Rejuvenate IT Logo
  1. Home
  2. Guides
  3. Compliance & Regulation

Explainer

What insurers now ask about your IT

Mostly about five things: multi-factor authentication, tested backups, patching, endpoint protection, and who holds administrator rights. Your answers now shape the premium and whether a claim is paid.

By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read

The short version

  • Insurers increasingly price on your controls, not only your turnover and sector
  • MFA, tested backups and endpoint protection come up on nearly every form
  • Around 47% of UK businesses hold some cyber cover, and 22% are unsure either way
  • A wrong answer on the form is a problem at claim time, not at renewal
  • Cyber Essentials answers a good deal of the form in one go

Why the forms got harder

Cyber insurance used to be priced much like any other policy: your sector, your turnover, your claims history. Then insurers paid out on a great many ransomware claims and discovered that the businesses affected were often missing the same handful of basic controls.

So the questions changed. A proposal form now asks what you actually have in place, in some detail, and the answers affect the premium, the excess, the limits, and sometimes whether cover is offered at all. Some insurers decline businesses without multi-factor authentication outright.

This has an odd side effect worth noticing. Your insurer has become one of the more effective drivers of security improvement in small businesses – not because they know your systems, but because they will not cover you until you answer the questions.

The questions that now appear on nearly every form

  • Is multi-factor authentication enabled for email, remote access and admin accounts?
  • Do you take backups, are any kept offline, and when did you last test a restore?
  • How quickly are critical updates applied, and is anything unsupported still running?
  • What protection is installed on computers and servers, and does anybody monitor it?
  • How many people hold administrator rights, and are those accounts used day to day?
  • Is remote access exposed to the internet, and how is it protected?
  • Do staff receive security awareness training, and how often?
  • Do you have a written incident response plan, and has anyone rehearsed it?
  • Do you hold card data or special category personal data, and how much?
  • Have you had a previous incident or claim?

Why the answers matter more than the premium

A proposal form is not a questionnaire. It is the basis on which the insurer decides to take the risk, and a commercial policyholder is expected to present that risk fairly and accurately.

The practical consequence is uncomfortable. If you tick “yes” to multi-factor authentication because it is on for most people, and a claim later arises from an account that did not have it, you are in an argument at the worst possible moment – after an incident, when you need the money. The same applies to backups described as tested when nobody has restored anything in two years.

None of this means insurers are looking for excuses. It means the form should be completed by somebody who actually knows, with evidence behind each answer, rather than by whoever happens to be renewing the policies.

Where Cyber Essentials fits

The overlap is substantial and not accidental. Cyber Essentials covers firewalls, secure configuration, update management, access control and malware protection – which is most of what a proposal form asks about, in roughly the same order.

Certifying does not guarantee a lower premium, and any provider promising that is guessing. What it does is let you answer the security questions from an assessment rather than from memory, and give the insurer something independent to look at. UK organisations turning over under £20 million also receive cyber liability insurance through the scheme itself, which is worth understanding before buying separate cover.

Worth gathering before you renew

  • A current list of every machine, and confirmation each is supported and patched
  • Written confirmation of which accounts have MFA, including administrators
  • The date of your last tested restore, and what was actually restored
  • A note of who holds administrator rights and why
  • Any security training records for the past twelve months
  • Your incident response plan, even if it is one page

Common questions

Will having all this reduce our premium?

Sometimes, and it is not the main reason to do it. The bigger effects are on whether cover is offered, what the excess is, and whether ransomware is fully covered or sub-limited. Two businesses with the same turnover can be offered noticeably different terms on controls alone.

Our broker fills the form in for us. Is that fine?

A broker can present it, but the answers have to come from somebody who knows your systems. The most common problem we see is a form completed from a general sense of what is in place, with nobody checking. Get your IT provider to confirm each technical answer in writing.

What if we cannot honestly answer yes to some of them?

Say so. An accurate "no" gets you a workable policy at a fair price; an inaccurate "yes" gets you a policy that may not respond. Insurers are used to businesses with gaps, and several will offer terms conditional on fixing something within a set period.

Is cyber insurance worth having at all?

For most businesses, yes - chiefly for the incident response that comes with it. The value is often less the payout than having somebody experienced on the phone within the hour, at a point when nobody in your business knows what to do first.

Do we need to tell our insurer when things change?

If something material changes mid-term - you take on card payments, adopt a new remote access setup, or drop a control you declared - tell them. It is far easier than explaining it after the event.

Written by Claire Donnelly

Renewal coming up and unsure how to answer the form?

Send us the questions. We'll tell you which answers are genuinely yes today, which are nearly, and what would take a fortnight to fix - before you commit anything in writing.

Ask us to check the form