Accountants hold exactly the information criminals want: Social Security numbers, tax records, payroll files, bank details and login credentials. Cyber insurance for accountants can help a firm pay for forensic investigation, client notification, legal guidance, data restoration, business interruption and certain claims after a covered cyber incident.

It does not replace strong security, a written information security plan or professional liability coverage. The practical goal is to make the controls and the policy work together before an incident occurs.

Quick answer: U.S. accountants, CPAs, bookkeepers and tax practices should compare standalone cyber policies whenever they store or transmit sensitive client information. A current Insureon benchmark says accountants, CPAs and auditors pay an average of about $80 per month, or $964 per year, but an individual quote can differ materially. Revenue, record count, policy limits, prior incidents and security controls all affect price. Verify every limit, deductible, sublimit and exclusion with a licensed insurance professional.

Use this guide to:

  • decide whether a standalone cyber policy is appropriate;
  • identify the coverage sections that matter to an accounting practice;
  • compare a quote against your WISP and incident-response plan; and
  • avoid assuming that E&O or a business owner’s policy covers every cyber loss.

Why accounting firms face a concentrated cyber risk

An accounting firm may have fewer employees than a retailer or manufacturer, yet hold a much more valuable concentration of nonpublic personal information. Exposure can come from phishing and business-email-compromise attacks; stolen tax-software, email or cloud-storage credentials; ransomware; lost devices; compromised payroll or file-sharing providers; misdirected records; and fraudulent payment instructions sent from a hijacked mailbox.

Tax preparation firms are specifically included among the financial institutions covered by the Federal Trade Commission’s Safeguards Rule. The FTC says a covered firm’s information-security program must be written and appropriate to the firm’s size, complexity, activities and data sensitivity. The IRS also reminds tax and accounting professionals to create and maintain a Written Information Security Plan (WISP).

Insurance can finance parts of the response. It does not make a firm compliant, correct weak controls or guarantee that every event is covered.

What cyber insurance for an accounting firm can cover

Cyber policies usually combine first-party coverage, for costs your firm incurs directly, and third-party coverage, for claims or regulatory proceedings involving other people. Wording varies by carrier.

Coverage area What it may pay for Accounting-firm example
Breach response Forensics, privacy counsel, notification, call-center and credit-monitoring costs A stolen laptop exposes unencrypted client tax files
Data restoration Recovering or recreating data and software after a covered event Ransomware corrupts local files and backups
Business interruption Lost income and extra expense during a covered outage The firm cannot access tax software during filing season
Cyber extortion Specialist response and, when lawful and covered, extortion-related costs An attacker encrypts client records
Network-security liability Defense and covered damages arising from a security failure A client alleges a compromised portal exposed personal data
Privacy liability Defense and covered damages involving mishandled private information Records are sent to the wrong client and a claim follows
Regulatory defense Counsel and certain covered investigation or penalty costs where insurable A regulator investigates the firm’s breach response
Social engineering Certain direct financial loss, often under an endorsement and sublimit A hijacked vendor email redirects a payment

The National Association of Insurance Commissioners notes that first-party cyber coverage can include forensic services, notification expenses, credit monitoring, public relations, business interruption and data restoration. Treat any summary as a starting point; the policy contract controls.

Cyber insurance versus accountants’ professional liability

Professional liability insurance for accountants—often called errors and omissions or E&O insurance—generally addresses claims that professional services, advice or mistakes caused a client financial harm. Cyber insurance generally addresses privacy, security, data-restoration and incident-response losses.

The two can overlap. A client may allege that both negligent professional services and inadequate security contributed to a loss. Ask how the policies coordinate and whether either contains a cyber exclusion.

Loss scenario Policy to examine first Important question
Incorrect tax advice causes a client penalty Accountants E&O Are the service and claimant covered?
Ransomware locks the firm’s systems Cyber Is restoration and business interruption covered?
Stolen credentials expose client records Cyber Does the policy cover privacy response and liability?
Fraudulent email changes payment instructions Cyber/crime endorsement Is social engineering covered, and at what sublimit?
A security failure allegedly causes a professional error Both How do the policies allocate the claim?

How much does cyber insurance cost for accountants in 2026?

Insureon reports that accountants, CPAs and auditors pay an average of approximately $80 per month or $964 per year for cyber insurance. This is a benchmark, not a quote. A firm’s actual premium may be lower or substantially higher.

Factors that can change the price

  • annual revenue and number of employees;
  • number and type of client records retained;
  • tax, payroll, audit and bookkeeping services performed;
  • coverage limits, retention or deductible, and sublimits;
  • prior incidents, claims or known vulnerabilities;
  • multifactor authentication on email, remote access and privileged accounts;
  • encryption, endpoint protection, patching and access controls;
  • frequency and testing of isolated backups;
  • employee training and phishing controls;
  • vendor-management practices; and
  • quality of the WISP and incident-response plan.

Ask each broker or carrier to quote the same limits and options. Otherwise, a lower price may simply reflect a larger retention, narrower trigger or smaller sublimit.

The WISP-to-policy crosswalk

A WISP describes how a firm protects information. A cyber policy describes when an insurer may fund a covered response. They should be checked against each other.

