Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West


MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES

Cyber Insurance

And Compliance.

"I would have no hesitation in recommending Soltech.”

Janie Tucker, Managing Director, Waste-Disposer Warehouse

SME

Cyber Insurance and Compliance

Corporate

Cyber Insurance and Compliance

Charity

Cyber Insurance and Compliance

Public Sector

Cyber Insurance and Compliance

Cyber Security Requirements Are Becoming Business Requirements


Cyber security is no longer simply an IT issue.


Customers, insurers, suppliers, regulators and larger organisations increasingly expect businesses to demonstrate that appropriate security controls are in place.


For some businesses, failing to meet those requirements could mean:


  • Being unable to obtain cyber insurance
  • Paying higher premiums
  • Failing a customer security assessment
  • Losing a contract
  • Being unable to tender for certain work
  • Delaying a new customer relationship


At Soltech IT Ltd, we help businesses understand their cyber security requirements, identify gaps and implement practical controls to improve their security and compliance position.


Why Cyber Insurance Matters


Cyber insurance can provide financial protection following certain types of cyber incidents, subject to the terms, exclusions and conditions of your policy.


However, insurers increasingly want to know what you are doing to prevent and respond to cyber attacks.

You may be asked about:


  • Multi-Factor Authentication
  • Endpoint protection
  • Email security
  • Backups
  • Patch management
  • Cyber security training
  • Incident response
  • Administrator accounts
  • Vulnerability management
  • Security monitoring


The requirements vary between insurers and policies.

Cyber Insurance Isn't a Replacement for Cyber Security


Insurance can help manage the financial consequences of an incident.


It doesn't prevent:


  • Operational disruption
  • Lost productivity
  • Customer impact
  • Reputational damage
  • Data loss
  • Stress and disruption to your employees


The best approach is:


Reduce the likelihood of an attack → Detect it quickly → Respond effectively → Recover quickly


Cyber insurance should form part of that strategy, not replace it.


Cyber Insurance Security Requirements


Many organisations are asked questions about their security controls before obtaining or renewing cyber insurance.

Common areas include:


Multi-Factor Authentication

Is MFA enabled, particularly for administrator and remote access accounts?


Endpoint Security

Are business devices protected with appropriate security technology?


Backups

Are critical systems backed up, protected from ransomware and regularly tested?


Patch Management

Are critical security updates applied promptly?


Email Security

Are phishing, malware and impersonation risks being addressed?


Employee Training

Are employees trained to recognise cyber threats?


Incident Response

Does the business know what to do if it suffers a cyber attack?


Cyber Essentials & Cyber Insurance


Cyber Essentials can provide a recognised baseline of cyber security controls.


It can help demonstrate that your organisation has implemented fundamental security measures.


However, Cyber Essentials does not automatically satisfy every cyber insurance requirement.


Your insurer may require additional controls depending on your business and policy.


Soltech IT can help you understand where Cyber Essentials fits within your wider security strategy.


Cyber Essentials Plus


Cyber Essentials Plus provides additional assurance through independent technical testing.


It can demonstrate that your organisation's security controls have been independently assessed.


For businesses with higher customer, contractual or insurance requirements, Cyber Essentials Plus may be appropriate.


Customer Security Requirements


Cyber security requirements aren't only coming from insurers.


Your customers may also require evidence that your business is secure.


For example, a large organisation may require suppliers to demonstrate:


  • Cyber Essentials
  • Cyber Essentials Plus
  • Penetration testing
  • MFA
  • Secure backups
  • Security awareness training
  • Incident response
  • Vulnerability management


This can become particularly important when supplying larger organisations, regulated businesses or organisations with their own customer security obligations.


Cyber Security & Supply Chains


Your business may be part of someone else's supply chain.


Your customer could therefore be responsible for protecting information or systems that you can access.


This means their cyber security requirements can become your business requirement.


A customer may effectively say:


"We want to continue working with you, but you must meet our cyber security requirements."


Being prepared can prevent security requirements from becoming a barrier to winning or retaining business.


Cyber Security Compliance


"Compliance" can mean different things depending on the organisation.


You may need to meet requirements relating to:


  • Customer contracts
  • Cyber insurance
  • Cyber Essentials
  • Cyber Essentials Plus
  • Data protection
  • Industry standards
  • Supplier requirements
  • Internal security policies


There isn't a single cyber security certification that makes every organisation "compliant".


The correct approach depends on what your business does and what requirements apply to you.


Cyber Security Audit


Our Cyber Security Auditing service can help establish where you currently stand.


  • We can review areas including:
  • Network security
  • Microsoft 365
  • Email
  • Endpoints
  • Servers
  • Identity
  • Backups
  • Vulnerability management
  • User security
  • Security policies


The result is a clearer picture of your current security position and the improvements that should be prioritised.


Vulnerability Management


Insurers and customers increasingly expect businesses to manage vulnerabilities appropriately.


We can help identify:


  • Out-of-date systems
  • Unsupported operating systems
  • Missing security updates
  • Vulnerable applications
  • Network vulnerabilities
  • Internet-facing vulnerabilities


Rather than simply producing a list of vulnerabilities, we help prioritise them according to risk.


Security Awareness & Phishing


Your employees are an important part of your cyber security controls.


We can provide:


Security Awareness Training

Teach employees how to recognise modern cyber threats.


