Telappliant
Cyber Security Guide · 15 August 2026

Cyber liability insurance: what UK insurers now expect

Cover is harder to get and the questionnaire is now a technical audit. The controls insurers ask for, and what invalidates a claim.

By the Telappliant team

Two business professionals reviewing a cyber risk document in a boardroom

Cyber insurance used to be a tick-box purchase. It is now underwritten properly: insurers ask precise technical questions, price on the answers, and decline claims where the answers turn out to be wrong. Treat the proposal form as a security baseline rather than paperwork.

What a policy usually covers

  • Incident response: forensics, legal advice and breach notification
  • Business interruption while systems are unavailable
  • Data recovery and system rebuild costs
  • Third-party liability where customer data is exposed
  • Cyber extortion, subject to sanctions and regulatory limits

What insurers now ask for

  • Multi-factor authentication on email, remote access and administrative accounts
  • Endpoint detection and response, not just traditional antivirus
  • Offline or immutable backups, with a tested restore
  • A patching regime with evidence, typically 14 days for critical fixes
  • Security awareness training and phishing simulation
  • Privileged access separation and prompt leaver removal

The gap that voids claims

Most disputes come from a mismatch between the proposal form and reality: MFA claimed on all remote access but missing on one legacy service, or backups described as offline when they sit on a share the domain admin can reach. Verify each answer against the estate before you sign, and keep the evidence.

Cyber Essentials shortens the conversation

Certification demonstrates the baseline controls insurers care about, and several UK insurers price accordingly or include limited cover for smaller organisations. It is not a substitute for a policy, but it makes the underwriting straightforward.

How much cover, and how to size it

Model the cost of five days of downtime, the cost of a rebuild, and the regulatory and notification exposure of your data set. Small professional services firms typically buy in the low millions; anyone holding special-category data or processing payments should model higher.

Before renewal

  • Re-run the proposal questions as an internal audit
  • Close any control that is partial rather than complete
  • Test a restore and keep the evidence
  • Document your incident response plan and who is called first

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation