Most cyber insurance applications ask the same nine to twelve control questions, and the best policies cover breach response, ransomware, business interruption, liability, and notification costs. Underwriters increasingly require evidence — screenshots, policies, or attestation — not just yes/no answers.
In a hurry? Get your free Compliance Score, then come back to this guide.
Take the Free Quiz View Sample WISPCyber insurance applications have shifted from one-page checkboxes to multi-page security questionnaires with evidence requests. This checklist covers what carriers consistently ask — and how a small firm (tax preparer, CPA, EA, bookkeeper, insurance agency, or any small business) can answer with confidence and documentation.
For the deeper context on questionnaire format, see the cyber insurance questionnaire guide for tax preparers.
The twelve controls underwriters consistently ask about
- Multi-factor authentication on email, remote access, privileged accounts, and tax/financial software.
- Endpoint detection & response (EDR) on every workstation and laptop.
- Backups — 3-2-1 with at least one immutable/off-site copy and tested restores.
- Patching — operating systems, browsers, and tax suite kept current.
- Security awareness training at hire and annually with completion records.
- Data encryption at rest and in transit (TLS, full-disk).
- Written Information Security Plan — see the WISP pillar guide.
- Incident response plan — see the IRP template.
- Vendor controls — written diligence and contract clauses for any third party handling client data.
- Access reviews — periodic review of who has access to what.
- Email security — anti-phishing, DMARC/SPF/DKIM, banner warnings.
- Network segmentation — guest Wi-Fi separated from production.
Checklist: what to gather before you start the application
- Current WISP — see the WISP template guide.
- Most recent risk assessment.
- Incident response plan and breach playbook — pair with the breach response checklist.
- MFA enforcement screenshots or admin reports.
- EDR vendor name and console screenshot.
- Backup vendor, frequency, immutability, last successful restore test.
- Training platform and most recent completion report.
- Vendor list with SOC 2 or security attestation status.
- Encryption confirmation (BitLocker/FileVault status reports).
- Annual WISP review approval — see the annual review checklist.
Common questionnaire pitfalls
- Answering "yes" to MFA when it is only on email, not on remote access.
- Claiming "encrypted backups" without immutability — ransomware targets backups first.
- Listing a WISP that has not been reviewed in over a year.
- Missing a written incident response plan — increasingly a hard requirement, not optional.
- No documented vendor management — underwriters will ask for the list.
What coverage types should be on your checklist
A completed application is only half the task. When you compare quotes, make sure the policy form actually covers the losses a small tax or accounting firm is most likely to face. Here are the coverage types to verify before binding.
- First-party data breach response costs — forensics, legal guidance, call-center support, and credit monitoring for affected clients. Check whether these are subject to a separate sub-limit.
- Cyber extortion / ransomware coverage — ransom payments, negotiation services, and the IT labor required to recover systems. Some forms cap or exclude this, so confirm the limit and any coinsurance.
- Business interruption — lost revenue and extra expenses if systems or tax software are unavailable during peak season. Look for a short waiting period and a clear definition of covered interruption.
- Third-party liability — defense and settlement costs if a client or regulator sues after a breach. This is separate from first-party response coverage and often has its own limit.
- Regulatory fines and defense costs — coverage for FTC, state attorney general, or IRS-related defense costs where insurable. Many policies exclude punitive or statutory fines, so read the exclusions carefully.
- Client notification costs — postage, email, call centers, and identity-protection services. State breach-notification laws can make this expensive quickly; verify the per-notification cap.
This section describes common coverage types, not a recommendation to buy any specific policy. Compare forms with your broker.
How WISPWolf helps answer these questions
WISPWolf produces a living WISP, a current Compliance Score, and an evidence pack mapped to the standard cyber insurance questionnaire. The same evidence supports IRS Publication 5708, IRS Publication 4557, the GLBA Safeguards Rule, and the FTC Safeguards checklist. We do not promise premium reductions or coverage; we make it easier to defend the answers you submit.
Educational content, not legal or insurance advice. Coverage decisions are made by your broker and carrier.
Make your next renewal easier
Take the Free WISP Readiness Quiz to get a Compliance Score and an evidence checklist mapped to common cyber insurance questionnaires.
Sources & References
Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.
- IRS Publication 5708 — Creating a Written Information Security Plan
- IRS Publication 4557 — Safeguarding Taxpayer Data
- FTC Safeguards Rule (16 CFR Part 314)
- Gramm-Leach-Bliley Act (GLBA) Safeguards
- IRS Tax Security — Protect Your Clients, Protect Yourself
- NIST Cybersecurity Framework
- Microsoft Security Documentation
Get the free WISPWolf Compliance Starter Kit
Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.
Get Your Free WISP Compliance Score
See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.
IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required