Cyber Insurance 7 min read

Cyber Insurance UK: The NCSC's 7 Questions Every Business Should Ask

The National Cyber Security Centre, the UK government's own cyber authority, published a seven-question framework specifically to help businesses buy cyber insurance properly. Here's what each question actually means when you're comparing policies.

Cyber insurance policies are notoriously dense, full of technical exclusions and jargon that can leave a genuine gap in cover nobody notices until a claim gets refused. In response to what it called a lack of clear information for businesses, the NCSC published official guidance built around seven core questions.

Why this matters: Sarah Lyons, the NCSC's deputy director for economy and society engagement, said the guidance exists because "when it comes to cyber insurance, there simply hasn't been enough information up to now." The guidance was welcomed by both BIBA (British Insurance Brokers' Association) and the ABI.

The NCSC's seven questions, explained

1. What existing cybersecurity defences do you already have in place?

Insurers price cover based partly on your existing controls. Being precise here matters, misstating what protections you have (for example, claiming multi-factor authentication covers all remote access when one system is exempt) can cause a claim to be disputed later.

2. How do you bring expertise together to assess a policy?

Cyber policies contain technical language most business owners aren't equipped to evaluate alone. The NCSC suggests involving whoever handles IT internally, or using your broker's technical expertise, before signing.

3. Do you fully understand the potential impacts of a cyber incident?

This means mapping out what a breach would actually cost you: system downtime, data loss, the cost of notifying affected customers, and lost revenue while you recover, not just the headline "we got hacked" scenario.

4. What does the policy cover, and not cover?

Check specifically whether ransomware payments, business interruption, and third-party data losses are all included, or whether some sit in a separate, optional extension.

5. What cybersecurity services are included, and do you need them?

Many policies bundle in incident response support, monitoring tools, or staff training. Check whether these genuinely add value for your business or whether you're paying for services you'll never use.

6. Does the policy include support during or after an incident?

A good policy gives you access to an incident response team immediately, not just a payout after the fact. This support is often the most valuable part of the policy in the first 48 hours of a breach.

7. What must be in place to claim, or to renew?

Most policies are reassessed every 12 months, and it's your responsibility to keep the insurer updated on your security posture. Overstating your controls to get a cheaper premium is one of the most common reasons cyber claims get rejected.

A real example of what's at stake

Jaguar Land Rover's 2025 cyber attack is a genuine, well-documented case of exactly the scenario this guidance exists for. The attack forced JLR to halt production across its UK plants for weeks, disrupting its supply chain and dealer network far beyond the company itself. It's widely reported as one of the most costly cyber incidents to hit a UK manufacturer, and it illustrates a point the NCSC's guidance makes directly, the impact of a cyber incident is rarely contained to IT systems alone, it can stop physical operations entirely.

Why this matters more than most business owners assume

Cyber risk isn't a large-company problem anymore. Recent UK government breach surveys have consistently found a substantial share of small and medium businesses report a cyber breach or attack within the past 12 months, and the financial impact, downtime, recovery costs, reputational damage, can be serious enough to threaten a small business's survival.

The NCSC is explicit that cyber insurance is not a replacement for basic security practice. It's there to reduce the financial shock of an incident and bring in specialist support quickly, not to make good security optional.

Compare cyber insurance built for your business

Free, no obligation. We match you with insurers who actually understand SME and corporate cyber risk.

See My Cover Options →

This article references publicly available guidance from the National Cyber Security Centre for context. CoverMatch is not affiliated with, and this article is not endorsed by, the NCSC. Always refer to ncsc.gov.uk for the most current official guidance.