Close Menu
small business insured
  • Insurance Guides
  • Coverage
  • Compliance & Security
  • Costs & Tools
  • About
What's Hot

Cyber Insurance for Accountants: 2026 Cost, Coverage & WISP Checklist

October 8, 2026

Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool

October 6, 2026

Tax Preparer Data Breach Response Plan: 2026 Checklist

October 5, 2026
Facebook X (Twitter) Instagram
small business insured
Subscribe
  • Insurance Guides
  • Coverage
  • Compliance & Security
  • Costs & Tools
  • About
small business insured
Home»Tax & Accounting Professionals»Cyber Insurance for Accountants: 2026 Cost, Coverage & WISP Checklist
Tax & Accounting Professionals

Cyber Insurance for Accountants: 2026 Cost, Coverage & WISP Checklist

Small Business Insured Editorial TeamBy Small Business Insured Editorial TeamOctober 8, 2026Updated:October 8, 2026No Comments10 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Accountant reviewing cybersecurity and insurance readiness at a laptop
Share
Facebook Twitter LinkedIn Pinterest Email

Accountants hold exactly the information criminals want: Social Security numbers, tax records, payroll files, bank details and login credentials. Cyber insurance for accountants can help a firm pay for forensic investigation, client notification, legal guidance, data restoration, business interruption and certain claims after a covered cyber incident.

It does not replace strong security, a written information security plan or professional liability coverage. The practical goal is to make the controls and the policy work together before an incident occurs.

Quick answer: U.S. accountants, CPAs, bookkeepers and tax practices should compare standalone cyber policies whenever they store or transmit sensitive client information. A current Insureon benchmark says accountants, CPAs and auditors pay an average of about $80 per month, or $964 per year, but an individual quote can differ materially. Revenue, record count, policy limits, prior incidents and security controls all affect price. Verify every limit, deductible, sublimit and exclusion with a licensed insurance professional.

Use this guide to:

  • decide whether a standalone cyber policy is appropriate;
  • identify the coverage sections that matter to an accounting practice;
  • compare a quote against your WISP and incident-response plan; and
  • avoid assuming that E&O or a business owner’s policy covers every cyber loss.

Table of Contents

Toggle
  • Why accounting firms face a concentrated cyber risk
  • What cyber insurance for an accounting firm can cover
  • Cyber insurance versus accountants’ professional liability
  • How much does cyber insurance cost for accountants in 2026?
  • The WISP-to-policy crosswalk
  • Seven restrictions to inspect before buying
  • A 12-question quote checklist
  • A practical buying sequence
  • Frequently asked questions
  • Bottom line
  • Sources and methodology

Why accounting firms face a concentrated cyber risk

An accounting firm may have fewer employees than a retailer or manufacturer, yet hold a much more valuable concentration of nonpublic personal information. Exposure can come from phishing and business-email-compromise attacks; stolen tax-software, email or cloud-storage credentials; ransomware; lost devices; compromised payroll or file-sharing providers; misdirected records; and fraudulent payment instructions sent from a hijacked mailbox.

Tax preparation firms are specifically included among the financial institutions covered by the Federal Trade Commission’s Safeguards Rule. The FTC says a covered firm’s information-security program must be written and appropriate to the firm’s size, complexity, activities and data sensitivity. The IRS also reminds tax and accounting professionals to create and maintain a Written Information Security Plan (WISP).

Insurance can finance parts of the response. It does not make a firm compliant, correct weak controls or guarantee that every event is covered.

What cyber insurance for an accounting firm can cover

Cyber policies usually combine first-party coverage, for costs your firm incurs directly, and third-party coverage, for claims or regulatory proceedings involving other people. Wording varies by carrier.

Coverage areaWhat it may pay forAccounting-firm example
Breach responseForensics, privacy counsel, notification, call-center and credit-monitoring costsA stolen laptop exposes unencrypted client tax files
Data restorationRecovering or recreating data and software after a covered eventRansomware corrupts local files and backups
Business interruptionLost income and extra expense during a covered outageThe firm cannot access tax software during filing season
Cyber extortionSpecialist response and, when lawful and covered, extortion-related costsAn attacker encrypts client records
Network-security liabilityDefense and covered damages arising from a security failureA client alleges a compromised portal exposed personal data
Privacy liabilityDefense and covered damages involving mishandled private informationRecords are sent to the wrong client and a claim follows
Regulatory defenseCounsel and certain covered investigation or penalty costs where insurableA regulator investigates the firm’s breach response
Social engineeringCertain direct financial loss, often under an endorsement and sublimitA hijacked vendor email redirects a payment

The National Association of Insurance Commissioners notes that first-party cyber coverage can include forensic services, notification expenses, credit monitoring, public relations, business interruption and data restoration. Treat any summary as a starting point; the policy contract controls.

