Most CPA Firms Need at Least 10 Cybersecurity Controls to Qualify for Strong Cyber Insurance Coverage
A CPA firm applying for cyber insurance should be prepared to document at least 10 core controls: multi-factor authentication, endpoint detection and response, secure backups, email protection, employee training, patch management, access controls, incident-response planning, vendor oversight, and continuous monitoring.
Insurer requirements vary by carrier, policy, firm size, revenue, data volume, claim history, and coverage limit. However, a 25–50 employee CPA firm should expect detailed questions about how it protects taxpayer information, Microsoft 365 accounts, remote access, administrative credentials, backups, and financial transactions.
The application should be treated as a security assessment rather than a paperwork exercise. Inaccurate, incomplete, or overly broad answers can create problems during underwriting and may complicate a future claim. Every response should reflect controls that are actually implemented, monitored, and documented.
Why CPA Firms Receive Detailed Cyber Insurance Questions
CPA firms store information that is attractive to cybercriminals, including tax returns, Social Security numbers, payroll data, bank details, financial statements, and business ownership records.
They also depend on systems and workflows that attackers frequently target:
- Microsoft 365 email accounts
- Tax preparation applications
- Document-management systems
- Client portals
- Remote-access platforms
- Payroll and payment processes
- Cloud file-sharing services
- Third-party application integrations
A successful attack may create costs involving forensic investigation, legal advice, client notification, business interruption, data recovery, fraud, regulatory response, and public relations.
Insurance underwriters use security questions to estimate how likely an incident is to occur and how severe the resulting loss could be. Stronger controls may improve insurability, reduce exclusions, support higher limits, or produce more favorable pricing.
The 911 IT 10-Control CPA Cyber Insurance Readiness Framework
Use this framework to prepare for an application, renewal, insurer questionnaire, or security-control review.
1. Multi-Factor Authentication
Multi-factor authentication, or MFA, requires users to provide more than a password before receiving access. It is one of the most frequently reviewed controls because stolen passwords are commonly used to compromise email, cloud services, remote access, and financial systems.
MFA should be evaluated for:
- Microsoft 365
- Remote access
- Virtual private networks
- Tax applications
- Client portals
- Cloud storage
- Payroll systems
- Administrator accounts
- Backup platforms
- Remote monitoring tools
The firm should not answer “yes” to a broad MFA question when only some employees or systems are protected. Document which platforms require MFA, which users are covered, and whether exceptions remain.
Administrator and remote-access accounts should receive particular attention because compromise of a privileged account may allow an attacker to reach multiple systems.
2. Managed Endpoint Detection and Response
Endpoint detection and response, commonly called EDR, monitors workstations, laptops, and servers for suspicious activity. It is more capable than traditional antivirus because it can identify behavior associated with ransomware, credential theft, malicious scripts, and attacker movement.
A managed EDR program should include:
- Protection on every approved workstation and server
- Continuous monitoring
- Centralized alerting
- Investigation by qualified personnel
- Isolation of affected devices
- Documented escalation procedures
- After-hours response for serious alerts
- Regular confirmation that agents remain active
The application may ask whether monitoring occurs 24/7, whether alerts are reviewed by the firm or a third party, and how quickly critical activity is investigated.
3. Protected and Tested Backups
Backups can reduce business interruption and recovery costs, but only when they are protected from the same attack that damages production systems.
A cyber insurance application may ask:
- Which systems are backed up?
- How frequently do backup jobs run?
- Are backup copies encrypted?
- Are backups stored separately from production?
- Are immutable or offline copies maintained?
- Do backup administrators use MFA?
- How frequently is recovery tested?
- How long would critical systems take to restore?
Critical jobs should be reviewed every business day, representative file restorations should be tested monthly, and important servers or applications should be recovery-tested at least quarterly.
Explore business continuity services for backup monitoring, ransomware-resistant storage, recovery testing, and continuity planning.
4. Email Security and Phishing Protection
Email is a primary target for credential theft, fraudulent payment requests, malicious attachments, impersonation, and data theft.
A layered email-security program may include:
- Spam and malware filtering
- Link and attachment analysis
- Impersonation protection
- Domain-authentication controls
- External-message warnings
- Suspicious forwarding-rule monitoring
- Mailbox auditing
- Employee phishing-reporting tools
- Automated removal of malicious messages
The firm should also document procedures for verifying unusual requests involving payments, payroll, bank-account changes, tax documents, and client information.
