How to Get Cyber Insurance in the UK
Cyber insurance protects UK businesses against the financial costs of cyber attacks. To get the best terms, you need to demonstrate strong security controls. Insurers increasingly require MFA, EDR, and regular backups as minimum prerequisites.
Quick answer
To get cyber insurance in the UK, you must prove strong security controls before you apply. Insurers now treat MFA, endpoint detection, tested backups, email security and staff training as minimum entry requirements. Get these in place first and you secure cover at sensible terms; skip them and you face higher excess, exclusions, or outright rejection.
What Cyber Insurers Require
Common prerequisites that UK cyber insurers look for during underwriting.
Multi-Factor Authentication
MFA on all remote access, admin accounts, and cloud services is now a universal requirement. Insurers will not cover businesses without MFA.
Endpoint Protection (EDR)
Modern endpoint detection and response on all devices. Traditional antivirus alone is no longer sufficient for most insurers.
Tested Backups
Regular, tested, immutable backups stored separately from your network. Insurers want evidence that backups are tested, not just that they exist.
Email Security
Advanced email filtering, DMARC/SPF/DKIM authentication, and anti-phishing controls to reduce the most common attack vector.
Staff Awareness Training
Regular security awareness training and simulated phishing exercises. Insurers recognise that human error is the biggest risk factor.
With vs Without Proper Security Controls
How your security posture affects insurance outcomes.
| Feature | Weak ControlsHigh premiums / Rejection | Strong ControlsBetter termsRecommended |
|---|---|---|
| Application outcome | Often rejected | Accepted |
| Annual premium (50 users) | £3,000–£8,000+ | £1,500–£3,000 |
| Excess/deductible | Higher | Lower |
| Coverage exclusions | Many | Fewer |
| Claims honoured | Risk of rejection | More likely |
Most UK businesses approach this backwards. They get quoted, get shocked at the price or the refusal, then scramble to fix controls. The cheaper, faster route is to treat the proposal form as a security checklist and close the gaps before an underwriter ever sees you. That is exactly the work our managed cybersecurity team does for clients heading into renewal.
What is cyber insurance and does my UK business need it?
Cyber insurance covers the financial fallout of a cyber attack: incident response costs, data recovery, business interruption, legal fees, regulatory defence, and in some policies, extortion payments. For UK SMEs it is now close to essential, because the cost of a serious breach routinely exceeds what a small business can absorb from cash flow.
The numbers make the case. "The average cost of the most disruptive breach is £3,550 (DSIT 2025)" for businesses overall, with medium and large organisations facing far higher figures, according to the government's Cyber Security Breaches Survey 2025. Insurance exists to stop a single incident becoming an existential event.
What security controls do UK cyber insurers require?
Underwriters now assess your security posture before they price the risk. The proposal form is effectively a controls audit, and weak answers either raise your premium or end the application. These are the controls UK insurers ask about most consistently in 2026.
- Multi-factor authentication (MFA): MFA on all remote access, admin accounts and cloud services is a universal requirement. Insurers will not cover businesses without it. This matters because "Only 40% of UK businesses have two-factor authentication enabled (DSIT 2025)" — meaning most applicants fail at the first hurdle. Our MFA setup for Microsoft 365 guide covers enforcement properly, not just switching it on.
- Endpoint detection and response (EDR): Modern detection on every device. Traditional signature antivirus alone is no longer accepted by most insurers. See our endpoint security page for what "good" looks like.
- Tested, immutable backups: Regular backups stored separately from the network, with evidence they have been restored — not just that they exist. Underwriters ask about restore testing frequency specifically.
- Email security: Advanced filtering plus DMARC, SPF and DKIM authentication to blunt the most common attack vector. Our email security service covers the full stack.
- Staff awareness training: Regular training and simulated phishing. Insurers know human error is the dominant risk factor, which is why phishing simulation and training carries weight on the proposal form.
- Patch management cadence: A documented process for applying critical patches quickly, usually within 14 days for high-severity vulnerabilities.
The NCSC's cyber insurance guidance makes the same point: insurance is a complement to good security, never a substitute for it.
How does Cyber Essentials affect cyber insurance?
Cyber Essentials is the UK government-backed certification that maps almost exactly onto what insurers want — boundary firewalls, secure configuration, access control, malware protection and patch management. Holding it tells an underwriter your baseline is sound, which is why many insurers reward it.
