Quick answer: Cyber insurance requirements in the UK for 2026 centre on a handful of controls: multi-factor authentication, tested offline backups, timely patching, endpoint protection and an incident response plan. Insurers now ask for evidence, not just a tick on a form. If your IT provider can’t produce that evidence quickly, your renewal could cost more, come with exclusions, or be declined.
After a few hard years, the cyber insurance market has settled. Gallagher’s UK Cyber Market Report 2026 notes plenty of capacity, and many insurers have trimmed their questionnaires for smaller firms. That sounds like good news, and partly it is. The catch is that the questions which remain focus on a small set of core controls, and those answers carry more weight than ever.
For many Aberdeen businesses, the renewal lands on the desk of a finance director or office manager who has to answer technical questions about systems they don’t run day to day. That’s where your IT provider should step in. This post explains what insurers are asking for, and how to check your provider is ready before the renewal date arrives.
Ransomware claims hit the market hard earlier in the decade, and insurers tightened their rules in response. Since then, conditions have eased. More insurers are competing for small business cover, and pricing has become more stable.
Easier entry doesn’t mean lower standards, though. Underwriters have learned which controls make the biggest difference to claims, and they concentrate on those. The government’s Cyber Security Breaches Survey continues to show that a large share of UK businesses face some form of breach or attack each year, so insurers still price risk carefully.
The practical result for an Aberdeen SME is a market that rewards good, evidenced controls. Businesses that can show the basics tend to get better terms. Those with gaps may face higher premiums, lower limits, or specific exclusions in the policy wording.
Questionnaires vary between insurers, but in our work with SME clients the same controls appear on almost every form.
MFA on email, remote access and admin accounts is now close to non-negotiable. Expect questions about whether it covers every user, not just most of them, and whether it applies to cloud services and backups too.
Underwriters want to know your backups are isolated from the main network, so ransomware can’t encrypt them as well. They also ask how often restores are tested. A backup nobody has ever restored is an assumption, not a control.
You’ll be asked how quickly critical updates are applied and whether any unsupported systems remain. Old servers and devices still running out-of-support software are a common reason for awkward conversations at renewal.
Basic antivirus is often no longer enough. Many insurers now ask about endpoint detection and response (EDR) and whether someone is actually watching the alerts, day and night.
Phishing remains a leading way in. Expect questions on email filtering, domain protections such as DMARC, and whether staff receive regular security awareness training.
The underwriter wants to see that you know what you’d do in the first hours of an attack. Our guide to the first 72 hours after a cyber attack shows what a sensible plan covers.
The biggest shift isn’t the list of controls. It’s the expectation of proof. Answering “yes” to a question about MFA and later being unable to show it was in place could give an insurer grounds to dispute a claim.
That makes accuracy matter. Before you sign the declaration, you should be able to point to:
If those documents don’t exist, or nobody knows where they are, that’s the gap to close before renewal.

Cyber Essentials is the UK government-backed scheme covering five technical controls. Many insurers view it favourably, and certified organisations that meet the eligibility criteria can receive cyber liability cover as part of the scheme. It also gives you a structured, independently checked starting point for a renewal questionnaire.
It isn’t a substitute for the questionnaire, but it makes answering it much easier. We covered the 2026 changes in Cyber Essentials in 2026: what’s changed.

Run through the core controls with your IT provider and sort each one.
Start this at least two to three months before renewal. Some fixes, like replacing an unsupported server, take time to plan.
Your IT partner should make renewal easier, not leave you guessing. Ask them directly:
A provider who answers quickly, with documents, is doing their job. Vague answers, or “we’ll look into it”, are a signal worth noting.
A few issues come up again and again when we review renewal questionnaires with growing businesses:
Each of these is fixable, usually within weeks rather than months.
Getting the questionnaire wrong carries real cost. Overstating your controls can put a future claim at risk. Understating them may mean paying more than you need to.
The bigger risk is the attack itself. Insurance covers some of the financial loss, but it doesn’t stop the disruption, the lost trading days, or the damage to client trust. We looked at what that disruption costs in the true cost of IT downtime. The controls insurers ask for are the same ones that reduce the chance you’ll ever need to claim.
The most useful way to think about cyber insurance is as a yearly health check you’d want anyway. The questionnaire gives you a clear list of controls the market considers essential. Use it to drive improvements, and keep the evidence on file throughout the year rather than scrambling in the final week.
For growing businesses in Aberdeen and the North East, that steady approach usually leads to smoother renewals, fewer surprises in the small print, and a genuinely safer business.
Most insurers expect multi-factor authentication on all accounts, isolated and tested backups, prompt patching, endpoint detection and response, email security, staff training and a written incident response plan. Requirements vary, so always read your insurer’s questionnaire in full.
It can help. Many insurers view certification favourably because it shows independently checked baseline controls. Pricing depends on your insurer and wider risk profile, so it’s not a guaranteed discount.
Inaccurate answers on a proposal form may give an insurer grounds to reduce or dispute a claim. Check every answer against real evidence before signing, and ask your broker if anything is unclear.
Start two to three months before the renewal date. That leaves time to gather evidence and fix any gaps, such as missing MFA or untested backups.
Yes. Many of the questions are technical, and your IT provider holds the evidence. A good partner will review the answers with you so they’re accurate.
If your renewal is coming up and you’re not sure how your controls would stand up, we can help. Our cyber security team offers a renewal readiness assessment that checks each control, gathers the evidence and flags gaps in plain English. Get in touch to book yours.
