Show your underwriter exactly how your systems are run
Cyber insurance rates have been falling, but what you are offered still turns on the controls you can demonstrate. Running the estate properly produces that evidence along the way.
Meet the requirements you will be assessed against
Multi-factor authentication
Proposal forms tend to open here: MFA on email, remote access, administrative accounts and every cloud service that holds your data. What underwriters want to see is coverage rather than availability, so the useful evidence is a tenant-wide report showing which accounts are enrolled and which are not.
Endpoint detection and response
Expect questions about what is deployed, on how many devices, and whether someone reviews what it finds. A deployment report reconciled against your asset list answers all three at once, and it is a far stronger answer than the name of a product.
Backups you have restored from
The question has moved on from whether backups run. Underwriters ask about offsite or immutable copies, credentials held separately from production, and the date of your last full restore alongside the recovery time you achieved.
A patching cadence you can measure
How quickly do critical and high-severity updates reach every machine? A figure drawn from patch reporting carries considerably more weight than a policy document setting out an intention, because one can be checked and the other cannot.
Security awareness training
Completion records, phishing simulation results and the date of the last session. Training that has happened is straightforward to evidence. Training that is planned for next quarter is not, and underwriters read the difference.
A tested incident response plan
Named roles, contact routes, containment steps and a recovery sequence. The detail underwriters look for is the date of the last exercise, because that is what separates a plan people know from a document nobody has opened.
Where the cyber insurance market sits
The cyber insurance market has softened. In Rebooting growth: 2025 cyber insurance report, published on 24 September 2025, the broker Howden describes rates “continuing to fall in the low-double-digit range” and notes that “rates are falling, competition is ramping up and the market’s exposure-base isn’t expanding quickly enough”. More capacity is chasing broadly the same number of buyers.
Take-up is rising slowly to match. The government’s Cyber Security Breaches Survey 2025/26 found that 47% of UK businesses reported being insured against cyber security risks in some way, up from 45% the year before and 43% the year before that. Among small businesses the figure was 55%, and among medium-sized businesses 61%.
That is a genuinely better environment to renew into than the one firms faced a few years ago. What it has not changed is the underwriting question itself. A softer market moves the price level; it does not stop an underwriter from pricing what they can see. The firms that get the benefit of the softening are the ones whose answers to the technical questions hold up.
What underwriters ask you to evidence
Insurers write their own questionnaires, but the core set of questions barely varies, and each one maps onto a control that shows up repeatedly in incident reporting.
Multi-factor authentication comes first. Sophos’s State of Ransomware 2026, a survey of 2,158 IT and cyber security leaders across 17 countries whose organisations had a ransomware incident in the previous year, found that 79% of attacks used identity-based methods. That is why the MFA question sits at the top of the form. It is also still a meaningful differentiator: the Breaches Survey found only 47% of UK businesses have any two-factor authentication in place at all, so a firm that can show enforcement across every account is describing something a good many of its peers cannot.
Endpoint detection and response, and its actual coverage. The interesting number is not the product name, it is the gap between the endpoints you own and the endpoints it is installed on.
Backups you have restored from. The Breaches Survey found 74% of businesses back up to a cloud service and 48% back up by other means. Widespread backup is not the differentiator any more. The date of your last full restore is.
Patching speed. How long a critical update takes to reach every machine, measured rather than asserted.
An incident response plan somebody has rehearsed. Only 25% of UK businesses have a formal incident response plan — 21% of micro businesses, 57% of medium-sized ones and 76% of large ones. If you are a mid-sized professional firm, this is one of the few questions where a well-run answer visibly separates you from the average respondent.
None of this is exotic. It is a description of a well-run IT estate, written down.
Answer the proposal form as the legal document it is
A commercial insurance proposal is not a marketing exercise. Under Part 2 of the Insurance Act 2015, a commercial insured must make a “fair presentation of the risk”: disclosing every material circumstance it knows or ought to know, in a manner “which would be reasonably clear and accessible to a prudent insurer”, with material representations of fact that are “substantially correct”. Section 8 gives the insurer a remedy where it can show that, but for a breach of that duty, it would not have entered into the contract at all or would have done so only on different terms.
