Cyber Insurance Is Getting Harder to Get
UK cyber insurance has changed dramatically in the last three years. Following a wave of ransomware claims that cost insurers billions globally, underwriters have tightened their requirements significantly. Businesses that were previously able to obtain affordable cover with minimal vetting now face detailed questionnaires, higher premiums, and in some cases outright refusals.
If you are renewing your policy, applying for new cover, or trying to understand why your premium has doubled, this guide explains what UK insurers are now looking for — and how your security posture affects your position.
What Insurers Are Now Asking
Modern cyber insurance applications typically run to 15–30 pages of technical questions. The days of ticking "yes, we have antivirus" and obtaining cover are over. Underwriters now ask specifically about:
Multi-Factor Authentication (MFA)
This is now close to a hard requirement across the market. Insurers ask:
- Is MFA enforced for all remote access to your network (VPN, RDP, remote desktop)? - Is MFA enforced for email (Microsoft 365 or Google Workspace)? - Is MFA enforced for privileged accounts (admin access to servers, cloud infrastructure)?
A business that cannot confirm MFA on remote access will either be refused cover or face a significant premium loading. A single compromise of a remote access account without MFA has been the root cause of the majority of ransomware incidents.
Endpoint Detection and Response (EDR)
Insurers increasingly distinguish between traditional antivirus (blacklist-based, file-scanning) and EDR tools (behaviour-based, with real-time monitoring and incident response capability). They ask whether you have EDR deployed and whether you have 24/7 monitoring capability.
Backup Configuration
Ransomware is only successful as an extortion tool if the victim cannot restore their systems. Insurers ask:
- Are backups taken regularly (daily or more frequent for critical systems)? - Are backups stored offline or in a separate environment from your production systems (air-gapped)? - Have you tested restoring from backup in the last 12 months? - Are backups encrypted?
The critical question is the air-gap: backups stored on a network-connected device in the same environment as your production systems are often encrypted by ransomware alongside everything else.
Patch Management
Insurers ask about your patching cadence, specifically: - How quickly do you apply critical security patches after release? - Do you have a formal patch management process? - Are you running any end-of-life operating systems (Windows 7, Windows Server 2008)?
Unpatched systems are the entry point for a high proportion of ransomware attacks. Running end-of-life software that no longer receives security patches is a significant red flag for underwriters.
Penetration Testing and Vulnerability Scanning
This is increasingly common in underwriting questionnaires:
- Have you conducted a penetration test in the last 12 months? - Have you conducted vulnerability scanning against your internet-facing systems? - Were significant findings remediated?
Being able to answer yes to these questions — and provide evidence — demonstrates a proactive security posture that reduces risk. Some insurers now offer premium discounts for businesses that conduct regular security testing.
How Insurers Use Your Answers
Underwriters use your answers in two ways. First, they assess your risk profile and decide whether to offer cover and at what premium. Second, in the event of a claim, they review your answers and may decline to pay if they find you misrepresented your security controls.
This matters because cyber claims investigations include technical examination of your environment at the time of the incident. If your application stated you had MFA on all remote access and the investigation reveals you did not, you may face a coverage dispute.
What Constitutes Evidence of Security Testing?
If an insurer or broker asks for evidence of security testing, acceptable documentation typically includes:
**Automated scan reports** — Reports from tools like Yrzo AI showing what was tested, what was found, and when. PDF reports with specific findings, severity ratings, and remediation guidance are appropriate.
**Penetration test reports** — Reports from qualified penetration testers showing scope, methodology, findings, and remediation status. These carry more weight than automated scanning alone.
**Cyber Essentials or Cyber Essentials Plus certification** — The UK government's Cyber Essentials scheme is well-recognised by insurers. Certification demonstrates that you meet a baseline of security controls.
How Security Testing Affects Your Premium
Beyond simply qualifying for cover, demonstrating a mature security posture can materially reduce your premium. Factors that help:
- Regular vulnerability scanning (monthly or quarterly) - Annual penetration testing with evidence of remediation - Cyber Essentials or Cyber Essentials Plus certification - MFA universally deployed - Security awareness training with documented completion rates
Some insurers offer 10–25% premium reductions for businesses that meet specific security benchmarks. At the scale of a typical SME premium (£2,000–£10,000 per year), the savings from a better security posture can easily offset the cost of security testing.
The Practical Checklist
Before your next cyber insurance renewal, verify:
**MFA** — Enabled on Microsoft 365, Google Workspace, VPN/remote access, and admin accounts.
**Backups** — Daily, tested, stored offline or in a separate cloud tenant.
**Patching** — Critical patches applied within 14 days of release; no end-of-life operating systems.
**Endpoint protection** — EDR or at minimum business-grade antivirus on all endpoints.
**Vulnerability scanning** — At least annual automated scan of internet-facing systems, with findings documented.
**Incident response plan** — A documented plan for how you would respond to a ransomware or data breach incident.
Running Yrzo AI's automated security scanner against your internet-facing applications gives you a documented scan report that demonstrates you are actively monitoring your security posture — and often surfaces vulnerabilities worth fixing before your insurer's surveyor does.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →