Insurance

How to prepare for cyber insurance

What insurers actually assess, how to document your controls, and how to compare policies beyond the headline premium — a step-by-step guide for UK SMEs.

7 steps·12 min read·Covers underwriter questionnaire requirements
01

Understand what insurers actually assess

Cyber insurance applications are not general risk questionnaires — they are structured assessments of specific technical controls. Most insurers assess the same seven areas: MFA on remote access and email admin, endpoint detection and response (EDR), patching cadence, backup frequency and air-gap/offline copy, email filtering and anti-phishing, incident response plan, and privileged access management. Understanding these areas before you start the application lets you gather evidence rather than guess at answers.

MFA

Multi-factor authentication on remote access (VPN, RDP), email admin, cloud platforms, and privileged accounts. This is the most commonly assessed control.

EDR vs antivirus

Most insurers now distinguish between antivirus (signature-based, reactive) and EDR (behavioural, with threat hunting). EDR typically gets a lower premium.

Backup completeness

Frequency, retention period, whether backups are tested, and whether at least one copy is offline or immutable. Untested backups score poorly.

Patching SLAs

How quickly critical patches are applied, and whether third-party software (browsers, Office, plugins) is included — not just the OS.

What they look for

Insurers do not take your word for control implementation — their underwriters score your answers against statistical breach likelihood data. An answer of 'yes' to 'do you use MFA' with no supporting detail scores differently to a specific answer naming the technology and the accounts in scope. Prepare to be specific.

02

Document your baseline controls before applying

Applying for cyber insurance without a documented baseline is a risk — you may understate controls you have (leading to higher premiums) or overstate controls you lack (leading to policy voidance if you claim). Before completing any application, run a structured assessment that produces a scored record of your current position across the standard control areas. This document becomes the foundation for your application and the evidence you hold if a claim is disputed.

Scope the assessment

Include all systems in scope for the insurance: cloud platforms, on-premise servers, endpoints, remote access tools, and any systems that process or store the insured data.

Record the current state

For each control area, document: what tool or process is in place, who is responsible for it, when it was last reviewed or tested, and any known gaps.

Date your evidence

Insurers and loss adjusters check dates. Evidence assembled in response to a claim that was created immediately before the incident is scrutinised. Dated baseline records from before the policy period carry more weight.

What they look for

If you make a claim and the insurer investigates, their loss adjusters will ask for your pre-incident security documentation. A scored baseline assessment with a date predating the policy period is the single most valuable document you can hold. It demonstrates that the controls you declared were actually in place at the time of application.

03

Assess your data exposure before you declare it

The value of a cyber insurance policy depends partly on what data you hold and how much of it could be exposed in a breach. Insurers ask about categories of personal data, volume of records, and whether you handle sensitive categories (health, financial, payment card data). Underestimating your data exposure leads to under-insurance; overstating it leads to unnecessarily high premiums. Map your data before you declare it.

Personal data categories

UK GDPR categories that affect risk rating: health data, financial data, children's data, criminal records. Know which of these you hold and roughly how many individuals are represented.

Third-party data

Data you hold on behalf of customers or partners is counted in your exposure — you are still liable for a breach of it. Check your contracts to understand what customer data you process.

Payment card data

PCI DSS scope. If you process card payments directly (not through a payment processor) your risk profile changes significantly. Know whether you are in scope.

Cloud and SaaS

Data held in cloud platforms counts. Insurers assess whether cloud data is protected by the same controls as on-premise data.

What they look for

Your GDPR Record of Processing Activities (ROPA) is the document that demonstrates you have mapped your data systematically. Having a ROPA — even a simple one — shows the insurer that you know what you hold and where. Organisations without a ROPA are assessed as having higher data management risk.

04

Disclose prior incidents accurately

All cyber insurance applications ask about prior incidents: breaches, ransomware events, phishing successes, data loss, and regulatory investigations. This is a material question — inaccurate or incomplete answers are the most common grounds for policy voidance at claim time. A prior incident does not necessarily make you uninsurable; the way it was handled, what improvements were made, and whether it has been mitigated often matters more than the incident itself.

What counts as a reportable incident

Any security event that resulted in unauthorised access, data loss, service disruption, or a regulatory notification — regardless of whether you made a public disclosure.