Read positively, that is a helpful piece of law. It tells you exactly what a good submission looks like: accurate, complete, clearly presented, and supported by something you could produce again in twelve months. It also tells you what to do during the policy year, which is to let your broker know when something material changes rather than waiting for the next renewal.
The practical discipline is simple. Answer each technical question from a report rather than from memory, keep the reports you relied on with the submission, and note the date each one was produced.
Weigh what cover is actually for
The Breaches Survey is unusually clear-eyed about cost, and the figures are worth sitting with. The median perceived cost of the most disruptive breach or attack was £0 for businesses, rising to £30 for medium and large businesses. Most incidents are genuinely absorbed: an hour of disruption, a password reset, a wasted afternoon.
The money is in the tail. For the top 5% of cases the perceived cost was £4,000 for businesses generally, rising to £10,000 for medium and large businesses. And the share of businesses reporting that a breach cost them revenue or share value rose from 2% to 5% in a single year, with reputational damage rising from 1% to 3%.
Above that sit the incidents that reach the news. Sophos puts the average recovery cost at $1.7 million, up 11% year on year, and found the UK had the highest median ransom demand of any country surveyed at $2.5 million. IBM’s Cost of a Data Breach Report 2026, published on 29 July 2026, puts the global average cost of a breach at $4.99 million, up 12% and a record — a global figure rather than a UK one, and worth reading as a direction of travel rather than as a number that would appear on your own invoice.
Cover is not bought for the median event. It is bought for forensic investigation, legal advice, notification, business interruption and third-party liability when something lands in that tail.
Cyber Essentials as independent evidence
Cyber Essentials is the most efficient piece of third-party evidence available to a smaller firm, and it comes with cover attached. The NCSC states that any UK organisation with a turnover under £20m that achieves certification covering their whole organisation is automatically entitled to Cyber Liability Insurance arranged by IASME, its Cyber Essentials Delivery Partner.
There is a gap here that is worth knowing about. The Breaches Survey found that only 5% of UK businesses hold Cyber Essentials, up from 3% the year before, and that just 17% had even heard of it. Yet 24% reported having the technical controls associated with the scheme in all five areas. In other words, roughly one business in four is already doing the work without holding the certificate that would demonstrate it to an underwriter, a client or a procurement team.
We prepare and sponsor clients through both Cyber Essentials and Cyber Essentials Plus. The certificate itself is always issued by an IASME licensed body, which is precisely what makes it worth something on a proposal form.
Expect the supply-chain questions to grow
Third-party risk is the part of the questionnaire that has been expanding fastest, and the survey shows why: only 15% of UK businesses review the risks posed by their immediate suppliers, and 6% look at their wider supply chain.
Regulated firms are being pulled forward faster than the rest. DORA has applied to in-scope EU financial entities since 17 January 2025, and the FCA’s Policy Statement PS26/2, published on 18 March 2026, makes operational incident and material third-party reporting mandatory from 18 March 2027 — including a register of material third-party arrangements submitted annually. What starts as a regulatory obligation for financial services has a way of arriving in everyone else’s supplier questionnaires a year or two later.
Evidence that comes out of running the estate well
The reason a managed service helps with insurance is not that we know a form. It is that the artefacts an underwriter asks for are the same artefacts a well-run estate produces anyway.
Enforcing MFA generates an enrolment report. Deploying endpoint detection and response generates a coverage report. Running backups to an agreed schedule and testing restores against it generates a dated result with a recovery time in it. Patching to a defined cadence generates compliance reporting. Running security awareness training generates completion records and phishing simulation results. Rehearsing an incident response plan generates a date and a set of notes.
Gather those six things and you have answered most of the questionnaire. That is the whole trick, and it is why the work is worth doing whether or not the premium moves.
