September’s #InfosecLunchHour focused on cyber insurance, which was an ask by a regular group attendee in terms of a topic/theme for discussion, and it turned out to be a subject with far more heat in it than anyone expected.
The room included people from digital forensics, GRC, awareness and culture, journalism, certification bodies, cyber insurance advisory and a few small business owners. Under Chatham House Rules, the conversation covered what the insurance bundled with Cyber Essentials does and does not give you, why so many businesses have no idea what their policy covers, the long delays and disputes at claim time, third party risk and whether insurance has any place at all for the smallest firms.
Setting The Scene: The Insurance Nobody Reads
The discussion started with the basic level of cyber liability insurance included with Cyber Essentials certification for smaller organisations. The attendee who raised the topic admitted a degree of ambivalence about the whole subject, which set the tone for an unusually candid hour. The bundled cover is minimal. One participant with a background in insurance advisory was clear about this: treat the free cover as a starting point, not a plan. Reputable cyber insurers increasingly offer consultancy alongside the policy, and the advice was to speak to one before deciding anything. Understanding your exposure, what the policy will and will not pay out for and what controls reduce the premium is worth doing even if you end up buying nothing.
Several people made the same point from different angles. Businesses underestimate cyber insurance because they have never sat down and worked out what an incident would cost them. The insurer’s questionnaire is often the first time a small firm has been asked a structured question about its security at all.
Support, Not Protection
A participant closely involved in the early development of Cyber Essentials gave some useful history. The original idea for the scheme involved technical testing which priced most SMEs out of certification entirely. The moderated self assessment model was designed to bring the cost down to something a small business would pay. Insurance, in that framing, was always meant to be a support mechanism rather than a form of protection. You still have to keep your controls current. A policy does not patch anything.
The same participant drew on the idea, attributed to a former NCSC technical director, of learning to live with bad actors already on your systems rather than assuming you will keep them out. Cybernetics came up as a lens for this. One attendee clarified in the chat, to general amusement, that this was Beer as in Stafford Beer, not beer as in free.
What The Market Has Learned
An attendee who had written a master’s dissertation on cyber insurance shared what the research found. Many companies, and a surprising number of brokers, do not understand risk management well enough to advise on cover. Fewer still understand what evidence an insurer will demand when a claim is made. If you cannot show logs, an incident management process and a record of the decisions taken during the breach, expect a fight.
The advisory participant described how the market has moved. Some organisations now cannot get cyber insurance at any price because their risk profile is too high. There are live discussions in the sector about a pooled scheme for cyber, along the lines of Flood Re, for exactly this reason. On the positive side, boards are starting to recognise they need cyber expertise at the table. On the negative side, a policy gives directors a false sense of security and is used as a reason to reject spending on controls which would have reduced the risk in the first place.
Claims, Delays And Who Sets The Rules
This was where the frustration came out. One participant was blunt about the industry’s record: payouts take far too long, and insurers have started dictating what security practices a business must follow as a condition of cover. Others pushed back slightly. If the insurer’s requirements force a business to adopt controls the business should have had anyway, is that a bad thing?
The reply from the advisory side was pointed. An insurer’s job is to put you back where you were. Why would an insurer pay to install the controls and processes which would have prevented the breach? That is not what you bought. One attendee summed the whole thing up in a line the chat enjoyed: car insurance will replace your car, but it will not make you a better driver.
The reinsurance model came up as a practical alternative for businesses which understand their exposure. Decide what you are prepared to lose, self insure for that amount and buy cover for the layer above. It is cheaper and it forces you to think about your actual risk appetite rather than outsourcing the question to a broker.
The Smallest Business Problem
A participant working in digital forensics questioned whether cyber insurance has any relevance for the smallest businesses at all, and shared some examples of the security practices seen in the field. The pattern was consistent. After a breach, the forensic investigator explains what happened and why. 9 times out of 10 the business does not learn from it. They do not train their staff, let alone pay for audits or insurance. The problem is not the absence of a policy. The problem is a total lack of awareness about what is at stake.
Third Party Risk
The conversation moved to third party and supply chain risk. What happens when the breach originates with a supplier? Whose policy responds? One attendee observed that the whole discussion sounded a lot like the software supply chain problem: everyone assumes someone else in the chain is carrying the risk, and nobody has checked. Tying insurance to specific security measures or vendor requirements was floated as one way to make the dependencies visible, though nobody thought this was a complete answer.
Closing Reflections
Where the group landed was fairly clear. Cyber insurance is not a solution on its own and was never meant to be. The businesses which get value from it are the ones which already understand their risk, hold the evidence to support a claim and treat the insurer’s questions as a free audit. The businesses which need it most are the ones least equipped to buy it well. That gap is an education and awareness problem before it is an insurance problem, and it is one the people in this room are well placed to help close.
The attendee who proposed the topic offered to follow up with anyone who wants to go further on coverage, considerations and value for small and large businesses, so do connect with him if you would like to continue the conversation. My thanks to everyone who joined and contributed, and to those who kept the conversation moving while I was stuck on my other call.
The next #InfosecLunchHour takes place on Wednesday 7 October 2026 at 12.30pm BST. If you would like to join a group of cyber and infosec professionals for some relaxed chat over lunch, please contact me via lisa@unitysolutions.org.uk to be added to the calendar invite.
#InfosecLunchHour is a free, open, community networking event hosted by Lisa Ventura MBE FCIIS. All discussions take place under Chatham House Rules: participants may use information shared in the meeting, but may not attribute it to named individuals or organisations.



