Cyber insurance used to be simple to buy. You would fill in a short form, pay the fee, and be covered. That’s no longer how it works.
Insurers have changed their approach. They’ve paid out on too many claims where basic protections were missing. Now, before they’ll cover you, they want proof. Proof that your cyber security is doing its job and if something goes wrong later, they’ll check that proof again before they pay anything out.
This matters more than most business owners realise. Your policy and your IT setup are no longer separate. They’re closely tied together.
Why Insurers Got Stricter
A few years ago, cyber insurance was priced almost like a formality. Attacks were less common back then where insurers didn’t fully understand the risk yet. That’s changed fast.
Ransomware attacks on UK small and medium businesses now cost well over £200,000 per incident, on average, when things go badly. Multiply that across thousands of policyholders, and it’s easy to see why insurers tightened their rules. They’re not trying to make life harder for small businesses. They’re trying to stop paying for losses that proper security would have prevented in the first place.
So now, insurers ask questions before offering cover. Do you use multi-factor authentication? Are your systems patched regularly? Do you test your backups? Is there a written plan for what happens after an attack? Weak answers mean one of three things: you pay more, you get less cover or you get turned down completely.
The Controls Insurers Actually Want to See
A handful of security measures now sit at the centre of most cyber insurance applications.
Multi-factor authentication. This is often the first question asked, and for good reason. Most successful attacks start with a stolen password where MFA adds a second check, like a code sent to your phone. A stolen password alone isn’t enough to get in anymore.
Regular patching. Software companies release updates to fix security holes. If those updates sit unapplied for months, those holes stay open. Insurers want to see a routine for this and not a one-off effort from months ago.
Tested backups. It’s not enough to just have backups sitting somewhere. Insurers want proof they’ve been tested and they want to know data can be restored quickly if needed. A backup nobody has checked in a year might not work when it counts most.
Endpoint protection. This means proper security software on every laptop, desktop, and device connected to your network. Not just a basic free antivirus tool left over from years ago.
A written incident response plan. If something goes wrong, insurers want proof your business knows what to do next, who to call, what to shut down and how to keep working while the mess gets sorted.
Staff training. People are still the easiest way into a business. Insurers increasingly ask whether your team has been shown how to spot scams and odd activity.
What Happens If You Can’t Show These Controls
Some businesses assume they can answer the application questions honestly, get a policy, and sort out the real security later. That’s a risky habit.
If a claim comes in, and the insurer finds the controls you claimed weren’t really in place, they can refuse to pay. This has already happened to UK businesses who thought basic promises were enough. A missing piece of MFA, or a backup that turned out broken, has been reason enough for a denied claim.
In other words, a policy bought on shaky answers might feel like protection. But it may not protect you at all when it actually matters.
Good IT Security Also Lowers Your Premium
There’s a more positive side to this too where insurers reward businesses that can clearly show strong security. That often means lower premiums, wider cover, and a smoother renewal process each year.
Think of it like car insurance where a driver with a clean record and safety features fitted pays less than one without. Cyber insurance now works on a similar idea that the stronger your setup looks on paper, the less risky you appear, and the better your terms tend to be.
This also means your IT security budget isn’t sitting apart from your insurance costs. The two are linked in that money spent well on MFA, patching, and monitoring can pay itself back through cheaper, more reliable cover down the line.
A Quick Story That Shows Why This Matters
Picture two similar businesses and both get hit by a ransomware attack on the same day where both have cyber insurance in place.
The first business has MFA switched on, patches applied on a schedule, and backups tested every month. Their claim gets paid and their systems are back up within days. The insurer treats it as exactly the kind of event the policy was written for.
The second business ticked the same boxes on their application form last year, but never actually followed through. No MFA on half their accounts and backups that hadn’t been checked since they were set up. Their claim gets challenged, delayed, and eventually only partly paid. The gap between those two outcomes isn’t luck, it’s preparation and execution.
How Cheeky Munkey can help manage your IT security setup
Most businesses don’t need to overhaul everything overnight. A sensible first step is a plain review. Where are the gaps? What would an insurer ask about? Could you answer those questions confidently today, without guessing?
From there, it’s usually a case of closing the obvious holes first. Multi-factor authentication across every important account. A clear patching routine, instead of one that happens whenever someone remembers. Backups tested on a proper schedule, not just set up once and left alone.
Cheeky Munkey works with clients across St Albans and the wider UK to get this groundwork of managed IT support sorted, and to keep it maintained over time. We know what insurers ask for, because we see the same questions come up again and again. If you’d like help reviewing your setup before your next renewal, or before applying for cover for the first time, get in touch with our team for a straightforward chat.
About The Author
Charles Martin
Charles Martin is an experienced IT operations and service delivery leader with over a decade spent building strong teams and keeping technology running smoothly in fast‑moving environments. As Head of Operations at Cheeky Munkey Ltd, he makes sure the company delivers reliable, forward‑thinking IT support and consulting services to clients across the region.
Throughout his career, Charles has worked across IT service management, service desk leadership, field operations, and professional services. He’s well‑versed in ITSM best practices, process improvement, and creating service models that put people at the centre. From managing large teams to delivering enterprise‑scale projects, he’s built a reputation for bringing structure, clarity, and consistency to complex operational challenges.
Previous