lead-forensics Skip to main content

Net Platforms

UK insurers paid out £197 million in cyber claims during 2024, more than three times the £59 million paid out the year before, according to the Association of British Insurers[DS1] . Malware and ransomware alone accounted for just over half of those claims, up from under a third in 2023. Demand moved in the same direction. The same data recorded 17% more cyber insurance policies taken out in 2024 than the year before, so more businesses are buying cover at the exact moment insurers are tightening who qualifies for it. That combination explains most of what has changed on the renewal form this year. When claims costs move that quickly, insurers stop taking a business’s word for its security and start asking for proof of it.

The change shows up as longer applications and fewer assumptions that last year’s answers still hold. A cyber insurance form used to read like a short checklist, tick a box for anti-virus software and another for backups, then move on. What underwriters ask for now sits closer to evidence than opinion. They want to know whether multi-factor authentication covers every account that touches company data, including the ones an IT team can easily forget. They want a date for when a backup was last restored and evidence that the restore succeeded. Meeting the current cyber insurance requirements increasingly means being able to demonstrate a control on the day it is asked about.

What underwriters are focused on

Government data helps explain where insurers are concentrating their attention. The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology, found that a large majority of UK businesses have the older hygiene measures in place: 81% use updated malware protection and 74% back up data via a cloud service. Multi-factor authentication tells a different story. Less than half of UK businesses (47%) have two-factor authentication in place across networks or applications at all, and only around a third have a policy to apply software security updates within 14 days. Those happen to be exactly the controls now treated as standard cyber insurance requirements. Insurers are asking directly about the specific things national data shows most businesses have not yet implemented, which is worth remembering the next time a renewal form feels like an arbitrary hurdle. It is closer to a reasonable check on risk.

For a business in Essex renewing cover this year, that pattern is worth noticing before the form arrives. A business that has always run anti-virus software and backups will likely get through the older sections of the form without difficulty. The newer ones, on authentication coverage and patch timing, are where the shortfall usually shows up, and they are the ones insurers are now weighting most heavily.

What happens if you claim without them in place

The National Cyber Security Centre is direct about the consequence. Its guidance on cyber insurance states plainly that if an organisation claims security measures are in place when they are not, the insurer may not be obliged to pay out. That single point covers most of the disputes that surface after a breach. A business renews in good faith, confirms multi-factor authentication because it is switched on for most accounts, and only discovers during a claim investigation that one legacy system or one supplier login was never brought into scope. The insurer’s review after an incident tends to be far more thorough than the declaration made at renewal, and it is usually that mismatch, rather than the attack itself, where cover gets challenged or reduced.

Preparing before renewal, not after an incident

None of this is complicated to prepare for, but it needs to happen ahead of a renewal date. Businesses that clear this bar comfortably are usually the ones who can already produce evidence on request: a record showing multi-factor authentication enforced across every account, a note of when backups were last tested for restore, and confirmation of when patches were last applied to systems facing the internet.

Cyber Essentials, the government-backed certification scheme overseen by the NCSC, is a useful marker of how closely these two worlds have moved together. UK organisations with a turnover under £20 million that certify their whole organisation to Cyber Essentials are automatically entitled to cyber liability cover through the scheme’s delivery partner. Certification and insurance eligibility have moved onto the same page.

We touched on a related point recently when writing about what it means to hold ISO 27001 certification. The difference between telling someone you take security seriously and being able to show it is not a technicality. At Net Platforms, it is the same discipline we apply to our own systems that we help Essex clients build into theirs, because from an insurer’s point of view, a control that cannot be demonstrated carries the same weight as one that is not there.

Cyber insurance was never intended to replace good security practice, and the NCSC says as much directly. It will not prevent an attack, and it does not fix weak foundations on its own. What has changed for 2026 is how closely insurers now check whether those foundations exist before they agree to stand behind them. Fewer than half of UK businesses currently hold any form of cyber insurance at all, so for those who do, protecting that cover deserves the same attention as buying it did. The practical answer for any business renewing this year is the one that has always applied to insurance of any kind. The paperwork should be accurate on the day it is submitted and still accurate on the day a claim is being investigated.

A useful step before your next renewal date is to walk the form as if a claims investigator will read your answers back to you. Our cyber security page covers the practical measures we help Essex businesses put in place, from multi-factor authentication coverage to patching cadence.

Secret Link