MDR can mean different things in insurance paperwork. It may appear in a renewal question, statement, warranty, condition precedent or policy endorsement. Those labels matter. If you say you have 24/7 Managed Detection and Response, but only check antivirus alerts during office hours, an insurer may challenge a related claim.
MDR wording decides whether an insurer can rely on it
An MDR clause has legal force through its exact wording and its place in the insurance contract.
First identify the document and label
A warranty is a strict promise within the policy. A policy condition creates an ongoing duty. A condition precedent may require compliance before the insurer pays a particular claim.
Words such as “warranted”, “subject to”, “you must maintain”, and “condition precedent to liability” need close attention. They can change the result after a cyber incident.
The most common error is treating every MDR question as a simple technical preference. Its legal effect depends on the document where it appears.
| Where MDR appears | What it usually means | What to retain |
|---|
| Quote or renewal form | A statement used to assess and price risk | Completed form and supporting records |
| Policy condition | An ongoing contractual duty | Contract, scope and service records |
| Condition precedent | A duty linked directly to liability for a claim | Evidence of compliance at the loss date |
| Endorsement | A specific change that may override standard wording | The signed policy schedule and endorsement |
The Insurance Act 2015 changes the analysis
The Insurance Act 2015 applies to most business insurance in England. It requires a fair presentation of the risk.
In plain English, you must give enough clear information for a prudent insurer to assess the risk. You must not make a careless, deliberate or reckless misstatement.
The Act does not make every missed security control an automatic claim refusal.
MDR is cyber monitoring, not medical regulation
Under the Insurance Act 2015, the remedy depends first on what went wrong. A failure of fair presentation at placement or renewal can lead to different remedies.
The result depends on whether the breach was deliberate, reckless, or neither. It also depends on what the insurer would have done with the true facts.
For a non-deliberate and non-reckless breach, the insurer may change the premium or terms. It may reduce a claim payment proportionately. Automatic avoidance is not the only outcome.
A breach of a policy condition is a separate issue. Section 11 may protect you where non-compliance could not have increased the risk of that loss.
Think of section 11 like a lock on a garden shed. A missing lock may matter less where the loss was a burst pipe.
The MDR wording, cyber endorsement, and any condition precedent must be read together. A broker or solicitor can review this wording for a live dispute.
EDR alone rarely proves a 24/7 MDR promise
Endpoint Detection and Response, often called EDR, is software on devices. It records and flags suspicious activity.
MDR adds people and a Security Operations Centre, or SOC. The SOC monitors alerts and follows an agreed response process, often 24 hours daily.
EDR alone rarely proves a promise of 24/7 MDR. A tool can raise an alert without anyone seeing it overnight.
Check what assets the policy actually names
Ask the provider for an enrolment report on the policy start date. Ask for another report at least monthly.
One unmonitored server can matter if the policy promises cover for all endpoints. It may matter less where the policy allows a defined selection.
An endpoint is a device connected to your business network. It can include a laptop, server, desktop, or virtual machine.
Check who responds outside business hours
Your agreement should state response times in minutes or hours. It should name escalation contacts and who can approve containment overnight.
A sensible test asks what happens between 10 pm and 7 am. Creating a ticket for the next working day is not always a response.
A common scenario involves ransomware at 2 am. The provider sends an email, but nobody monitors the mailbox.
Does your service match the insurance promise?
1. Policy
“All endpoints, 24/7 MDR”
2. Contract
Named assets and response duties
3. Records
Agents, logs, alerts and tickets
Gap?
Tell broker before a claim
“MDR or equivalent” needs written clarity
“MDR or equivalent” is less precise than a named managed service. It may allow another setup.
Antivirus alone is rarely equivalent if the insurer expects monitoring, alert triage and incident response. Get the insurer’s acceptance in writing.
MDR is often only one cyber insurance requirement at quotation and renewal. An insurer may also ask about multi-factor authentication, immutable backups, and patching.
Multi-factor authentication, or MFA, requires more than one proof of identity. It is like needing both a door key and a phone code.
These controls address different parts of an attack. MFA can reduce account takeover. Patching can reduce initial compromise.
Immutable backups can support recovery after ransomware. MDR can spot and contain suspicious activity.
A strong MDR service does not automatically meet a separate backup, MFA or patching condition. Read the policy schedule and proposal carefully.
Claim outcomes depend on timing, scope and loss link
A late or incomplete MDR service does not change past facts. Those facts include inception, renewal, and the point when ransomware entered the network.
Claim outcomes often turn on timing, service scope, and the loss link. The insurer must assess the actual incident, not just a policy label.
Ransomware outside normal office hours
Ransomware can start at 2 am, outside normal office hours. The provider may see suspicious activity but only send an unattended email.
If the policy required 24/7 monitoring and response, two questions matter. Did the provider have that duty, and did missing action worsen the loss?
This works well in theory, but contracts often split detection from containment. A provider may investigate alerts but need your approval before isolating devices.
An endpoint was not enrolled
An unenrolled endpoint creates a different issue from a missed alert. The key facts are the policy scope, the provider scope, and the loss date.
For example, a new server may be added after a business acquisition. If it never received the MDR agent, records should show when it joined.
A gap may matter more if ransomware entered through that server. It may matter less if the loss had no connection to it.
