Cyber Insurance in 2026: The 6 Controls Insurers Now Demand Before They’ll Renew You

The cyber insurance requirements UK small business owners face in 2026 are becoming stricter.

Your cyber insurance renewal may look like a routine administration task. In 2026, it is anything but.

UK insurers have raised the bar for small and medium-sized businesses. Instead of asking whether you have “some security in place”, underwriters increasingly want evidence that specific controls are properly enforced, monitored and tested.

For a Hampshire business, this could mean providing technical reports, training records, backup test results and incident response documents before cover is renewed.

This guide explains the six controls insurers commonly expect and what you should prepare before completing your renewal questionnaire.

Important: Insurance requirements vary between providers and policies. Always check your policy wording and speak to your broker. Never confirm that a control is in place unless you can demonstrate that it is genuinely enforced.

What are the cyber insurance requirements UK small business owners must meet?

Cyber insurance can help with costs arising from incidents such as ransomware, data breaches, business interruption and cyber extortion. However, it is not a replacement for good security.

The National Cyber Security Centre’s cyber insurance guidance explains that organisations may need to provide accurate information about their technical, procedural and human controls. It also warns that if you claim security measures are in place when they are not, the insurer may not be obliged to pay a claim.

That is the key point for 2026:

Insurers are not simply asking what you purchased. They want to know what is active, who manages it and whether it works.

Consider a small professional services firm in Winchester. Its renewal form says that multi-factor authentication is enabled, backups are running and staff receive security training. The owner answers “yes” to each question.

Later, an investigation finds that:

  • MFA was enabled for Microsoft 365 administrators but not all ordinary users.
  • A remote desktop account was still protected only by a password.
  • Backups had been failing for several weeks.
  • Staff training was last completed three years ago.

Those gaps could affect the firm’s premium, cover, excess or ability to make a successful claim.

1. Enforce MFA for business-critical access

Multi-factor authentication (MFA) requires users to prove their identity using more than one method. For example, they might enter a password and approve a sign-in through an authenticator app.

MFA for business is now one of the most important insurance controls. However, “MFA is enabled somewhere” is not enough.

Insurers commonly expect MFA to be enforced on:

  • Email accounts, including Microsoft 365 or Google Workspace.
  • VPN access.
  • Remote desktop and other remote access tools.
  • Cloud administration consoles.
  • Privileged administrator accounts.
  • Systems containing sensitive financial, personal or customer data.

Do not rely on a policy that merely recommends MFA. Check that users cannot bypass it and that exceptions are documented, limited and reviewed.

Practical steps:

  1. List every system that allows remote or administrative access.
  2. Identify all administrator and privileged accounts.
  3. Enforce MFA rather than leaving it optional.
  4. Remove unused accounts and review exceptions.
  5. Keep a report showing which users and systems are protected.

Pro tip: Test remote access from outside the office. A business may have MFA on email but still expose an old VPN or remote desktop service protected by a password alone.

Geometric illustration of multi-factor authentication protecting email, VPN, cloud and administrator access

2. Use EDR, not just traditional antivirus

Antivirus remains useful, but it is no longer the whole answer.

Insurers increasingly expect endpoint detection and response (EDR). EDR is business-grade security software that monitors laptops, desktops and servers for suspicious behaviour. It can raise an alert, investigate activity and help isolate an infected device.

Traditional antivirus may recognise known malicious files. EDR looks more broadly at what is happening on the device, such as:

  • An unusual programme launching PowerShell.
  • A user account behaving differently from normal.
  • Files being rapidly encrypted.
  • A remote access tool being installed unexpectedly.
  • Suspicious movement between devices.

Your EDR should be centrally managed. Someone must review alerts and respond to them. Installing a product and ignoring its warnings will not provide meaningful protection.

Prepare evidence such as:

  • A list of covered devices.
  • The current EDR deployment report.
  • Monitoring and alert-handling procedures.
  • Records of security alerts and actions taken.
  • Evidence that servers and remote workers are included.

BITSmart’s cybersecurity services include endpoint detection and response, real-time monitoring and patch management as part of a broader security approach.

3. Patch promptly and document the process

Criminals regularly exploit known weaknesses in operating systems, applications, network devices and security products. A patch is a software update that fixes one of those weaknesses.

In 2026, insurers want more than an assurance that “updates happen automatically”. They may ask:

  • Which devices and applications are covered?
  • Who is responsible for patching?
  • How quickly are critical updates installed?
  • What happens when a patch fails?
  • How are unsupported systems managed?
  • Can you produce a recent compliance report?

Many organisations use 14 days for critical or high-risk patches as a practical benchmark, although your policy may specify different timescales.

Create a documented patching process:

  1. Maintain an accurate list of hardware and software.
  2. Classify critical systems and high-risk vulnerabilities.
  3. Use automated updates where appropriate.
  4. Investigate devices that fall behind.
  5. Record exceptions and the reason for them.
  6. Review patch compliance regularly.

