Cyber risk insurance, and the controls an underwriter is really asking about

Cyber risk insurance describes the same product from the underwriter's side of the desk. What decides the price is not the industry code or the headcount so much as a short list of controls that the market has converged on, because those controls are what separate an incident that costs a weekend from one that costs a quarter. Understanding the list is the cheapest thing a buyer can do.

The control list that moves the premium

Multi factor authentication on email and on remote access. Backups held off the live network, tested, and recent. A patching routine with a defined window for critical fixes. Administrator rights limited to people who need them. Some form of endpoint protection that is actually monitored. Staff who have been told what a fraudulent payment instruction looks like. Almost every UK proposal form is a rewording of that list, and a yes to all of it changes both the price and the number of insurers willing to quote.

Answering the proposal form is a contractual act

The answers are not a survey. They form part of the contract, and a control you said was in place but was not can turn into an argument at claim time or a condition precedent that defeats the claim entirely. If a control is partial, say so and describe it. Underwriters price uncertainty they can see, and they decline uncertainty they discover later.

What actually drives the exposure, beyond the controls

Volume and sensitivity of personal data held. Whether the business instructs payments. Dependence on a single system or a single supplier. Whether it trades with the United States. Whether it has been hit before. A small firm with a large client database and a payments role can present a bigger exposure than a larger firm that holds almost nothing and sells for cash.

Why the market hardened, and what that means for a buyer

Ransomware losses pushed insurers from light touch underwriting to a control based approach, and that is now the settled position. For a buyer the practical consequence is that the cheapest route to a lower premium is usually to turn on multi factor authentication and fix the backups rather than to shop the quote around. The controls also reduce the chance of the claim, which is the point.

Questions people ask about cyber risk insurance

Will I be refused cover if I have weak controls?

Sometimes, particularly for remote access without multi factor authentication. More often you will be quoted with a condition, a higher excess or a lower limit. Fixing the control before you apply is usually cheaper than accepting the loading.

Does a previous incident stop me getting cover?

No, but it has to be disclosed and it will be underwritten. What insurers want to see is what changed afterwards. A firm that was hit and then hardened is a different risk from one that was hit and did nothing.

Do I need a formal risk assessment?

Not for most small business policies. A documented view of what data you hold and how money leaves the business will answer most of the proposal form and is worth writing down once.

Is Cyber Essentials enough on its own?

It is a recognised floor and it answers a large part of the form, but it is a baseline rather than a ceiling. Insurers will still ask about backups, payment verification and remote access in their own words.

Sources

Related answers

See what insurers printCompare by trade