Your insurance questionnaire is the policy

· · Security Commentary

At some point a renewal form lands on your desk asking whether every login has a second step, whether your backups are tested, and how quickly you apply security updates. It is tempting to read those as box-ticking and answer optimistically. Do not: in insurance law, that questionnaire is a statement of fact, and what you write on it decides whether the policy pays when you finally need it.

This is the plain-English version of how the product sold as "cyber insurance" actually behaves: what it pays for, where it refuses, and the free cover a lot of small firms qualify for without knowing.

First, the reassuring part

The market pays. The Association of British Insurers counted £197 million paid out to UK businesses in 2024, a 230% rise on the year before, with ransomware behind half the claims. When the ABI last published an acceptance rate, back in 2018, 99% of claims were paid, among the highest of any insurance product. And if an insurer treats a small firm unfairly, the Financial Ombudsman Service can hear the dispute: by its own estimate about 99% of UK small businesses qualify to use it.

So the horror story is not "insurers never pay". It is narrower and more avoidable: policies pay for what they cover, to businesses that described themselves honestly.

What a policy covers, and the gaps that surprise people

A typical standalone policy covers the expensive middle of a bad week: incident response and legal help, recovering data and systems, business interruption, liability to the people whose data leaked, and often extortion cover. The ABI's guide is a fair map of the standard shape.

The standard gaps matter more:

  • Fraud usually is not in it. The NCSC's insurance guidance flags that a business email compromise, somebody tricked into paying a fake invoice, is typically not covered by a standard policy. That is the most common expensive incident a small firm faces, so check for fraud or crime cover explicitly.
  • State-backed attacks are excluded. Since March 2023 Lloyd's has required standalone policies to exclude losses from war and from state-backed attacks that significantly impair a state. You will not be arguing attribution with a nation; your insurer's lawyers might.
  • Fines mostly are not covered, nor physical damage, nor claims from your own group companies.
  • One more wrinkle on extortion cover: the ICO has said in terms that paying a ransom will not be viewed as mitigation in regulatory action. Cover for a payment is not a reason to make one.

Where refusals really come from

Under the Insurance Act 2015 you owe the insurer a "fair presentation" of your risk. Get it wrong honestly and the insurer can scale the payout down in proportion to the premium you should have paid. Say something untrue recklessly or deliberately and the insurer can void the policy entirely, keep the premium, and pay nothing.

This is not theoretical. In the first case of its kind, US insurer Travelers had a policy rescinded from inception after a ransomware attack revealed the insured had claimed multi-factor authentication was in use everywhere when it protected only a firewall. The NCSC's guidance puts the UK position mildly: if you claim security measures are in place when they are not, the insurer may not be obliged to pay.

So treat the questionnaire the way you would treat accounts you are signing. Before you tick "yes" to a control, have whoever runs your IT confirm it in writing. A renewal form answered from hope is a policy that exists only until it is tested.

The controls insurers now require anyway

UK brokers are open about the minimum controls under which applications get declined rather than priced: multi-factor authentication enforced on remote access and admin accounts, off-site backups with an untouchable copy, timely patching of critical flaws, and malware protection. If that list sounds familiar, it should: they are close to the same controls that now fail Cyber Essentials outright when missing, and a backup only counts once you have proved a restore works. The questionnaire and the certification are converging on the same short list, which makes doing the list once doubly useful.

Worth knowing while you are at it: certifying your whole organisation to basic Cyber Essentials, if your turnover is under £20 million, includes security liability insurance at no extra cost, with a £25,000 limit and an incident helpline. It excludes stolen money and fraud, and £25,000 does not go far in a serious incident, but for a small firm it is a real floor, and it comes free with a certification your customers increasingly ask for anyway.

Finally, the statistic that should prompt a five-minute check today: the government's 2025/26 breaches survey found 47% of UK businesses have some form of cover, only 10% hold a standalone policy, and 22% do not know whether they are covered at all. If you are in that last group, the first action is not buying anything: it is finding out what your existing business policies already include, or specifically exclude.

What to do this quarter

  • Find every policy that might respond to a security incident and read the exclusions, looking for fraud, fines, and state-backed attack wording.
  • Answer the next proposal form as a set of written statements of fact, each confirmed by the person who actually runs the control.
  • Close the four-control gap on its own merits: second login step, tested off-site backups, prompt patching, malware protection. It is the same list whether the asker is an insurer, a customer, or an attacker.
  • If a claim is refused and you are a small firm, remember the ombudsman route exists.

How Steelwise can help

Reading a renewal questionnaire against what your business actually has, and closing the gaps before you sign it, is a short piece of security advisory work with a clear finish line. Get in touch if this year's form is asking for things you are not sure about.

Further reading

← All filings