An underwriting pack service supplies a ready-made template plus bespoke evidence — MFA, EDR, backups screenshots, policy PDFs, incident plan and a short risk summary — and includes sector-specific examples so UK SMEs can meet insurer requirements, speed up quotes and renewals, and reduce declination risk. SME cyber insurance underwriting pack services make it possible to hand a complete, broker-ready packet to an insurer within a clear SLA, often with screenshots annotated and cut to exactly what underwriters ask for, not a technical dump of logs or vague statements.
Summary of the process
- Gather what exists: user list, policies, backup schedule, logs and device inventory.
- Run a short evidence-gathering session to capture dated screenshots (MFA enrolment lists, EDR console exports, backup snapshots).
- Populate the underwriting pack template with concise answers, a one-page risk summary and sector-specific wording.
- Submit to broker with a labelled evidence folder and short cover email; allow insurer 24–72 hours for quick review or 3–7 days for bespoke packs.
- Track insurer follow-ups and keep the pack updated for renewal.
Step 1: What an SME cyber insurance underwriting pack service delivers
An SME cyber insurance underwriting pack service bundles a ready-to-fill template plus the supporting evidence insurers expect. The deliverable should include: a completed underwriting questionnaire (insurer format) or an insurer-ready summary, policy PDFs (IT and HR), a dated screenshot pack showing MFA enrolment with timestamps, EDR or antivirus console exports, backup snapshots with retention dates, patching/asset reports, an incident response plan (one page), a short risk summary describing the business, and sector examples tailored to the SME. The why is simple: underwriters do not need raw logs; they need concise, auditable proof that controls exist and were active before the policy begins. Proof should be legible, dated, and tied to named users or machines so insurers can map controls to exposure. A good service will annotate screenshots (who, what, when) and deliver a one-page checklist for broker submission.
SME cyber insurance underwriting pack services: how insurers assess SME cyber risk and premiums
Underwriters combine three things: the business profile (sector and size), technical controls (MFA, EDR, backups, patching cadence), and recent history (incidents or claims). For UK SMEs the typical process weights controls heavily: a firm of five consultants with MFA, automated backups and basic EDR will usually present a much lower pricing profile than a 40-person retailer using one shared admin account and no centralised backups. Underwriters often use scoring models where missing controls increase premium or lead to exclusions. For example, many panels apply a step-up in premium or refuse cover if no MFA is in place for admin accounts; insurers have tightened wording around EDR or equivalent for firms with more than 20 users. This is why pack quality matters: clear, dated evidence converts a 'maybe' underwriter into a 'yes' and avoids follow-up questions that add weeks to renewal.
Quick risk score factors
- MFA for all admin accounts
- Centralised backups with test restores
- EDR or managed AV on endpoints
- Formal incident response plan
Underwriters read the pack to confirm those four items. If documentation is missing or vague the pack is returned for clarification, which often delays binding or increases the initial quotation. A good pack anticipates questions and attaches short, annotated screenshots and store-proof documents.
Step 2: What to include in an underwriting pack (exact evidence underwriters accept)
Underwriters accept a narrow set of evidence types when prepared correctly. The list below describes exactly what to capture and how to label it so a non-technical director or broker can collect it quickly.
- Screenshots with timestamps and user lists: MFA admin page showing which users are enrolled, taken with the browser clock visible or with a system-print showing date. Label as "MFA_users_YYYYMMDD.png" and include a short caption in the pack.
- EDR console exports: Many insurers accept a CSV or PDF export from the EDR showing policy status and last-seen time. If the tool cannot export, a screenshot of the policy page with date and the machine list is acceptable.
- Backups: A screenshot showing the backup policy, last successful backup date and retention period for critical data. Underwriters prefer proof of at least 30 days retention for basic SME policies, and 90 days for higher ransomware limits — note this depends on insurer wording.
- Patching reports: A screenshot or export from patch management (or endpoint security showing patch status) indicating automatic updates enabled and the percentage of devices compliant. If there is no management tool, a manual inventory list with last update dates will suffice.
