Estimated reading time: 9 minutes
The Association of British Insurers has published what its members’ claims data says actually reduces cyber losses. Several of the controls sit outside Cyber Essentials entirely, including backups.
The Association of British Insurers has published good practice guidance on cyber resilience, setting out the cyber insurance controls its members regard as most effective. The document runs to ten pages and was developed with cyber insurers and government representatives.
It does something most cybersecurity advice does not. It ranks.
Eleven controls appear in total. Five are the existing Cyber Essentials core. The other six were identified separately by association members and are, in the document’s own framing, roughly ranked for effectiveness. Training and staff awareness comes first, ahead of backups, incident response planning, logging, encryption and supply chain security.
CINI glossary: Cyber Essentials is a UK government-backed certification scheme designed by the National Cyber Security Centre in 2014. It sets five core controls aimed at the most common internet-based attacks. Around 50,000 UK organizations hold an active accreditation.
Where the Guidance Comes From
The evidentiary basis is the point of difference. This is not a vendor framework or a consultancy model. The association says the document draws on cyber insurers’ experience, insight and claims data. It reflects failures behind paid losses rather than controls that appear prudent in theory.
Three caveats are stated up front and matter for how the document should be read. It is not an exhaustive list of measures. It is not a baseline every organization must achieve. And the controls are not all required by insurers in order to provide cover, with each insurer weighing them independently through its own underwriting process.
That third point is worth holding onto. This is not a checklist for getting a policy bound. It is a statement of what the market looks at.
The Ranking, and What It Says
The six additional controls run in this order: training and staff awareness, backups, incident response and continuity planning, logging and monitoring, encryption, and supply chain understanding and security.
Training first is the finding. It places human behavior above every technical control on the list, from an industry that has spent a decade telling buyers to invest in tooling.
The report sets out its claims reasoning plainly. It identifies business email compromise, phishing and social engineering as major causes of financial loss. Attackers often use spear phishing to compromise end-user devices and launch advanced persistent threats. Those attacks frequently lead to data breaches. Artificial intelligence is making this worse on both axes, with threat actors able to send more phishing attempts and more convincing ones.
On Rankings
The document then qualifies its own ranking twice, and both qualifications are worth reporting. Insurers assess the impact of each control differently, and the ordering is explicitly rough rather than scored. More pointedly, the guidance warns against treating training as a substitute for technology: carrying it out is not sufficient on its own, and technical controls remain necessary.
What members actually measure is more specific than most cyber advice manages. Regular training with content updated to reflect current threats, rather than one-off onboarding. Completion and participation rates. Phishing simulation failure rates. And the time staff take to report a simulated phishing email, which is a metric rather than a policy, and the kind of thing a broker can reasonably be asked to evidence.
There is also a cultural instruction. The guidance calls for a non-punitive culture of security and learning. Organizations that discipline staff for failing phishing simulations are, on this reading, doing it wrong. That aligns with what practitioners have been arguing for some time, including the compliance-versus-security case made on our podcast by Spektrum Labs.
What Cyber Essentials Does Not Require
The single most useful line for any business holding a certificate concerns backups. The National Cyber Security Centre recommends them, including through Cyber Essentials, but they are not mandated as part of the certification itself.
That gap matters. Backups rank second on the insurers’ list, and the growth of ransomware is what put them there. It means an organization can hold a current Cyber Essentials certificate, answer a broker honestly, and still have no tested backup regime.
The guidance is careful not to attack the scheme. It presents Cyber Essentials as a baseline for preventing common attacks and notes government research finding it effective at reducing incidents. But the structure of the document, five core controls followed by six the association considers necessary in addition, makes the argument on its own. Certification is the floor.
Cloud Sync is Not a Backup
The bluntest passage in the guidance concerns what many smaller organizations believe their backup to be.
Cloud sync lacks lengthy version histories. It is not immutable, so deletion or corruption of a file replicates to the cloud immediately. It is not offline or air-gapped. An attacker who reaches the cloud account can delete, encrypt, or corrupt files, and those changes then synchronize across connected systems.
The document acknowledges that cloud backups can provide reliable protection. Companies must isolate them properly, control access, make them immutable or offline, and test them regularly.
For any business that has assumed its file-sync service constitutes a backup, that is the paragraph to read twice. What insurers want is backups that are resilient, immutable or offline, tested regularly, and protected from credential compromise. An underwriter will likely ask how many copies the company holds and where it keeps them. They will also examine the storage medium and whether each copy remains online or offline.
