What Do Cyber Insurers Require From Accounting Firms in 2026?

Layered security controls for insurance readiness cinematic visual | Verito
Summarize and analyze this article with:

Cyber insurers now ask accounting firms to prove MFA, endpoint detection and response (EDR), encrypted backups, a written incident response plan, documented employee security training, and a Written Information Security Plan (WISP) before binding a policy. Firms that can’t document these controls face higher premiums, coverage exclusions, or declined renewal.

Key takeaways

  • Insurers now require six specific controls, up from a one-page form in past renewal cycles.
  • MFA, EDR, encrypted backups, an incident response plan, security training, and a WISP top the list.
  • A WISP built for IRS Pub 4557 also covers what insurers and the FTC Safeguards Rule ask for.
  • Missing controls mean higher premiums, ransomware exclusions, or declined renewal.
  • VeritShield WISP delivers audit-ready documentation covering both standards in 5 business days.

Why Did Cyber Insurance Renewal Applications Get Longer?

Insurers tightened underwriting across the board because claims data showed most breached firms lacked the controls now being asked about upfront. Accounting firms hold Social Security numbers, bank details, and tax records for hundreds of clients, which puts them under extra scrutiny compared to other small professional services firms.

This isn’t arbitrary. It’s a direct response to what insurers are paying out on. Firms that get breached usually didn’t have MFA, EDR, or a documented WISP in place before the incident, so those are exactly the items now showing up on the application.

Firms with 6 to 50 preparers are fielding these longer questionnaires for the first time in 2026, often without a template for how to answer them.

What Security Controls Do Cyber Insurance Applications Ask About?

Most 2026 applications for professional services firms ask about six specific controls: MFA on email and remote access, EDR on every device, encrypted backups stored separately from production, a written incident response plan, documented annual security training, and a WISP under IRS Publication 4557.

The full list, in the order most applications ask for it:

  • Multi-factor authentication (MFA) on email, remote access, and any system touching client data
  • Endpoint detection and response (EDR), not just antivirus, on every device
  • Encrypted backups, stored separately from the production environment
  • A written incident response plan with named responsibilities
  • Employee security training, documented and repeated at least annually
  • A Written Information Security Plan (WISP), the same document the IRS requires under Publication 4557
Multi factor authentication for secure accounting access cinematic visual | Verito

That last item catches most firms off guard. The WISP a firm already needs for IRS compliance is also becoming table stakes for insurance underwriting. A firm with one is most of the way to a clean application. A firm without one is now failing two requirements with a single gap.

How Does the FTC Safeguards Rule Connect to a Cyber Insurance Application?

Firms with 6 to 20 preparers usually know the IRS requires a WISP. Fewer know the FTC Safeguards Rule applies to them too, and insurers are increasingly underwriting to that standard rather than the IRS minimum alone. A WISP built to FTC Safeguards standard covers both requirements at once.

The FTC rule is more specific about controls than IRS Pub 4557 alone: MFA, encryption, access controls, and a designated person responsible for the security program. An insurer reading your application is effectively checking whether you’ve met FTC Safeguards, whether or not the questionnaire names it directly.

The practical upshot: a WISP that only checks the IRS box may not satisfy what your insurer is actually looking for. A WISP built to the FTC Safeguards standard covers both from the start.

Protected information security plan for firm compliance cinematic visual | Verito

“The data security Verito provides is immense; it ensures my tax data is secure, eliminating worries about hackers, natural disasters, or computer crashes, offering immense peace of mind.”

Robin R., Owner, Robin M Rudisill CPA PC · G2, Oct 2025

What Happens If a Firm Can’t Answer the Cyber Insurance Questionnaire?

Firms that can’t document these controls typically see one of three outcomes: higher premiums because insurers price in the unknown, coverage exclusions where ransomware payouts are denied if MFA wasn’t active at the time of the incident, or declined renewal outright. None of this requires an enterprise security budget to fix.

