top of page

What insurance companies really look for before they pay a cyber claim

Sep 1
3 min read

Updated: Sep 2

And how to make sure your answers hold up when it matters



Our companion guide, ‘How Cyber Essentials protects your business - and your insurance payout’, looked at why Cyber Essentials and cyber insurance are more closely linked than most business owners realise.


This article takes the insurer's side of that relationship: what underwriters and claims handlers are actually checking for, how that's changed in recent years, and where Somerbys IT can help - both with the certification itself, and with the insurance paperwork that follows it.


Read the full guide here:

Guide How Cyber Essentials protects your business and insurance payout

How insurers actually assess your business

Five years ago, most cyber insurance applications asked a handful of broad questions: do you have antivirus, do you back up your data. Today's underwriting questionnaires are far more specific - multi-factor authentication on email and remote access, patch management timeframes, who holds admin rights and how that's reviewed, whether backups are tested and how quickly they can be restored.


Insurers price risk using a combination of factors: sector, turnover, how much sensitive data is held, how dependent the business is on its digital systems, previous claims history, and, increasingly heavily, the specific security controls in place.


A business that can answer those questions with evidence, rather than a best guess, is in a materially stronger position, both for the premium it's quoted and for what happens if it ever needs to claim.


The gap between the application and the claim

The harder truth is that the questionnaire completed at renewal isn't the end of the story - it's a set of promises. If a claim is made, insurers and their forensic teams check whether the controls declared on the application were genuinely in place and properly maintained at the time of the incident, not simply present in theory. That's the single biggest reason cyber insurance claims get reduced or disputed: not that a business lied on its application, but that it couldn't prove, months or years later, that what it declared was still true.


This is exactly where Cyber Essentials earns its keep. As covered in more detail in our guide, a current, dated certificate gives an insurer independently checked evidence, rather than a business's word against a forensic report after the fact.


How Somerbys IT can help

This is an area we work on with clients directly, in two ways:


Getting you certified - and keeping you certified

We help businesses achieve Cyber Essentials and Cyber Essentials Plus certification, closing the specific gaps - multi-factor authentication, patch management, access control, backups — that both attackers and insurers are looking for. Because certification is only valid for 12 months, we also help keep those controls maintained year-round, not just tightened up in the weeks before reassessment.


Helping with the insurance side directly

Renewal questionnaires about cyber security controls are often technical enough that they land on the desk of someone who isn't an IT specialist - an office manager, a finance director, sometimes the owner themselves. We work alongside businesses, and their brokers where relevant, to complete the cyber security sections of insurance renewal and application questionnaires accurately, so the answers given reflect what's actually in place, not a guess made under time pressure.


Where your business stands right now

If you're not sure exactly what an insurer would see if they looked closely - or where the gaps are between your policy and your current setup - that's worth finding out before renewal, not after a claim.


IT review

For the full picture on how Cyber Essentials and cyber insurance fit together, read the companion guide: ‘How Cyber Essentials protects your business - and your insurance payout’.


bottom of page