A report showing 98% compliance is useful. A report showing 98% compliance with no plan for the remaining devices is not enough. Insurers will want to understand the risk and your response.

Geometric illustration of centrally monitored business endpoints receiving security patches

4. Maintain tested offline or immutable backups

A backup is only valuable if you can restore from it after an incident.

Ransomware can encrypt files connected to a network. It may also attempt to delete or damage backups. That is why insurers increasingly expect at least one backup copy to be offline or immutable.

  • Offline means the copy is disconnected from the network and cannot be reached during an attack.
  • Immutable means the backup cannot be changed or deleted for a defined period.

You should also test the restoration process. A dashboard showing “backup successful” does not prove that your files can be recovered.

Your backup evidence should show:

  • What data is backed up.
  • How often backups run.
  • Where each copy is stored.
  • Which copy is offline or immutable.
  • When a restore test was completed.
  • What was restored and whether the test succeeded.
  • Who investigates failed backups.

The NCSC recommends keeping backups separate from the network or using a cloud service designed for this purpose. Read its guidance on offline backups in an online world.

Note: A backup test should resemble a real recovery. Restore important documents, applications or systems to a separate environment and record the outcome.

Geometric illustration of business data copied into an offline vault and immutable backup archive

5. Train staff regularly and measure the results

People are a critical part of your security controls. A convincing phishing email can bypass expensive technology if an employee is tricked into sharing a password or approving a fraudulent payment.

Annual training is a useful minimum. Many insurers now expect a more regular and measurable programme, particularly for businesses handling sensitive information or payments.

Effective training should cover:

  • Recognising phishing and impersonation attempts.
  • Safe use of passwords and MFA.
  • Reporting suspicious emails quickly.
  • Handling customer and confidential information.
  • Risks from personal devices and home working.
  • Payment fraud and supplier impersonation.
  • What to do if an account or device may be compromised.

Keep records of completion. Consider using simulated phishing exercises to measure how people respond. Staff who click should receive additional support rather than blame.

Useful evidence includes:

  • Training dates and course content.
  • Completion records.
  • Phishing simulation results.
  • Follow-up training.
  • Your process for reporting incidents.

Security awareness is not a one-off project. New starters, temporary workers and contractors must be included, and existing staff should receive refreshers.

6. Create and test an incident response plan

When an incident occurs, people need to know what to do immediately. A documented incident response plan reduces confusion and helps limit damage.

Your plan should explain:

  1. How staff report a suspected incident.
  2. Who makes the initial decision.
  3. Who contacts your IT provider or managed security team.
  4. When systems should be isolated.
  5. How evidence is preserved.
  6. Who contacts the insurer and approved response providers.
  7. When legal, regulatory or customer notifications may be required.
  8. How the business continues operating during recovery.
  9. How lessons are recorded after the incident.

Check your policy carefully. Some insurers require notification within a specific period or insist that you use approved legal, forensic or recovery providers.

Test the plan at least annually with a tabletop exercise. For example, ask your team to work through this scenario:

“A member of staff reports that several files are being renamed and a ransom note has appeared. What happens in the first 15 minutes?”

Record what worked, where decisions were unclear and which contact details need updating. Then improve the plan.

The NCSC provides further guidance on incident management and preparation for small and medium-sized organisations.

Geometric illustration of a Hampshire business team following a tested cyber incident response plan

What evidence should you prepare before renewal?

Start at least several weeks before your policy renewal date. Create a simple evidence folder containing:

  • MFA coverage reports.
  • EDR deployment and monitoring reports.
  • Patch compliance reports.
  • Asset and software inventories.
  • Backup schedules and restore test records.
  • Staff training completion data.
  • Incident response plans and exercise notes.
  • Security policies and records of recent reviews.
  • Details of changes to your systems, staff or suppliers.

This makes the renewal process easier and helps you identify gaps before the insurer does.

The GOV.UK overview of Cyber Essentials describes it as a government-backed scheme designed to help organisations protect themselves against common online threats. Certification does not automatically meet every cyber insurance requirement, but it can provide a useful baseline and demonstrate a structured approach.

Do not guess on the insurance questionnaire

The most serious mistake is treating the renewal form as a formality.

If a control is partly implemented, say so and ask your broker or IT provider what the insurer requires. If an answer changes during the policy period, update the relevant people. An inaccurate declaration can create problems when you need support most.

Why aim for failproof cybersecurity? No business can eliminate every risk, but you can make your controls clear, consistent and demonstrable.

Book a call about your cyber insurance controls

Preparing for renewal does not have to be overwhelming. A practical review can identify where MFA is missing, whether EDR covers every device, whether backups can be restored and what evidence your business should retain.

BITSmart provides managed IT services in Hampshire for businesses that need proactive monitoring, patch management, endpoint protection, secure cloud services and responsive support.

If you are approaching renewal or want to understand your current position, book a call with BITSmart. We will help you review the essentials in plain English and agree sensible next steps.

Better preparation protects more than your policy. It helps protect your people, your data, your customers and your ability to keep trading when something goes wrong.

You might also like