Email security should work with MFA, employee training, identity monitoring, and incident response rather than operating as a standalone product.
5. Employee Security Awareness Training
Cyber insurance applications often ask whether employees receive recurring security awareness training and phishing simulations.
A practical program should cover:
- Phishing recognition
- Password and MFA protection
- Business email compromise
- Payment-change verification
- Secure document sharing
- Remote-work security
- Lost-device reporting
- Incident reporting
- Use of approved applications
- Handling taxpayer information
Training should occur during onboarding and continue throughout the year. The firm should maintain completion records and follow up with employees who repeatedly fail simulations or ignore required training.
Short monthly or quarterly lessons can be more effective than relying on one annual presentation.
6. Patch and Vulnerability Management
Unpatched systems can allow attackers to exploit known weaknesses. Insurers may ask how quickly critical security updates are installed and whether the firm scans for vulnerabilities.
The program should cover:
- Windows and other operating systems
- Web browsers
- Microsoft Office
- Tax and accounting applications
- PDF software
- Firewalls and network equipment
- Servers
- Remote-access tools
- Third-party applications
The firm should define patching timelines based on risk. Critical vulnerabilities may require accelerated action, while routine updates can follow a standard maintenance schedule.
Vulnerability reports should be reviewed, assigned, remediated, and retested. A list of findings without owners and completion dates does not demonstrate an active program.
7. Access Control and Privileged Account Management
Cyber insurance underwriters may ask how the firm limits access, manages administrators, and removes former employees.
Controls should include:
- Role-based access
- Documented onboarding
- Prompt offboarding
- Quarterly administrator reviews
- Separate administrative accounts
- Limited local administrator rights
- Unique user credentials
- Password-management procedures
- Seasonal account expiration dates
- Vendor access restrictions
Employees should receive only the access required for their responsibilities. Shared administrator accounts should be minimized because they reduce accountability and increase the impact of one compromised password.
The firm should retain appropriate ownership of its domain, Microsoft 365 tenant, cloud services, and other critical accounts even when those platforms are managed by an MSP.
8. Incident Response Planning
A written incident-response plan explains how the firm reports, contains, investigates, and recovers from a cybersecurity event.
The plan should identify:
- Firm leadership contacts
- IT and cybersecurity contacts
- Cyber insurance reporting contacts
- Legal counsel
- Forensic resources
- Communication responsibilities
- Evidence-preservation procedures
- Recovery priorities
- After-hours reporting methods
The firm should conduct a tabletop exercise at least annually. A realistic scenario may involve ransomware, a compromised partner email account, fraudulent payment instructions, or a tax application outage during filing season.
Testing confirms whether contact information, authority, insurance procedures, and communication plans are usable during an actual emergency.
9. Vendor and Technology Provider Oversight
CPA firms rely on tax applications, client portals, payroll platforms, Microsoft 365, cloud storage, managed IT providers, and other vendors that may store or access sensitive information.
Vendor oversight should document:
- Services provided
- Information accessed or stored
- Security responsibilities
- Incident-notification requirements
- Backup responsibilities
- Data-retention and deletion terms
- Primary security contacts
- Contract and renewal dates
- Available security reports or certifications
Higher-risk vendors should receive more detailed review. The firm should also understand which controls are managed by the vendor and which remain the firm’s responsibility.
SOC 2 reports and other security documentation can provide useful information, but they should be reviewed in context rather than treated as automatic proof that every risk has been addressed.
10. Continuous Monitoring and Security Documentation
Insurers may ask not only whether security products are installed but whether they are actively monitored.
Continuous monitoring may include:
- Endpoint security alerts
- Microsoft 365 sign-ins
- Administrator changes
- Email threats
- Backup failures
- Firewall events
- Vulnerability findings
- Device health
- Patch status
- Suspicious remote access
The firm should maintain evidence showing that alerts are reviewed, failures are corrected, and significant risks are reported to leadership.
Useful evidence may include:
- Security reports
- Training records
- Backup test results
- Access reviews
- Risk assessments
- Incident exercises
- Patch reports
- Vendor reviews
- Remediation tracking
What Questions Appear on Cyber Insurance Applications?