Cyber insurance versus accountants’ professional liability

Professional liability insurance for accountants—often called errors and omissions or E&O insurance—generally addresses claims that professional services, advice or mistakes caused a client financial harm. Cyber insurance generally addresses privacy, security, data-restoration and incident-response losses.

The two can overlap. A client may allege that both negligent professional services and inadequate security contributed to a loss. Ask how the policies coordinate and whether either contains a cyber exclusion.

Loss scenarioPolicy to examine firstImportant question
Incorrect tax advice causes a client penaltyAccountants E&OAre the service and claimant covered?
Ransomware locks the firm’s systemsCyberIs restoration and business interruption covered?
Stolen credentials expose client recordsCyberDoes the policy cover privacy response and liability?
Fraudulent email changes payment instructionsCyber/crime endorsementIs social engineering covered, and at what sublimit?
A security failure allegedly causes a professional errorBothHow do the policies allocate the claim?

How much does cyber insurance cost for accountants in 2026?

Insureon reports that accountants, CPAs and auditors pay an average of approximately $80 per month or $964 per year for cyber insurance. This is a benchmark, not a quote. A firm’s actual premium may be lower or substantially higher.

Factors that can change the price

  • annual revenue and number of employees;
  • number and type of client records retained;
  • tax, payroll, audit and bookkeeping services performed;
  • coverage limits, retention or deductible, and sublimits;
  • prior incidents, claims or known vulnerabilities;
  • multifactor authentication on email, remote access and privileged accounts;
  • encryption, endpoint protection, patching and access controls;
  • frequency and testing of isolated backups;
  • employee training and phishing controls;
  • vendor-management practices; and
  • quality of the WISP and incident-response plan.

Ask each broker or carrier to quote the same limits and options. Otherwise, a lower price may simply reflect a larger retention, narrower trigger or smaller sublimit.

The WISP-to-policy crosswalk

A WISP describes how a firm protects information. A cyber policy describes when an insurer may fund a covered response. They should be checked against each other.

WISP or security controlWhat to confirm in the applicationWhy it matters
Named Qualified IndividualThe person responsible for cybersecurity is accurately identifiedApplication answers must match real responsibilities
Data and system inventoryRecord counts, storage locations and critical systems are accurateUnderwriters price the exposure described
Multifactor authenticationMFA use is stated precisely for email, remote access and administratorsAn inaccurate answer can create disputes
EncryptionEncryption at rest and in transit is described accuratelyPolicies may condition or price coverage around controls
BackupsFrequency, isolation and restoration testing are correctRestoration works best when clean backups exist
Vendor oversightCloud, payroll, tax-software and managed-service providers are listed where requestedVendor incidents may have distinct triggers or limits
Incident-response planInsurer contact and consent requirements are incorporatedUnapproved vendors or costs may not be reimbursed

Start with our tax and accounting practice WISP template and data-breach response checklist, then adapt them to the firm’s real systems and responsibilities.

Seven restrictions to inspect before buying

1. Prior knowledge and known incidents

A policy may exclude an incident, circumstance or vulnerability known before the policy began. Report known issues accurately and ask how the application treats them.

2. Security-control representations

Applications often ask about MFA, backups, encryption and employee training. Answer using verified facts, not intentions. Ask what happens if a stated control fails temporarily or is not deployed everywhere.

3. Social-engineering sublimits

Funds-transfer and invoice fraud may be excluded, endorsed separately or capped far below the main limit. Confirm whether verification procedures affect coverage.

4. Contingent business interruption

If a cloud provider or tax-software platform fails, the firm’s own network may be intact while revenue stops. Ask whether dependent business interruption applies and which providers qualify.

5. Waiting periods and loss calculation

Business-interruption coverage may begin only after a waiting period. Review how lost net income, continuing expenses and extra expenses are calculated—especially during filing season.

6. Ransomware, extortion and sanctions

Confirm extortion sublimits, consent requirements and approved response specialists. Payment may be unlawful or unavailable in some circumstances, and no firm should assume a ransom will be paid.

7. Devices, contracts and professional services

Look for restrictions involving portable devices, contractual promises, payment-card obligations and professional services. Coordinate cyber with E&O, crime and business-owner coverage.

A 12-question quote checklist

  1. Is the policy standalone cyber coverage or an endorsement?
  2. What are the first-party and third-party limits?
  3. Which coverages have lower sublimits?
  4. What retention or deductible applies to each section?
  5. Are forensics, privacy counsel, notification and credit monitoring covered?
  6. How are ransomware, cyber extortion and data restoration treated?
  7. Does social-engineering or funds-transfer fraud need a separate endorsement?
  8. Is business interruption covered, and what waiting period applies?
  9. Does contingent interruption cover key cloud and software providers?
  10. Is there a panel of required breach counsel, forensic firms or vendors?
  11. How does the policy coordinate with accountants E&O, crime and general liability?
  12. What controls must the firm maintain for the application to remain accurate?

