Cyber insurance renewals have got harder and more expensive. Premiums have risen sharply over the past few years, questionnaires have grown longer, and some Berkshire businesses have had cover refused because they couldn’t demonstrate the security controls insurers now expect. This piece explains why the market changed, what insurers are asking about, and how to walk into your next renewal with the right answers ready.
Why cyber insurance got more expensive
Cyber insurance used to be straightforward. You answered a short questionnaire, paid your premium, and the policy renewed without much fuss. Then the claims started landing.
UK insurers have spent the last few years paying out on ransomware, business email compromise, and supply chain breaches. The market hardened in response. According to industry body techUK, small and micro businesses commonly saw premium increases of 30 to 50% during the hard market, with some technology-heavy firms seeing rises of 500% or more. The government’s most recent Cyber Security Breaches Survey found that 43% of UK businesses reported a breach or attack in the last 12 months, with ransomware affecting around 1% of firms (an estimated 19,000 businesses).
Insurers have responded by changing how they underwrite. Applications now resemble a basic security audit rather than a simple tick-box exercise. Insurers used to ask whether you had antivirus, but now they want to see the configuration.
What insurers now want to see on the renewal form
Different insurers phrase things differently, but the controls they care about have converged. Most renewal questionnaires now ask about:
- Multi-factor authentication (MFA) on email, remote access, and admin accounts. Microsoft has long reported that MFA blocks most account takeover attempts, which is why insurers treat it as a baseline.
- Managed detection and response (MDR), rather than traditional antivirus. Insurers want ongoing 24/7/365 monitoring, with analysts who can detect, isolate, and respond to suspicious activity on laptops and servers around the clock, not just software that blocks known malware.
- Backups that are tested, separated from the live network, and ideally immutable. Ransomware groups target backups first, so a copy that cannot be encrypted matters.
- Patch management with a defined timeline for critical vulnerabilities and a plan for end-of-life software.
- Email filtering and staff awareness training, since phishing remains the most common attack route reported in the government survey.
The shift to evidence is the part that catches businesses out. Many firms have most of these controls in place already but cannot quickly produce screenshots, policy exports, or restore test reports when the broker asks.
What happens when you can’t demonstrate the controls
The consequences vary by insurer and severity, but they fall into a few clear patterns.
The mildest is a higher premium. If MFA is not fully rolled out, or patching is informal, you may still get cover at a noticeably higher price. The next step up is exclusions or sub-limits. The policy renews, but the insurer carves out cover for ransomware payments, business interruption, or claims tied to the specific weakness. In some cases, cover is declined outright. Businesses running unsupported operating systems may find fewer insurers willing to offer cover.
The harder outcome to see in advance comes at the point of claim. Some policies now include warranty clauses where the insured confirms specific controls are in place. If a breach later shows those controls were not operating as described, the insurer may dispute the claim. A good IT provider will flag this when they review your last application before renewal, so the answers match reality.
Getting the basics right protects more than your premium
The controls insurers ask about are not insurance jargon. They map almost directly onto the five technical controls in the NCSC’s Cyber Essentials scheme: firewalls, secure configuration, user access control, malware protection, and security update management. The government-backed certification is the recognised UK baseline, and many insurers increasingly consider Cyber Essentials certification when assessing cyber risk.
Putting these in place doesn’t only lower your premium. It reduces the chance of a breach happening in the first place and shortens recovery time if one does. Cyber Essentials Plus, which involves an independent technical audit, signals to clients and partners that your business takes security seriously, which is useful when tendering for work or being assessed by a larger client’s procurement team.
A good IT partner will treat renewal preparation as part of a wider conversation about resilience, not a separate compliance exercise. The controls that satisfy your insurer are the same ones that protect your operations, your data, and your reputation.
How SolCo helps Reading businesses prepare with confidence
For businesses in Reading and across Berkshire, the practical question is what to do before the next renewal lands on the desk.
SolCo works with businesses across the Thames Valley to map current security posture against insurer expectations, close the gaps that matter most, and document what’s in place so the renewal questionnaire can be answered with evidence rather than guesswork. As a Cyber Essentials certified team, we know what the baseline looks like, and we know where the questions trip people up. Our case study with Kirkpatrick and Hopes shows how that kind of structured approach pays off.
Whether you’re approaching renewal, taking out cover for the first time, or trying to understand why your premium jumped this year, getting the controls and the documentation in order is the most useful place to start. Clients we support in Reading have used these reviews to make better-informed decisions about cover and to have more constructive conversations with their brokers.
Renewal doesn’t need to be something to dread. With the right preparation, it becomes a useful prompt to check the basics are doing their job.
Book a free consultation to review your current security controls and prepare for a smoother renewal process.



