A cyber insurance renewal can now expose gaps that have sat unnoticed for years: a shared administrator account, incomplete backup testing, ageing servers that no one is sure can be patched. Cyber insurance requirements trends are making these weaknesses far harder to overlook. For UK organisations, cover is no longer simply a financial safety net bought at renewal. It is increasingly linked to the day-to-day controls that keep people working, data protected and services available.

This is a positive shift when handled properly. The same measures that help secure appropriate cover also reduce the likelihood and impact of an incident. The difficulty is that insurers often ask technical questions in language that can feel disconnected from operational reality. A practical response starts with understanding what they are trying to establish: whether your organisation can prevent common attacks, detect suspicious activity and recover without prolonged disruption.

Why cyber insurance requirements are tightening

Ransomware remains a major driver. Criminal groups have become more organised in how they gain access, move through networks and apply pressure after stealing data. An attacker does not need to compromise every system to cause serious disruption. Access to email, finance software, customer records or production planning can be enough.

Insurers have also seen that basic security controls make a material difference. Organisations using multi-factor authentication, managed endpoint protection and tested backups are generally harder to compromise and better placed to contain an event. As a result, underwriters are asking more detailed questions before offering terms, adjusting excesses or agreeing limits.

Requirements vary by insurer, sector, turnover, claims history and the sensitivity of the data you hold. A manufacturer with connected operational technology faces different risks from an academy trust managing pupil information, for example. However, the direction of travel is consistent: evidence of sensible, maintained controls is becoming a condition of meaningful cover rather than a desirable extra.

The controls insurers increasingly expect to see

There is no single universal checklist, but several controls now appear regularly in applications and renewal discussions. The key is not to treat them as tick-box exercises. Insurers may ask whether a control exists, but after a claim they may also examine whether it was genuinely in use.

Multi-factor authentication across critical systems

Multi-factor authentication, often called MFA, is one of the clearest expectations. It adds a second check beyond a password, such as an authenticator app or security key. It should cover email, cloud platforms, remote access, administrator accounts and any application containing sensitive information.

MFA is particularly important because stolen passwords remain a common route into business systems. A strong password policy alone is no longer enough. Organisations should also avoid exceptions that leave older protocols, shared mailboxes or remote access routes outside the protection of MFA.

Managed endpoint protection and monitoring

Traditional antivirus has limited value if it is installed but unmanaged. Insurers increasingly look for endpoint detection and response tools, often referred to as EDR, or a comparable managed protection service. These tools can identify suspicious behaviour, isolate affected devices and provide the information needed to investigate quickly.

For a smaller organisation, buying a sophisticated tool without anyone monitoring alerts may create a false sense of security. The better question is who receives alerts, who can respond outside office hours and how quickly they can act. Technology that just works includes a clear process behind it.

Patch management and supported systems

Unpatched software is an avoidable opening for attackers. Insurers commonly ask how quickly critical vulnerabilities are addressed and whether unsupported operating systems or applications remain in use. This can be uncomfortable for organisations reliant on specialist machinery, older line-of-business systems or software that cannot be updated without supplier involvement.

Where immediate replacement is not realistic, the risk should be managed openly. Network segmentation, restricted user access, application controls and a funded replacement plan may reduce exposure. Hiding an unsupported system, or assuming it is safe because it is rarely used, is unlikely to stand up well during a claim review.

Backups that are separate and tested

A backup is only useful if it can be restored within the time the organisation can tolerate. Insurers are placing greater weight on backups that are protected from the main network, resistant to deletion or alteration, and tested routinely. Attackers often seek out backup systems early because they know a failed restore makes a ransom demand more powerful.

Backup arrangements should cover more than core files. Consider cloud data, configuration settings, critical applications and the information needed to rebuild systems. Test restores should be documented, including how long recovery took and any issues discovered. This turns a reassuring assumption into evidence of resilience.

Secure email, identity and privileged access

Email remains the front door for phishing, payment fraud and account takeover. Filtering, phishing protection and user reporting processes are all relevant, but identity management matters just as much. Insurers may ask whether privileged accounts are separate from everyday user accounts, whether access is reviewed when staff leave, and whether unnecessary administrator rights have been removed.

Shared accounts make accountability difficult and can complicate incident investigations. A practical improvement is to give each person an individual account, grant only the access they need and review elevated permissions regularly. It is a modest governance change with a significant security benefit.

Evidence matters as much as the answer

A common mistake at renewal is to complete a cyber insurance questionnaire from memory. That can lead to answers which are technically inaccurate, overly optimistic or inconsistent with the policy wording. If a question asks whether MFA is enabled for all remote access, an answer of “yes” should account for every pathway, not only the main Microsoft 365 login.

Keep a straightforward evidence pack that records the controls in place, who owns them and when they were last reviewed. This might include backup test records, patching reports, access review notes, incident response contacts and confirmation of staff security training. It does not need to be a large compliance project. It needs to be accurate, current and easy to retrieve.

Senior leaders should also read the policy conditions, exclusions and notification requirements before an incident occurs. Many policies require prompt notification and specify how external incident response, legal support and forensics are engaged. Calling an unapproved supplier first, or delaying notification while trying to resolve the issue internally, can create unnecessary complications.

Cyber insurance is not a substitute for resilience

Insurance can help fund specialist response, legal advice, notification costs, recovery work and certain business interruption losses. It cannot restore trust, recover lost time or remove the pressure on staff when core services are unavailable. Nor will every loss be covered in the way an organisation expects.

This is why security decisions should be based on business risk, not simply the next insurer questionnaire. Start with the systems that keep your organisation operating: communications, finance, customer service, production, teaching, care delivery or public services. Establish how long each can be unavailable, what data is essential and which suppliers you depend on. The answers will help prioritise investment far better than a generic checklist.

For many SMEs, the sensible route is a phased plan. Address the controls that reduce the most immediate exposure first, then improve visibility, recovery and governance over time. Cyber Essentials can provide a useful baseline, particularly for organisations working with public sector bodies, but certification alone does not replace ongoing monitoring, patching or recovery testing.

Turning renewal pressure into a practical plan

Begin the process well before renewal, ideally several months in advance. Review the previous application, identify where answers rely on assumptions and involve the people responsible for IT, finance, operations and risk. This prevents a last-minute scramble and gives time to resolve genuine issues.

Next, separate quick fixes from longer-term work. Enabling MFA, removing dormant accounts and confirming backup alerts may be achievable quickly. Replacing unsupported infrastructure, improving network segmentation or developing a tested incident response plan may need budget, supplier engagement and board oversight. Both matter, but they should be planned realistically.

An experienced managed technology partner can help translate insurer questions into a clear view of your environment, then prioritise improvements against operational risk. CETSAT takes this approach by connecting security controls with the wider requirements for reliable systems, productive staff and recoverable operations.

The best outcome is not simply a smoother renewal or a lower premium, although both may follow. It is the confidence that, if a malicious email lands in an inbox or a device is compromised, your organisation has the controls, information and support needed to keep moving.

Stoic sysadmin plotting a midnight patch — CETSAT-approved glare ready to block malware

Chat with Dave