WISP or security control What to confirm in the application Why it matters
Named Qualified Individual The person responsible for cybersecurity is accurately identified Application answers must match real responsibilities
Data and system inventory Record counts, storage locations and critical systems are accurate Underwriters price the exposure described
Multifactor authentication MFA use is stated precisely for email, remote access and administrators An inaccurate answer can create disputes
Encryption Encryption at rest and in transit is described accurately Policies may condition or price coverage around controls
Backups Frequency, isolation and restoration testing are correct Restoration works best when clean backups exist
Vendor oversight Cloud, payroll, tax-software and managed-service providers are listed where requested Vendor incidents may have distinct triggers or limits
Incident-response plan Insurer contact and consent requirements are incorporated Unapproved vendors or costs may not be reimbursed

Start with our tax and accounting practice WISP template and data-breach response checklist, then adapt them to the firm’s real systems and responsibilities.

Seven restrictions to inspect before buying

1. Prior knowledge and known incidents

A policy may exclude an incident, circumstance or vulnerability known before the policy began. Report known issues accurately and ask how the application treats them.

2. Security-control representations

Applications often ask about MFA, backups, encryption and employee training. Answer using verified facts, not intentions. Ask what happens if a stated control fails temporarily or is not deployed everywhere.

3. Social-engineering sublimits

Funds-transfer and invoice fraud may be excluded, endorsed separately or capped far below the main limit. Confirm whether verification procedures affect coverage.

4. Contingent business interruption

If a cloud provider or tax-software platform fails, the firm’s own network may be intact while revenue stops. Ask whether dependent business interruption applies and which providers qualify.

5. Waiting periods and loss calculation

Business-interruption coverage may begin only after a waiting period. Review how lost net income, continuing expenses and extra expenses are calculated—especially during filing season.

6. Ransomware, extortion and sanctions

Confirm extortion sublimits, consent requirements and approved response specialists. Payment may be unlawful or unavailable in some circumstances, and no firm should assume a ransom will be paid.

7. Devices, contracts and professional services

Look for restrictions involving portable devices, contractual promises, payment-card obligations and professional services. Coordinate cyber with E&O, crime and business-owner coverage.

A 12-question quote checklist

  1. Is the policy standalone cyber coverage or an endorsement?
  2. What are the first-party and third-party limits?
  3. Which coverages have lower sublimits?
  4. What retention or deductible applies to each section?
  5. Are forensics, privacy counsel, notification and credit monitoring covered?
  6. How are ransomware, cyber extortion and data restoration treated?
  7. Does social-engineering or funds-transfer fraud need a separate endorsement?
  8. Is business interruption covered, and what waiting period applies?
  9. Does contingent interruption cover key cloud and software providers?
  10. Is there a panel of required breach counsel, forensic firms or vendors?
  11. How does the policy coordinate with accountants E&O, crime and general liability?
  12. What controls must the firm maintain for the application to remain accurate?

For a side-by-side review, download the tax and accounting insurance quote worksheet.

A practical buying sequence

  1. Inventory the exposure. Count sensitive records, list systems and vendors, and map how client data enters, moves through and leaves the firm.
  2. Verify security controls. Confirm MFA, encryption, endpoint protection, backups, access reviews and training.
  3. Update the WISP and response plan. Assign responsibilities and record real procedures.
  4. Choose a limit deliberately. Consider likely response costs, downtime, contractual requirements and risk tolerance.
  5. Request comparable quotes. Give each broker the same facts, limits and endorsements.
  6. Read the forms. Compare definitions, exclusions, waiting periods and sublimits.
  7. Connect the policy to the response plan. Add carrier hotlines, deadlines and approved-vendor rules.
  8. Review annually and after major changes. Revisit coverage when services, revenue, staff, software or vendors change.

Frequently asked questions

Do accountants need cyber insurance?

No single answer fits every firm. An accounting firm that holds sensitive client data should at least evaluate standalone cyber coverage, considering its data, services, contracts, financial capacity and existing exclusions.

Is cyber insurance required by the IRS or FTC?

The FTC Safeguards Rule and IRS guidance require covered tax and accounting professionals to maintain appropriate safeguards and a written plan. Those requirements are not the same as a universal federal mandate to buy cyber insurance. A client contract, lender, state rule or other obligation may still require coverage.

Does a business owner’s policy cover a data breach?

Some packages include limited cyber endorsements, but limits and covered events may be narrow. Compare the endorsement with a standalone policy rather than assuming the package is sufficient.

Does accountants E&O cover ransomware or stolen client data?

E&O and cyber policies serve different primary purposes. An E&O form may restrict cyber events, while a cyber form may exclude professional-service claims. Review both and ask how overlapping claims are handled.

What cyber insurance limit should an accounting firm buy?

There is no universal limit. Consider record count and sensitivity, response expenses, possible filing-season downtime, contractual limits, defense costs, sublimits and the firm’s ability to retain loss.

Can a weak WISP invalidate cyber coverage?

Coverage depends on the policy and facts. Inaccurate application statements, known incidents or failure to satisfy a condition may create disputes. Keep the WISP accurate, implement its controls and report material changes.

Bottom line

For an accounting practice, the best cyber policy is not simply the cheapest proposal or the largest headline limit. It is the option whose definitions, sublimits, response services and exclusions fit the firm’s real data and operating risks.

Next step: Use the free insurance quote worksheet to compare cyber and E&O proposals side by side.


Sources and methodology

Cost figures are publisher-reported benchmarks, not quotes or guarantees. Small Business Insured does not sell insurance and does not receive compensation for including these sources.

This article provides general educational information, not legal, tax, cybersecurity or insurance advice. Policy wording, underwriting, availability and legal requirements vary by insurer, state and firm. Consult qualified professionals about your circumstances.

Share.

The Small Business Insured Editorial Team publishes independent, source-led guidance for U.S. tax preparers, bookkeepers, accountants, and other small-business professionals. Our work follows a documented editorial and corrections process and is reviewed against primary government and industry sources.

Comments are closed.

Exit mobile version