The six things cyber insurers check (and where most Kent businesses fall short)
Insurers now decline applications over the same handful of missing controls. Here is what they actually ask about, the two gaps we see most often, and a free tool to score yourself before an underwriter does it for you.
Cyber insurance used to be easy to buy. You filled in a short form, ticked a box saying you had antivirus, and a policy arrived. Renewal was a formality.
That market is gone. Insurers paid out heavily on ransomware between 2020 and 2023, tightened their underwriting sharply, and now ask questions that expect specific technical answers. Businesses that would have been covered without a second thought a few years ago are getting declined, loaded, or offered cover with exclusions that make the policy considerably less useful than it looks.
The frustrating part is that it is almost always the same handful of controls. Not obscure ones. Not expensive ones. The same six things, over and over.
What insurers actually ask about
Proposal forms vary between insurers, but the core is remarkably consistent.
Multi-factor authentication. This is the big one, and it is asked about first. Not "do you have MFA", but where: on email, on remote access, on administrator accounts, on VPN. An answer of "on some accounts" is treated very differently from "on all of them". If there is one question that decides whether an application proceeds smoothly, it is this.
Backups. Again, more specific than it used to be. Are the backups reachable from your network with ordinary credentials? Because if they are, ransomware will find and encrypt them, and insurers know it. They want to hear about offline copies, immutable storage, or backups held under separate credentials. They also ask when you last tested a restore, which is a different question from whether you have backups.
Endpoint detection and response. Traditional antivirus matches known signatures. EDR watches behaviour and can respond. Most insurers now treat signature-only antivirus as below baseline, and several ask specifically whether alerts are monitored outside office hours. That is not an idle question: attacks are deliberately timed for Friday evenings and bank holiday weekends.
Encryption. Full-disk encryption on laptops and mobile devices. It is built into modern Windows and macOS, it costs nothing, and it turns a laptop left on a train from a reportable data breach into an irritating expense.
Passwords. Whether staff use a password manager, whether passwords are unique across services, and whether administrators use separate accounts for admin work rather than doing it from the account they read email on.
Staff training. Whether people receive security awareness training, how often, and whether you can evidence it. Insurers increasingly ask for completion records rather than a statement of intent.
Why the answers matter more than you think
Two things make this worth taking seriously beyond the premium.
The first is that these questions are asked again at claim time. If you stated on the proposal form that MFA was enforced everywhere, and an investigation after an incident shows it was not, you have a problem that is considerably worse than a declined application. Insurers are within their rights to decline a claim where the risk presented was materially different from the risk that existed.
The second is that the questions are a decent free security audit. Insurers are not asking about these six areas arbitrarily. They are asking because their claims data says these are the controls that decide whether an incident is an inconvenience or a catastrophe. A business that can answer all six honestly and positively is genuinely harder to attack, insurance or not.
This matters even more for regulated or data-sensitive sectors. IT support for accountants in Kent almost always needs to satisfy a stricter version of these same six questions, given the client financial data involved, so it is worth treating cyber insurance readiness and client data security as the same conversation rather than two separate ones.
The most common gap, by a distance
In our experience with Kent businesses, the single most common failure is partial MFA.
It usually happens like this. MFA gets switched on for the leadership team, or for anyone using a laptop remotely, because someone read an article or a client asked. It never gets rolled out to everyone, because there is always a handful of accounts that are awkward: the shared mailbox, the person who struggles with their phone, the old service account nobody wants to touch.
Those are exactly the accounts that get compromised. Attackers do not test the accounts you protected.
The second most common gap is backups that look fine and are not. A backup running to a network share, using domain credentials, on a machine that is part of the same domain, is not protection against ransomware. It is another thing for the ransomware to encrypt. Plenty of businesses discover this on the worst possible day.
Where you stand, in about two minutes
We have built a free tool that runs through the eleven questions insurers ask most often and scores you against them.
Take the Cyber Insurance Readiness Score
It takes about two minutes, one question per screen. You answer Yes, Partly or No, and Partly counts for something, because "MFA on some accounts" is genuinely different from none and underwriters treat it that way.
The report comes back by email and includes your score, where you sit against the level most insurers expect, and a list of exactly what is missing, ordered by how much each gap is costing you. That ordering matters. If you have four gaps and budget for two, you want to know which two to fix.
Two things it is not. It is not an insurance assessment, and no score from us commits any insurer to anything. Every insurer sets its own requirements, and a real proposal form goes further than eleven questions. It is a self-assessment designed to show you where the gaps are before an underwriter finds them, which is a much better time to find out.
If the score comes back lower than you hoped
That is useful information, not a disaster, and most of what it will tell you is fixable in weeks rather than months.
Enforcing MFA across all accounts is a configuration change, not a project. Full-disk encryption is already in your operating system. Separating admin accounts costs nothing but a bit of process. Even the harder items, moving to immutable backups and deploying EDR, are measured in weeks and are things you should want regardless of what your insurer thinks.
The businesses that struggle are the ones that discover the gaps at renewal, three weeks before the policy lapses, with a broker asking for answers they cannot give.
If you would rather someone worked through it with you, our free IT health check covers all of this and more, and produces a plain-English action plan with no obligation attached. Or just take the assessment and see where you land.
Written by CT1 Technologies