Questions vary by insurer, but CPA firms may be asked about the following areas:
| Application area | Typical information requested |
|---|---|
| Business profile | Revenue, employees, locations, services, records, and prior claims |
| Multi-factor authentication | Coverage for email, remote access, administrators, and cloud applications |
| Endpoint security | EDR deployment, monitoring, isolation, and after-hours response |
| Backups | Frequency, isolation, immutability, encryption, and testing |
| Email protection | Filtering, impersonation safeguards, and phishing reporting |
| Employee training | Frequency, simulations, documentation, and follow-up |
| Access management | Administrator controls, offboarding, password practices, and reviews |
| Incident response | Written plan, testing, legal contacts, insurance procedures, and recovery |
| Vulnerability management | Scanning, patch timelines, unsupported systems, and remediation |
| Financial controls | Verification procedures for payments and banking changes |
Some applications use yes-or-no questions that appear simple but contain several conditions. Read each question carefully and confirm the answer with the people who manage the relevant system.
Who Should Complete the Cyber Insurance Application?
The application should be completed collaboratively rather than assigned to one person without technical input.
Participants may include:
- Firm leadership
- The insurance broker
- The managed IT provider
- The cybersecurity provider
- The security or compliance coordinator
- Legal counsel when appropriate
- Finance or operations leadership
The firm should answer business, revenue, claim, and financial questions. The IT provider can help verify technical controls such as MFA, EDR, backups, patching, monitoring, and administrator access.
Before submission, the firm should retain a copy of:
- The completed application
- Supporting control evidence
- Clarifications provided to the broker or insurer
- The final policy
- Endorsements and exclusions
- Incident-reporting instructions
Why Accurate Answers Matter
Cyber insurance applications often form part of the underwriting record. The firm should avoid making assumptions or describing planned controls as though they are already active.
Commonly inaccurate answers include:
- Stating that MFA protects every user when exceptions remain
- Calling antivirus a managed EDR service
- Claiming backups are tested when only job notifications are reviewed
- Stating that employee training is annual when records are incomplete
- Confirming administrator reviews that have never been documented
- Claiming 24/7 monitoring when alerts wait until the next business day
- Describing all cloud data as backed up without verifying each platform
When a control is partially implemented, describe the actual scope and the remediation plan. Clear, accurate answers are better than broad statements that cannot be supported.
What Documents Should Be Prepared for Underwriting?
An insurer may request supporting information before issuing or renewing coverage.
Prepare current copies of:
- Written Information Security Plan
- Cybersecurity risk assessment
- Incident-response plan
- Business continuity and disaster-recovery plan
- Backup testing reports
- Employee training records
- Phishing simulation reports
- Device and software inventory
- MFA coverage report
- Endpoint security report
- Vulnerability or patch reports
- User and administrator access reviews
- Vendor inventory
- Prior incident documentation
Learn how to build and maintain a practical Written Information Security Plan that connects policies with actual controls.
What Cyber Insurance Coverage Should a CPA Firm Review?
Coverage varies significantly between policies. Firm leadership and a qualified insurance advisor should review how the policy addresses different loss categories.
Relevant coverage areas may include:
- Incident-response expenses
- Digital forensics
- Legal counsel
- Notification and communication
- Credit or identity-monitoring services
- Data restoration
- Business interruption
- Cyber extortion
- Social engineering fraud
- Funds-transfer fraud
- Privacy liability
- Regulatory defense
- Media liability
- Vendor-related incidents
The presence of a category does not mean every event is covered. Review limits, sublimits, waiting periods, deductibles, conditions, exclusions, and consent requirements.
How Much Cyber Insurance Does a CPA Firm Need?
There is no universal coverage amount for every CPA firm. Appropriate limits depend on the firm’s revenue, data volume, client contracts, technology dependence, financial activity, and potential business interruption.
Leadership should estimate potential costs involving:
- Forensic investigation
- Legal services
- Client notification
- Credit monitoring
- System restoration
- Lost revenue
- Employee downtime
- Fraudulent payments
- Public relations
- Third-party claims
For example, if 40 employees lose access to critical systems for three business days, the incident creates 960 employee-hours of disruption before considering recovery expenses, missed deadlines, or lost revenue.
