Cyber Security

Why Your Cyber Insurance Might Not Pay Out — And What to Do About It

31 July 2026

Why Your Cyber Insurance Might Not Pay Out — And What to Do About It

Your business pays for cyber insurance. You have answered the application questions, ticked the boxes, and the premium comes out every year. If something goes wrong — a ransomware attack, a data breach, a phishing email that lands — you are covered.

Except you might not be.

UK insurers are increasingly scrutinising claims before paying out, and the gap between what businesses say they have and what they actually run in practice is where claims go to die. This is not about fraud. It is about the difference between writing something on a form and having those controls working day to day.

What insurers actually check at claim time

When you apply for cyber insurance, you answer a series of questions about your security controls. Most businesses answer honestly — based on what they believe is true. The problem is that "we use multi-factor authentication" and "we have MFA enforced on every account with no exceptions" are very different statements. Insurers treat them very differently too.

Here are the five areas where claims most frequently run into difficulty.

Multi-factor authentication

Nearly every policy now requires MFA. But requiring it and having it consistently applied are not the same thing. If a breach occurs through an account without MFA — a legacy system, a shared mailbox, an account created before your rollout — your insurer may argue the control was not in place in the way you represented it.

What insurers want to see: MFA applied to all remote access, all email, and all administrative accounts, with no exceptions and documented evidence of enforcement.

Backup and recovery

Most businesses have backups. Far fewer have tested them. A backup that exists but has not been restored in over a year is not a working backup — it is an assumption. If ransomware encrypts your data and restoration fails, or the backups were also encrypted because they sat on the same network, your claim is in serious difficulty.

What insurers want to see: regular tested restores, offsite or air-gapped copies, documented recovery times, and evidence that someone has actually verified the data is recoverable.

Patch management

Unpatched software is the entry point for a large proportion of cyber incidents. If an insurer's forensic team establishes that a known vulnerability — one with a published patch — was present on your systems at the time of the incident, they have grounds to question whether reasonable controls were maintained.

What insurers want to see: a documented patching schedule, evidence of regular updates, and a process for critical patches measured in days rather than weeks.

Access controls

The principle of least privilege — giving people access only to what they actually need — is a basic control that many businesses state in policy without enforcing in practice. If an attacker gains access through one account and immediately reaches your entire network, an insurer will ask why that was possible.

What insurers want to see: role-based access, regular access reviews, and administrative privileges restricted to accounts used exclusively for administrative tasks.

Incident response

How you respond in the first hours of an incident matters both operationally and for your claim. Insurers expect you to have a documented incident response plan and to follow it — including notifying them within the required window, typically 24 to 72 hours. Delayed notification is one of the more common grounds for complicating a claim.

What insurers want to see: a written plan, clear internal responsibilities, and evidence that staff know what to do and who to call.

The gap between the form and reality

The businesses most exposed are not the ones with no controls. They are the ones with reasonable controls on paper that have drifted in practice. MFA is enabled — for most people. Backups are running — but no one has checked the restore. Patches are applied — eventually. The insurance application was accurate when it was filled in. The controls have shifted since.

None of this is negligent. It is what happens when a business grows, IT responsibilities are spread across several people, and no one has a complete, audited picture of the current state.

What you can do about it

The straightforward answer is to know your actual control posture before something goes wrong — not because your insurer asked, but because you need to know.

The Technology Resilience Score™ is a free assessment that measures exactly the controls your insurer cares about: backup and recovery, access management, device and patch management, and incident preparedness. It gives you a scored view of where your business stands today and what needs addressing — the same picture an insurer's forensic team would build after a claim, except you get it beforehand.

If your score shows gaps, you have the opportunity to close them before your next renewal — and well before you ever need to find out the hard way whether your policy would pay out.

Get your free Technology Resilience Score →

We are not insurance advisers. For guidance on your specific policy and coverage, speak to your broker. What we can tell you is what the controls look like in practice, and whether yours would hold up.

Is your business's technology environment resilient?

Find out how prepared you really are to keep operating and recover quickly if disruption hits — with a free Technology Resilience Score™.

Get Your Technology Resilience ScoreTalk to us directly