Cyber Insurance Readiness Check
Fifteen questions covering the controls UK insurers keep asking about — MFA, EDR, backups, patching, incident response. Find the likely friction points on your next proposal form before your broker does. Not insurance advice; a preparation tool.
Quick answer
This free check reviews your business against the security controls that appear most often on UK cyber insurance proposal forms: multi-factor authentication across email, remote access and admin accounts; endpoint detection and response; tested, isolated backups; patch cadence; privileged access; incident response planning; and staff training. It flags likely friction points — it does not predict cover, premium or claims outcomes, and it is not insurance advice.
Cyber Insurance Readiness Check
Fifteen questions covering the controls that appear again and again on UK cyber insurance proposal forms — MFA, endpoint protection, backups, patching, privileged access, incident response and training. "Not sure" counts as a gap: a proposal form will make you find out.
1.Is MFA enforced on all email accounts?
2.Is MFA enforced on remote access (VPN, remote desktop)?
3.Is MFA enforced on administrator accounts?
4.Are admin rights limited to those who need them, using separate admin accounts?
5.Is EDR (endpoint detection and response) deployed on all endpoints — beyond traditional antivirus?
6.Does anyone actually monitor and respond to endpoint alerts (in-house or a managed service)?
7.Do automated backups cover all business-critical data (including Microsoft 365 / cloud data)?
8.Is at least one backup copy offline, immutable, or otherwise unreachable by ransomware on your network?
9.Have you tested a restore in the last six months?
10.Are critical security updates applied within 14 days across your estate?
11.Is any end-of-life software (no longer receiving security fixes) still in use?
12.Do you have a written incident response plan?
13.Has the plan been tested (even a tabletop walkthrough) in the last year?
14.Have staff had security awareness training in the last 12 months?
15.Do you run phishing simulations?
0/15 answered — results are calculated in your browser.
Before your next renewal
Check the controls
Fifteen questions, instant results. These are the controls proposal forms ask about because they are the ones that decide how ransomware incidents end.
Close the friction points
MFA enforcement, EDR deployment, backup isolation and patch discipline are all fixable in weeks — and Cyber Essentials certification evidences several in one recognised package.
Answer the form honestly
Proposal forms are warranties — inaccurate answers surface at claim time, which is the worst possible moment. Fix the controls; don't finesse the form.
The controls insurers ask about
MFA everywhere it matters
Email, remote access and admin accounts — increasingly a condition of cover rather than a discount.
EDR, not just antivirus
Endpoint detection and response with someone actually watching the alerts.
Backups that survive ransomware
Automated coverage of critical data with an offline or immutable copy, and restores that have actually been tested.
Patch discipline
Critical updates within 14 days and no end-of-life software in production.
Incident response
A written plan someone has tested — evidence an insurer can request after a claim.
People controls
Awareness training with dates against names, and phishing simulations that measure it.
Related resources
Cyber Essentials readiness assessment
Twenty questions against the five certification controls — several overlap with what insurers ask.
Cyber Essentials: the complete guide
The UK baseline certification that evidences many insurer-required controls in one package.
Managed cybersecurity
MDR, email security and the day-to-day control operation insurers want to see.
All free security tools
The full toolkit: attack surface scan, readiness assessments, certificate checker and more.
Fix the friction points before renewal
AMVIA implements the controls insurers ask about — MFA, managed EDR, isolated backups, patching — as managed services with evidence you can hand to a broker.
Cyber insurance readiness questions
Requirements vary by insurer and change with the claims environment, but the recurring themes on UK proposal forms are MFA (especially on email, remote access and admin accounts), endpoint detection and response, isolated and tested backups, prompt patching, restricted admin rights, an incident response plan and staff training. Weak answers increasingly mean exclusions, higher premiums or declined cover.
No. It is general guidance about controls insurers commonly ask about, drafted by an MSP — not by a broker or insurer. It does not predict cover, premium or claim outcomes. Speak to your broker about your specific policy; use this to prepare for the questions they will relay.
Typically yes, in two ways: the certification process forces several of the controls insurers ask about (MFA, patching, access control), and basic Cyber Essentials certification through IASME includes cyber liability insurance for eligible UK organisations with under £20 million turnover. It is not a substitute for a standalone policy sized to your risk.
Because they decide how ransomware incidents end. MFA blocks the credential-based intrusions that start most incidents, and isolated, tested backups determine whether an incident is a bad week or an existential loss. Claims data has pushed both from "nice to have" to near-conditions.
Proposal answers generally operate as warranties or representations — if a claim investigation finds a control you attested to wasn't actually in place, the insurer may reduce or decline the claim. That is why the honest fix is closing the gap, not wordsmithing the answer.
Yes — MFA enforcement, managed EDR, backup design with isolation and restore testing, patch management and incident response planning are core managed cybersecurity work. We can also take you through Cyber Essentials, which evidences several controls at once.