The Association of British Insurers (ABI) has published new guidance on cyber security controls for UK organisations, a development that matters to institute professionals as insurers move to shape de facto security standards in the absence of mandatory regulation beyond existing government schemes. The guidance draws on industry claims data to identify controls linked to preventing attacks and limiting losses, and followed discussions between the insurance industry and government representatives. ABI said it is not a mandatory baseline, and organisations should apply controls proportionately to their own risk profile.
ABI is the trade association representing UK insurers and long-term savings providers.
The guidance responds to a documented surge in costly UK cyber incidents rather than a routine advisory update.
Some 43 per cent of UK businesses reported a cyber breach or attack in the latest government Cyber Security Breaches Survey, with the average significant incident costing almost 195,000 pounds and total business losses reaching around 14.7 billion pounds a year, according to Citation Cyber. High profile 2025 attacks on Jaguar Land Rover, Marks & Spencer and the Co-op carried estimated combined costs running into the billions, according to the UK Cyber Monitoring Centre.
ABI's guidance treats multi-factor authentication as central to underwriting decisions, particularly for privileged accounts, email and remote access, and recommends phishing resistant methods over SMS or email codes. It also highlights supply chain exposure, noting that vendor security failures can affect customers even when internal systems remain uncompromised.
For the sector, an insurer trade body publishing detailed technical controls, rather than only pricing risk, signals that underwriting criteria are becoming a practical substitute for mandatory regulation. For the sector's smaller organisations specifically, guidance pitched above the roughly 50,000 businesses holding Cyber Essentials certification effectively raises the bar those firms must clear to secure affordable cover.
Whether insurers begin treating these controls as hard requirements, rather than advisory good practice, will determine how much weight this guidance carries beyond renewal negotiations.
Source: Beinsure / Citation Cyber / The Global Statistics



.png)