Coverage limits should be reviewed with an experienced insurance professional using realistic business-impact scenarios.
What Is Social Engineering Coverage?
Social engineering coverage may address certain losses caused when an employee is deceived into sending money, changing banking information, or taking another financial action.
Examples may include:
- Fraudulent vendor bank changes
- Executive impersonation
- Fake client payment instructions
- Payroll diversion
- Fraudulent wire-transfer requests
This coverage may have a lower sublimit than the overall cyber policy and may require specific verification procedures.
The firm should document controls such as:
- Call-back verification using trusted telephone numbers
- Dual approval for large payments
- Separation of payment creation and approval
- Independent verification of banking changes
- Employee training
- Escalation for urgent or unusual requests
What Happens After a Cybersecurity Incident?
The firm should follow the policy’s reporting instructions promptly. Some policies require the insured to contact a designated hotline, breach counsel, or approved incident-response provider before incurring major expenses.
The response process may include:
- Report the incident internally.
- Contain affected accounts or systems.
- Preserve evidence.
- Contact the insurer or approved response hotline.
- Engage legal, forensic, and recovery resources.
- Determine the scope and business impact.
- Restore systems in a controlled order.
- Complete approved communications.
- Document expenses and decisions.
The firm should keep current insurance contacts somewhere accessible even when normal email or systems are unavailable.
Seven Cyber Insurance Readiness Mistakes
1. Waiting Until Renewal Week
Security improvements may require several weeks or months. Begin the readiness review 60–90 days before renewal.
2. Answering Without Technical Verification
Leadership may believe a control exists everywhere when it covers only some users or systems.
3. Treating Antivirus as EDR
Traditional antivirus may not provide the monitoring, investigation, isolation, and response capabilities requested by the insurer.
4. Claiming Backups Are Tested When They Are Only Monitored
A completed backup job does not prove that data and applications can be restored.
5. Ignoring Financial Verification Controls
Technology alone may not prevent social engineering. Payment and banking changes should require independent verification.
6. Failing to Review Policy Exclusions
A policy may exclude or limit losses involving unencrypted devices, prior incidents, certain vendors, social engineering, or failure to maintain stated controls.
7. Forgetting to Update the Insurer After Material Changes
Mergers, acquisitions, major revenue changes, new services, prior incidents, and significant technology changes may affect the policy or underwriting information.
A 60-Day CPA Cyber Insurance Readiness Timeline
| Time before renewal | Recommended activity |
|---|---|
| 60–45 days | Obtain the application, review prior answers, and identify control gaps |
| 44–30 days | Complete MFA, EDR, backup, access, and patch remediation |
| 29–21 days | Update the WISP, incident plan, vendor inventory, and recovery documentation |
| 20–14 days | Complete technical verification and gather supporting reports |
| 13–7 days | Review answers with leadership, IT, and the insurance broker |
| Final week | Submit accurate responses and review proposed limits, exclusions, and conditions |
The 911 IT CPA Cyber Insurance Readiness Checklist
Identity and Access
- MFA protects Microsoft 365.
- MFA protects remote access.
- MFA protects administrator accounts.
- Former employee access is removed promptly.
- Administrator privileges are reviewed quarterly.
- Seasonal accounts have expiration dates.
Endpoint and Network Security
- Every approved device has managed EDR.
- Critical alerts receive after-hours response.
- Operating systems and applications are patched.
- Vulnerability findings are tracked to completion.
- Portable devices use encryption.
- Firewalls and remote-access systems are maintained.
Email and Employee Protection
- Email filtering and impersonation controls are active.
- Employees complete recurring security training.
- Phishing simulations are documented.
- Employees know how to report suspicious activity.
- Payment and banking changes require verification.
Backup and Recovery
- Critical systems and cloud data are identified.
- Backup jobs are reviewed daily.
- At least one recovery copy is immutable or isolated.
- Backup administrator access uses MFA.
- File and system restorations are tested.
- Recovery objectives are documented.
Planning and Documentation
- The WISP is current.
- The risk assessment is current.
- The incident-response plan is documented.
- An annual tabletop exercise has been completed.
- High-risk vendors are inventoried and reviewed.
- Supporting security reports are available.
