Cyber insurance requirements

What Cyber Insurers Actually Require

Cyber insurance and cyber security are usually bought from different people, at different times, using different vocabulary.

That is how businesses end up holding a policy which does not quite cover the way they would actually be attacked, or having spent money on controls their insurer gives them no credit for.

Meanwhile, cyber insurance requirements have shifted considerably in the last few years, and a lot of businesses are answering proposal forms to a standard that no longer applies.

Fourarmed exists in the space between the two, because that is where we came from.

Born from Insurance

Nobody was standing between the two disciplines

We came out of Castlemead, an insurance broker. Fourarmed was founded because of a pattern Castlemead kept seeing from the brokering side. Clients who had bought cyber cover in good faith, believed they were adequately protected, then had a much worse experience than they should have when something went wrong.

Sometimes that was due to cover that did not fit the business. More often it was security that looked fine on a proposal form and turned out to be thinner in practice, with the discovery of that gap happening at the worst possible moment, during a claim.

Security firms do not read policy wordings. Brokers are not in a position to audit a client's network.

In response, we built a security business that speaks insurance and kept it close to a broker that speaks security. Our approach explains what that changes in practice.

The Controls Underwriters Ask For

Eight things they consistently want to see

Cyber underwriting has tightened considerably, and the claims figures explain why. The Association of British Insurers reported £197m paid out on UK cyber claims in 2024, a 230% increase on the previous year, with ransomware and malware making up 51% of claims. Underwriters have responded by asking harder questions and asking for evidence to back up the answers.

  • Multi-factor authentication. Enforced on email, remote access and administrative accounts, and not merely available. This is close to a hard requirement now.
  • Backups that are isolated and tested. Offline or immutable, separated from the production network, with a documented restore test. A backup nobody has restored from is a plan, not a control.
  • Patching within a defined window. This includes critical and high-risk vulnerabilities, with records to prove it.
  • Endpoint detection. Traditional anti-virus on its own no longer satisfies most underwriters.
  • Access control and administrator separation. Including a process for removing leavers promptly.
  • An incident response plan. One that names people and includes their out-of-hours contact details.
  • Staff awareness training. With evidence it is happening. See training.
  • Business interruption figures you have calculated. If you cannot estimate your own downtime cost, the underwriter will estimate it for you, conservatively.

A Cyber Essentials certificate helps and it is a sensible thing to hold, but it is not the same as satisfying an underwriter. The scheme covers five technical controls at a point in time. Insurers are pricing your ability to keep trading, which is a broader question.

Avoiding Claim Denials

Where businesses get hurt

A cyber policy is a contract, and what you tell the insurer when you buy it forms part of that contract. Under the Insurance Act 2015, commercial buyers have a duty of fair presentation: a duty to disclose what a prudent underwriter would want to know. Policies also carry conditions and, sometimes, warranties, which are specific requirements about controls you must have in place.

You described your controls more optimistically than reality

This is usually not deliberate. Somebody in the business answered "yes, we have MFA" because it was enabled for the leadership team, and it turned out not to be on for the account that was compromised. The insurer's position is that they priced a different risk from the one they actually carried.

A policy condition was not met

If the wording requires MFA on remote access, or backups held offline, and the loss happens through the gap, the insurer has grounds to decline or reduce.

You cannot evidence what you said

Even where your controls were genuinely in place, a claim needs proof, such as patch records, access logs, training records, and backup test results. Organisations that have never had to produce these find it hard to do so under time pressure, especially in the middle of an incident.

None of that is insurers behaving badly. It is the ordinary consequence of a contract priced on a description of your business. The fix is to make sure the description is accurate before you sign it, and that you can back it up afterwards.

How We Bridge the Gap

Four things we do differently

Audit before the proposal form

We start with a cyber security audit, before you answer the proposal form. That way your answers are grounded in evidence and not in the best understanding of whoever filled the form in. It is considerably cheaper than finding out during a claim.

Underwriter-facing findings

We flag the items most likely to affect your premium or your terms separately from the rest, so you can deal with a short list ahead of renewal instead of the whole plan.

Business interruption

The audit produces a defensible number for what downtime would cost you, which tells you how much cover you actually need. Plenty of businesses turn out to be over-insured on one limb of a policy and under-insured on another.

Evidence on demand

Audit reports, monitoring reports, phishing simulation results and training records are provided. Twelve months of documentation makes both renewal and any future claim substantially easier.

Certification helps too. Cyber Essentials or Cyber Essentials Plus gives underwriters a recognised reference point. Basic certification also includes £25,000 of cyber liability cover for eligible organisations in the UK or Crown Dependencies turning over under £20m. It is a floor, not a policy, though it is worth having.

Getting Renewal-Ready

Working backwards from your renewal date
  1. Three months out, audit

    A cyber security audit establishes what is true, including the business interruption figure.

  2. Two months out, fix the underwriter-facing items

    We flag these separately in the report, so this is a short list rather than the whole plan.

  3. One month out, assemble the evidence

    This should include patch records, access reviews, backup restore tests, training and simulation results, as well as the incident response plan with names and numbers in it.

  4. At renewal, present the evidence

    Walk into the conversation with documentation and a defensible view of the cover you need.

  5. Through the year, keep it current

    Monitoring reports and training records accumulate the evidence for next time without anyone having to reconstruct it.

Our Partnership with Castlemead

You are under no obligation to use both

Fourarmed handles security, while Castlemead handles insurance. Between us you can get your risk assessed, improved, evidenced and then covered, without having to act as the translator between two industries that do not naturally share a vocabulary.

You are under no obligation to use both. Plenty of our clients have brokers they are happy with, and we will work with any broker. We would rather your cover was right than that it came from a particular place, but if you would like the security work and the insurance to join up, that is what the arrangement is for.

Common questions

Five questions
Does Cyber Essentials reduce cyber insurance premiums?
A Cyber Essentials certificate helps and it is a sensible thing to hold, because it gives underwriters a recognised reference point. It is not the same as satisfying an underwriter. The scheme covers five technical controls at a point in time, while insurers are pricing your ability to keep trading, which is a broader question.
Can a cyber insurance claim be refused?
A cyber policy is a contract, and what you tell the insurer when you buy it forms part of that contract. There are three practical ways a claim gets difficult: you described your controls more optimistically than reality, a policy condition was not met, or you cannot evidence what you said. The fix is to make sure the description is accurate before you sign it, and that you can back it up afterwards.
Do insurers require MFA?
Multi-factor authentication enforced on email, remote access and administrative accounts, and not merely available, is close to a hard requirement now.
What evidence will our insurer ask for?
Patch records, access reviews, backup restore tests, training and simulation results, and an incident response plan with names and out-of-hours numbers in it. Organisations that have never had to produce these find it hard to do so under time pressure.
How far ahead of renewal should we audit?
Two to three months. That is typically long enough to fix what needs fixing and to arrive with something to show for it.
Get audit-ready for your insurer

The best time to start is two to three months before renewal

That is typically long enough to fix what needs fixing, and to arrive with something to show for it.