- Policy PDFs: Named documents (Information Security Policy, Acceptable Use, Data Retention, Incident Response Plan) dated and signed or versioned. Even a simple one-page incident plan is better than nothing.
- Access control lists: A short CSV showing admin accounts, privileged users and confirmation that unique accounts per user are used. Avoid exporting password lists — never include credentials.
- Proof of Cyber Essentials: a copy of the certificate and scope. Many insurers provide preferential terms for Cyber Essentials (or Cyber Essentials Plus).
Each piece of evidence must be labelled, dated and have a one-line explanatory caption. Underwriters prefer PDFs and PNGs. If the SME cannot export, take clear phone-camera photos of the screen but ensure the date is visible and the image is legible.
Step 3: Preparing accurate answers for underwriting questionnaires
Underwriting questionnaires are often long and use slightly different wording between insurers. The core principle is to answer accurately and verifiably. Avoid subjective phrases such as "we have strong security"; instead use measurable statements such as "MFA enabled for 100% of admin accounts as of 2026-02-14 (see MFA_users_20260214.png)". The underwriter’s assessor wants to map answers to evidence quickly.
Practical steps: copy answers into the insurer's questionnaire but keep a master answers document labelled with the insurer name and date. Where the insurer asks about frequency (e.g. patching cadence), provide exact routines: "Monthly Windows updates via WSUS; critical patches deployed within 72 hours." If the business uses a Managed Service Provider (MSP), include the MSP contract excerpt that specifies responsibilities — underwriters will want to know who owns patching and backups. For third-party services (SaaS accounting, e-commerce platforms), list provider names and whether MFA is enforced by the provider.
Proving cyber controls: Cyber Essentials and backups
Cyber Essentials often shortens underwriting friction. A Cyber Essentials certificate (or Cyber Essentials Plus) demonstrates basic hygiene: firewalls, secure configuration, patching, malware protection and access control. Many insurers now offer clearer premium reductions for Cyber Essentials Plus at higher limits. However, a certificate alone is not sufficient; underwriters still expect corroborating screenshots showing the certificate scope and the systems covered.
Backups are a frequent sticking point. Insurers look for three things: regular automated backups, offsite or immutable copies, and tested restores. A screenshot of the backup schedule alone is weak without proof of a successful restore test. Provide dated evidence of a restore test (a short log or a signed statement from the IT provider) and the last successful backup timestamp. Common insurer minimums seen in panels: 30 days retention for low limits, 90 days retention for higher ransomware cover. If the SME uses a cloud provider, include the provider's SLA and where data is located.
Backup checklist visual
Automated schedule
(daily for data, weekly for image backups)
Offsite/immutable copy
(cloud or air-gapped)
Restore test record
(include date and result)
Step 4: Sector-specific examples and sample wording insurers expect
Different sectors require different emphases. Two anonymised examples illustrate what to include and the sample wording insurers like to see.
-
5-user consultancy (professional services): The focus is identity and backups. Evidence: MFA screenshot for Office 365 with user list, EDR export showing all endpoints protected, daily cloud backups of client data with 30-day retention, signed engagement letter with clients about data handling, and a one-page incident plan. Sample insurer-friendly wording: "MFA is enforced on all Office 365 accounts and enabled for 5 users as of 2026-02-10 (see MFA_users_20260210.png). Backups occur nightly to an encrypted cloud service with 30-day retention and quarterly restore tests (last test 2026-01-15). EDR deployed to all endpoints with central management. No incidents in the past 36 months."
-
40-staff e-commerce retailer: The focus is PCI scope, backups and third-party platform security. Evidence: screenshot of e-commerce platform security settings (MFA enforced for admin panel), EDR on POS devices, offsite backups of order database with 90-day retention, PCI-DSS compliance evidence if applicable, supplier contracts for payment gateways, and a data flow diagram. Sample wording: "E-commerce platform admin access is protected by MFA for all 7 admin users. Payment processing is handled by Stripe/Worldpay (PCI scope offloaded). Backups of transactional database retained 90 days; last restore test executed 2026-01-22. EDR covers POS and staff workstations with central logging."
