Skip to content

Association of British Insurers sets out cyber security controls for UK businesses

ABI sets out cyber security controls for UK businesses

The Association of British Insurers has published new guidance on cybersecurity measures UK organisations should consider when preparing for cyber incidents. The document draws on industry experience and claims data to identify controls associated with preventing attacks and limiting losses.

The guidance followed discussions between the insurance industry and government representatives. ABI said it isn’t a mandatory baseline or an exhaustive cybersecurity standard, and organisations should apply controls proportionately to their own risk profile.

Cyber Essentials provides the starting point. Introduced by the National Cyber Security Centre in 2014, the scheme covers secure configuration, user access, malware protection, security updates and firewalls.

Around 50,000 UK organisations currently hold active Cyber Essentials certification, according to NCSC figures cited by ABI. The association said newer threats require additional measures beyond those five controls.

Identity and access management is one of the main areas identified. Threat actors increasingly use stolen credentials and legitimate accounts, making authentication, permissions and privileged account controls more important.

Multi-factor authentication receives particular attention. ABI said most cyber insurers now treat MFA as an important underwriting consideration, especially for privileged accounts, email, remote access, cloud applications and endpoints.

Phishing-resistant methods such as authenticator apps, passkeys and biometric authentication are generally preferred. SMS and email codes are viewed as weaker options in higher-risk scenarios.

Endpoint protection is another core measure. Modern endpoint detection and response systems continuously monitor devices for suspicious activity and can isolate compromised machines.

Vulnerability management should include visibility across an organisation’s IT assets and regular scanning for weaknesses. ABI also points to risk prioritisation and timely remediation, while Cyber Essentials requires critical vulnerabilities to be patched within 14 days.

Employee training is listed among the additional measures organisations should consider. Business email compromise, phishing and social engineering remain major sources of financial loss, while AI is making fraudulent messages more convincing and easier to produce at scale.

ABI recommends recurring training rather than relying on one-off onboarding sessions. Useful measures include completion rates, phishing simulation results and how quickly staff report suspicious messages.

Backups are another priority, particularly because of ransomware. They should be regularly tested and protected from credential compromise, with immutable or offline copies offering stronger protection against attackers attempting to destroy recovery data.

Cloud synchronisation alone doesn’t provide the same protection. Deleted or encrypted files can be replicated across connected systems unless backup copies are isolated and protected against modification.

Incident response and business continuity planning are also central to the guidance. Effective preparation can reduce disruption and recovery costs after an attack.

Organisations should maintain current response plans defining responsibilities and escalation procedures. Those plans should also be tested through realistic tabletop exercises and linked with wider continuity arrangements.

Logging and monitoring provide the information needed to identify attacks and investigate incidents afterward. The NCSC recommends retaining important logs for at least six months because some breaches aren’t detected immediately.

Encryption is another measure highlighted by ABI. Protecting information both at rest and in transit can reduce the usefulness of data stolen during breaches or double-extortion ransomware attacks.

Supply chain exposure has also become more important. Organisations increasingly depend on third-party technology providers and other vendors whose security failures can affect customers even when internal systems haven’t been directly compromised.

ABI recommends vendor risk assessments and tighter controls around third-party access. Businesses should also identify critical suppliers and understand how operations or data would be recovered if one of those providers suffered an attack.

The guidance is intended to help organisations assess their cyber posture and discuss appropriate controls with brokers and insurers. It also provides a reference point for understanding which security services may be available alongside cyber cover.