Cyber insurers can reject claims if your security controls don't match what you declared. Coreitech helps UK SMEs implement all required controls. 0203 834 9728.

— Cyber Insurance · SME Security · UK-Wide

CYBER INSURANCE
REQUIREMENTS
UK SME GUIDE · 2026

UK cyber insurers now require specific security controls before they'll pay out. Many SME claims are rejected because controls weren't properly implemented. Coreitech ensures your security posture matches what your insurer requires.

Gap assessment against your insurer's specific requirements
MFA, EDR, patching, backups — all implemented, not just documented
Cyber Essentials certification — 100% first-time pass rate
Signed attestation letter for your insurer
Ongoing managed security to maintain compliance at renewal

Cyber insurance security
requirements for UK SMEs

Controls required by Hiscox, Travelers, AXA XL, Beazley, CFC, and Aviva. Coreitech implements and maintains all of them.

mandatory

Multi-Factor Authentication (MFA)

MFA on all email, remote access, and admin accounts. Most insurers now class this as mandatory — no MFA, no cover.

mandatory

Endpoint Detection & Response (EDR)

NextGen AV/EDR on all endpoints. Basic antivirus no longer satisfies most insurer requirements for SMEs.

mandatory

Patching & Vulnerability Management

Critical patches applied within 14–30 days. Documented patch management process required by most insurers.

mandatory

Privileged Access Controls

Admin accounts separated from standard user accounts. Least-privilege access enforced across all systems.

recommended

Cyber Essentials Certification

Many UK insurers now offer premium discounts or require Cyber Essentials as a baseline for SMEs.

mandatory

Tested Backup & Recovery

Immutable offsite backups tested regularly. Insurers increasingly require documented recovery time objectives.

recommended

Security Awareness Training

Documented annual phishing training for all staff. Insurers treat untrained staff as a major underwriting risk.

recommended

Incident Response Plan

Written and tested IR plan. Insurers need confidence you can respond to and contain an incident quickly.

What major UK cyber insurers
specifically require

Hiscox

MFA, EDR, patching within 30 days, privileged access controls, tested backups

Travelers

MFA mandatory, EDR/AV, patch management, backup testing, email security (DMARC)

AXA XL

MFA, endpoint protection, privileged access, IR plan, security awareness training

Beazley

MFA, EDR, patching SLA, tested backups, Cyber Essentials recommended for SMEs

CFC Underwriting

MFA, EDR, patch management, email filtering, Cyber Essentials or equivalent

Aviva

MFA, endpoint security, access controls, business continuity plan, tested backups

Based on publicly available insurer security questionnaires as of 2025/2026. Always verify with your broker.

From gap assessment to
insurer-ready in weeks

Most UK SMEs applying for cyber insurance don't fully understand what they're signing up to. The application asks if you have MFA — you say yes, because it's switched on for some accounts. A breach occurs and the insurer investigates: MFA wasn't on your finance director's email. Claim denied.

Coreitech's cyber insurance readiness service starts with a gap assessment. We map your current security controls against your insurer's specific requirements, document what's missing, implement the fixes, and provide a signed attestation letter for your broker.

01
Gap assessment
We map your controls against your insurer's specific requirements. Delivered as a written report.
02
Remediation
We implement MFA, EDR, patching controls, email security, and tested backups — all documented.
03
Cyber Essentials (if required)
100% first-time pass rate. Fixed-fee £1,200–£2,500 including all technical remediation.
04
Insurer attestation letter
Written confirmation of your security controls satisfying most UK cyber insurers and brokers.
05
Ongoing compliance
Managed IT keeps controls in place. Annual review ahead of renewal ensures you stay insurable.

Cyber insurance requirements —
questions answered

Q.What cyber security requirements do insurers ask for in the UK?

UK cyber insurance providers now have strict minimum security requirements for SMEs. The most commonly required controls are: Multi-Factor Authentication (MFA) on all email, remote access, and admin systems; Endpoint Detection & Response (EDR) on all devices; Critical patch management within 14–30 days; Privileged access controls and account separation; Tested, immutable offsite backups; Email security (DMARC, anti-phishing filtering); and an Incident Response plan. Failing to have these in place can void your policy in the event of a claim.

Q.Will my cyber insurance claim be rejected if I don't meet the requirements?

Yes — this is the critical risk many SMEs don't understand. Cyber insurers include "warranty clauses" requiring you to maintain the security controls you declared at application. If you suffered a ransomware attack and did not have MFA enabled, or your backups had not been tested, most UK cyber insurers would decline or significantly reduce the claim payout. The solution is to implement the controls properly — not just tick boxes at renewal.

Q.Does Cyber Essentials certification help with cyber insurance?

Yes, significantly. UK cyber insurers including Hiscox, CFC, and Beazley offer premium discounts to businesses holding Cyber Essentials or Cyber Essentials Plus certification. Some insurers require it as a baseline for SMEs under 50 users. Coreitech offers end-to-end Cyber Essentials certification with a 100% first-time pass rate, from £1,200 fixed-fee.

Q.How much does it cost to meet cyber insurance requirements as an SME?

For a typical UK SME (10–50 users): MFA deployment (Microsoft Entra ID) is included in Microsoft 365 Business Premium (£19.80/user/month); EDR/NextGen AV: £3–8/device/month; Backup solution: £50–200/month; Cyber Essentials certification: £1,200–£2,500 fixed-fee; Security awareness training: £5–15/user/month. Coreitech's Advanced managed IT package at £50/user/month includes most of these controls under one fixed price.

Q.Can Coreitech help us pass a cyber insurance assessment?

Yes. Coreitech's cyber insurance readiness service covers: a gap assessment against your insurer's specific requirements; remediation of identified gaps (MFA, EDR, patching, backups, email security); Cyber Essentials certification if required; documentation of your security controls for the insurer; and an ongoing managed security service to maintain compliance between renewals.

Q.What happens if I don't meet cyber insurance requirements at renewal?

At renewal, most UK cyber insurers now require a detailed security questionnaire. If your security controls have deteriorated, you may face a premium increase, policy exclusions, or refusal to renew. Some insurers now require evidence of controls (e.g. a Cyber Essentials certificate or signed attestation from an IT provider). Maintaining strong security posture year-round is now inseparable from maintaining insurable risk.

Need to meet cyber insurance
requirements?

Free gap assessment — we'll tell you exactly which requirements you currently meet, what's missing, and what it will cost to fix it.