Search the blog
The government's Cyber Security Breaches Survey 2025/2026 found that 47% of UK businesses now have some form of cyber cover, but only 10% hold a standalone cyber policy; the other 37% rely on a cyber section inside a wider commercial policy (DSIT, 2026). Among small businesses of 10 to 49 staff the figure is 55%.
The catch is that the cover is only worth what the proposal form says it is. Insurers have turned a handful of security controls into conditions of cover, and the Association of British Insurers (ABI) published guidance on exactly those controls on 19 August 2026 (ABI, 2026). This article sets out what a UK insurer will ask, what a policy will and will not pay for, how the free Cyber Essentials-linked cover works, and what to fix before you apply.
What a cyber policy actually covers
The ABI's explainer splits cover into first-party losses (your own costs) and third-party liability (claims against you). A typical policy pays for incident response — forensics, legal advice, notifying customers, PR, dealing with the regulator — plus data restoration, business interruption and cyber extortion, described as "reimbursement of the ransom amount demanded by the attacker as well as any consultant's fees" (ABI, n.d. a). Post-incident support is usually standard.
The ABI and PwC's August 2026 market assessment says the product has moved "from pure risk transfer to continuous risk engagement" (ABI and PwC, 2026) — which is why the questionnaire has become so specific.
What insurers ask on the proposal form
The ABI guidance lists eleven controls: the five Cyber Essentials controls plus six that ABI member insurers ranked roughly by effectiveness — staff training, backups, incident response planning, logging and monitoring, encryption, and supply-chain security (ABI, 2026). It notes that the controls "are not all required by cyber insurers to provide cover and each insurer will consider them and other factors independently".
The market assessment is blunter about the floor: three minimum hygiene standards are now expected across the UK market — multi-factor authentication (MFA), immutable backups, and incident response and recovery planning — and "the market has the most appetite for businesses that meet the minimum control requirements" (ABI and PwC, 2026). Table 1 maps the questions you will meet to the control that answers them.
| Question on the form | What the insurer is really checking | Control that answers it |
|---|---|---|
| Is MFA enforced on email, remote access and admin accounts? | Whether a stolen password alone gets an attacker in. | MFA on every cloud service, phishing-resistant where possible (authenticator app or passkey). |
| Are backups offline or immutable, and when were they last tested? | Whether ransomware can reach the backups too. Cloud sync does not count. | Immutable or offline backups with a documented restore test. |
| Is endpoint detection and response (EDR) on all devices? | Whether an intrusion is spotted before it becomes ransomware. | EDR, not just antivirus, on every laptop, desktop and server. |
| Are critical patches applied within 14 days? | Exposure to known, exploited vulnerabilities. | A patch process covering operating systems, applications and firmware. |
| Do you have a written, tested incident response plan? | Whether it has been tested in a "realistic tabletop exercise". | A one-page plan with named roles and contacts, rehearsed yearly. |
| Do you keep security logs, and for how long? | Whether a breach can be investigated. The NCSC advises at least six months. | Central log retention for email, identity and endpoint events. |
| Do staff receive regular security training? | Phishing, business email compromise, social engineering. | Recurring, scenario-based training, not a one-off induction. |
| Do you hold Cyber Essentials or Cyber Essentials Plus? | Independent evidence that the basics are in place. | Current certification under the Danzell question set. |
Two points deserve emphasis. MFA is a condition, not a preference: "most insurers now treat MFA as a critical cyber underwriting consideration" and "cover or claims may be declined if MFA has not been deployed in line with the insurer's requirements" (ABI, 2026). Tick "yes" and let an incident reveal three accounts without it, and you have a misrepresentation problem before you have a claim. And cloud sync is not backup: it replicates deletion and encryption to the cloud within seconds.
The Cyber Essentials link, and the free cover
When a UK-domiciled organisation with turnover under £20 million certifies its whole organisation to Cyber Essentials (the self-assessed level), it can opt in to cyber liability insurance at no extra cost. The policy carries a £25,000 total limit of indemnity, a £1,000 excess (£5,000 for claims arising in the USA or Canada), a six-hour network-interruption retention and a 24-hour helpline; it runs for the twelve months of the certificate, underwritten by American International Group UK Limited and administered by Sutcliffe & Co (IASME, 2026). It covers liability, event management, extortion, regulatory investigations and network interruption, but "does not cover you for money that may be stolen via electronic means or cyber fraud".
For a 25-person firm, treat £25,000 as a floor and the certificate as the thing that makes a proper policy easier to obtain. Certification is rising — 5% of businesses overall, up from 3%, and 12% of small businesses, up from 5% (DSIT, 2026) — and we covered the April 2026 changes in our post on what changed in Cyber Essentials.
What it costs
There is no published price list; premiums depend on turnover, sector, the limit you buy and, increasingly, your answers to the questions above. The market has turned in the buyer's favour: capacity and appetite are "at historically high levels", with softer pricing for well-controlled risks, and some insurers are removing the sub-limits and co-insurance that used to hollow out ransomware and incident-response cover (ABI and PwC, 2026). The same report shows why underwriters still care: ABI members paid nearly £200 million in cyber claims in 2024, up 230% on the previous year, with ransomware and malware accounting for over half of claims.
