Metaluxo
← Blog

Cyber Insurance in 2025: What Changed and What to Do

Cyber Insurance in 2025: What Changed and What to Do

The cyber insurance market hardened significantly in 2024. Premiums rose by an average of 15%, with some sectors seeing increases of 30% or more. At the same time, coverage limits tightened, deductibles increased, and insurers added new exclusion clauses.

For SMEs, this means cyber insurance is still available — but it requires more preparation, better documentation, and a clearer understanding of what is actually covered.


The 2024 market shift

Premium increases. The average SME cyber insurance premium increased 10–20% at renewal. Companies with previous claims or in high-risk sectors (healthcare, fintech, critical infrastructure) saw larger increases.

Coverage narrowing. Insurers are adding exclusions for:

  • State-sponsored attacks (war and terrorism clauses)
  • Social engineering losses without specific rider coverage
  • Ransom payments in sanctioned jurisdictions
  • Known but unpatched vulnerabilities

Higher deductibles. The average deductible for a policy with £1 million coverage increased from £5,000 to £10,000. For policies with business interruption coverage, waiting periods extended from 8 hours to 24 hours.

Underwriting scrutiny. Applications that were previously accepted with minimal review now require detailed security questionnaires. Some insurers are requiring external audits or penetration test reports.


What insurers now require

The security controls that insurers consistently ask about in 2025:

ControlRequired byEvidence needed
Multi-factor authentication95% of policiesMFA enrollment report
Endpoint detection and response70% of policiesEDR console screenshot
Email filtering65% of policiesSPF/DKIM/DMARC records
Backup and recovery90% of policiesBackup test log
Patch management80% of policiesVulnerability scan report
Incident response plan75% of policiesDocumented plan with roles
Employee training60% of policiesTraining completion records
Privileged access management50% of policiesAdmin account inventory

If you cannot provide evidence for the controls your policy requires, your claim may be denied.


The SME response

Start early. Begin your renewal process 8–10 weeks before the expiry date. This gives time to fix gaps and gather evidence.

Get a second opinion. A vCISO or security consultant can review your application before submission and identify weak answers.

Consider a broker. Cyber insurance is a specialist product. A broker who understands the market can find policies that match your risk profile and budget.

Do not over-insure. A £5 million policy with a £25,000 deductible is not useful if your most likely loss is £50,000. Match coverage to realistic scenarios.


At Metaluxo we review cyber insurance applications for SMEs as part of our vCISO engagements. If your renewal is coming up and you are not sure whether your controls will satisfy your insurer, book a free 30-minute consultation and we will audit your readiness.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now