Cyber insurance has changed dramatically over the past few years. Five years ago, getting covered was relatively straightforward. Today, insurers apply the same rigorous scrutiny to your IT environment as underwriters once reserved for physical fire suppression systems. If the controls aren’t in place, you either pay significantly more or get declined entirely.
For businesses in Manchester and Sale, this shift is increasingly urgent. The UK cyber insurance market has hardened sharply since 2021. Premiums have risen, exclusions have expanded, and insurers are asking pointed questions about your IT security posture before offering a quote. Getting the answer wrong — or discovering the gap only when a claim is in flight — is expensive. Understanding the cyber insurance IT controls that underwriters actually require is the starting point.
The Controls Audit: What Insurers Are Checking
Before issuing or renewing a policy, insurers send a security questionnaire. These have grown significantly more detailed. Where once they asked broadly about antivirus and firewalls, modern questionnaires probe specific technical controls. Your answers are verified against the claim history, and in some cases against third-party threat intelligence feeds that scan your perimeter without you knowing.
The controls below are not optional extras. They represent the baseline most UK cyber insurers now require. Businesses in Sale and across Greater Manchester that cannot demonstrate these in place face either exclusions, higher excesses, or outright refusal.
Multi-Factor Authentication
Why MFA Is Now Non-Negotiable
Multi-factor authentication (MFA) is the single most commonly required cyber insurance IT control. Insurers want to see it applied to email, remote access, privileged admin accounts, and cloud services such as Microsoft 365. Some require MFA across all user accounts without exception.
The reason is simple: credential theft is the leading cause of breaches, and MFA blocks around 99% of automated account-takeover attacks. Without it, a phishing email that captures a password is all an attacker needs. Insurers know this and price accordingly. If your Manchester business isn’t running MFA on Microsoft 365 today, this is the first thing to fix. Our cyber security team can help you roll it out quickly across your organisation.
Endpoint Detection and Response
EDR vs Standard Antivirus
Standard antivirus software, which works by comparing files against a list of known threats, is no longer considered adequate by most insurers. Endpoint Detection and Response (EDR) tools go much further: they monitor device behaviour in real time, detect unusual activity that signature-based tools miss, and can isolate a compromised device automatically before a threat spreads across your network.
Many insurers now require EDR — not just antivirus — as a policy condition. If your business IT support provider is still deploying legacy antivirus on your endpoints, that conversation needs to happen soon. Tools such as Microsoft Defender for Business, SentinelOne, and CrowdStrike Falcon are now standard requirements in many UK policy wordings.
Patch Management and Vulnerability Scanning
Unpatched systems are one of the most common entry points for attackers, and insurers know it. They want to see a documented patch management process: how often patches are assessed, how quickly critical vulnerabilities are remediated, and whether someone is accountable for it.
Some insurers now run external vulnerability scans against your public-facing systems as part of the application process. If they detect open RDP ports, unpatched software, or expired SSL certificates, those will appear in your risk assessment. A Sale or Manchester business with a documented, regular patching cycle in place will consistently get better insurance terms than one that patches when it remembers to.
Backup and Disaster Recovery
The 3-2-1 Backup Rule
Cyber insurers need confidence that if ransomware hits, you can recover without paying the ransom. That means they look closely at your backup strategy. The industry standard is the 3-2-1 rule: three copies of data, on two different media types, with one copy stored offsite or in an air-gapped environment that attackers cannot reach through your network.
Critically, backups must be tested. Many businesses discover their backups were failing silently only when they need them. Insurers want to see evidence of regular restore tests, not just the existence of a backup job. If you’re not certain your backups are working and restorable, our IT support team can audit your current setup and put a compliant process in place for your Manchester or Sale business.
Email Security Protocols
Email remains the primary attack vector for phishing, business email compromise, and ransomware delivery. Insurers increasingly require properly configured email authentication protocols:
- SPF (Sender Policy Framework): specifies which mail servers are authorised to send email on behalf of your domain.
- DKIM (DomainKeys Identified Mail): adds a cryptographic signature to outbound emails, proving they haven’t been tampered with in transit.
- DMARC (Domain-based Message Authentication): tells receiving mail servers what to do with emails that fail SPF or DKIM checks, and provides reporting on spoofing attempts against your domain.
Without these in place, your domain can be spoofed by attackers sending convincing phishing emails to your customers or suppliers. Many UK insurers now treat missing DMARC as a significant risk factor. Configuring these records is a quick win for any Manchester business reviewing its cyber insurance IT controls.
Privileged Access Management
Privileged accounts — those with administrator access to systems, servers, or sensitive data — are a prime target for attackers. If a privileged account is compromised, the attacker inherits all the permissions that come with it. Insurers want to see that privileged access is tightly controlled.
In practice, this means using separate admin accounts for administrative tasks rather than day-to-day browsing, applying MFA to all privileged accounts, enforcing least-privilege principles, and logging privileged account activity. For smaller businesses in Sale and across Greater Manchester, this doesn’t need to be complex — but it does need to be deliberate and documented.
Incident Response Planning
When a cyber incident occurs, the first 30 minutes are critical. Insurers want confidence that your business won’t panic and make things worse — deleting evidence, paying ransoms impulsively, or failing to notify the Information Commissioner’s Office (ICO) within the required 72-hour window.
A documented incident response plan doesn’t need to be lengthy. It needs to answer: who to call first, how to isolate affected systems, who has authority to make decisions, and how communications are handled internally and externally. Having this in place and having tested it is increasingly expected as a policy condition. Our IT helpdesk can work with Manchester businesses to build a simple, practical incident response playbook.
Security Awareness Training
The majority of successful cyber attacks begin with a human mistake: clicking a phishing link, using a weak password, or plugging in an unknown USB drive. Insurers want to see that staff are trained to recognise and respond to these threats.
Effective security awareness training isn’t a one-hour annual video. It involves regular phishing simulations, ongoing micro-training sessions, and a culture where staff feel comfortable reporting suspicious activity without fear of blame. Many UK insurers now ask how frequently training is delivered and what format it takes. Manchester businesses that can answer clearly tend to get better terms.
What Happens Without These Controls?
Insurers handle gaps in cyber insurance IT controls in several ways. Some simply won’t offer cover. Others issue a policy with exclusions that mean a ransomware attack — the most likely claim — isn’t actually covered. Others will offer cover but set an excess so high it renders the policy almost worthless for a smaller business in Sale or Manchester.
There is a second, more serious risk: if you misrepresent your controls on the application and a claim arises, the insurer may void the policy entirely. This has happened to businesses across the UK. If your questionnaire says MFA is deployed across all systems but it isn’t, a subsequent ransomware claim can be declined on grounds of misrepresentation. The policy becomes worthless at exactly the moment you need it.
Getting Your Controls in Order
Most of these controls, once properly implemented, make your business significantly more resilient — not just more insurable. MFA, EDR, patching, and robust backups address the most common attack vectors regardless of whether an insurer is watching.
If you’re a Manchester or Sale business preparing for a cyber insurance renewal, or you’ve been declined cover and aren’t sure why, the right starting point is an honest assessment of your current IT security posture. Get in touch with PC Express IT for a straightforward conversation about where your gaps are and what it would take to close them before your renewal deadline.
Frequently Asked Questions
What IT controls do cyber insurers most commonly require?
The most commonly required cyber insurance IT controls are multi-factor authentication (especially for email and remote access), endpoint detection and response (EDR), a documented patch management process, tested backups with offsite copies, email security protocols (SPF, DKIM, DMARC), and a written incident response plan. These appear in most UK cyber insurance questionnaires as baseline requirements.
Can a small business in Manchester get cyber insurance without these controls?
Some insurers will still offer cover, but typically with higher premiums, larger excesses, or significant exclusions. The most common exclusion is for social engineering and ransomware attacks, which are exactly the scenarios most Manchester businesses need cover for. It is almost always more cost-effective to implement the required controls than to accept a policy with wide exclusions.
What happens if I answer the cyber insurance questionnaire incorrectly?
If your answers misrepresent the actual state of your IT security and a claim arises from a gap you didn’t disclose, the insurer can void the policy and refuse to pay out. Completing the questionnaire accurately is the right approach. Insurers often allow time to implement missing controls before the policy is finalised, so honesty about gaps is always the better approach.
How often do cyber insurers audit IT controls?
Many insurers now run automated external scans of your internet-facing systems as part of the application or renewal process. These scans check for open ports, unpatched software, missing security headers, and other vulnerabilities visible from outside your network. Some also purchase data from threat intelligence providers to see if your credentials have appeared in breach data. The audit is increasingly continuous, not just annual at renewal.
Is Cyber Essentials certification relevant to cyber insurance?
Yes, and increasingly so. Cyber Essentials covers five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. Holding Cyber Essentials certification demonstrates to insurers that your Manchester business has at least a baseline level of control in place, and some insurers offer reduced premiums to certified businesses. It is a sensible starting point for any SME reviewing its security posture.
Does Microsoft 365 include the cyber insurance IT controls insurers require?
Microsoft 365 Business Premium includes many of the required tools: MFA via Entra ID, Microsoft Defender for Business (which provides EDR), email security features, and Intune for device management. However, having the licences is not the same as having the controls configured correctly. Many Manchester businesses pay for Business Premium but have never activated or properly configured the included security features, which means the protection isn’t actually in place.
How long does it take to get cyber insurance IT controls in place?
For a typical Sale or Manchester SME, deploying MFA, enabling EDR, configuring email security records, and documenting an incident response plan can be done in one to four weeks depending on the size of the business and the state of existing infrastructure. Patch management processes and backup improvements take slightly longer to establish properly, but the quick wins can be completed rapidly and should be prioritised before a renewal deadline.
