Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West
MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES
Cyber Insurance
And Compliance.
"I would have no hesitation in recommending Soltech.”
Janie Tucker, Managing Director, Waste-Disposer Warehouse
SME
Cyber Insurance and Compliance
Corporate
Cyber Insurance and Compliance
Charity
Cyber Insurance and Compliance
Public Sector
Cyber Insurance and Compliance
Cyber Security Requirements Are Becoming Business Requirements
Cyber security is no longer simply an IT issue.
Customers, insurers, suppliers, regulators and larger organisations increasingly expect businesses to demonstrate that appropriate security controls are in place.
For some businesses, failing to meet those requirements could mean:
- Being unable to obtain cyber insurance
- Paying higher premiums
- Failing a customer security assessment
- Losing a contract
- Being unable to tender for certain work
- Delaying a new customer relationship
At Soltech IT Ltd, we help businesses understand their cyber security requirements, identify gaps and implement practical controls to improve their security and compliance position.
Why Cyber Insurance Matters
Cyber insurance can provide financial protection following certain types of cyber incidents, subject to the terms, exclusions and conditions of your policy.
However, insurers increasingly want to know what you are doing to prevent and respond to cyber attacks.
Cyber Insurance Isn't a Replacement for Cyber Security
Insurance can help manage the financial consequences of an incident.
It doesn't prevent:
- Operational disruption
- Lost productivity
- Customer impact
- Reputational damage
- Data loss
- Stress and disruption to your employees
The best approach is:
Reduce the likelihood of an attack → Detect it quickly → Respond effectively → Recover quickly
Cyber insurance should form part of that strategy, not replace it.
Cyber Insurance Security Requirements
Many organisations are asked questions about their security controls before obtaining or renewing cyber insurance.
Common areas include:
Multi-Factor Authentication
Is MFA enabled, particularly for administrator and remote access accounts?
Endpoint Security
Are business devices protected with appropriate security technology?
Backups
Are critical systems backed up, protected from ransomware and regularly tested?
Patch Management
Are critical security updates applied promptly?
Email Security
Are phishing, malware and impersonation risks being addressed?
Employee Training
Are employees trained to recognise cyber threats?
Incident Response
Does the business know what to do if it suffers a cyber attack?
Cyber Essentials & Cyber Insurance
Cyber Essentials can provide a recognised baseline of cyber security controls.
It can help demonstrate that your organisation has implemented fundamental security measures.
However, Cyber Essentials does not automatically satisfy every cyber insurance requirement.
Your insurer may require additional controls depending on your business and policy.
Soltech IT can help you understand where Cyber Essentials fits within your wider security strategy.
Cyber Essentials Plus
Cyber Essentials Plus provides additional assurance through independent technical testing.
It can demonstrate that your organisation's security controls have been independently assessed.
For businesses with higher customer, contractual or insurance requirements, Cyber Essentials Plus may be appropriate.
Customer Security Requirements
Cyber security requirements aren't only coming from insurers.
Your customers may also require evidence that your business is secure.
For example, a large organisation may require suppliers to demonstrate:
- Cyber Essentials
- Cyber Essentials Plus
- Penetration testing
- MFA
- Secure backups
- Security awareness training
- Incident response
- Vulnerability management
This can become particularly important when supplying larger organisations, regulated businesses or organisations with their own customer security obligations.
Cyber Security & Supply Chains
Your business may be part of someone else's supply chain.
Your customer could therefore be responsible for protecting information or systems that you can access.
This means their cyber security requirements can become your business requirement.
A customer may effectively say:
"We want to continue working with you, but you must meet our cyber security requirements."
Being prepared can prevent security requirements from becoming a barrier to winning or retaining business.
Cyber Security Compliance
"Compliance" can mean different things depending on the organisation.
You may need to meet requirements relating to:
- Customer contracts
- Cyber insurance
- Cyber Essentials
- Cyber Essentials Plus
- Data protection
- Industry standards
- Supplier requirements
- Internal security policies
There isn't a single cyber security certification that makes every organisation "compliant".
The correct approach depends on what your business does and what requirements apply to you.
Cyber Security Audit
Our Cyber Security Auditing service can help establish where you currently stand.
- We can review areas including:
- Network security
- Microsoft 365
- Endpoints
- Servers
- Identity
- Backups
- Vulnerability management
- User security
- Security policies
The result is a clearer picture of your current security position and the improvements that should be prioritised.
Vulnerability Management
Insurers and customers increasingly expect businesses to manage vulnerabilities appropriately.
We can help identify:
- Out-of-date systems
- Unsupported operating systems
- Missing security updates
- Vulnerable applications
- Network vulnerabilities
- Internet-facing vulnerabilities
Rather than simply producing a list of vulnerabilities, we help prioritise them according to risk.
Security Awareness & Phishing
Your employees are an important part of your cyber security controls.
We can provide:
Security Awareness Training
Teach employees how to recognise modern cyber threats.
Phishing Simulation Testing
Safely test whether employees would recognise and report realistic phishing attacks.
