The Renewal Is The Audit You Did Not Schedule.
Few companies of fifty people commission a security audit. Almost all of them buy insurance, and the renewal that arrives each year has quietly become the audit they did not commission. The proposal form now asks for named controls and documentary evidence, the answers determine the premium, the exclusions and in some cases whether cover is offered at all, and the same answers are checked again if a claim is ever made. Our view is that the renewal should be treated as a commercial event with an owner and a prepared file, rather than an administrative task handed to whoever holds the policy documents.
in 2024
on the year before
or ransomware
formal incident response plan
Situation
The economics of the UK cyber insurance market have changed, and the change is now reaching the proposal form. The Association of British Insurers reported in November 2025 that £197m was paid out to help businesses recover from cyber incidents during 2024, an increase of 230% on the previous year and £138m more in absolute terms, with malware and ransomware accounting for more than half of all claims. In the same period, 17% more policies were taken out than in the year before. Insurers are therefore covering more organisations while paying materially more to those that suffer a loss.
The response has been to underwrite on evidence. UK broker and insurer guidance published through 2026 is consistent about what is now expected at renewal: multi-factor authentication on email, remote access and administrative accounts; endpoint detection and response rather than traditional antivirus; backups that are isolated or immutable, with a documented restore test; a written incident response plan with named roles that has been exercised; staff awareness training with phishing simulation; and critical patches applied inside a defined window, commonly fourteen to thirty days. A company that cannot evidence these is offered a higher price, narrower cover, or no terms.
Set that against the state of the market it is underwriting. The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 47% of businesses hold some form of cyber cover, but only 10% hold a specific cyber policy, rising to 24% of medium and 32% of large businesses, and that just 25% have a formal incident response plan. The insurer is asking for a document that three quarters of the market does not have.
Insight
The renewal is usually read as a procurement exercise about price. It is more accurately an annual attestation about the company's operating controls, made in writing, by someone who may not be in a position to verify it.
That distinction matters because the attestation is durable. The answers given at renewal describe the controls the insurer has priced. If a loss occurs and the controls were not in place as described, the insurer's position is informed by what was declared, and the company discovers the gap at the worst possible moment. In practice the risk is rarely deliberate misstatement. It is a finance director or office manager answering a technical proposal form in good faith, ticking multi-factor authentication because it is enabled on email, when the administrative accounts and the remote access path are the ones that matter.
There is a second point, and it is the commercially interesting one. The evidence pack the insurer wants is substantially the same pack an enterprise buyer requests in a security questionnaire, and the same one required for Cyber Essentials. The National Cyber Security Centre, marking a decade of the scheme in November 2024, cited analysis from the provider of the insurance bundled with certification indicating that certified organisations were 92% less likely to make a claim. That figure describes a specific cohort rather than the market as a whole, and should be read with that caveat. The structural point survives it: one set of controls, documented once, satisfies the insurer, the buyer and the certification body.
Options
Three approaches are open to a company of between twenty and two hundred people as renewal approaches.
The first is to answer the proposal form as it arrives. Whoever holds the policy completes it from memory, the broker submits it, and the company accepts whatever terms result.
The second is to buy the premium down. The company treats the renewal as a price negotiation, accepting higher excesses, sub-limits or ransomware exclusions in exchange for a lower figure, without changing the underlying controls.
The third is to prepare the evidence before the form arrives, close the gaps that are cheap to close, and present the renewal as a documented control set. The same file is then used for customer security reviews and for certification.
Trade-offs
Answering as it arrives costs nothing in the week of the renewal and is the reason most companies choose it. The cost appears later, in a premium set at the underwriter's assumption rather than the company's actual position, and in an attestation nobody has verified. It is the only one of the three options that creates a liability rather than merely missing an opportunity.
Buying the premium down produces a defensible saving and a worse balance sheet outcome in the event that matters. Ransomware and malware are where the claims are, so a sub-limit or exclusion in that area removes cover precisely where the market's losses are concentrated. It also leaves the controls untouched, which means the same conversation recurs next year from the same position.
Preparing the evidence takes several weeks of somebody's attention and may surface gaps that cost money to close, which is the honest objection to it. In exchange, the premium is negotiated from a documented position, the cover is worth what it appears to be worth, and the work is reusable: the enterprise questionnaire, the certification assessment and the next renewal all draw on the same file. The Association of British Insurers, in guidance published in August 2026 and drawing on its members' claims experience, sets out the controls that take an organisation beyond prevention and roughly ranks them for effectiveness. Staff training comes first, then backups, then incident response and continuity planning, ahead of logging and monitoring, encryption and supply chain security. The first three are among the least expensive to put in place.
Recommendation
We recommend the third option, run on a defined timetable. Ninety days before renewal, obtain the proposal form from the broker and treat it as a gap analysis rather than a form. Sixty days out, close what can be closed: multi-factor authentication extended to administrative and remote access, endpoint detection and response deployed, an immutable backup with a restore actually tested and the date recorded, and a two hour incident response exercise with a written note of what was learned. Thirty days out, assemble the evidence file: policies, the restore test record, the training completion record, the patching standard and the incident plan. Then answer the form from documents rather than from memory, and have the person who owns the controls sign it off rather than the person who owns the policy.
