A cyber insurance proposal can look deceptively simple: a few questions about passwords, backups and security software. Yet the answers can decide whether a claim is paid, restricted or declined. Cyber insurance requirements 2026 are less about buying a policy and more about proving your business has sensible, working controls in place before an incident happens.
For a small business, that does not mean building an enterprise security operation. It means knowing where your risk sits, putting proportionate protections around it, and being able to show that those protections are actually used. Insurers differ, and every policy wording matters, but the direction is clear: basic cyber hygiene is increasingly treated as a condition of cover rather than a nice extra.
Why cyber insurance questions are getting tougher
Ransomware, invoice fraud and account takeover can stop a business from trading within hours. A policy may help with incident response, data recovery, legal advice, customer notifications and lost income, depending on the cover selected. But insurers do not want to underwrite risks that could have been reduced with straightforward controls.
That is why proposal forms now look more closely at how people access systems, whether backups can survive an attack, and how quickly a business can spot unusual activity. The question is no longer simply, “Do you have antivirus?” It is, “Can an attacker use one stolen password to reach your email, files, finance system and backups?”
For firms in Sussex with a mix of office staff, remote workers, shared devices and cloud applications, the practical challenge is often visibility. Technology may have grown in stages, with different suppliers responsible for internet, phones, Microsoft 365, backups and line-of-business software. That can leave gaps which are hard to spot until renewal time.
The cyber insurance requirements 2026 checklist
There is no single universal checklist. An insurer will assess your sector, turnover, data held, claims history, use of payment systems and the limit of cover requested. Still, the following controls are commonly expected and are a sensible starting point for most UK small and midsize businesses.
Multi-factor authentication across key systems
Multi-factor authentication, or MFA, should be enabled for email, cloud storage, remote access, finance platforms and administrator accounts. It adds a second check beyond a password, such as an app approval or security key. This is one of the clearest ways to reduce the chance that a stolen password leads to a major breach.
A common weak point is enabling MFA for Microsoft 365 but leaving it off for remote desktop access, a payroll portal or an old administrator account. Insurers may ask whether MFA applies to all remote access and privileged accounts, not merely whether it exists somewhere in the business. Review exceptions carefully, particularly service accounts and legacy applications.
Managed, patched devices
Laptops, desktops, servers, firewalls and mobile devices need security updates applied promptly. Attackers regularly exploit known weaknesses because they know some organisations delay patching for weeks or months.
This is not a case for installing updates blindly in the middle of a busy day. A managed approach should assess patches, test where appropriate, schedule them around operations and confirm completion. The point is to have an accountable process rather than relying on staff to click reminders when they have time.
Your insurer may also look for centrally managed endpoint protection. Traditional antivirus alone is not always enough. Modern endpoint detection tools can identify suspicious behaviour, isolate an affected device and give your IT team useful evidence during an investigation.
Backups that are separate and recoverable
Backups are essential, but simply seeing a green tick beside “backup complete” is not enough. A ransomware attack may encrypt files on the network and any backup location it can access. Insurance questions often focus on whether backups are protected from alteration or deletion, kept separately from day-to-day systems, and tested through real restoration exercises.
Think about what needs to be restored first. For an automotive business, that may include booking systems, customer records and specialist diagnostic data. For a charity, it may be donor information, finance records and shared documents. Recovery priorities should reflect how the organisation actually works, not just what is easiest to copy.
Secure email and payment controls
Email remains a major route into small businesses. Phishing messages can steal login details, install malware or persuade a member of staff to change a supplier’s bank details. Good email filtering, domain protection and MFA reduce the risk, but clear procedures matter too.
No single employee should be able to authorise a significant payment following an emailed request alone. Confirm bank-detail changes using a trusted telephone number already held on file, and use approval steps that match the value and risk of the payment. These controls can prevent both fraud and difficult conversations with an insurer later.
Access control and offboarding
People need access to do their jobs, but access should not be permanent by default. Review who has administrator rights, who can access finance data, and whether former employees, contractors or old suppliers still have accounts.
Offboarding needs to happen quickly when someone leaves or changes role. Disable accounts, recover devices, remove shared passwords and check any third-party software they could access. A quarterly access review is a manageable rhythm for many smaller organisations, while businesses handling sensitive data may need to review more often.
Staff awareness and a response plan
Security awareness training is not about catching people out with trick questions. It gives staff the confidence to pause when an email, attachment, login page or payment request feels wrong. Training should be short, relevant and repeated, with an easy route for reporting suspicious activity.
Insurers may also ask for an incident response plan. It does not need to be a thick manual that no one reads. A useful plan sets out who calls your IT provider, who can make decisions, how to contact your insurer’s incident line, where key contacts are stored, and how staff should communicate if email is unavailable. Test it with a short scenario once or twice a year.
Evidence matters as much as the control
A proposal form is a declaration, not a marketing exercise. If you answer “yes” to MFA, backups or patching, make sure you can support that answer. Keep records of security settings, patch reports, backup restoration tests, training completion and access reviews. Your managed IT provider should be able to produce much of this information without turning renewal into a scramble.
Be especially careful with broad wording such as “all users” or “all systems”. If a director has an old mailbox without MFA, or an on-site server is excluded from backup, say so and obtain advice. Honest disclosure may affect terms or premiums, but inaccurate answers can create a far bigger problem after a claim.
Where businesses commonly fall short
The most frequent issue is assuming that a cloud service automatically covers every security responsibility. Microsoft 365, Google Workspace and similar platforms provide strong security capabilities, but these still need to be configured, monitored and supported. Deleted files, compromised accounts and incorrect permissions can all create disruption.
Another issue is unmanaged technology outside the main office. Home computers, personal mobiles, old laptops and devices used by temporary staff can fall outside standard protection. Not every device has to be company-owned, but every route into business data needs a clear security standard.
Finally, businesses can focus heavily on preventing an attack and overlook continuity. Cyber cover is valuable, but it does not remove the cost of downtime, customer concern or operational pressure. Tested recovery arrangements and clear communications usually matter just as much as the policy limit.
Preparing for renewal without the last-minute rush
Start a review well before the renewal date, ideally while there is time to fix gaps. Gather your current policy, the insurer’s questions, an asset list and a simple map of the systems that keep the business running. Then identify where MFA is missing, which backups have not been tested, and whether access rights and security updates are being managed consistently.
Some requirements will be straightforward to meet. Others may need investment, particularly where older servers, unsupported software or fragmented suppliers are involved. The right answer depends on the risk, the value of the data and the disruption your business could tolerate. A small gap is not always a reason to replace everything, but it should be understood and managed rather than ignored.
My Tech Team helps businesses turn those insurance questions into practical actions, without jargon or unnecessary complexity. A focused security review can establish what is already in place, what needs attention and what evidence to keep for future renewals.
The best time to test whether your protection is good enough is before an insurer asks for proof – and well before an unexpected email brings work to a halt.