Most cyber insurance applications ask the same nine to twelve control questions: MFA, endpoint protection, backups, patching, security awareness training, encryption, a Written Information Security Plan, incident response plan, and vendor controls. Underwriters increasingly require evidence — screenshots, policies, or attestation — not just yes/no answers.
In a hurry? Get your free Compliance Score, then come back to this guide.
Take the Free Quiz View Sample WISPCyber insurance applications have shifted from one-page checkboxes to multi-page security questionnaires with evidence requests. This checklist covers what carriers consistently ask — and how a small firm (tax preparer, CPA, EA, bookkeeper, insurance agency, or any small business) can answer with confidence and documentation.
For the deeper context on questionnaire format, see the cyber insurance questionnaire guide for tax preparers.
The twelve controls underwriters consistently ask about
- Multi-factor authentication on email, remote access, privileged accounts, and tax/financial software.
- Endpoint detection & response (EDR) on every workstation and laptop.
- Backups — 3-2-1 with at least one immutable/off-site copy and tested restores.
- Patching — operating systems, browsers, and tax suite kept current.
- Security awareness training at hire and annually with completion records.
- Data encryption at rest and in transit (TLS, full-disk).
- Written Information Security Plan — see the WISP pillar guide.
- Incident response plan — see the IRP template.
- Vendor controls — written diligence and contract clauses for any third party handling client data.
- Access reviews — periodic review of who has access to what.
- Email security — anti-phishing, DMARC/SPF/DKIM, banner warnings.
- Network segmentation — guest Wi-Fi separated from production.
Checklist: what to gather before you start the application
- Current WISP — see the WISP template guide.
- Most recent risk assessment.
- Incident response plan and breach playbook — pair with the breach response checklist.
- MFA enforcement screenshots or admin reports.
- EDR vendor name and console screenshot.
- Backup vendor, frequency, immutability, last successful restore test.
- Training platform and most recent completion report.
- Vendor list with SOC 2 or security attestation status.
- Encryption confirmation (BitLocker/FileVault status reports).
- Annual WISP review approval — see the annual review checklist.
Common questionnaire pitfalls
- Answering "yes" to MFA when it is only on email, not on remote access.
- Claiming "encrypted backups" without immutability — ransomware targets backups first.
- Listing a WISP that has not been reviewed in over a year.
- Missing a written incident response plan — increasingly a hard requirement, not optional.
- No documented vendor management — underwriters will ask for the list.
How WISPWolf helps answer these questions
WISPWolf produces a living WISP, a current Compliance Score, and an evidence pack mapped to the standard cyber insurance questionnaire. The same evidence supports IRS Publication 5708, IRS Publication 4557, the GLBA Safeguards Rule, and the FTC Safeguards checklist. We do not promise premium reductions or coverage; we make it easier to defend the answers you submit.
Educational content, not legal or insurance advice. Coverage decisions are made by your broker and carrier.
Make your next renewal easier
Take the Free WISP Readiness Quiz to get a Compliance Score and an evidence checklist mapped to common cyber insurance questionnaires.
Sources & References
Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.
- IRS Publication 5708 — Creating a Written Information Security Plan
- IRS Publication 4557 — Safeguarding Taxpayer Data
- FTC Safeguards Rule (16 CFR Part 314)
- Gramm-Leach-Bliley Act (GLBA) Safeguards
- IRS Tax Security — Protect Your Clients, Protect Yourself
- NIST Cybersecurity Framework
- Microsoft Security Documentation
Get the free WISPWolf Compliance Starter Kit
Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.
Get Your Free WISP Compliance Score
See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.
IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required