These examples show the granularity insurers expect: exact dates, named providers, and test proof.
Table comparing basic and enhanced underwriting pack services
| Service level |
Typical turnaround |
Typical price (GBP) |
Includes |
| Basic pack |
24–72 hours |
£150–£450 |
Template, annotated screenshots, one-page risk summary, broker email draft |
| Enhanced pack |
3–7 days |
£450–£1,500 |
Everything in basic + bespoke insurer questionnaire completion, MSP liaison, restore test verification |
| Rapid response (urgent) |
Same day (limited) |
£450–£900 (rush fee) |
Prioritised evidence capture and phone handover to broker |
Step 5: The broker-phone submission workflow and ready-to-send email copy
A smooth submission keeps the insurer engaged and reduces chasing. The recommended workflow: prepare the pack, name files clearly, compress into a single passworded ZIP (password sent separately), call the broker with a 3–5 minute briefing, and follow up by email with the attached pack and the password in a separate message or phone call. Brokers often prefer a single PDF for quick review and the original files in a labelled Dropbox/OneDrive link.
Suggested broker call script (3–5 minutes): "This is [Director name] from [Company]. Sending an underwriting pack for [Insurer name/panel]. Key points: MFA enabled for admin as of [date], nightly backups with 30-day retention and last restore test [date], EDR on all endpoints, no incidents in last 36 months. Pack sent to email [broker email] and link in SMS. Please submit to [insurer/panel]." Keep it factual and state where evidence sits; do not volunteer extra commentary.
Ready-to-send broker email copy (short, editable):
Subject: Underwriting pack for [Insurer] — [Company name]
Dear [Broker name],
Attached is the SME cyber insurance underwriting pack for [Company name] to support the quote/renewal for [Insurer]. Key points: MFA for admin accounts enabled [date]; nightly backups with 30-day retention, last successful restore test [date]; EDR deployed to all endpoints. The pack includes annotated screenshots and the completed questionnaire. Files are in the ZIP attachment; password sent by text.
Please confirm receipt and next steps.
Regards,
[Name]
[Role]
[Phone]
This short email reduces back-and-forth and tells the broker exactly where to find evidence.
Step 6: Common policy exclusions and wording pitfalls explained
Policy wording varies and the difference between a declined claim and a paid claim can be a few sentences in an exclusion. Common pitfalls include unclear ransomware cover, regulatory fines and social engineering fraud. Examples:
- Ransomware: Some policies exclude ransom payments unless specific controls were in place before the incident (EDR, tested backups, MFA). If the pack lacks proof of tested restores, insurers may decline ransom element payments.
- Regulatory fines: Not all cyber policies include fines for breaches of the UK GDPR or Data Protection Act; they may be excluded or limited to specific amounts. If the firm processes special categories of data, this must be declared and evidenced.
- Social engineering / CEO fraud: Some SME policies exclude or limit cover for authorised payments made after deception. If payment controls are weak (single sign-off), insurers will either apply endorsements or exclude cover.
A practical step is to have the broker highlight any requested endorsements or prior incidents. When answering questions about exclusions, do not assume cover exists — read the policy schedule and ask the broker to point out ransom, fines and social engineering wording.
Managing claims, incidents and GDPR obligations post-breach
When an incident happens, the pack helps speed response. The first actions: contain, preserve evidence, contact insurer and, if required, notify the ICO and data subjects. Many SME policies require immediate notification to insurer and retention of forensic evidence. Underwriters expect an incident response partner where possible; if no partner exists, use the insurer’s panel responder.
GDPR obligations are separate from insurance. For personal data breaches that risk individuals’ rights, the ICO must be notified within 72 hours when feasible. Include contact details for the company's Data Protection Officer (or director responsible) in the pack. If the insurer or forensics firm recommends a test restore or a live forensic capture, avoid wiping systems before discussing with them. Poor handling of evidence often voids parts of cover; for example, deleting logs before a forensic review can lead to disputes.