This provides evidence that security awareness is being actively managed rather than simply documented.
Backup & Cyber Resilience
A cyber insurance application may ask about your backup arrangements.
We can assess:
- Backup frequency
- Off-site copies
- Backup access controls
- Immutable backups
- Ransomware protection
- Recovery testing
- Disaster recovery
The goal is to ensure that your backups provide a genuine recovery option if systems are compromised.
Incident Response Planning
A good incident response plan can help reduce confusion during a cyber attack.
We can help establish:
- Who should be contacted
- Who has decision-making responsibility
- How systems should be isolated
- How employees should report incidents
- How backups will be recovered
- How external specialists will be engaged
- What information should be recorded
Importantly, your cyber insurance policy may specify particular requirements around incident notification and the use of approved providers.
Always follow the requirements of your individual policy following an incident.
What Happens If You Don't Meet the Requirements?
This depends entirely on the contract or insurance policy.
Failure to meet a particular security requirement could potentially:
- Delay an insurance claim
- Affect coverage
- Increase premiums
- Prevent a policy being offered
- Cause a customer to reject a supplier
- Require remedial action
You should never assume that a security control is optional simply because your IT system continues to operate without it.
Don't Guess What Your Insurer Requires
Cyber insurance policies can contain detailed conditions and warranties.
The exact requirements vary between:
- Insurers
- Policies
- Industries
- Business sizes
- Levels of cover
Soltech IT can help you implement and evidence technical security controls, but your insurance broker or insurer should confirm the precise requirements of your policy.
Discover the right certification for your business.
Explore Cyber Essentials and Cyber Essentials Plus.
A Practical Compliance Roadmap
We can help you work through security requirements in stages.
Step 1 — Understand
Identify the requirements from customers, insurers and relevant standards.
Step 2 — Assess
Review your existing security controls.
Step 3 — Identify Gaps
Determine where your current environment doesn't meet the requirements.
Step 4 — Prioritise
Focus on the highest-risk issues first.
Step 5 — Remediate
Implement the required improvements.
Step 6 — Evidence
Maintain appropriate records demonstrating that security controls are being managed.
Step 7 — Maintain
Continue monitoring and improving your security position.
Soltech IT's Cyber Security Services
We can help you meet many of the technical requirements associated with cyber insurance and customer security assessments through:
- Cyber Essentials
- Cyber Essentials Plus
- Cyber Security Auditing
- Penetration Testing
- Managed Security Risk
- Managed Security Operations
- Managed Detection & Response
- Endpoint Detection & Response
- Vulnerability Management
- Microsoft 365 Security
- Email Security
- Security Awareness Training
- Phishing Simulation Testing
- Dark Web Monitoring
- Cyber Incident Response
- Backup & Disaster Recovery
Speak to Soltech IT about your businesses Cyber Security needs
Contact Us
Why Choose Soltech IT?
One of the biggest advantages of working with Soltech IT is that we don't just identify compliance gaps—we can help fix them.
For example:
Customer requires Cyber Essentials
→ We assess your environment
→ Identify gaps
→ Remediate technical issues
→ Prepare you for certification
Insurer requires MFA, EDR and secure backups
→ We assess your existing controls
→ Implement appropriate technology
→ Configure and monitor it
→ Help maintain those controls
Customer requires stronger security assurance
→ Cyber Security Audit
→ Penetration Testing
→ Remediation
→ Ongoing Managed Security
This creates a practical route from requirement to implementation.
Frequently Asked Questions
Does Cyber Essentials make us compliant with cyber insurance requirements?
Not necessarily. Cyber Essentials provides a recognised security baseline, but your insurer may have additional requirements.
Can Soltech IT help us prepare for a cyber insurance renewal?
Yes. We can review your technical security controls against the requirements provided by your insurer or broker and identify areas requiring attention.
Can cyber insurance requirements change?
Yes. Requirements can change between policies and renewal periods. Always check your current policy and application documentation.
Can you help with customer security questionnaires?
Yes. We can help you understand the technical security requirements behind customer questionnaires and identify where your current controls may need improvement.
Do you provide Cyber Essentials certification?
We can help you prepare your organisation for Cyber Essentials and Cyber Essentials Plus and support the technical remediation process.
Turn Cyber Security Requirements Into a Competitive Advantage
Cyber security requirements don't have to be a burden.
For businesses that take security seriously, certification and strong security controls can become a competitive advantage.
They can help you:
- Protect your business.
- Retain customers.
- Win new contracts.
- Meet insurance requirements.
- Reduce cyber risk.
Don't wait until a customer or insurer tells you that your security isn't good enough.
Contact Soltech IT Ltd today for a Cyber Security Compliance & Insurance Assessment.

Meet the team
Executive Director
Working within the business and educational sectors for many years, Adam has been instrumental in harnessing the latest technology to innovate and deliver new and effective systems.
Prior to joining Soltech IT in 2011, Adam spent 12 years managing the IT systems and operations of Focus DIY's offices and stores throughout the United Kingdom.

