Insurance Review
- Technical answers have been verified.
- A copy of the application is retained.
- Coverage limits and sublimits are reviewed.
- Exclusions and conditions are understood.
- Incident-reporting contacts are documented.
- Renewal preparation begins at least 60 days in advance.
Real Client Scenario: Strong Documentation Makes Security Easier to Explain
A CPA firm preparing for cyber insurance renewal may know that its IT provider manages security, but leadership still needs clear evidence showing what is protected and how each control works.
A useful readiness package might include:
- A report showing MFA coverage for 38 employees
- Confirmation that EDR is active on 46 workstations and four servers
- A quarterly server-recovery test completed in 92 minutes
- Security training completion records for every employee
- A current administrator-access review
- An incident-response tabletop report
Instead of relying on general claims such as “we have strong security,” the firm can provide specific, verifiable answers.
“Their support is collaborative, and they actually solve the problem the first time.”
That same collaborative approach is important during insurance preparation. Firm leadership, the broker, and the IT provider should work from the same verified information rather than making separate assumptions.
How 911 IT Helps CPA Firms Prepare for Cyber Insurance
911 IT provides managed IT services and cybersecurity support for CPA and financial firms that need stronger controls, accurate technical documentation, and responsive incident support.
Cyber insurance readiness services may include:
- Security-control assessments
- MFA implementation and reporting
- Managed endpoint detection and response
- Microsoft 365 security monitoring
- Email and phishing protection
- Vulnerability and patch management
- Device encryption
- Backup security and recovery testing
- Employee awareness training
- Administrator-access reviews
- WISP and incident-response support
- Application questionnaire assistance
- 24/7 technical support
911 IT combines CPA-industry familiarity with cybersecurity-first technology management, local Salt Lake City IT support, strategic vCIO guidance, 24/7 access to live technicians, and a 100% satisfaction guarantee.
Explore cybersecurity services, learn more about IT support for CPA and financial firms, or read experiences from 911 IT clients.
Frequently Asked Questions
Does every CPA firm need cyber insurance?
The decision depends on the firm’s risks, contracts, financial resources, data, and existing coverage. Firm leadership should review the need with a qualified insurance professional.
Does cyber insurance replace cybersecurity?
No. Insurance may help finance certain covered losses, but it does not prevent account compromise, ransomware, data theft, fraud, or downtime.
Is multi-factor authentication required for cyber insurance?
Requirements vary, but MFA is commonly reviewed for email, remote access, cloud services, administrators, and other high-risk systems.
Is antivirus enough for cyber insurance?
Many applications ask for endpoint detection and response rather than basic antivirus. The firm should verify the product’s monitoring, detection, isolation, investigation, and response capabilities.
Do backups have to be immutable?
Requirements vary by insurer. Immutable or isolated recovery copies can reduce ransomware risk and are frequently viewed as a stronger control than backups that remain fully accessible from the production network.
How often should employees receive security training?
Employees should receive training during onboarding and recurring education throughout the year. Phishing simulations and targeted follow-up should also be documented.
Can the IT provider complete the entire application?
The provider can verify technical controls, but firm leadership should answer business, financial, operational, and prior-incident questions. The final application should be reviewed collaboratively.
What should the firm do when the application asks an unclear question?
Ask the broker or insurer for clarification and document the interpretation used. Do not guess or provide a broad “yes” when the control is only partially implemented.
How early should a CPA firm prepare for renewal?
Begin 60–90 days before the renewal date so there is enough time to verify controls, correct gaps, gather evidence, and compare policy terms.
What should the firm keep after submitting the application?
Retain the final application, supporting evidence, clarifications, policy, endorsements, exclusions, reporting procedures, and contact information.
Build the Controls Before Completing the Application
A strong cyber insurance application begins with implemented, monitored, and documented security controls. CPA firms should verify MFA, endpoint protection, backups, email security, training, patching, access management, incident response, vendor oversight, and monitoring before answering underwriting questions.
Specific evidence is more useful than general statements. Document the number of protected users and devices, the frequency of backup tests, the date of the most recent access review, and the results of the latest incident-response exercise.
Schedule a discovery call with 911 IT to review your CPA firm’s cyber insurance security controls, application readiness, recovery planning, and technical documentation.
