- Does Cyber Essentials reduce cyber insurance premiums?
- A Cyber Essentials certificate helps and it is a sensible thing to hold, because it gives underwriters a recognised reference point. It is not the same as satisfying an underwriter. The scheme covers five technical controls at a point in time, while insurers are pricing your ability to keep trading, which is a broader question.
- Can a cyber insurance claim be refused?
- A cyber policy is a contract, and what you tell the insurer when you buy it forms part of that contract. There are three practical ways a claim gets difficult: you described your controls more optimistically than reality, a policy condition was not met, or you cannot evidence what you said. The fix is to make sure the description is accurate before you sign it, and that you can back it up afterwards.
- Do insurers require MFA?
- Multi-factor authentication enforced on email, remote access and administrative accounts, and not merely available, is close to a hard requirement now.
- What evidence will our insurer ask for?
- Patch records, access reviews, backup restore tests, training and simulation results, and an incident response plan with names and out-of-hours numbers in it. Organisations that have never had to produce these find it hard to do so under time pressure.
- How far ahead of renewal should we audit?
- Two to three months. That is typically long enough to fix what needs fixing and to arrive with something to show for it.