Business Insights | Cyber risk

Cyber Insurance Review Checklist 2026

A practical downloadable guide for UK SMEs reviewing ransomware, phishing, data breach response, supplier dependency, business interruption, governance and underwriting evidence before comparing cyber insurance cover.

Published 1 September 2026 GSC-led topic Cyber, data and interruption

Executive summary

Cyber insurance can help UK businesses respond to ransomware, phishing, data breach, cyber fraud, system outage and cyber business interruption events. The renewal risk is assuming all cyber policies answer the same question. They do not: incident response, first-party loss, third-party liability, supplier outage, fraud and interruption wording can differ materially by insurer.

This monthly Business Insights guide was selected from the latest repository-held Google Search Console export, covering 15 August 2026 to 28 August 2026. The `/cyber-insurance/` page recorded 2,146 impressions and zero clicks, while query rows included "cyber insurance" at 465 impressions, "cyber insurance brokers" at 126, "cyber insurance cost" at 88, "cyber insurance coverage" at 81, "cyber insurance quotes" at 78, "cyber insurance comparison" at 70, "compare cyber insurance" at 60 and "business cyber insurance" at 58, all with zero clicks.

The opportunity is a practical review asset rather than another product explainer. Insure24 already has commercial pages for cyber insurance, cyber insurance quotes, cyber insurance cost, cyber liability insurance, small business cyber insurance, ransomware cover, data breach response, cyber business interruption and cyber insurance providers. The gap is a downloadable guide that helps SMEs prepare better evidence before they request terms.

Why this matters now

The UK government's Cyber Security Breaches Survey 2025/2026 reported that 43% of businesses identified a cyber security breach or attack in the previous 12 months, equivalent to approximately 612,000 UK businesses. The same official statistics reported that phishing remained the most common breach or attack type, experienced by 38% of businesses.

The survey is also useful because it shows where practical preparation is still thin. Only 30% of businesses conducted a risk assessment covering cyber security, 15% reviewed risks from immediate suppliers, 6% looked at wider supply chain risk, and 25% had a formal incident response plan. Almost half of businesses, 47%, reported being insured against cyber security risks in some way, which means cyber cover is already part of the discussion for many firms but may not always be matched to governance, supplier and response evidence.

Government guidance has also moved the issue further into board and senior-management territory. The Cyber Governance Code of Practice, published in April 2025, asks boards and directors to identify critical digital processes, agree senior ownership, define cyber risk appetite, assess supplier risk and ensure regular risk assessments. The Cyber Resilience Pledge, updated after its July 2026 launch, also focuses on board responsibility, NCSC Early Warning and Cyber Essentials across supply chains.

For small organisations, the National Cyber Security Centre's 2026 small organisations guide gives a simple starting point: secure email, secure important online accounts, protect devices, back up data and spot cyber attacks. This Business Insights checklist does not replace that technical guidance. It translates the same resilience themes into insurance preparation questions so a broker or insurer can understand how the business would respond if a live incident tested the cover.

What to separate before renewal

Incident response

Check who detects the event, who decides whether to isolate systems, who contacts the broker, insurer, IT provider, legal adviser, bank, NCSC, Action Fraud, ICO or customers, and whether the policy gives immediate access to specialist response support.

First-party loss

Review forensic costs, restoration, data recreation, cyber extortion response, system recovery, additional costs, loss of income and whether waiting periods or trigger wording would fit the way the business actually trades.

Third-party liability

Consider allegations from customers, suppliers, clients, employees or partners after a data breach, confidentiality failure, malware transmission, system compromise or privacy event. This is not the same as recovering the business's own lost income.

Supplier and cloud dependency

Map the payment, website, booking, EPOS, payroll, CRM, manufacturing, logistics, accounting and managed-service providers that could stop trade if they failed. Check whether outsourced-service interruption is covered or restricted.

Cyber insurance evidence checklist

The strongest cyber renewal file explains how the business operates, not just what software it uses. Underwriters normally need enough information to understand data sensitivity, control maturity, incident readiness, previous events and the likely financial impact of downtime.

  • Record turnover, business activities, employee count, user count, locations and the sectors or customer types served.
  • Describe the data held: customer records, employee data, payment information, health data, financial data, confidential client files or member information.
  • List critical systems such as email, website, ecommerce, EPOS, booking platforms, finance software, CRM, payroll, cloud storage, production systems and remote access tools.
  • Confirm whether multi-factor authentication is used for email, remote access, administrator accounts, cloud services and finance systems.
  • Explain backup frequency, offline or immutable backup controls, restore testing and who is responsible for recovery.
  • Keep patching, anti-malware, firewall, endpoint, access-control, password and leaver-process notes current enough to answer insurer questions accurately.
  • List suppliers whose failure could stop trade, then record whether contracts, service levels, support routes and security assurances are available.
  • Document prior incidents, near misses, phishing attempts, fraudulent payment attempts and any remedial action taken.
  • Prepare an incident contact list covering directors, IT support, broker, insurer, legal adviser, bank, communications lead and external reporting routes.
  • Estimate downtime impact by scenario: one day without email, one day without payment systems, one week without core files, one week without website or booking systems, and loss of a key supplier platform.