Alerts ignored by the business
An enrolled endpoint can still create a claim issue where staff ignore an alert. That differs from an out-of-hours failure by the MDR provider.
Ambiguous language should be tested against the incident facts. It should not be assumed to favour either side.
“Continuous monitoring” may mean automated telemetry collection. It may also require human triage.
“Reasonable security controls” is broader. It may be judged against your business, stated controls, and the risk known to the insurer.
If an acquisition or new cloud estate changes MDR scope, record the date. Tell the broker where the policy or proposal requires notice.
Endpoint reports, tickets, and escalation records can show which scenario applied. They can be vital after an incident.
Keep a claims-ready MDR evidence file
A claims-ready evidence file should show that the service was live. It should show that the service covered promised systems and was acted upon.
Think of this file as a receipt folder for your cyber protection. It helps show what you bought and what happened.
Documents that prove the service existed
Keep the signed MDR contract, statement of work, service description, invoices, and service-level agreement. A service-level agreement, or SLA, sets response commitments.
The agreement should state whether coverage is 24/7. It should say which alerts receive investigation.
It should also say whether the provider can contain an incident. Containment can include isolating a compromised device from the network.
Records that prove coverage and action
Keep endpoint and identity inventories, agent deployment reports, exclusions, alert logs, tickets, incident reports, and escalation emails. Keep records for the policy period.
Keep records longer if the policy says so. Your adviser may also recommend a longer period.
A monthly report can reveal gaps before a claim. This is far easier than rebuilding evidence after ransomware.
Your practical review: Match every policy promise with a provider document and a live record. For “24/7 MDR on all endpoints”, keep the contract, asset-enrolment report, monitoring terms, and proof that alerts reached a responsible person.
A material change is a fact that could affect the insurer’s view of risk. It may include a new cloud system, acquisition, or a lapse in endpoint coverage.
Do not leave those changes in informal chats. Record the date, affected systems, and action taken.
Tell your broker if the policy or proposal requires notice. Ask for written confirmation of any insurer response.
Review the clause before accepting or renewing cover
Before accepting a policy, compare the MDR clause with your actual service. Put that comparison in writing.
The safest approach is to match the insurer’s words, your provider contract, and live records. All three should tell the same story.
Questions to put to your broker or insurer
Ask whether MDR is a proposal answer, policy condition, warranty, condition precedent, endorsement, or reasonable precautions clause. Each label can have a different legal effect.
Ask what “equivalent” means in your policy. Ask whether all identities and cloud systems are included.
Ask whether the insurer accepts your existing EDR provider. Get the answer in writing.
Ask what notice is needed if coverage drops. Also ask what happens when you add a material system.
Written answers matter after a cyber incident. Verbal reassurance can be hard to prove.
Weigh the cost against the contractual promise
Compare the cost of MDR with the promise you made to the insurer. Check whether the provider covers all endpoints, all hours, and the response expected.
Do not buy a service based only on its name. Two services called MDR can have very different overnight duties.
Ask the broker to confirm any gap before renewal. That can avoid a dispute at the worst possible time.
This guidance is less relevant if your policy has no MDR, continuous-monitoring, or reasonable-security-controls wording. It also does not decide a live claim. A professional must review the full policy, schedule, proposal, endorsements, facts, and applicable law.
Your questions answered
Do cyber insurance policies require MDR?
No, MDR is not required by every cyber policy. Some insurers require it for higher limits, higher-risk sectors, or businesses with hundreds to thousands of endpoints.
Your schedule and endorsements decide your position. Check them before you rely on a quote summary.
Is EDR the same as MDR for insurance?
No, EDR is usually a detection tool on devices. MDR normally includes people who monitor and investigate alerts.
EDR may meet the requirement only if the insurer accepts your monitored service as equivalent in writing. A 24/7 promise needs clear proof.
Can an insurer refuse a claim over missing MDR?
Potentially, but not merely because the insurer says “MDR requirement”. The clause type, Insurance Act 2015, breach type, and loss link can affect the remedy.
A condition precedent may have stronger effects than a general renewal answer. The full wording still matters.
Does Cyber Essentials satisfy an MDR clause?
No, Cyber Essentials is a UK baseline cyber security certification supported by the NCSC. It can support your risk evidence.
It does not prove 24/7 monitoring, alert handling, or managed response. An MDR clause normally needs separate evidence.
What if we bought MDR after the policy began?
Buying MDR later may reduce future risk. It does not change an inaccurate answer or breach that existed at inception or renewal.
Tell your broker about the change. Ask whether the insurer needs to endorse the policy.
What evidence should we keep from our MDR?
Keep the contract, service scope, SLA, invoices, enrolment reports, exclusions, logs, tickets, and incident reports. Keep records for each important asset.
Those records should show whether each asset was covered on the cyber incident date. Monthly enrolment reports can help prove this.
Must our MDR provider respond to alerts for us?
Not always, because some services only detect and escalate. If your policy says “detection and response”, check who can isolate devices.
Your staff may need to act within a defined period. That period can be between 15 and 60 minutes.
Match the promise, service and proof
Do not describe MDR more broadly than your contract and records can prove. A policy promise, service scope, and evidence file should align on the claim date.
Check the clause before accepting or renewing cover. Then ask your broker or insurer to confirm unclear wording in writing.
This is a practical insurance review, not legal, broking, or technical advice. A live claim needs advice based on its own facts and wording.