UK cyber insurance has changed. Five years ago you ticked a few boxes and paid a few hundred pounds. Today, a typical SMB renewal involves a 30-question technical questionnaire, evidence requests, and (increasingly) a refusal to renew if controls aren’t good enough.
This guide gets you through it. Every question your insurer will ask, what they’re actually checking for, and how to answer in a way that gets you covered without burning a week of fee earner time.
In short: passing a cyber insurance renewal now hinges on a handful of controls, MFA, backups, patching and endpoint protection, that insurers expect to see in place. Here is how to answer the questions honestly and pass.
Key takeaways
- Cyber Essentials certification answers most insurer questionnaires in one tick.
- The 12 most-asked questions cluster around MFA, backups, EDR, patching and email filtering.
- Saying “yes” without evidence is the fastest way to invalidate your policy if you ever claim.
- Most renewal failures come from being unable to answer “what would happen if your finance system was encrypted by ransomware right now?”

The 12 questions every UK cyber renewal asks
Insurer questionnaires vary, but the same 12 questions recur across nearly every UK provider. If you can answer “yes, with evidence” to all of them, you’ll renew smoothly.
1. Is multi-factor authentication enforced for all staff on email and remote access?
What they want: MFA on for every team member, not just admins, on Microsoft 365, Google Workspace, your VPN/SSO and any externally accessible system. Self-attestation that “staff have it available” is not enough.
2. Are backups segregated from your live environment and tested regularly?
What they want: immutable backups (the attacker can’t delete them even with admin access), stored separately from the systems being backed up, and a documented recent test restore. “We have OneDrive sync” is not a backup.
3. Is endpoint detection and response (EDR) deployed on all devices?
What they want: a modern EDR product (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) on every workstation and server, with monitoring and response. Old-school antivirus alone increasingly fails this question.
4. Are systems patched within 14 days of a critical vulnerability being announced?
What they want: a documented patching cadence, automated where possible, with an audit trail. “We do it when we remember” doesn’t cut it.
5. Do you use email filtering with anti-phishing and impersonation protection?
What they want: Microsoft Defender for Office 365, Mimecast, Barracuda or equivalent. Plain Microsoft 365 mail filtering without Defender add-ons is borderline.
6. Are admin accounts separated from staff accounts?
What they want: domain admins, M365 global admins and other privileged accounts are separate from the daily-use accounts of the people who hold them. Andy Price has andy@ for email and andy.admin@ for elevated work, with MFA on both and the admin account never used for browsing or email.
7. Have you implemented Cyber Essentials or Cyber Essentials Plus?
What they want: ideally yes. If yes, several other questions get auto-passed. If no, expect more probing on the technical questions.
8. Do you provide regular cyber awareness training to staff?
What they want: at least quarterly training, simulated phishing campaigns, and records showing completion. Annual e-learning that nobody finishes is not adequate.
9. Do you have a documented incident response plan?
What they want: a written IRP covering detection, containment, eradication, recovery and lessons-learned. Bonus points if it’s been tabletop-tested in the last 12 months.
10. Are remote desktop services (RDP) exposed to the internet?
What they want: NO. RDP open to the internet is the single largest ransomware attack vector. If you have remote access, it must go through a properly configured VPN, ZTNA service or RD Gateway with MFA.
11. What’s your retention period for security logs?
What they want: at least 12 months of authentication, system and security logs centrally collected and searchable. If a breach is discovered 6 months later, can you reconstruct what happened?
12. Do you have a Business Email Compromise (BEC) financial verification process?
What they want: a documented process where any payment instruction received by email is verified by a second channel (phone call to a known number) before processing. BEC is the most common route to financial loss for SMBs.
The two questions that catch most businesses out
From experience helping clients through renewals, two questions trip up the highest number of businesses.
“Are your backups immutable and separated?”
Most SMBs think OneDrive sync or even regular file backups count. They don’t, because if an attacker compromises your admin account, they can delete the backups too. Immutable means the backup, once written, cannot be modified or deleted by anyone, including admins, for the retention period.
“Is RDP exposed to the internet?”
This question catches businesses with legacy remote-desktop setups, especially anyone whose IT person set up “Remote Desktop on port 3389” years ago and never reviewed it. If your firewall has port 3389 (or 3388, 3390, etc.) open to the world, you’ll fail this question. Move to a VPN, ZTNA or RD Gateway with MFA before renewal.
The honest truth about declarations
If you tick “yes” to questions you can’t actually evidence, and you later make a claim, the insurer can void your policy on the grounds of misrepresentation. Two real consequences:
- Renewal premiums: insurers cross-check your previous answers. Saying “yes” one year and “no” the next without explanation triggers questions.
- Claims handling: if you claim and the breach involves a control you said you had but didn’t, expect the claim to be challenged.
Be honest. Where you don’t yet have a control, say so and outline the timeline to put it in place. Most underwriters prefer “no, but we’re rolling out X by date Y” to a hopeful tick.
Frequently asked questions
Do I need cyber insurance?
For most UK SMBs, yes. The average ransomware demand is now in six figures, and the cost of forensic response, business interruption and notification under UK GDPR easily reaches that even without paying a ransom. A reasonable cover level for a 25-person SMB is £1m-£5m, often costing £1,200-£3,500/year.
What does cyber insurance not cover?
Read your policy carefully, but typical exclusions include: physical damage, fraud where the policyholder was complicit, fines for regulatory non-compliance, and (increasingly) attacks attributed to nation-state actors. Acts of war exclusions are tightening every year.
Will Cyber Essentials reduce my premium?
Often yes, sometimes by 15-30%. Some insurers offer a Cyber Essentials Plus discount specifically. Ask your broker.
How often do I need to renew?
Annually. Some specialist policies have multi-year terms but most are 12-month.
Can my MSP help with the questionnaire?
Yes, this is a standard part of what we do. We answer the technical questions accurately on your behalf, supply the evidence, and flag any gaps before submission. Saves you significant time and increases your chance of getting cover at the right premium.
We help UK SMBs prepare for cyber insurance renewals as part of our managed IT services. Most clients pass first time at favourable premiums.
