Cyber liability insurance: what UK insurers now expect
Cover is harder to get and the questionnaire is now a technical audit. The controls insurers ask for, and what invalidates a claim.
By the Telappliant team

Cyber insurance used to be a tick-box purchase. It is now underwritten properly: insurers ask precise technical questions, price on the answers, and decline claims where the answers turn out to be wrong. Treat the proposal form as a security baseline rather than paperwork.
What a policy usually covers
- Incident response: forensics, legal advice and breach notification
- Business interruption while systems are unavailable
- Data recovery and system rebuild costs
- Third-party liability where customer data is exposed
- Cyber extortion, subject to sanctions and regulatory limits
What insurers now ask for
- Multi-factor authentication on email, remote access and administrative accounts
- Endpoint detection and response, not just traditional antivirus
- Offline or immutable backups, with a tested restore
- A patching regime with evidence, typically 14 days for critical fixes
- Security awareness training and phishing simulation
- Privileged access separation and prompt leaver removal
The gap that voids claims
Most disputes come from a mismatch between the proposal form and reality: MFA claimed on all remote access but missing on one legacy service, or backups described as offline when they sit on a share the domain admin can reach. Verify each answer against the estate before you sign, and keep the evidence.
Cyber Essentials shortens the conversation
Certification demonstrates the baseline controls insurers care about, and several UK insurers price accordingly or include limited cover for smaller organisations. It is not a substitute for a policy, but it makes the underwriting straightforward.
How much cover, and how to size it
Model the cost of five days of downtime, the cost of a rebuild, and the regulatory and notification exposure of your data set. Small professional services firms typically buy in the low millions; anyone holding special-category data or processing payments should model higher.
Before renewal
- Re-run the proposal questions as an internal audit
- Close any control that is partial rather than complete
- Test a restore and keep the evidence
- Document your incident response plan and who is called first



