The cyber insurance market hardened significantly in 2024. Premiums rose by an average of 15%, with some sectors seeing increases of 30% or more. At the same time, coverage limits tightened, deductibles increased, and insurers added new exclusion clauses.
For SMEs, this means cyber insurance is still available — but it requires more preparation, better documentation, and a clearer understanding of what is actually covered.
The 2024 market shift
Premium increases. The average SME cyber insurance premium increased 10–20% at renewal. Companies with previous claims or in high-risk sectors (healthcare, fintech, critical infrastructure) saw larger increases.
Coverage narrowing. Insurers are adding exclusions for:
- State-sponsored attacks (war and terrorism clauses)
- Social engineering losses without specific rider coverage
- Ransom payments in sanctioned jurisdictions
- Known but unpatched vulnerabilities
Higher deductibles. The average deductible for a policy with £1 million coverage increased from £5,000 to £10,000. For policies with business interruption coverage, waiting periods extended from 8 hours to 24 hours.
Underwriting scrutiny. Applications that were previously accepted with minimal review now require detailed security questionnaires. Some insurers are requiring external audits or penetration test reports.
What insurers now require
The security controls that insurers consistently ask about in 2025:
| Control | Required by | Evidence needed |
|---|---|---|
| Multi-factor authentication | 95% of policies | MFA enrollment report |
| Endpoint detection and response | 70% of policies | EDR console screenshot |
| Email filtering | 65% of policies | SPF/DKIM/DMARC records |
| Backup and recovery | 90% of policies | Backup test log |
| Patch management | 80% of policies | Vulnerability scan report |
| Incident response plan | 75% of policies | Documented plan with roles |
| Employee training | 60% of policies | Training completion records |
| Privileged access management | 50% of policies | Admin account inventory |
If you cannot provide evidence for the controls your policy requires, your claim may be denied.
The SME response
Start early. Begin your renewal process 8–10 weeks before the expiry date. This gives time to fix gaps and gather evidence.
Get a second opinion. A vCISO or security consultant can review your application before submission and identify weak answers.
Consider a broker. Cyber insurance is a specialist product. A broker who understands the market can find policies that match your risk profile and budget.
Do not over-insure. A £5 million policy with a £25,000 deductible is not useful if your most likely loss is £50,000. Match coverage to realistic scenarios.
At Metaluxo we review cyber insurance applications for SMEs as part of our vCISO engagements. If your renewal is coming up and you are not sure whether your controls will satisfy your insurer, book a free 30-minute consultation and we will audit your readiness.