Cyber Insurance: Requirements and How to Lower Premiums
Key Takeaways
- General liability, professional liability, and crime coverage all exclude the costs of a cyber incident, leaving a gap only a standalone cyber policy fills.
- Cyber insurance pays first-party costs like forensics and business interruption, plus third-party costs like client lawsuits and regulatory fines.
- Multifactor authentication, EDR, independent backups, and a documented incident response plan are now baseline requirements for coverage, not nice-to-haves.
- The FTC Safeguards Rule and IRS Security Six tie compliance directly to insurability, since insurers audit these same controls before paying a claim.
- Partnering with security experts, training staff regularly, and completing annual security assessments are the most effective ways to lower premiums.
It’s late. The office is quiet because you’re the last person in it now. As you’re working, the Outlook notification chimes, and you toggle over to see what one of your clients could possibly want this late. The email looks just like all the others in this already-too-long thread—same signature, same tone, and a link to a file your client is asking you to ‘take a quick look’ at. Sighing, you click to review it.
The tab opens, but…did it just hesitate? Did the whole screen flicker to something you don’t quite recognize, or are you just too tired? You feel a thud of adrenaline and the cold thought forms in your mind: “What the heck did I just do?”
Does this sound at all familiar? If so, you probably have a colleague, or know of a firm that’s experienced a compromise which had its origins in exactly this kind of scenario.
Cyber Criminals Want What You’ve Got
Cyber criminals target accounting firms every day because your firm has the two things bad actors want: data and money. IBM’s Cost of a Data Breach Report 2025 puts the average U.S. breach at $10.2 million—a new all-time high, with financial sector breaches running well above $5 million. Business email compromise alone drove $2.77 billion in reported U.S. losses in 2024, according to the FBI. And the trend line isn’t flattening out. Cyberattacks are up roughly 600% since 2020, and 60% of small businesses close within six months of one.
Plainly stated: yes, you need cyber insurance. Below, I’ll explain why (if you’re still not convinced), plus:
- What cyber insurance covers
- What it requires of you
- How to keep a cyber insurance premium low
Your Existing Policies Weren’t Built for Cyber Incidents
The reason so many firms feel protected is that your existing policy sounds like it should apply. The problem is that each one was written for a different kind of loss than the kind a cyber incident creates.
General Liability
General liability insurance typically covers bodily injury, property damage, and personal injury—the client who trips over an upturned corner of the rug in your office lobby, the vase you knock over with your bag at their office (it cost how much?).
Professional Liability
Professional liability (errors and omissions) covers claims arising from your professional work—a miscalculation, a missed filing deadline, or just incorrect advice.
Crime or Fidelity Coverage
Crime or fidelity coverage is where firms most often assume they’re protected against fraud, and it’s where the gap probably creates the most exposure for your business.
A typical crime policy will cover employee dishonesty and theft. But losses from social engineering—where that same employee was tricked into wiring money to a criminal rather than stealing it outright—are often excluded unless you’ve specifically endorsed the policy for it.
None of these policies were designed to protect you against the risk you’re most likely to actually face: an attacker you’ll never see in person, who wants the client data that’s the lynchpin of your business, and the money your firm touches on behalf of those clients.
Do You Need Cyber Insurance?
If you’re like most firms and small businesses, security already ranks high on your list of concerns. Cyber insurance should rank right alongside it. Cyberattacks can be devastating, and your organization may not have the funds to recover from one without help.
Think of cyber insurance (also called cyber liability insurance) as the other half of a two-part strategy: the right security controls help you avoid a breach in the first place, and the right cyber insurance policy helps you recover if the worst still happens. As AI reshapes the threat landscape on both sides—attackers and defenders alike—having both pieces in place matters more than ever.
What a Cyber Insurance Policy Actually Covers
A standalone cyber insurance policy is designed around the anatomy of a real incident and will typically respond on two fronts:
1. First-party coverage
First party coverage pays for the firm’s own costs:
- Forensic investigation to determine what happened
- Legal counsel
- Client notification and credit monitoring
- Data recovery and system restoration
- Ransomware and extortion negotiation
- Business interruption income loss while systems are down
- Crisis management and PR support to help rebuild trust after the incident
2. Third-party coverage
Third-party coverage kicks in when someone comes after the firm:
- Client lawsuits following a breach
- Regulatory investigations, fines, and penalties (where insurable by law)
- Privacy liability tied to regulations like GDPR and CCPA
- Multimedia liability for claims like defamation or copyright issues tied to online content
Because a firm’s breached data can be used to turn around and attack its clients, third-party exposure tends to run larger for accounting firms than for a lot of other small businesses.
What Cyber Insurance Won’t Cover
It’s just as important to know where the policy stops. Common exclusions—and what to pair them with—look something like this:
| Category | What’s excluded | Pair it with |
|---|---|---|
| Physical impact | Bodily injury, property damage, equipment failure | General liability or property insurance |
| Security compliance | Incidents caused by missed updates or unimplemented required controls | A documented WISP and regular compliance checks |
| External events | Acts of war, terrorism, infrastructure failure | Ask about “electronic terrorism” add-ons |
| Legal disputes | Patent/copyright claims, contract disputes, some regulatory fines | Specialized IP or legal liability coverage |
| Internal risks | Known prior issues, intentional employee acts, lost/stolen devices | Strong security policies and device management |
| Improvements | System upgrades, security enhancements, technology modernization | A separate IT improvement budget |
Review your exclusions annually, document your security measures so a claim doesn’t get denied on a technicality, and plug the gaps with the right complementary coverage.
Compliance: Cyber Insurance Is No Longer Optional
Compliance, insurability, and protection are all merging into the same set of requirements.