The same firm gets a different quote depending on whether it can say "yes" to MFA, immutable backups and a tested plan; fixing those three is the largest lever on price.
What it will not cover
The ABI's list of common exclusions is the place to start (ABI, n.d. b):
- Fines and penalties. Cyber insurance "will not cover criminal, civil or regulatory fines, penalties or sanctions". An Information Commissioner's Office penalty is yours.
- Claims from related parties. Claims by your own employees, contractors and partly owned subsidiaries are normally outside cover.
- Physical damage, and outages of national infrastructure such as electricity or telecoms.
- War and state-backed attacks. Since 31 March 2023 standalone cyber policies at Lloyd's must, unless Lloyd's agrees otherwise, exclude losses from war and from state-backed cyber-attacks that "significantly impair the ability of a state to function" or its security capabilities, with an agreed basis for attribution (Lloyd's, 2022). Ask how your insurer defines "state-backed" and who decides.
- Money stolen by fraud. The Cyber Essentials-linked policy excludes it outright (IASME, 2026), and commercial policies often treat funds-transfer fraud as an optional extension. With phishing reported by 38% of businesses this year (DSIT, 2026) — see our post on phishing — it is the extension to price.
Read the conditions as carefully as the exclusions: a control you declared and then let lapse can void a claim just as effectively.
Ransomware payments: where the law stands
The Home Office consulted in 2025 on: a ban on ransom payments by public-sector bodies and critical national infrastructure operators; a “payment prevention” regime under which any other organisation intending to pay must first notify the government; and mandatory incident reporting. The government's response of 22 July 2025 reported 72% support for the targeted ban and 63% for economy-wide mandatory reporting, and committed to “continue to develop” all three proposals (Home Office, 2025). It gave no date for legislation.
For a private small business, paying is therefore not banned at the time of writing: organisations outside the ban "remain able to make ransomware payments", though the proposed regime would let the government block a payment that "could go to criminals subject to sanctions designations", and "the Government does not advise paying ransoms" (Home Office, 2025). Extortion cover can reimburse a payment (ABI, n.d. a); it does not make paying a good idea. Backups the attacker cannot reach make the question irrelevant.
What a 25-person firm should do before applying
Suppose a 25-person firm on Microsoft 365 with two on-premises servers wants a standalone policy this autumn:
- Turn on MFA everywhere — Microsoft 365, accounting, CRM, VPN, remote desktop, the backup console — using authenticator-app or passkey methods, then audit for exceptions.
- Separate the backups from the network. Immutable cloud backup for servers and Microsoft 365 data, with a dated restore test.
- Replace antivirus with EDR on every device, including laptops that live at home.
- Write the incident response plan on one page and rehearse it for an hour.
- Get Cyber Essentials. It gives you the free £25,000 cover and answers several form questions in one line.
- Fill in the form truthfully, keep a copy, and review every "yes" before renewal.
- Price the extensions — funds-transfer fraud, and a business-interruption limit sized to real monthly revenue.
It is the list we work through for managed IT support clients. If you want the gaps found before the underwriter finds them, get in touch.
Sources
- ABI (2026) From prevention to resilience: good practice guidance on cyber resilience. Association of British Insurers, August 2026. https://keystone-cms-production-amfyhhecavg8gneq.northeurope-01.azurewebsites.net/blob/keystoneproduction/publicFile/2026/08/abi-good-practice-guidance-cyber-resilience-august2026-cmt05ib211zqdg9mkfhze6aqc.pdf (accessed 25 August 2026).
- ABI and PwC (2026) UK cyber insurance market assessment. Association of British Insurers and PwC UK, August 2026. https://keystone-cms-production-amfyhhecavg8gneq.northeurope-01.azurewebsites.net/blob/keystoneproduction/publicFile/2026/08/cyber-insurance-market-assessment-august2026-cmt05ikq300jfgaqr9xjh5zz1.pdf (accessed 25 August 2026).
- ABI (n.d. a) What does cyber insurance cover? Association of British Insurers. https://www.abi.org.uk/products-and-issues/choosing-the-right-insurance/cyber-insurance/what-does-cyber-insurance-cover/ (accessed 25 August 2026).
- ABI (n.d. b) Common exclusions: cyber insurance. Association of British Insurers. https://www.abi.org.uk/products-and-issues/choosing-the-right-insurance/cyber-insurance/common-exclusions-cyber/ (accessed 25 August 2026).
- DSIT (2026) Cyber security breaches survey 2025/2026. Department for Science, Innovation and Technology, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026 (accessed 25 August 2026).
- Home Office (2025) Government response to ransomware legislative proposals: reducing payments to cyber criminals and increasing incident reporting. 22 July 2025. https://assets.publishing.service.gov.uk/media/6899a4ddad0cbc0e276431e3/Government_Response_Ransomware_proposals_to_increase_incident_reporting_and_reduce_payments_to_criminals.pdf (accessed 25 August 2026).
- IASME (2026) Cyber liability insurance — Cyber Essentials. IASME Consortium. https://iasme.co.uk/cyber-essentials/cyber-liability-insurance/ (accessed 25 August 2026).
- Lloyd's (2022) Market Bulletin Y5381: state backed cyber-attack exclusions. Lloyd's of London, 16 August 2022. https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf (accessed 25 August 2026).