Where cover gaps often appear

Cyber business interruption assumptions

Business interruption is often the section SMEs care about most after an incident, but wording can vary. Some policies require a defined cyber event affecting the insured's systems. Some include outsourced-service failure only in limited circumstances. Some apply waiting periods, sub-limits or different calculations for loss of income and additional costs. Before comparing quotes, a business should model the systems that actually stop revenue.

Fraud, phishing and payment diversion

Phishing is a common route into incidents, but not every cyber policy responds to every fraud loss. Email compromise, invoice manipulation, social engineering, mandate fraud and unauthorised payment instructions may sit under cyber, crime, fidelity guarantee or separate extensions depending on wording. Businesses should avoid assuming that "phishing covered" means all financial fraud is covered.

Minimum security requirements

Some cyber policies include security conditions around multi-factor authentication, backups, patching, remote access, endpoint protection, privileged users or incident notification. If the answer given during quotation does not match the real controls, the business may create avoidable problems later. The checklist should be used to check facts before submission, not to make the risk look stronger than the evidence supports.

Data breach and regulatory response

Data incidents can create legal advice, forensic investigation, notification, communication and liability costs. Businesses should review what personal data they hold, whether any special category data is involved, who acts as controller or processor, where data is stored, and whether contracts create additional obligations after a breach.

Professional indemnity overlap

Technology consultants, accountants, agencies, surveyors, healthcare firms, manufacturers with digital products and other professional services may need to review cyber insurance alongside professional indemnity insurance. A cyber event can become a professional negligence allegation if the dispute is about advice, design, implementation, service failure or client financial loss.

Insure24 commentary: "A useful cyber insurance review starts with the operating model. If the broker can see the data held, systems relied on, supplier dependencies, controls, incident plan and downtime assumptions, the comparison becomes about how the policy would respond to a real event rather than just which quote is cheapest."

Board and management questions

Cyber insurance is not only an IT purchase. The government Cyber Governance Code frames cyber as a board and director responsibility because incidents can affect continuity, customer trust and financial viability. Even smaller organisations can use the same principle at an appropriate scale: somebody senior should own the risk, understand the controls, approve the insurance limit and know what happens on day one of an incident.

  • Who owns cyber risk at director, partner, trustee or senior-manager level?
  • Which digital processes are critical to revenue, customer service, compliance or safety?
  • What level of cyber risk is acceptable, and where is the business currently outside that appetite?
  • What suppliers could stop the business trading, and what assurance has been collected?
  • When was the last cyber risk assessment, incident exercise, backup restore test or access review?
  • What insurance limit would realistically support response costs, downtime, liability and recovery?

How to use the downloadable checklist

The PDF version is designed for renewal meetings, board packs and broker preparation. It is intentionally practical: use it to collect facts, identify gaps and decide whether the business needs a quote, a wording review, a higher limit, a separate crime policy, improved controls or further IT advice before cyber cover is placed.

Download the Cyber Insurance Review Checklist 2026 PDF and use it alongside the commercial cyber insurance, cyber risk assessment, claims examples, exclusions and cyber business interruption pages.

Internal linking and related reading

This guide supports the main cyber insurance money page and the quote-led cyber insurance quote route. It also links to small business cyber insurance, cyber insurance cost, cyber insurance providers UK, cyber liability insurance, ransomware insurance and data breach response.

Related Business Insights include the Professional Indemnity Review Checklist 2026, where AI, cyber and client contract risk overlap, the Manufacturing Insurance Review Checklist 2026, where production downtime and cyber exposure often meet, the Freight Cargo Theft and Goods in Transit Checklist 2026, where logistics systems and supplier platforms can affect continuity, and the Pub Stock, Cellar and Business Interruption Checklist 2026, where EPOS, booking and payment systems sit alongside physical interruption risks.

Frequently asked questions

What should a business check before buying cyber insurance?

A business should check its data profile, critical systems, user access, multi-factor authentication, backups, supplier dependency, incident response plan, cyber business interruption exposure, prior incidents and any contractual or regulatory requirements before comparing cyber insurance.

Does cyber insurance replace good cyber security controls?

No. Cyber insurance is a financial and response-support tool, not a substitute for controls such as secure email, account protection, patching, backups, staff awareness, supplier checks and incident planning.

Why do insurers ask about suppliers and cloud services?

Suppliers, cloud platforms, payment providers, IT support firms and software vendors can affect interruption, data breach and recovery risk. Insurers may need to understand which services are critical and what resilience or contractual protections exist.

Should cyber insurance be reviewed with business interruption cover?

Yes. Cyber incidents can stop websites, EPOS, booking systems, finance tools, manufacturing systems or client portals. Businesses should check how cyber business interruption works and whether any waiting periods, triggers, limits or outsourced-service restrictions apply.

Can Insure24 help compare cyber insurance quotes?

Yes. Insure24 can help UK businesses compare cyber insurance options, understand wording differences and prepare underwriting information before requesting terms.

Sources used for this guide

Compare cyber cover against the way your business really trades

If your business depends on email, cloud tools, customer data, payment systems, websites, booking platforms, finance software or outsourced IT, review the evidence file before renewal. Insure24 can help UK SMEs compare suitable cyber insurance options where insurer appetite is available.