Published:

What UK SMEs Need to Know About Cyber Insurance in 2026
The landscape has shifted substantially over the last few years. According to the government's Cyber Security Breaches Survey 2025/2026, 43% of UK businesses experienced a cyber breach or attack in the twelve months covered by the survey — roughly 612,000 businesses. Of those, 55% of small businesses hold some form of cyber cover, but only 10% hold a specific standalone cyber insurance policy; the rest rely on cyber cover embedded within a wider commercial policy.
How Cyber Insurance Underwriting Has Changed
If you renewed a cyber-insurance policy in the last year, you will have noticed the questionnaire. It used to be a handful of questions about backups and antivirus. It is now a comprehensive security audit that takes a competent IT team several days to answer properly.
The controls that underwriters now check fall into five areas: multi-factor authentication (MFA), endpoint detection and response (EDR), tested immutable backups, incident response plan, and Cyber Essentials certification.
Does Cyber Essentials Actually Affect Your Insurance?
The short answer is yes — but not in the way most SMEs assume. Cyber Essentials certification does not automatically guarantee you cover, nor does any insurer treat it as a blanket waiver of their questionnaire. What it does do is three things: it opens access to coverage, it earns premium reductions, and it strengthens your claims position.
The Gap Between Cyber Essentials and What Insurers Want
Cyber Essentials certifies five technical controls. It does not assess backups, incident response plans, or monitoring. These are the three controls that underwriters weight most heavily for ransomware risk.
What Your SME Should Do Next
If you do not currently hold cyber insurance, the first step is to establish whether your contracts require it. If you already hold cyber insurance, review your renewal questionnaire against the controls listed above. Where gaps exist, Cyber Essentials certification is the fastest path to closing them.
Frequently Asked Questions
Does cyber insurance legally require Cyber Essentials?
No. There is no statute that makes you buy cyber insurance, and no law requiring Cyber Essentials. However, many commercial contracts now require cyber cover as a condition of supply, and several underwriters use Cyber Essentials as a factor in determining whether to offer cover and at what premium.
What happens if we claim on a cyber policy without Cyber Essentials?
You are not automatically denied a claim. However, many policies include technical conditions requiring specific controls. A valid Cyber Essentials certificate provides independent verification that your baseline controls are in place.
How much does Cyber Essentials cost for a small business?
Official IASME assessment fees are tiered by organisation size. Micro businesses (0–9 employees) pay £320+VAT. Small businesses (10–49 employees) pay £440+VAT. Medium organisations (50–249 employees) pay £500+VAT.
What is the £25,000 free insurance that comes with Cyber Essentials?
Any UK organisation turning over under £20 million that achieves whole-organisation Cyber Essentials certification is automatically entitled to £25,000 of cyber liability insurance arranged by IASME.
How often do insurers review our Cyber Essentials certificate?
Most insurers will ask for a current, valid certificate at renewal — typically annually. Certification is valid for 12 months, after which you must recertify to maintain both the certification and any insurance benefits tied to it.
This article was generated with AI assistance and reviewed by the Infinite Cloud IT marketing team.

Cyber Security
Endpoint Protection for Small Business in Kent: A 2026 Guide

Managed IT Services
Cloud IT Services for Sussex SMEs — What You Should Expect in 2026

Cyber Security
Cyber Risk for UK SMEs: A Practical Guide for Owner-Managed Businesses

Cyber Security
Cyber Insurance for SMEs: Why a Cyber Essentials Baseline Is No Longer Optional

Modern Workplace