Cyber insurance for UK SMEs in 2026 looks very different from five years ago. Premiums have stabilised, but the questionnaires have hardened. The controls below are no longer optional — they're effectively pre-conditions for cover.
The non-negotiables in 2026
- MFA on email, remote access and all privileged accounts.
- EDR (not legacy antivirus) on every endpoint, with monitored alerts.
- Offline or immutable backups, with tested restores.
- Security awareness training and phishing simulations at least quarterly.
- A documented incident response plan with named contacts.
- Patching of high/critical vulnerabilities within 14 days.
What weakens or voids a claim
- Answering 'yes' to controls you don't actually have in place.
- Allowing MFA gaps on service accounts, ex-staff or admins.
- Backups that were online and got encrypted with everything else.
- Paying a ransom without insurer approval.
- Failing to notify within the policy's required window.
How to make renewal easier
- Get Cyber Essentials — it answers half the questionnaire.
- Adopt a managed cyber security subscription that maps cleanly to insurer controls.
- Keep an evidence pack ready: MFA reports, EDR coverage, backup tests, training completion.
- Run a tabletop exercise so your IR plan isn't just a document.
The bigger picture
Insurance is risk transfer, not risk reduction. The cheapest path to lower premiums is genuinely lower risk — the same controls that keep you out of an incident keep you in cover.
Next step
Renewal coming up? Book a free 30-minute review and we'll map your current setup against typical underwriter requirements.