At renewal we complete the technical sections with your broker, assemble the evidence behind each answer, and flag anything that would currently have to be answered unfavourably in time for you to do something about it. Our companion guide to preparing for a cyber insurance renewal walks through the process month by month and goes into more detail on the proposal form itself.
Talk to us about your next renewal
If you would like a second pair of eyes on where you currently stand, we are glad to help. Send us your renewal date and, if you have it, last year’s questionnaire, and we will go through it with you and set out what the evidence would look like for each answer. There is no charge for that conversation, and you will end it knowing where you are strong and what is worth closing before the submission.
Last updated:
FAQ
Frequently asked questions
Are cyber insurance premiums going up or down?
Down, across the market as a whole. Howden's report Rebooting growth: 2025 cyber insurance report, published on 24 September 2025, describes rates continuing to fall in the low-double-digit range and competition among insurers increasing. Your own renewal is a narrower question than the market average, though: sector, turnover, claims history and the controls you can evidence all feed into it, and a firm that cannot answer the technical questions well can still see its terms move the wrong way in a soft market.
What will an underwriter ask us to evidence?
In broad terms: multi-factor authentication and how widely it is enforced, endpoint detection and response and its coverage, backups including when you last restored from one, how quickly critical updates are applied, security awareness training records, and a documented incident response plan with a date against its last exercise. Questionnaires differ between insurers, but that core set is remarkably consistent, so preparing for one prepares you for most.
Does Cyber Essentials come with insurance?
It does, within limits. The NCSC states that any UK organisation with a turnover under £20m that achieves certification covering their whole organisation is automatically entitled to Cyber Liability Insurance arranged by IASME, the NCSC's Cyber Essentials Delivery Partner. That is a baseline level of cover rather than a substitute for a policy sized to your business, but it is included, and the certificate itself is useful at renewal because it gives an underwriter an independent check rather than your own description.
What happens if the controls we described are not in place when we claim?
A commercial insurance proposal is a legal presentation of risk. Under Part 2 of the Insurance Act 2015 the insured must make a fair presentation of the risk, disclosing every material circumstance it knows or ought to know, in a manner that is reasonably clear and accessible to a prudent insurer. Section 8 gives the insurer a remedy where it can show that, but for the breach, it would not have written the risk at all or would have written it on different terms. The practical takeaway is calm rather than alarming: answer the form from evidence, keep a copy of what you relied on, and tell your broker if something material changes during the year.
Do we still need cover if our IT is well managed?
Yes, and the government's own figures show why. In the Cyber Security Breaches Survey 2025/26 the median cost of the most disruptive breach or attack was £0, rising to £30 for medium and large businesses — most incidents are absorbed without a bill. The top 5% of cases is where the money sits: £4,000 for businesses generally and £10,000 for medium and large ones, and that is only the direct perceived cost. Insurance is not there for the median event. It is there for forensic investigation, legal advice, notification, business interruption and third-party liability when something lands in the tail.
How does Nerdster help at renewal?
We complete the technical sections of proposal forms and renewal questionnaires alongside your broker, and we assemble the evidence behind each answer: MFA enrolment reports, endpoint coverage, restore test results, patch compliance, training records and your incident response plan. Where a question would currently have to be answered honestly and unfavourably, we tell you well before the submission date so there is time to close it. We cannot set your price, because the underwriter does that, but we can make sure the picture in front of them is complete.
Talk to our team about this standard
Tell us where you are with this standard. A London-based engineer replies within 2 hours during business hours.
Message sent
Thanks for getting in touch. We will reply within 2 hours on a business day.
Contact details
0330 043 7414
Mon-Fri 8am-6pm
[email protected]
We reply within 2 hours
71-75 Shelton Street
Covent Garden, London WC2H 9JQ
IT assessment
A review of your IT, your security posture and your compliance readiness, free of charge.
- 30-minute consultation call
- Infrastructure & security review
- Compliance gap analysis
- Custom recommendations report
Related compliance services
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment