If your business’s cyber insurance is up for renewal this year, expect a longer questionnaire and a shorter list of insurers willing to cover you. Underwriters across the UK market have tightened their criteria sharply through 2026, and brokers are reporting a rising number of SMEs being declined outright — not because they’ve made a claim, but because they can’t tick enough boxes on the technical controls list. Three years ago, a firewall and an antivirus subscription were often enough. That’s no longer the case.

The shift matters because cyber insurance has moved from a nice-to-have to something clients, landlords and even some suppliers now ask to see proof of before they’ll sign a contract. Losing cover — or only being able to get it at a much higher premium with a reduced payout — is a real business cost, not just a compliance footnote.

The seven controls insurers now expect

Across renewal questionnaires this year, a consistent core set of requirements has emerged. Most UK cyber insurers now want to see:

  1. Multi-factor authentication (MFA) on email and any remote access — and increasingly, phishing-resistant MFA specifically, not just an SMS code.
  2. Endpoint detection and response (EDR), rather than traditional antivirus, on every device that touches company data.
  3. Tested, immutable backups — insurers want evidence backups have actually been restored from, not just that they exist.
  4. A documented incident response plan, even a simple one, showing who does what in the first 24 hours of an attack.
  5. Prompt patching, particularly for internet-facing systems and VPN or remote-access software — a theme that keeps recurring in this year’s ransomware advisories.
  6. Access control discipline — unique logins, limited admin rights, and leavers’ access removed quickly rather than left dangling.
  7. Staff training, usually annual, covering phishing recognition at minimum.

None of these are exotic. What’s changed is that insurers are now actually checking, sometimes via technical scans of your public-facing infrastructure before they’ll quote, rather than taking a self-declared questionnaire at face value.

What to do before your renewal date

Start the renewal conversation earlier than you think you need to. If your policy is up in the next two or three months, pull the questionnaire now rather than waiting for the reminder email, so gaps don’t turn into a scramble. Where you’re missing controls — MFA is the single most common gap brokers report — prioritise that first, since it’s usually the cheapest and fastest to close.

If you don’t have anyone in-house who can honestly answer “when did we last test our backups by actually restoring from them,” that’s worth fixing before it’s an insurer’s question rather than yours. This is where ongoing monitoring services like KeepSafe earn their keep: rather than treating cyber controls as a once-a-year renewal exercise, continuous incident monitoring gives you evidence of your posture on demand, and an early warning if something’s already gone wrong before a claim becomes necessary. For businesses that need technical implementation — actually deploying MFA properly across a mixed estate of laptops, phones and legacy systems — that’s exactly the kind of practical build work CoolCoding handles.

The takeaway

Cyber insurance renewal in 2026 isn’t about buying a policy, it’s about passing an audit. Treat the seven-control list above as a baseline health check for your business regardless of whether you’re up for renewal this quarter — because the same gaps that get a policy declined are the ones that get exploited. Fixing MFA and backup testing this month is far cheaper than discovering the gap during a claim, or worse, during an attack.