Phishing Simulation Testing

Safely test whether employees would recognise and report realistic phishing attacks.


This provides evidence that security awareness is being actively managed rather than simply documented.


Backup & Cyber Resilience


A cyber insurance application may ask about your backup arrangements.


We can assess:


  • Backup frequency
  • Off-site copies
  • Backup access controls
  • Immutable backups
  • Ransomware protection
  • Recovery testing
  • Disaster recovery


The goal is to ensure that your backups provide a genuine recovery option if systems are compromised.


Incident Response Planning


A good incident response plan can help reduce confusion during a cyber attack.


We can help establish:


  • Who should be contacted
  • Who has decision-making responsibility
  • How systems should be isolated
  • How employees should report incidents
  • How backups will be recovered
  • How external specialists will be engaged
  • What information should be recorded


Importantly, your cyber insurance policy may specify particular requirements around incident notification and the use of approved providers.


Always follow the requirements of your individual policy following an incident.


What Happens If You Don't Meet the Requirements?


This depends entirely on the contract or insurance policy.


Failure to meet a particular security requirement could potentially:


  • Delay an insurance claim
  • Affect coverage
  • Increase premiums
  • Prevent a policy being offered
  • Cause a customer to reject a supplier
  • Require remedial action


You should never assume that a security control is optional simply because your IT system continues to operate without it.


Don't Guess What Your Insurer Requires


Cyber insurance policies can contain detailed conditions and warranties.


The exact requirements vary between:


  • Insurers
  • Policies
  • Industries
  • Business sizes
  • Levels of cover


Soltech IT can help you implement and evidence technical security controls, but your insurance broker or insurer should confirm the precise requirements of your policy.



Discover the right certification for your business.

Explore Cyber Essentials and Cyber Essentials Plus.


Cyber Essentials Cyber Essentials Plus

A Practical Compliance Roadmap


We can help you work through security requirements in stages.


Step 1 — Understand

Identify the requirements from customers, insurers and relevant standards.


Step 2 — Assess

Review your existing security controls.


Step 3 — Identify Gaps

Determine where your current environment doesn't meet the requirements.


Step 4 — Prioritise

Focus on the highest-risk issues first.


Step 5 — Remediate

Implement the required improvements.


Step 6 — Evidence

Maintain appropriate records demonstrating that security controls are being managed.


Step 7 — Maintain

Continue monitoring and improving your security position.


Soltech IT's Cyber Security Services


We can help you meet many of the technical requirements associated with cyber insurance and customer security assessments through:



  • Cyber Essentials
  • Cyber Essentials Plus
  • Cyber Security Auditing
  • Penetration Testing
  • Managed Security Risk
  • Managed Security Operations
  • Managed Detection & Response
  • Endpoint Detection & Response
  • Vulnerability Management
  • Microsoft 365 Security
  • Email Security
  • Security Awareness Training
  • Phishing Simulation Testing
  • Dark Web Monitoring
  • Cyber Incident Response
  • Backup & Disaster Recovery

Speak to Soltech IT about your businesses Cyber Security needs


Contact Us

Why Choose Soltech IT?


One of the biggest advantages of working with Soltech IT is that we don't just identify compliance gaps—we can help fix them.


For example:


Customer requires Cyber Essentials


→ We assess your environment
→ Identify gaps
→ Remediate technical issues
→ Prepare you for certification


Insurer requires MFA, EDR and secure backups


→ We assess your existing controls
→ Implement appropriate technology
→ Configure and monitor it
→ Help maintain those controls


Customer requires stronger security assurance


→ Cyber Security Audit
→ Penetration Testing
→ Remediation
→ Ongoing Managed Security


This creates a practical route from requirement to implementation.


Frequently Asked Questions


Does Cyber Essentials make us compliant with cyber insurance requirements?

Not necessarily. Cyber Essentials provides a recognised security baseline, but your insurer may have additional requirements.


Can Soltech IT help us prepare for a cyber insurance renewal?

Yes. We can review your technical security controls against the requirements provided by your insurer or broker and identify areas requiring attention.


Can cyber insurance requirements change?

Yes. Requirements can change between policies and renewal periods. Always check your current policy and application documentation.


Can you help with customer security questionnaires?

Yes. We can help you understand the technical security requirements behind customer questionnaires and identify where your current controls may need improvement.


Do you provide Cyber Essentials certification?

We can help you prepare your organisation for Cyber Essentials and Cyber Essentials Plus and support the technical remediation process.


Turn Cyber Security Requirements Into a Competitive Advantage


Cyber security requirements don't have to be a burden.


For businesses that take security seriously, certification and strong security controls can become a competitive advantage.


They can help you:


  • Protect your business.
  • Retain customers.
  • Win new contracts.
  • Meet insurance requirements.
  • Reduce cyber risk.


Don't wait until a customer or insurer tells you that your security isn't good enough.



Contact Soltech IT Ltd today for a Cyber Security Compliance & Insurance Assessment.

Speak to Soltech IT about your businesses Cyber Security needs

Our IT Consultants and Account Managers are always happy to help

Meet the team

Adam Lane

Executive Director 


Working within the business and educational sectors for many years, Adam has been instrumental in harnessing the latest technology to innovate and deliver new and effective systems.

 

Prior to joining Soltech IT in 2011, Adam spent 12 years managing the IT systems and operations of Focus DIY's offices and stores throughout the United Kingdom.