Renewing or applying for cyber insurance has become noticeably harder for small and mid‑sized AEC practices over the last couple of years. Insurers have tightened their questionnaires, and a "no" to the wrong question can mean a declined application, a large excess, or a much higher premium.

Why insurers are asking harder questions

Ransomware and business email compromise remain the two most common claims across professional services firms, including architecture and design practices. Insurers have responded by requiring evidence of specific controls before they'll offer cover at a reasonable price – not just a tick‑box declaration.

The controls insurers now expect as standard

Across most proposal forms we see for AEC clients, the same set of questions keeps coming up:

  • Multi‑factor authentication (MFA) enforced on email and remote access, without exception.
  • Regular, tested backups that are isolated from your main network (immutable or offline copies).
  • A documented patching process for servers, workstations and key software.
  • Endpoint detection and response (EDR), not just traditional antivirus.
  • Restrictions on local admin rights for everyday user accounts.
  • A written incident response plan, even a simple one.

The good news: for most practices already using Microsoft 365 properly, several of these are switches to turn on rather than new products to buy.

1. Get your Microsoft 365 security baseline right first

Before looking at additional tools, most practices have unused security capability already sitting inside their existing licences:

  • Conditional Access policies in Entra ID to enforce MFA consistently.
  • Mail flow rules in Exchange Online to catch spoofing and suspicious forwarding.
  • Intune compliance policies covering encryption, screen lock and update status.

2. Back up what actually matters

SharePoint and OneDrive retention isn't the same as a true backup. Insurers increasingly want to see a genuine backup strategy for project data, drawings and financial systems – with copies that a compromised account can't touch or delete.

3. Write down your incident response plan

It doesn't need to be a 40‑page document. A single page covering who to call, who has authority to make decisions, and how you'd keep projects moving during an outage is usually enough to satisfy an insurer – and genuinely useful if something does go wrong.

Where this fits into a wider IT review

We usually cover cyber insurance readiness as part of a broader free IT assessment, so you're not just satisfying a proposal form – you're closing gaps that reduce your actual risk of an incident in the first place.

Not sure if you'd pass a cyber insurance renewal?

Book a free IT assessment and we'll walk through what your practice already has in place, and what's worth prioritising before your next renewal.

Book your free assessment call