Check Out Our Podcast
Closing the Cybersecurity Workforce Gap | Human Error & Cyber Insurance Risk
The Rest of The List
Incident response and continuity planning
Insurers look for a current plan containing an event playbook, escalation procedures, named contacts, and defined roles and responsibilities, tested in a realistic tabletop exercise. Some carriers will provide access to experts to run one. The guidance notes that business interruption and recovery costs are frequently the largest single portion of a cyber claim, which is what earns continuity planning its position.
Logging and monitoring
The National Cyber Security Centre advises organizations to retain key logs for at least six months. Organizations often discover incidents long after they begin. The guidance treats logging as cutting across every other control, valuable both for spotting an attack and for reconstructing one afterward.
Encryption
Valued by insurers because it reduces both the frequency and the severity of claims. Its specific use in a double extortion attack is to strip leverage: exfiltrated data that cannot be read is worth considerably less to an extortionist. Insurers and the National Cyber Security Centre both expect data encrypted at rest and in transit.
Supply chain
Vendor due diligence, continuous monitoring, access controls for vendors, and dependency mapping to establish who the critical vendors actually are. The stated minimum is that companies in a supply chain evidence Cyber Essentials certification. Organizations are also told to consider how they would recover and move data if a partner they depend on is attacked, a question sharpened by recent guidance on open source dependencies.
Vulnerability management
This sits inside the Cyber Essentials core, covers asset visibility across the entire estate, regular scanning including penetration testing, prioritization by criticality, and remediation. Cyber Essentials requires critical vulnerabilities patched within 14 days of identification. That is a demanding standard against current patch backlogs, as Contrast Security argued when launching its runtime blocking tool last month. Asset visibility carries its own difficulty, given how much of a typical estate is forgotten rather than defended, a problem Silent Push documented at scale in its dangling subdomain research.
The core controls section covers identity and access management and multi-factor authentication. We will return to the underwriting treatment of authentication separately, and our recent podcast with Lastwall covers the ground in detail.
How To Use It
The guidance is not a mandate and not a certification standard, and it says so twice. What it is is the closest thing to a published answer to the question brokers field constantly asks: what do underwriters actually want to see?
The document suggests two uses, and the second is the underrated one. The first is as support for discussions with brokers and insurers about which measures suit a given business. The second is as a prompt for asking an insurer what cyber services a policy already includes. A significant number of buyers do not know what their existing policy already gives them in threat monitoring, training or incident response, and never find out until they claim.
The association’s closing position is that “strong cyber resilience has become a cost of doing business,” applicable whether or not an organization buys a policy at all.
The guidance was published alongside the association’s UK Cyber Insurance Market Assessment with PwC UK, which we covered separately.
FAQ – Cyber Insurance Controls
It is a ten-page document published in August 2026 by the Association of British Insurers, developed with cyber insurers and government representatives. It sets out eleven cybersecurity controls drawn from insurers’ experience and claims data, covering the five Cyber Essentials core controls plus six additional measures for resilience.
The six additional controls are roughly ranked for effectiveness in this order: training and staff awareness, backups, incident response and continuity planning, logging and monitoring, encryption, and supply chain understanding and security. The guidance stresses the ranking is approximate and that individual insurers assess controls differently.
No. The National Cyber Security Centre recommends backups, including through Cyber Essentials, but they are not mandated as part of the certification. The guidance ranks backups second among the additional controls it identifies.
Generally not on its own. The guidance states cloud sync lacks lengthy version histories, is not immutable, and is not offline or air-gapped, so deletion or corruption replicates across systems. Cloud backups can be reliable where properly isolated, access-controlled, immutable or offline, and regularly tested.
No. The guidance states explicitly that the controls are not all required by cyber insurers in order to provide cover, and that each insurer considers them alongside other factors through its own underwriting process. It also states it is not a baseline every organization must achieve.
The National Cyber Security Centre advises retaining key logs for at least six months, on the basis that incidents are frequently detected late.
Related Cyber Insurance Posts
- Insurers Rule Out A Cyber Insurance Backstop As Capacity Hits Record Highs
- Cowbell Joins ABI to Strengthen UK Cyber Insurance Sector(Opens in a new browser tab)
- Few SMEs Have Cyber Insurance Despite Growing Cyber Threats, ABI Report Warns(Opens in a new browser tab)
- UK Cyber Insurance Industry Unites to Combat Ransom Payments(Opens in a new browser tab)
- New SEC Rule Requires Companies to Report Cyber Incidents, FBI Offers Guidance on Delaying Disclosure(Opens in a new browser tab)