Compliance & RiskCommercial

Cyber insurance for UK SMEs: what underwriters now require

MFA, EDR, backups and training — the controls quietly becoming mandatory at renewal.

26 February 2026 7 min read
Cyber insurance for UK SMEs: what underwriters now require — Compliance & Risk illustration

Cyber insurance for UK SMEs in 2026 looks very different from five years ago. Premiums have stabilised, but the questionnaires have hardened. The controls below are no longer optional — they're effectively pre-conditions for cover.

The non-negotiables in 2026

  • MFA on email, remote access and all privileged accounts.
  • EDR (not legacy antivirus) on every endpoint, with monitored alerts.
  • Offline or immutable backups, with tested restores.
  • Security awareness training and phishing simulations at least quarterly.
  • A documented incident response plan with named contacts.
  • Patching of high/critical vulnerabilities within 14 days.

What weakens or voids a claim

  • Answering 'yes' to controls you don't actually have in place.
  • Allowing MFA gaps on service accounts, ex-staff or admins.
  • Backups that were online and got encrypted with everything else.
  • Paying a ransom without insurer approval.
  • Failing to notify within the policy's required window.

How to make renewal easier

  1. Get Cyber Essentials — it answers half the questionnaire.
  2. Adopt a managed cyber security subscription that maps cleanly to insurer controls.
  3. Keep an evidence pack ready: MFA reports, EDR coverage, backup tests, training completion.
  4. Run a tabletop exercise so your IR plan isn't just a document.

The bigger picture

Insurance is risk transfer, not risk reduction. The cheapest path to lower premiums is genuinely lower risk — the same controls that keep you out of an incident keep you in cover.

Next step

Renewal coming up? Book a free 30-minute review and we'll map your current setup against typical underwriter requirements.

Related services

Free cyber security review

Get a plain-English view of where your business stands.

30 minutes with a UK specialist. No obligation, no sales pitch.

Book my free cyber security review