Errors that ruin the result
Several recurring mistakes slow underwriting or cause declinations: submitting vague claims such as "we use MFA" without screenshots or dates; sending screenshots without visible timestamps or user lists; claiming backups exist without restore tests; waiting until renewal week or after an incident to gather evidence; and failing to map SaaS providers and third parties. Another frequent error is supplying log files or console dumps without captions — underwriters dislike raw, unexplained technical exports. Label every item with a short caption explaining what it proves and when it was taken.
When this method does not apply and alternatives
This approach is not relevant if the broker already manages evidence collection end-to-end or if the insurance sought is basic high-level liability that explicitly excludes cyber controls evidence. It is also less applicable to a sole trader with no enterprise systems. Alternatives include: asking the broker for a broker-managed pack service, using an MSP to collect evidence (if the MSP has a standard evidence output), or arranging a short paid consultancy to prepare the pack if the business has complex third-party dependencies.
Practical SLAs, price ranges and what to budget for
Typical market SLAs and indicative prices for 2026 market practice are:
- Basic underwriting pack: 24–72 hours turnaround, cost £150–£450. Useful for small firms with few systems and clear controls.
- Enhanced underwriting pack: 3–7 days turnaround, cost £450–£1,500. Good for firms with MSP interaction, multiple SaaS providers or where bespoke insurer questionnaires need completion.
- Rapid or same-day packs: same-day delivery for urgent renewals, cost £450–£900 (rush fee). These are limited and only suit small evidence sets.
Budgeting tip: plan the pack 2–4 weeks ahead of renewal if possible. Waiting until the last week often triggers rush fees and leaves insufficient time for insurer follow-up. A basic pack will frequently reduce insurer questions and speed binding; an enhanced pack is an investment when there are multiple insurer panels to run or if the SME had a prior incident.
A typical case study (anonymised) and measurable outcomes
A 12-person accountancy firm with cloud accounting, Office 365 and a local server engaged an underwriting pack service recently. The initial quote round without a pack produced two insurer queries and a 12% premium uplift. After delivering a dated pack with MFA screenshots, EDR export, backup restore evidence and a one-page risk summary, the firm received three competitive quotes and a final premium 9% lower than the first quoted price and saved an estimated two weeks in binding time. This shows the tangible ROI: clearer evidence lowers perceived risk and translates into both faster binding and lower premium.
Edge cases and what to do when evidence is missing
If an SME genuinely lacks a control (no MFA, no backups), the pack should record that fact and include a clear remediation plan and timescale. Insurers prefer honesty with a concrete plan: e.g., "MFA not yet deployed on legacy admin account; scheduled for implementation by 2026-03-15 and currently protected by restricted network access (see network ACL screenshot)." In many cases underwriters will accept cover with a condition that remediation occurs within a set window; some will decline cover until the control is in place. If controls cannot be provided, consider lower limits or a specific endorsement.
Evidence-gathering quick checklist
Evidence-gathering quick checklist
MFA screenshot with date and user list
EDR export or console screenshot
Backup snapshot with last successful backup
Patching report or manual update log
Policy PDFs (security, incident, retention)
How to capture screenshots without technical jargon
Directors and non-technical staff can capture acceptable evidence with simple steps. Use a modern browser and open the admin or security page (Office 365 admin, Google Workspace admin, EDR console). Press Print Screen or use the system screenshot tool and include the browser address bar showing the URL and the system clock in the corner. Save as PNG and rename using the pattern: [control][YYYYMMDD][short].png (e.g., MFA_20260210_office365.png). For exports that require admin rights, ask the MSP to produce a dated PDF export and include a one-line caption. Annotate images with a short note that explains what the image proves (e.g., "Shows MFA enabled for 7 admin users; last sync 2026-02-10"). If the SME uses mobile apps for admin, a clear phone photo is acceptable; ensure the date is visible and the image is steady.
Submission and follow-up flow
Submission & follow-up flow
Prepare pack
Call broker (3 mins)
Email pack + link
Broker submits to insurer
Insurer review (24–72 hrs or 3–7 days)
Practical checklist before submission
Before handing the pack to the broker, ensure: all screenshots are dated and labelled, the risk summary is one page, the completed insurer questionnaire is included if requested, the file names use the pattern explained earlier, and the broker has the password for the ZIP or the link and a clear phone number for follow-up. Keep a version history: include a file named "pack_version_YYYYMMDD.pdf" so the broker and insurer know which set of evidence they are evaluating.