For accounting firms, cyber insurance isn’t purely a financial or reputational decision anymore—it’s part of the larger picture of federal compliance.
Under the Gramm-Leach-Bliley Act, the federal government classifies tax preparers and accountants as “financial institutions,” which puts you squarely subject to the FTC Safeguards rule. The rule requires a documented Written Information Security Plan (WISP).
Alongside it, IRS Publication 4557 also lays out the “Security Six” baseline controls: endpoint protection (EDR), a business-grade firewall, multifactor authentication (MFA), encrypted offsite backups, drive encryption, and a VPN.
The Connection to Your Insurance
Here’s the connection to your insurance: many carriers now use these same regulator-mandated controls as their baseline for coverage. Many won’t even quote you a cyber policy without a WISP and baseline controls like MFA and EDR in place. And remember—after an incident, your insurer will audit your security program before paying a claims. A firm that carries a policy but can’t demonstrate it’s meeting the controls it attested to can find its claim denied.
What Are the Minimum Requirements to Qualify for Coverage?
Insurers have tightened their underwriting standards as threats have evolved. Here’s what’s typically non-negotiable before you can get a quote at all:
- Multifactor authentication (MFA). No longer optional—it’s the standard, requiring more than a password to access your systems.
- Endpoint detection and response (EDR). Think of it as a digital security guard, constantly watching every device on your network for suspicious activity.
- Backups. Your critical data needs a secure, offline home. Regular backups stored separately from your main network are non-negotiable for most carriers—replication through your cloud provider is not the same thing as a full, independent backup.
- A documented incident response plan. This should spell out detection procedures, response protocols, recovery steps, and who on your team owns what.
- Network security controls. Advanced firewalls, intrusion detection, regular security audits, and continuous monitoring.
- Employee training. Ongoing, not one-and-done—human error remains the most common vulnerability in any firm’s defenses.
If you’re accessing your core applications through a secure cloud environment, you’ve already taken a meaningful first step: top-tier data centers and built-in MFA give you a head start on several of these requirements at once.
How to Lower Your Cyber Insurance Premiums
Premiums have climbed roughly 79% in recent years, so it’s worth being deliberate about how you position your firm for underwriting. A few levers worth pulling:
Partner with security experts.
If a breach happens, who do you call? If your firm isn’t already working with an outside partner on incident response, that’s a good place to start—and pairing it with ongoing, expert-led monitoring helps prevent incidents in the first place, without leaning entirely on your internal (and likely limited) IT resources.
Build a culture of security.
Verizon’s 2024 Data Breach Investigations Report found that 68% of breaches involved a non-malicious human element—someone falling for social engineering or simply making a mistake. Monthly training on emerging attack patterns measurably reduces that exposure.
Strengthen your data protection.
A separate, third-party backup service—one offering full, searchable, granular backups—is worth the investment. Replication from your cloud provider is a nice-to-have; it isn’t a substitute for independently maintained backups.
Test your security posture annually.
Regular assessments do double duty: they tighten your defenses and give you leverage with underwriters when it’s time to renew. Many security firms offer a free initial assessment if you haven’t had one done recently.
Next Steps for Your Firm
Your firm’s existing insurance program was likely built around two things: the risks of the physical world (general liability) and the risks of professional judgement (errors and omissions). Neither is designed to protect you against the risk you are most likely to face: an attacker you’ll never see, coming for your client data, and the money you handle on their behalf.
Cyber insurance isn’t some abstract, “nice to have” layer of coverage. It’s the policy written specifically for the scenario at the beginning of this article—the one where your existing general liability and E&O leave your business high and dry. And increasingly, that cyber insurance policy is inseparable from the compliance obligations your firm already carries under GLBA.
The question you should be asking yourself isn’t: “how do we afford yet another premium.” It’s “can we afford to find out where our gaps are in real time, the hard way?”
Next steps for your firm:
- Confirm you’re compliant. Do you have a current, documented WISP that covers the IRS Security Six?
- Ask your broker for a detailed breakdown of your current coverage. Where does each policy begin and end, and where could a cyberthreat fall through the cracks?
- Get a security assessment. See where you stand against the minimum requirements carriers are now underwriting to.
Need help building or updating your WISP, or want a second set of eyes on your current security posture before your next renewal? Reach out to our team—we’re happy to help.
FAQ
Cyber insurance covers two categories of loss: first-party costs, like forensic investigation, data recovery, ransomware negotiation, and business interruption, and third-party costs, like client lawsuits, regulatory fines, and privacy liability. Together, these address the financial fallout of a breach that general liability and professional liability policies don’t reach.
Yes. Professional liability covers claims tied to your professional work, such as a missed deadline or an error in judgment. It doesn’t cover breach response costs, ransomware payments, business interruption from a cyber event, or third-party claims arising from a data breach. Most firms need both policies, since each responds to a different kind of loss.
Most carriers require multifactor authentication, endpoint detection and response (EDR), independently maintained backups, a documented incident response plan, network security controls like firewalls and intrusion detection, and regular employee security training. Many insurers also expect a current Written Information Security Plan (WISP) before they’ll issue a quote.
Firms can lower premiums by partnering with outside security experts for incident response and monitoring, running ongoing security awareness training for staff, maintaining independent third-party backups rather than relying on cloud replication alone, and completing an annual security assessment to demonstrate a strong posture to underwriters.
Common exclusions include bodily injury and property damage, losses tied to unmet security requirements the firm already attested to, acts of war or terrorism, certain legal disputes like patent or copyright claims, and losses from known prior issues or intentional employee acts. Firms should pair cyber insurance with general liability, IP coverage, and strong internal security policies to close these gaps.