Documenting your response

For each prior incident, have on record: what happened, when, how it was discovered, what was affected, what you did in response, and what changed as a result. This narrative is what the insurer assesses.

ICO notifications

Any ICO report or formal complaint is visible to insurers through public records. Do not omit these.

Near misses

Phishing emails that were clicked but caused no breach, or ransomware that was contained before encryption, should be disclosed as near misses — they show awareness, not vulnerability.

What they look for

If you had a prior incident, the insurer's underwriter will ask: what changed? An incident with a documented response, root cause analysis, and evidence of the resulting improvements is often better received than an organisation claiming a clean history that looks implausible given their sector or size. Honesty, supported by evidence of improvement, is the strongest position.

05

Run a scored posture assessment to support your application

Insurers offer lower premiums to organisations that can demonstrate a better security posture — not just claim it. A scored assessment from a recognised tool or methodology gives you a number you can reference in your application and defend if questioned. It also identifies any remaining gaps that, if closed before application, would improve your score and your premium. For SMEs, a 10-minute structured assessment is often sufficient to produce a score that meaningfully differentiates your application.

What a good score covers

Access control, patch management, backup, network security, endpoint protection, incident response, staff training. These map directly to the standard underwriter questionnaire structure.

Closing pre-application gaps

If the assessment reveals a control gap that you can close quickly — MFA on a platform you missed, a backup frequency issue — close it and re-run before submitting. The time investment is usually worth the premium saving.

Score as a mid-policy reference

Keep your assessment record throughout the policy period. Insurers may conduct mid-term reviews or add policy conditions. A dated score gives you a documented baseline to refer to.

What they look for

Some insurers offer a premium discount for organisations that complete a recognised digital resilience or cyber hygiene assessment. Even where no formal discount is offered, underwriters treat an application supported by a scored assessment differently to one based on self-reported yes/no answers. A score creates accountability — and accountability reduces assessed risk.

06

Compare policies on cover, not just premium

Cyber insurance policies vary significantly in what they actually cover, and the cheapest premium is rarely the best value. Key differences between policies include: sublimits on specific claim types (ransomware payments, regulatory fines), waiting periods before business interruption cover kicks in, whether third-party liability (customers whose data you held) is included, coverage for social engineering fraud, and whether the insurer has a breach response panel you are required to use.

First-party vs third-party cover

First-party: your costs — forensics, restoration, ransom, business interruption. Third-party: claims from customers or partners whose data was affected. Policies vary significantly on third-party limits.

Ransomware sublimits

Some policies cap ransomware payment coverage well below the total policy limit. For high-revenue organisations, this gap can be significant. Check the sublimit, not just the headline cover.

Waiting periods

Business interruption cover typically only kicks in after a waiting period (often 8–24 hours). The daily revenue figure used to calculate BI loss is also subject to underwriting — check what's declared.

Panel requirements

Some policies require you to use the insurer's breach response panel (legal, forensic, PR). Others allow you to choose. If you have existing relationships with an IT or legal provider, check whether the policy allows it.

What they look for

Request a policy summary schedule from each insurer that lists: total limit, all sublimits, all exclusions, waiting period, panel restrictions, and renewal conditions. Compare these in a like-for-like table before deciding. An insurance broker specialising in cyber cover can produce this comparison for you — and their fee is often covered by the premium saving on the better policy they identify.

07

Maintain your controls throughout the policy period

A cyber insurance policy is not a one-time transaction — it is an ongoing declaration that the controls you stated at application remain in place. Most policies include a condition requiring you to notify the insurer of material changes to your security posture (significant technology changes, staff reductions, new processing activities). Failing to maintain controls — or failing to notify the insurer of material changes — gives them grounds to reduce or void a claim.

Mid-term notifications

Significant technology migrations, moving to cloud, changing EDR provider, closing an office, or suffering a near-miss incident are all examples of material changes that should be notified. Check your policy's definition of 'material change'.

Renewal review

At renewal, the market changes, your organisation changes, and your cover should be reviewed rather than auto-renewed. A brief assessment before renewal often identifies changes in your posture — or in the market — that warrant renegotiation.