For a side-by-side review, download the tax and accounting insurance quote worksheet.

A practical buying sequence

  1. Inventory the exposure. Count sensitive records, list systems and vendors, and map how client data enters, moves through and leaves the firm.
  2. Verify security controls. Confirm MFA, encryption, endpoint protection, backups, access reviews and training.
  3. Update the WISP and response plan. Assign responsibilities and record real procedures.
  4. Choose a limit deliberately. Consider likely response costs, downtime, contractual requirements and risk tolerance.
  5. Request comparable quotes. Give each broker the same facts, limits and endorsements.
  6. Read the forms. Compare definitions, exclusions, waiting periods and sublimits.
  7. Connect the policy to the response plan. Add carrier hotlines, deadlines and approved-vendor rules.
  8. Review annually and after major changes. Revisit coverage when services, revenue, staff, software or vendors change.

Frequently asked questions

Do accountants need cyber insurance?

No single answer fits every firm. An accounting firm that holds sensitive client data should at least evaluate standalone cyber coverage, considering its data, services, contracts, financial capacity and existing exclusions.

Is cyber insurance required by the IRS or FTC?

The FTC Safeguards Rule and IRS guidance require covered tax and accounting professionals to maintain appropriate safeguards and a written plan. Those requirements are not the same as a universal federal mandate to buy cyber insurance. A client contract, lender, state rule or other obligation may still require coverage.

Does a business owner’s policy cover a data breach?

Some packages include limited cyber endorsements, but limits and covered events may be narrow. Compare the endorsement with a standalone policy rather than assuming the package is sufficient.

Does accountants E&O cover ransomware or stolen client data?

E&O and cyber policies serve different primary purposes. An E&O form may restrict cyber events, while a cyber form may exclude professional-service claims. Review both and ask how overlapping claims are handled.

What cyber insurance limit should an accounting firm buy?

There is no universal limit. Consider record count and sensitivity, response expenses, possible filing-season downtime, contractual limits, defense costs, sublimits and the firm’s ability to retain loss.

Can a weak WISP invalidate cyber coverage?

Coverage depends on the policy and facts. Inaccurate application statements, known incidents or failure to satisfy a condition may create disputes. Keep the WISP accurate, implement its controls and report material changes.

Bottom line

For an accounting practice, the best cyber policy is not simply the cheapest proposal or the largest headline limit. It is the option whose definitions, sublimits, response services and exclusions fit the firm’s real data and operating risks.

Next step: Use the free insurance quote worksheet to compare cyber and E&O proposals side by side.


Sources and methodology

  • Federal Trade Commission: Safeguards Rule guide
  • Internal Revenue Service: WISP reminder for tax professionals
  • IRS Publication 5708
  • NAIC cyber insurance guidance
  • Insureon accountant and CPA insurance cost data

Cost figures are publisher-reported benchmarks, not quotes or guarantees. Small Business Insured does not sell insurance and does not receive compensation for including these sources.

This article provides general educational information, not legal, tax, cybersecurity or insurance advice. Policy wording, underwriting, availability and legal requirements vary by insurer, state and firm. Consult qualified professionals about your circumstances.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleTax Preparer WISP Readiness Scorecard: Free 20-Point Tool
Avatar photo
Small Business Insured Editorial Team
  • Website

The Small Business Insured Editorial Team publishes independent, source-led guidance for U.S. tax preparers, bookkeepers, accountants, and other small-business professionals. Our work follows a documented editorial and corrections process and is reviewed against primary government and industry sources.

Related Posts

Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool

October 6, 2026

Tax Preparer Data Breach Response Plan: 2026 Checklist

October 5, 2026

Tax Preparer WISP Requirements: 2026 Checklist

October 4, 2026
Add A Comment

Comments are closed.

Recent Posts
  • Cyber Insurance for Accountants: 2026 Cost, Coverage & WISP Checklist
  • Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool
  • Tax Preparer Data Breach Response Plan: 2026 Checklist
  • Tax Preparer WISP Requirements: 2026 Checklist
  • Bookkeeper Insurance: Coverage, Requirements & Risk Checklist

Independent, source-led business insurance and cyber-risk guidance for U.S. small businesses, with a focus on tax preparers, bookkeepers, accountants, and other professionals who protect sensitive client information.

Stay Informed

Practical Guidance for Your Practice

Get practical U.S. insurance and cyber-risk guidance for tax, bookkeeping, and accounting professionals.

© 2026 Small Business Insured.
  • Home
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Get In Touch
  • Advertising Disclosure
  • Corrections Policy
  • Editorial Policy
  • About
  • Your Privacy Choices

Type above and press Enter to search. Press Esc to cancel.