Where the customer base is enterprise or public sector, take Cyber Essentials in the same cycle. The control set overlaps almost entirely, and the certificate is separately useful in procurement.
Why
The commercial argument is threefold. First, price. Underwriters price uncertainty, and a documented control set removes the uncertainty that a loading is designed to cover. Second, cover integrity. Insurance is bought to convert a catastrophic loss into a manageable one, and cover that is contradicted by the company's actual controls does not do that, which makes an unverified attestation a governance failure rather than an administrative one. Third, reuse. The evidence assembled for the renewal is the evidence enterprise buyers request before they sign, so it earns its cost twice: once in the premium and again in deals that close faster because the answers already exist.
Risks
Four risks deserve naming. The renewal timetable can slip, which compresses the work into the fortnight before expiry and returns the company to answering from memory; the mitigation is to put the ninety day mark in the calendar as a standing item. Closing control gaps can cost more than the premium saved in the first year, and for a company with a low risk profile that may be a reasonable trade, so the analysis should be run on total cost rather than premium alone. Evidence decays: a restore test from eighteen months ago is not evidence, and a plan nobody has exercised since the last renewal is a document rather than a capability. Finally, certification can be mistaken for coverage. Cyber Essentials evidences a baseline, it does not underwrite a loss, and the two should be presented to the board as complementary rather than alternative.
Next Move
The starting point is to find the renewal date, obtain the current proposal form and schedule of cover, and mark the ninety day point. From there the exercise is a short one: identify which of the six controls the company can evidence today, which it can close within sixty days, and which require a decision about spend.
This is the work Garzon Cyber Solutions is built to do as a single sequence. The technical foundations are delivered with specialist technology partners: multi-factor authentication, endpoint detection and response, tested immutable backups and monitoring. The evidence and certification layer maps those controls to exactly what insurers, enterprise buyers and assessors ask for, so that one file answers all three. And where the company concludes that it needs a permanent owner for that file, we recruit on contingency, with nothing payable until the candidate accepts and starts. We are a young firm, and we built it around the view that security, compliance and the people who sustain them are worth more as one capability than as three separate purchases.
Confidence note
Confirmed. That the Association of British Insurers reported on 10 November 2025 that £197m was paid in cyber claims in 2024, a 230% year on year increase and £138m more than in 2023, that malware and ransomware accounted for over half (51%) of claims, and that 17% more policies were taken out than in the previous year. That the Cyber Security Breaches Survey 2025/2026, published by DSIT and the Home Office on 30 April 2026, reports 47% of businesses holding some form of cyber insurance, 10% holding a specific cyber policy, 55% of small and 61% of medium businesses holding some cover, and 25% of businesses holding a formal incident response plan. That the NCSC, in a blog marking ten years of Cyber Essentials published on 15 November 2024, cited data from the provider of the insurance bundled with certification indicating that certified organisations were 92% less likely to make a cyber insurance claim. That the Association of British Insurers published From Prevention to Resilience: Good Practice Guidance on Cyber Resilience in August 2026, which lists additional controls that members identify as taking an organisation beyond prevention, states that these are “roughly ranked for effectiveness”, and gives that order as training and staff awareness, backups, incident response and continuity planning, logging and monitoring, encryption, and supply chain understanding and security, while noting that insurers assess the impact of each control differently.
Assessed. The list of six controls expected at renewal is drawn from UK broker and insurer guidance published during 2026, including material from The Unite Group dated 5 May 2026 and from Amvia, rather than from a single insurer's published underwriting standard; individual insurers differ, and the fourteen to thirty day patching window is the range those sources describe. Indicative UK SME premiums of roughly £90 to £200 a year for micro policies, and broker ranges of £300 to £6,000, are secondary figures attributed to NimbleFins in 2026 and should be treated as illustrative. That the insurer's evidence pack substantially overlaps the enterprise security questionnaire and Cyber Essentials is our assessment from the control sets, not a published finding. The 92% figure describes the cohort holding the bundled policy and should not be read as a market-wide claim rate.
Not known. How many UK cyber claims are declined or reduced each year on the basis of control misstatement; no public UK figure exists. What proportion of small companies complete the proposal form without technical input. Whether the 2024 payout increase reflects a durable trend or a concentrated year of large losses.
If your insurer asked for evidence of your last tested restore, how long would it take to produce it?
Garzon Cyber Solutions puts the controls in place with specialist technology partners, assembles the evidence once so that it answers insurers, enterprise buyers and assessors alike, and recruits the person who owns it on contingency. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Sources: Association of British Insurers, Nearly £200 Million Paid in Cyber Claims, 10 November 2025 · Association of British Insurers, From Prevention to Resilience: Good Practice Guidance on Cyber Resilience, August 2026 · DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026 · NCSC, A Decade of Cyber Essentials, 15 November 2024 · The Unite Group, Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For, 5 May 2026 · Amvia, Cyber Insurance Requirements UK, 2026, citing NimbleFins