Evidence of ongoing compliance

Run your security assessment annually and keep the dated records. If a claim is made in month 11 of a 12-month policy, the insurer will ask for evidence of controls throughout the period — not just at inception.

What they look for

Cyber insurance claims are investigated with the same rigor as any other insurance claim. Forensic investigators will establish exactly when a breach began, and cross-reference that with the controls that were — or were not — in place at that time. A quarterly review record, dated assessments, and evidence of your maintained controls are the documentation that protects your position at claim time.

Where people go wrong

Common mistakes that invalidate cover or raise premiums

✕

Overstating controls on the application

The most common ground for cyber insurance claim voidance. Saying 'yes' to MFA when it is only partially deployed, or claiming EDR when you have standard antivirus, constitutes misrepresentation. Loss adjusters investigate claims thoroughly — discrepancies between the application and the actual control state are invariably found.

✕

Choosing the cheapest premium without checking sublimits

A policy with a £1m headline limit but a £100k ransomware sublimit may leave a significant gap precisely when you need cover most. Comparing on premium alone misses the structure of what is actually covered. Always compare sublimits, waiting periods, and exclusions alongside the headline figure.

✕

Not disclosing a prior incident

Prior incidents visible in the ICO public register, or discoverable through digital forensics, cannot be concealed. An undisclosed incident found during claim investigation is grounds for voidance of the entire policy — including the claim for the current incident. Disclose accurately and explain what changed.

✕

Letting controls lapse mid-policy

Disabling MFA 'temporarily', switching off EDR during a software migration, or skipping patches during a busy period — all of these can be established by forensic investigation. If those lapses contributed to the breach, the insurer has grounds to reduce the claim. Maintain your controls consistently, not just at renewal time.

✕

Applying before closing obvious gaps

If your pre-application assessment reveals that you lack MFA on admin accounts or have no offline backup, fixing those gaps before applying typically reduces your premium by more than the time taken. Applying with known gaps accepts a higher premium for the same exposure — and does not improve your claims position.

Frequently asked questions

Do I need cyber insurance if I am a small business?

Cyber insurance is increasingly expected by enterprise clients as part of their supplier due diligence process — a client contract may require minimum cover levels. Beyond contractual requirements, small businesses are disproportionately targeted by opportunistic attacks (phishing, credential stuffing, ransomware-as-a-service) because defences are typically weaker. The average cost of a small business data breach in the UK exceeds £10,000 when forensic, legal, notification, and operational costs are included.

What controls do I need before I can get cyber insurance?

There is no absolute minimum — but most insurers in the UK market now decline applications (or charge very high premiums) where MFA is absent on remote access and cloud admin, where there is no offline backup, and where there is no endpoint protection beyond standard antivirus. These three are effectively the minimum baseline the market expects. An application without them will either be declined or offered cover with exclusions that remove most of the value.

How is a cyber insurance assessment different from a Cyber Essentials assessment?

Cyber Essentials is a technical certification against a defined standard — you pass or fail. A cyber insurance underwriting questionnaire is a risk assessment that produces a premium, not a pass/fail outcome. The five Cyber Essentials control areas overlap significantly with what cyber insurers assess, so CE or CE+ certification is a strong signal to an underwriter and often results in lower premiums. However, insurers also assess business continuity, incident response planning, and data exposure — areas not covered by Cyber Essentials.

Can I get cyber insurance after a ransomware incident?

Yes, but it is more difficult and usually more expensive. Insurers will want to see: a detailed incident report, evidence of root cause remediation, and confirmation of controls now in place that were not in place at the time of the incident. An organisation that suffered a ransomware attack, handled it well, and made documented improvements is a different risk profile to one that suffered the same attack and made no changes. The improvements and their evidence are what determines insurability.

Does Fortify help with cyber insurance applications?

Fortify does not act as an insurance broker or provide regulated financial advice. However, the free Digital Resilience Assessment produces a scored baseline report across the control areas that cyber insurance underwriters assess — MFA, patching, backup, access management, and incident response. That report can be used to support your insurance application and gives you a dated record of your control position.

Get a scored baseline before you apply

The free Digital Resilience Assessment gives you a scored record of your current control position — the same areas cyber insurance underwriters assess. Useful before you apply, and useful at renewal.