Cyber Insurance for UK SMBs: What Insurers Now Require
Getting cyber insurance used to mean ticking a few broad boxes on a proposal form. Those days are over. UK insurers have quietly but significantly tightened their underwriting rules, and in 2026 the distance between what a policy appears to cover and what it will actually pay out has never been greater. If your business holds a cyber policy, or is thinking about taking one out, this is worth reading before your next renewal.
What cyber insurance actually covers
A cyber insurance policy is designed to help a business survive a serious digital incident: a ransomware attack, a data breach, business email compromise, or a prolonged system outage. At its best, it covers the cost of forensic investigation, data recovery, legal fees, regulatory fines, customer notification, and the loss of income while systems are offline.
Many policies also include access to an incident response team. These are specialists who pick up the phone at 2am, help you contain the breach, and walk you through notifying the ICO. For a smaller business without a dedicated IT function, that kind of support can be the difference between surviving an attack and having to close.
Why insurers tightened the rules
Ransomware payouts in the UK hit record levels in 2024 and 2025. Underwriters noticed, and they responded by shifting from broad, yes/no questions to legal declarations that require you to attest that specific controls are in place and working. If a post-incident forensic investigation finds that a declared control was absent or had been switched off, the insurer will almost certainly decline the claim.
The practical effect is this: a cyber policy is only as good as the controls beneath it. Buying cover without the underlying hygiene in place is not protection; it is false comfort.
What UK insurers require in 2026
Most UK cyber insurers now require all of the following as pre-conditions for cover, or as conditions that affect your premium:
Multi-factor authentication (MFA) on every business account. This means email, financial software, banking portals, payroll systems, and any remote access tool. Under the updated Cyber Essentials scheme from April 2026, MFA on all cloud services is mandatory for certification. Absence of MFA on a compromised account is the single most common reason for a declined claim.
Endpoint detection and response (EDR). Basic antivirus no longer meets the bar. Insurers want active endpoint monitoring that can detect and contain threats in real time, not just flag known virus signatures. Products such as ESET Inspect or Microsoft Defender for Business satisfy this requirement; legacy or free antivirus tools generally do not.
Regular, tested backups. The key word is tested. A backup that has never been restored is of unknown value. Insurers ask how recently your backups were tested and whether offline or immutable copies exist. An encrypted network backup is no use after ransomware has swept through your systems.
Patch management. You must demonstrate that security updates are applied promptly across all devices, operating systems, and applications. Running end-of-life software creates underwriting problems because those products stop receiving security patches. Exchange 2019, Office 2021, and Windows Server 2016 all reach end of mainstream support in October 2026, which means underwriters will start asking questions about them at renewal.
Cyber Essentials or Cyber Essentials Plus certification. For public-sector supply chains this has been a requirement for years. More commercial insurers are now asking for it as standard, particularly for businesses with significant online exposure or data-processing activity.
The Cyber Essentials free insurance benefit
Here is something many UK businesses do not know. If your annual turnover is under £20 million, achieving Cyber Essentials certification includes £25,000 of free IASME cyber insurance for twelve months. That is not a discount; it is a separate policy, bundled at no additional cost. For a smaller business just beginning to think about cyber risk, it provides a meaningful safety net while you build out your controls.
Our Cyber Essentials certification page explains the process and what we do to help you pass first time.
What cyber insurance typically costs
Premiums vary by sector, turnover, the amount of sensitive data you process, and the controls you have in place. As a rough guide:
- Micro-business or sole trader: £350–600 per year for £250,000 of cover
- Small business (10–50 staff): £500–1,500 per year for £500,000 of cover
- Mid-market (50–150 staff): £2,000–10,000 per year for £1–5 million of cover
Businesses with Cyber Essentials certification, enforced MFA, EDR, and tested backups in place typically sit at the lower end of these ranges. Businesses without them pay significantly more, or find they cannot get cover at all.
Common exclusions worth knowing
Read the exclusions as carefully as the cover. Common ones include:
- Attacks that exploited an unpatched vulnerability where a fix had been available for more than 30 days
- Incidents where the attacker had already gained access before the policy start date
- Employee fraud or insider threat, unless a specific endorsement covers it
- Accidental data loss or misconfiguration without malicious intent
What to do next
Start by reviewing the controls you have in place against the checklist above. If you are already a System Force client, these controls form part of the service we deliver and review with you on an ongoing basis. If you are not yet a client, the most practical starting point is a Cyber Essentials assessment. It gives you a clear baseline, forces a systematic review of your security posture, and the certification comes with the £25,000 free insurance cover to bridge the gap while you complete any remediation.
If a policy is due for renewal, do not simply let it roll over. Use the renewal as an opportunity to check whether the cover level still reflects your actual risk, particularly if you have grown, taken on new cloud services, or added remote workers since the last review.
You can explore our cyber security services and our approach to managed IT support on our website. To talk through your situation, get in touch via our contact page or call us on 01452 701355 for a no-obligation conversation.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