Several UK cyber insurers offer premium discounts of 10–25% (typical UK 2026 range) for organisations holding a current certification, and some now require it as a minimum condition of cover. There is also a direct incentive built into the scheme: businesses with annual turnover under £20m that certify their whole organisation to Cyber Essentials get free cyber liability insurance included, per the Cyber Essentials scheme. AMVIA holds Cyber Essentials Plus, so we know the assessment from the inside and can get you certified before your renewal date.
How much does cyber insurance cost with strong vs weak controls?
Your security posture is the single biggest lever on price. A business with the controls above gets accepted at lower premiums, lower excess and fewer exclusions. A business without them is quoted punitively or declined. The contrast for a typical 50-user firm looks like this.
| Factor | Weak controls (high premium / rejection) | Strong controls (better terms — recommended) |
|---|---|---|
| Application outcome | Often rejected | Accepted |
| Annual premium (50 users, 2026 market rates) | £3,000–£8,000+ | £1,500–£3,000 |
| Excess / deductible | Higher | Lower |
| Coverage exclusions | Many | Fewer |
| Claims honoured | Risk of rejection | More likely |
The pattern is clear: the money you spend closing security gaps is largely recovered through lower premiums and dramatically reduced breach risk. Cover is cheaper when you are genuinely harder to attack.
How do I apply for cyber insurance in the UK, step by step?
The fastest route to good terms is to prepare before you quote. Treat the proposal form as a pre-flight checklist and you turn a stressful negotiation into a formality. Here is the order we take clients through.
1. Run a gap assessment. Map your current controls against MFA, EDR, backups, email security, training and patching. A free security audit gives you this in writing. 2. Close the critical gaps. Enforce MFA everywhere, deploy EDR, prove your backups restore, and harden email. These are non-negotiable for cover. 3. Get Cyber Essentials certified. It evidences your baseline and enables discounts or free cover. 4. Document everything. Underwriters want evidence — policies, testing logs, training records — not assertions. 5. Answer the proposal form accurately. Never overstate your posture (see the next section on why). 6. Compare quotes on cover, not just price. Check exclusions, sub-limits, and incident-response support, including whether the policy gives you access to a breach response team.
If you cannot answer a proposal question confidently, that is a gap to fix — not a box to tick optimistically. Our 24/7 managed detection and response service exists partly because insurers increasingly expect round-the-clock monitoring on higher-value policies.
Can a cyber insurance claim be rejected after a breach?
Yes, and it happens. If an insurer finds you misrepresented your security on the application, or failed to maintain the controls you declared, the claim can be reduced or refused entirely. The "warranty" wording in most policies means a single false answer can void cover when you need it most.
This is the core risk of the tick-box approach. If you declared MFA on all accounts but left admin accounts exposed, and the breach came through one of them, expect a fight — or a refusal. Accuracy on the proposal form, backed by controls you actually run, is what makes a policy pay out.
Frequently Asked Questions
Evidence of controls, not promises: MFA everywhere, endpoint detection, tested backups, email security and staff training are now baseline expectations — applications without them face declined cover or loaded premiums. The proposal form is effectively a security audit.
Typical SME premiums run £1,500–£3,000 a year for meaningful cover, scaling with turnover, sector and controls. Weak security raises the premium faster than almost anything else — the same controls that protect you also price the policy.
Yes, twice over: certification evidences exactly the controls insurers ask about, and basic Cyber Essentials through IASME includes cyber liability insurance for eligible UK organisations under £20m turnover — a bundled floor of cover many SMEs don't realise they get.
If your application was accurate and controls were actually in place, that's what it's for. The claims that fail are the ones where the proposal form said MFA everywhere and the forensics found otherwise — which is why controls must be real, monitored and evidenced, not aspirational.
Get Insurer-Ready
AMVIA helps UK businesses meet cyber insurer requirements. We assess your current position and close the gaps.
Related Questions
Managed Cybersecurity
The security controls insurers expect, delivered as managed cybersecurity.
What Is Multi-Factor Authentication?
MFA is the single most impactful control insurers require — it prevents 99.99% of account compromise attempts.
How Much Does Managed Cybersecurity Cost?
Per-user pricing for managed cybersecurity — the controls insurers require, delivered as a fixed monthly service.
Protect your business → Get Cybersecurity Assessment