offline, or in a form that cannot be altered once written, and a restore that has actually been tested inside the last year
- Patching on a clock a written process that gets critical security updates onto your systems within about fourteen days
- Staff training you can evidence annual training with a record of who completed it and when
None of that is exotic, and most of it is what a decent IT setup should be doing anyway. What has changed is that it is now contractual rather than advisory.
The proposal form is the document that decides your claim
The proposal form looks like paperwork. It is not. It is a declaration, and you are signing to say the controls listed on it were genuinely in place. Under the Insurance Act 2015 a business owes its insurer what the law calls a fair presentation of the risk, which means answering accurately after a reasonable look at what is actually going on, rather than from memory or from how things were meant to be set up.
What happens if an answer turns out to be wrong depends on how it came to be wrong, and the difference is bigger than most businesses realise. If the misrepresentation was deliberate or reckless, the insurer can treat the policy as void from the start and keep the premium. If it was an innocent mistake, the remedies are proportionate instead. Where the insurer would still have offered cover but charged more, the claim is scaled down by the same proportion. Where they would have insisted on a condition, the policy is read as though that condition had been in it all along.
So for most businesses the realistic risk is not a flat refusal. It is discovering, in the middle of the worst week you have ever had, that the payout has been cut to a fraction of what you were expecting. None of it depends on the wrong answer having caused the breach either. The question the insurer asks is what it would have done differently had it known the truth when the policy was written.
Where the multi-factor authentication answer goes wrong
Multi-factor authentication is where this goes wrong more often than anything else, and almost nobody sets out to mislead anybody.
Almost nobody sets out to mislead. What happens is that it gets switched on for email, because that was the obvious risk, and never extended to the remote access tools, the administrator accounts or the finance system. Or it is on for everyone except two directors who found it irritating and were quietly made an exception. On the form that is still a yes. To an underwriter reviewing a claim, it is a no.
Before anyone answers that question, get someone to write down every account with administrative access and every route into your systems from outside the building, then check each one individually. That list is almost always longer than people expect.
You have to prove it was on at the time, not that it is on now
The shift over the last year has been towards evidence. Saying a control was in place when the incident happened is no longer enough on its own, and insurers increasingly want to see it. That means keeping the boring things, dated, somewhere you can find them.
- Your multi-factor authentication policy an export or screenshot showing it was enforced, and on exactly which accounts and services
- Endpoint protection coverage a deployment report showing every machine, not most of them
- Backup test logs with dates, showing a restore was genuinely run and worked
- Training records who completed it and when
- Your incident response plan the document itself, even if it runs to a single page
If your IT provider holds all of this, ask them for a copy once a year and file it with the policy documents. Evidence gathered after an incident is worth a great deal less than evidence dated before one.
Backups are the second most common gap
Every business says it has backups. Far fewer have tested restoring from them, and that is the question insurers have started asking. A backup nobody has ever restored is a theory rather than a plan.
There are two parts to getting this right. One copy has to sit beyond the reach of an attacker who gets into your network, held offline or in a form that cannot be overwritten, because ransomware, meaning the software that encrypts your files and demands payment to unlock them, goes hunting for the backups first and encrypts those too. And somebody has to have actually run a restore in the last twelve months, then written down that it worked and how long it took. That second figure is usually the unwelcome surprise.
What it costs, and cover you may already be entitled to
Premiums vary far more than businesses expect, because insurers price on turnover, sector, how much personal data you hold, the limit you want and your claims history. Published market guidance for 2026 puts a business of under ten people with half a million pounds of cover somewhere around £500 to £1,500 a year, and ten to fifty staff with a million pounds of cover at roughly £1,500 to £4,000. Those figures are indicative rather than authoritative, they assume the controls above are already in place, and they are no substitute for two or three real quotes.
There is also something smaller businesses often miss. UK-domiciled organisations with group turnover under £20 million that certify to Cyber Essentials can get £25,000 of cyber insurance included through IASME. Three conditions decide whether you actually have it:
- The whole organisation has to be certified not one department, one office or one part of a group
- You have to opt in it is not applied automatically when the certificate is issued
- It lasts as long as the certificate twelve months, so it lapses if you do not recertify
It will not carry a serious incident on its own, but it is worth knowing whether you actually hold it. Going through the certification also answers several of the questions a commercial insurer will ask you anyway.
Answer the form as though you will have to prove it
The useful test is a simple one. Read every question on the proposal form and ask whether you could evidence that answer to somebody assessing a claim eighteen months from now, in the worst week your business has ever had. Where the honest answer is no, the fix is either to put the control in place or to answer accurately and accept the premium that comes with it.
A slightly dearer policy that pays out is worth far more than a cheap one that does not. The businesses that get caught are almost never the ones that set out to mislead anybody. They are the ones that answered the way they wished things were.