The three most common outcomes, in order of severity:

OutcomeWhat triggers itHow common
Higher premiumsUndocumented controls, insurer prices in the unknownMost common outcome
Coverage exclusionsRansomware claim filed without MFA active at time of incidentIncreasingly written into new policies
Declined renewalNo documented WISP on fileIncreasingly common for smaller firms

Fixing this requires documentation and a handful of specific controls, most of which a hosting or IT partner should already be handling as part of the environment, not as a separate project.

Does Verito Include the Controls Cyber Insurers Ask About?

Yes. Firms hosted on VeritSpace or bundled under VeritComplete get MFA and endpoint protection built into the environment, not configured as an add-on. VeritShield WISP delivers audit-ready documentation in 5 business days, built to cover IRS Pub 4557 and FTC Safeguards together rather than the IRS minimum alone.

When an insurer’s IT auditor calls with a follow-up question, a firm isn’t stuck emailing a help desk and waiting. Every ticket reaches a real person in under 60 seconds, with no phone tree and no offshore handoff.

“I’ve called off season on the weekends. Someone proficient always answers the phone and resolves my issue.”

Irene W., Owner, Wachsler CPA LLC · G2, Jul 2025

How Do You Answer Each Question on the Cyber Insurance Application?

Take the six controls from the application and answer each with the component that provides it plus the document that proves it. VeritGuard supplies the device controls from $79 per device per month, VeritShield WISP handles the paperwork at $999 per year, and VeritComplete bundles both from $129 per user per month.

Insurers don’t score effort; they score what you can document. This mapping pairs each line item on a 2026 renewal application with the Verito component that provides the control and the paperwork the firm can attach or offer on request.

Questionnaire line itemWhat provides itWhat you hand the insurer
MFA on email, remote access, and client data systems2FA/MFA at sign-in on every VeritSpace and VeritComplete tier; VeritGuard Pro and Elite add identity management across devices and appsThe access-control section of your WISP, backed by Verito’s SOC 2 Type II certification
EDR on every deviceAntivirus plus EDR on every VeritGuard tier, from $79/device/moThe device inventory VeritGuard keeps for every covered endpoint
Encrypted backups stored separatelyHosted-server backups with 256-bit encryption and 60-day retention (90 on Elite); VeritGuard adds separate endpoint backup, 250 GB to 1 TB by tierThe data-protection section of your WISP, with retention stated
Written incident response planVeritShield WISP covers the FTC Safeguards Rule, which requires a written incident response plan, so the section ships inside the documentThe incident-response pages of your WISP, with your firm’s responsibilities assigned
Documented security trainingSecurity training for staff, included with VeritGuard Pro and EliteThe employee-training section of your WISP, naming the program
A WISP under IRS Pub 4557VeritShield WISP: custom-built, delivered in 5 business days, $999 per year with unlimited revisions; included with every VeritComplete tier and with VeritGuard Pro and EliteThe WISP itself, audit-ready and built for IRS Pub 4557 and the FTC Safeguards Rule

One bar keeps rising. Practitioners on r/taxpros report insurers now requiring MFA on every work device as a condition of quoting at all, not just on email and remote access (r/taxpros practitioner reports). That reaches past the hosted environment to every laptop in the office, which is the layer VeritGuard covers per device.

Two pieces of paper do extra work at renewal. VeritGuard Pro carries an annual FTC Safeguards audit, bi-annual on Elite, so when the insurer asks when the controls were last reviewed, the firm has a dated review on file. And VeritShield WISP runs as an annual subscription with unlimited revisions, so when next year’s application adds a control, the plan gets updated at no extra cost.

“I have been using VeritSpace hosting now for several years. I’ve just installed the VeritGuard service which provides monitoring and protection.”

Phil Hebner · Google, Dec 2025

How Can a Firm Get Renewal-Ready Before Its Cyber Insurance Application Is Due?

The fastest path is comparing the current setup against the six controls insurers actually ask about (MFA, EDR, encrypted backups, an incident response plan, documented training, and a WISP) before the renewal date, not after a declined application. A gap in any one of the six is worth closing before it shows up on paper.

Whether the application is due this month or the renewal is six months out, it’s worth knowing where the gaps are before the insurer finds them. See what your firm’s WISP is missing.

Sources

Want the next step based on this article?
Continue in your favorite AI assistant using this page as the source.
You May Also Like