Cyber Explained

Do I need cyber insurance — and what do insurers expect?

Cyber insurance is now a boardroom question for businesses of every size. Here’s what it covers, what insurers demand, and the catch most people miss.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

Cyber insurance isn’t a legal requirement, but it’s increasingly expected — by clients, contracts and sensible risk management. It covers costs like incident response, data recovery, legal fees, lost income and sometimes ransom payments and fines after an attack. The catch: insurers now require you to have basic protections in place before they’ll pay out — multi-factor authentication (MFA), tested backups, endpoint protection (EDR), regular patching and often Cyber Essentials. Without them, a claim can be reduced or refused.

What it covers

Where cyber insurance helps

A good cyber policy helps with the real costs of an attack: expert incident response, recovering your data and systems, legal and regulatory support, notifying affected people, lost income during downtime, and sometimes extortion/ransom and fines. It’s the financial safety net behind your technical defences.

The catch

What insurers now require

Here’s what catches businesses out: insurers increasingly make cover conditional on you having controls in place — and if you don’t, they can reduce or refuse a claim. Common requirements:

Insurers usually requireHow Foresight helps
Multi-factor authentication (MFA)We enforce MFA across Microsoft 365 and key systems
Tested, offsite backupsOur backup & recovery with documented test restores
Endpoint protection (EDR)Managed EDR and 24/7 monitoring
Regular patchingAutomated patching through our management platform
Cyber EssentialsWe get you Cyber Essentials certified — often the baseline for cover

The smart move

Become insurable first

Getting these controls right doesn’t just help you pass the questionnaire and often lower your premium — it also makes an attack far less likely in the first place. We help businesses become genuinely insurable, not just tick the box. Start with Cyber Essentials, or see where you stand with a free risk scan.

FAQs

Common questions

Is cyber insurance a legal requirement?
No, it isn’t legally required for most businesses — but it’s increasingly expected by clients and contracts, and it’s sensible given how common attacks now are.
What do insurers require for cyber cover?
Commonly: multi-factor authentication (MFA), tested offsite backups, endpoint protection (EDR), regular patching, and often Cyber Essentials certification. Requirements vary by insurer and cover level.
Will my policy pay out if I don’t have MFA?
Possibly not. If you declared controls you don’t actually have, or a required control like MFA was missing, insurers can reduce or refuse the claim. Getting the basics genuinely in place protects your cover.
Does Cyber Essentials reduce cyber-insurance premiums?
Often, yes — and some insurers include a level of cyber cover with Cyber Essentials for smaller organisations. It demonstrates the baseline controls insurers want to see.
How do I become insurable?
Put the required controls in place: MFA everywhere, tested backups, managed EDR, patching and ideally Cyber Essentials. We can assess where you are and close the gaps.

Make sure your cover will actually pay out

We’ll check your controls against what insurers expect and close the gaps. Start with a free risk scan or Cyber Essentials.