Warnings and legal considerations
This service helps prepare evidence for insurers but does not provide legal or forensic advice. If an incident is suspected, preserve systems and contact the insurer’s incident response line first; avoid altering logs or deleting files. Additionally, claims can be declined if material facts are misrepresented. For example, falsely claiming Cyber Essentials or a restore test that did not occur can lead to refusal of cover. Be honest and precise in all statements in the pack.
External guidance and further reading
For government guidance on cyber essentials and incident response, insurers and SMEs commonly refer to the National Cyber Security Centre: National Cyber Security Centre. The NCSC publishes pragmatic advice for SMEs on backups, MFA and incident handling that aligns with what underwriters expect.
Questions people also ask
What is an underwriting pack for cyber insurance?
An underwriting pack is a prepared bundle of answers and evidence that supports a cyber insurance application or renewal. It contains completed questionnaire answers, dated screenshots (MFA, EDR, backups), policy PDFs, a one-page risk summary and sector examples so brokers and insurers can assess risk quickly without repeated follow-up.
What evidence do insurers require for SME cyber insurance?
Insurers typically require proof of MFA for admin accounts, endpoint protection (EDR/AV), automated backups with retention and restore tests, patching records, and basic security policies. They prefer dated screenshots and exports labelled with simple captions; PDFs and PNGs are standard. Third-party SaaS provider details should also be included.
How do I prepare an underwriting pack for cyber insurance?
Start by collecting named evidence: MFA screenshots with user lists and dates, EDR exports, backup snapshots and restore test records, patch reports and policy PDFs. Use a standard template to map each insurer question to specific pieces of evidence, annotate screenshots, and prepare a one-page risk summary. Consider a basic pack for quick renewals or an enhanced pack if multiple insurers are involved.
How long does cyber insurance underwriting take?
For a clear, well-prepared pack insurers often review in 24–72 hours. Bespoke or complex packs usually take 3–7 days for full review and follow-up. Rapid same-day services exist but are limited and usually cost more. Planning 2–4 weeks before renewal avoids rush fees and delays.
Can small businesses get cyber insurance without MFA?
Some insurers will offer cover without MFA but at higher premium or with strict endorsements. Many panels now expect MFA for admin or critical accounts; absence of MFA commonly leads to higher premiums or exclusions for social engineering and related incidents. If MFA is not yet in place, include a remediation plan and timeline in the pack.
SME cyber insurance underwriting pack services?
SME cyber insurance underwriting pack services prepare the template, collect and annotate evidence, and deliver broker-ready packs under agreed SLAs. They save time, reduce insurer follow-ups and can materially affect premium and binding time. Typical services range from a basic 24–72 hour pack (£150–£450) to enhanced 3–7 day packs (£450–£1,500).
What if an insurer says additional evidence is needed?
If additional evidence is requested, provide it promptly and keep a clear audit trail (emails and timestamps). If a requested control cannot be implemented quickly, offer a short remediation schedule and ask the broker to negotiate a conditional endorsement. For disputes, seek written clarification from the insurer about any conditional terms.
Conclusion and next steps
SME cyber insurance underwriting pack services remove ambiguity from insurer assessments by delivering clear, dated proof of controls and a concise risk summary. For most SMEs a basic pack (24–72 hours) is sufficient; when third parties, prior incidents or bespoke questionnaires are involved, an enhanced pack (3–7 days) is a pragmatic investment. Prepare packs 2–4 weeks ahead of renewal, label evidence clearly, and use the broker-phone workflow to avoid delays. When done properly, the pack reduces follow-up questions, improves quote accuracy and lowers the chance of declination.
For fast next steps: gather screenshots with the filename pattern described, copy the ready-to-send email, and decide whether a basic or enhanced pack suits the company’s size and complexity. If needed, contact the broker and request their preferred insurer questionnaire format before finalising the pack.