Skip to main content
All resources
Cyber Insurance

WISP and Cyber Insurance for Tax Preparers: What You Need to Know

Most cyber insurance carriers require a WISP. No WISP means no coverage — or denied claims after a breach. Here's how to use your WISP compliance to strengthen your cyber insurance application.

June 20266 min read
By the WISPWolf Compliance Team· June 2026Reviewed by WISPWolf Compliance TeamLast Updated: June 2026 · Verified July 27, 2026
Short answer

Cyber insurance carriers now treat a Written Information Security Plan as a core underwriting requirement. A current WISP that documents MFA, encryption, backups, training, vendor oversight, and incident response strengthens your application and reduces the risk of a denied claim after a breach.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

Cyber insurance and WISP compliance have become inseparable. Most carriers now require a written security plan as a condition of coverage for tax preparers and CPA firms. But the bigger risk isn't failing to get a policy — it's having a policy, experiencing a breach, and discovering that the insurer denies the claim because your WISP was outdated, incomplete, or not implemented. This guide explains exactly what insurers look for and how your compliance posture directly affects coverage and claims.

For tax preparers regulated under the FTC Safeguards Rule and IRS Publication 5708, the WISP is already a compliance requirement. For cyber insurance, it has become a prerequisite that can determine whether your application is approved, surcharged, or declined outright.

Why Insurers Ask About Your WISP

Tax firms handle SSNs, bank data, income information, and other financial records that make them prime targets for ransomware and wire fraud. Before a carrier prices that risk, it needs to understand whether your security program is real or aspirational. A WISP demonstrates that you have assessed your risks, assigned responsibility, and implemented controls. It turns a collection of security tools into a governed program.

Without a WISP, you look like an unquantified risk. The underwriter cannot verify that MFA, backups, encryption, and training are connected to a consistent program, so the carrier either declines to quote or prices in the uncertainty with higher premiums. In a market where carriers are tightening underwriting and reducing capacity, an undocumented firm is increasingly uninsurable at standard rates. The WISP is what makes your other controls believable and your premium predictable. For tax preparers, this is why cyber insurance applications now treat the WISP as a basic underwriting gate.

What Underwriters Actually Check

Cyber insurance applications for tax preparers and CPA firms ask a consistent set of questions derived from the FTC Safeguards Rule and industry loss data. The exact wording varies by carrier, but underwriters are looking for documented answers to questions like these:

  • Do you have a written information security program?
  • Has it been reviewed within the last 12 months?
  • Do you use multi-factor authentication on all systems holding client data?
  • Do you conduct annual security training for all employees?
  • Do you have a written incident response plan?
  • Do you maintain data encryption in transit and at rest?
  • Do you test backups and keep immutable or offline copies?
  • Do you have written security agreements with vendors that access client data?

Carriers verify these answers through the application, supplemental questionnaires, and, after a breach, through forensic audit. A "yes" on the form that you cannot back up with documentation is worse than a "no" — it can constitute misrepresentation, giving the carrier grounds to void the policy entirely. The WISP is the document that ties each "yes" to a control, an owner, and a review date. Firms that can answer from a single, current source reduce underwriting friction and avoid the follow-up requests that delay quoting.

Claim Denial Without a WISP

Claim denial is the most expensive way to learn your WISP was inadequate. Consider the typical sequence: a tax firm has cyber insurance, experiences a phishing breach or ransomware incident, and notifies the carrier. The insurer assigns an investigator, who asks for the current WISP, training records, MFA evidence, and backup logs. If the firm cannot produce current records, or if the WISP was last updated three years ago, the carrier may deny the claim on grounds of material misrepresentation or failure to maintain the required security program.

The costs then fall entirely on the firm: breach response, forensic investigation, client notification, credit monitoring, legal fees, regulatory response, and business interruption. Industry estimates place the average small-business breach response well into five figures, and tax firms often face additional IRS or state regulatory scrutiny. A WISP that exists only on paper, without implementation records, is not a defense — it is a liability.

How Compliance Score Helps Your Application

A WISPWolf compliance score of 85 or higher triggers the insurance readiness export — a structured PDF showing your documented controls, evidence, and review history. This is the document to give your insurance broker. It demonstrates that you are not just saying you are compliant; you can prove it.

The export includes your current WISP, signed annual review attestations, staff training logs, technical evidence for MFA and encryption, vendor security documentation, and your incident response plan. Carriers receive this as a single, organized package that maps directly to the questions on their application.

Some brokers use this export to reduce underwriting time, and some carriers accept it as supporting documentation in lieu of scattered screenshots and spreadsheets. In competitive markets, firms that can document their controls clearly often receive better quotes and smoother renewals than firms that answer from memory.

Frequently Asked Questions

Can I get cyber insurance without a WISP?

You may find a market that will quote you, but it is becoming difficult. Most carriers now require a written information security program as a condition of coverage, and those that do not require it often surcharge the premium or limit coverage. A missing WISP also increases the risk of claim denial after a breach.

How does my compliance score affect my premium?

A high compliance score does not guarantee a lower premium, but it can reduce underwriting time and open access to carriers that require documented controls. Firms with weak or missing documentation often renew at higher rates or are placed in non-standard markets. The score is most valuable when it is backed by evidence.

What's in the WISPWolf insurance readiness export?

The export includes your current WISP, signed annual review and staff acknowledgement records, training logs, technical evidence for MFA and encryption, vendor security documentation, and your incident response plan. It is organized as a single PDF package for brokers and underwriters.

My insurer says they don't require a WISP — should I still have one?

Yes. Even if your carrier does not ask for it directly, the IRS and FTC require tax preparers to maintain a WISP. More importantly, a WISP is the foundation of your evidence if you ever need to file a claim. A carrier that does not require it today may require it at renewal, or may use its absence to contest a claim.

Conclusion

Cyber insurance is not a substitute for security, and a WISP is not just a compliance document. For tax preparers, the two are connected: a current, evidence-backed WISP helps you qualify for coverage, speeds underwriting, and protects your firm from claim denial after a breach. Start by getting your compliance score and building the evidence package behind it.

Get Your Compliance Score →

Related Resources

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. IRS Publication 5708 — Creating a Written Information Security Plan
  2. IRS Publication 4557 — Safeguarding Taxpayer Data
  3. FTC Safeguards Rule (16 CFR Part 314)
  4. Industry Cyber Insurance Application Benchmarks for Tax & Accounting Firms
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required