United Kingdom
Cyber insurance conditions in the United Kingdom, on a 90-day clock
In the United Kingdom the core list is UK Cyber Essentials, cited by its CE codes; our copy states no version, so the edition reads "as held". The test steps of Cyber Essentials Plus are not used. A control Cyber Essentials does not cover (backups, for example) is on the schedule as a condition beyond the core list. PCI DSS is an add-on when the business takes card payments.
Your insurer or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the United Kingdom template, or mark the controls in the control list.
The controls with a rule in the core list here (17)
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
- Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Other business applications are patched within the timeframe in the requirement
- Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
- Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
- Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
- Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
- Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
- Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
- Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
- Office and PDF software are hardened, blocked from creating child processes and executable content, and users cannot change their security settings
- Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
- Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed
Rule sets
- ISO 27001:2022: An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
- PCI DSS 4.0: Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
- UK Cyber Essentials: The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.