In 2019, obtaining cyber insurance took about as long as filling in a form. A few general questions, a signature, a premium that felt almost incidental. Brokers described it as an easy add-on.
That market no longer exists.
Insurers spent the following years paying out on ransomware claims at a rate nobody had priced for, and they responded the way insurers always do — by working out which controls actually correlate with claims, then requiring them. The result is an application process that now asks specific technical questions and expects specific answers.
For a Folsom accounting or advisory firm, this matters in a way it didn’t before. Your renewal is no longer a formality. It’s an assessment, and firms are failing it without realising until the paperwork arrives.
What insurers now expect to see
The requirements vary between carriers, but a consistent core has emerged across the market. These are the controls that appear on nearly every application.
Multi-Factor Authentication. Universally required now, and increasingly required to be enforced rather than merely available. Some carriers ask specifically about email, remote access, and administrative accounts as separate questions.
Endpoint detection and response. Several carriers have moved beyond asking about antivirus and now ask specifically about behaviour-based detection, having learned the difference matters.
Backup arrangements. Not simply whether backups exist, but whether they’re stored offline or off-site, how frequently they run, and whether recovery has been tested.
Email security. Filtering, and often specific questions about protections against business email compromise.
Patch management. How quickly critical patches get applied, and whether compliance is measured.
Access controls. Who holds administrative rights, and how access is reviewed when staff change roles or leave.
Employee training. Frequency, and whether completion is recorded.
Incident response planning. Whether a documented plan exists.
A firm answering “no” or “not sure” to several of these may still obtain coverage — but at a higher premium, with lower limits, or with exclusions that remove protection for exactly the scenarios most likely to occur.
The attestation problem
Here is the part that catches firms out, and it deserves emphasis.
The application is a legal document. Whoever signs it is making representations on behalf of the practice, and those representations are relied upon when the policy is issued.
Claims have been reduced and, in some cases, denied where a business attested to controls it didn’t actually have in place. This rarely involves anyone lying. The far more common sequence is that a form arrives, someone forwards it to whoever handles the computers, an answer comes back that sounds right, and a box gets ticked based on a reasonable assumption nobody verified.
“Do you enforce MFA?” — yes, we turned that on. Except it was enabled for some staff, not enforced for all, and two principals were exempted eighteen months ago because they found it inconvenient.
“Are backups tested?” — yes, they run every night. Except a completed backup job is not a tested restore, and nobody has attempted a recovery since the system was installed.
Both answers were given in good faith. Neither would survive scrutiny after a claim.
The practical takeaway: before signing your next application, take an hour to verify each answer rather than assume it. If the verification reveals gaps, closing them is almost always cheaper than the coverage problem they’d otherwise create.
Why financial firms face sharper scrutiny
Carriers segment by industry, and accounting and advisory practices sit in a category that attracts particular attention.
The reason isn’t complicated. You hold Social Security numbers, bank details, and complete financial pictures for hundreds of clients, concentrated in one place. You also move money, or advise on moving it, on schedules that are predictable to anyone reading your email.
That combination makes financial firms a high-value target and, from an underwriting perspective, a higher-risk one. Applications for this sector frequently include additional questions about wire transfer procedures, client fund handling, and verification protocols that a general business application wouldn’t ask.
The attack the questions are really about
Behind the technical questionnaire sits one specific scenario carriers are trying to price.
It begins with a fake login page — a message about a shared document, a password expiry notice, a portal update. Someone enters their Microsoft 365 credentials during a busy afternoon. Nothing visible happens.
The attacker now has legitimate access to a real mailbox, and doesn’t rush. They read. They learn which clients have transactions pending, how the firm communicates, who authorises payments, how the principals write. Some create mail rules so their activity stays hidden from the account’s actual owner.
Then, at a well-chosen moment — a distribution, a closing, a substantial invoice — they send updated payment instructions from that genuine address, inside a conversation already underway. Everything about the message is authentic except its purpose.
This is business email compromise, and across the market it takes more money from financial firms than ransomware does. It’s also why MFA sits at the top of every application: it prevents the initial account access in the overwhelming majority of cases.
The second control that stops it costs nothing at all. Any change to payment or banking instructions gets verified by telephone, using a number already on file — never one supplied in the email requesting the change. Carriers increasingly ask whether such a procedure exists, because they know it works.
Running your own pre-application check
Before your renewal arrives, this exercise will tell you where you stand. Work through it with whoever manages your technology and note the answer you’d genuinely be able to defend.
☐ Is MFA enforced on every account, with no exemptions? Not enabled. Enforced, everyone, including principals.
☐ Can you produce a report showing MFA coverage? “I believe so” isn’t an answer an underwriter accepts.
☐ When was the last actual restore test? You need a date.
☐ Is at least one backup copy unreachable from your office network? If ransomware on a workstation could reach it, the answer is no.
☐ Do you run endpoint detection and response, or traditional antivirus? These are different products and carriers now distinguish between them.
☐ What is your current patch compliance percentage? If nobody measures it, that itself is the finding.
☐ Are systems monitored continuously, and by whom? Staff reporting problems isn’t monitoring.
☐ Is there a written incident response plan? Written, not understood.
☐ Do you have a documented payment verification procedure? And does everyone who handles payments actually follow it?
☐ Is training delivered on a schedule, with completion recorded? Records matter as much as the training.
☐ Are accounts removed promptly when staff leave? Including seasonal preparers from previous years.
☐ Do you maintain a written information security plan? For tax professionals, the IRS requires this.
Count the boxes you couldn’t tick confidently. Anything above two or three is worth addressing before an application, not after.
What closing the gaps typically involves
Firms often assume this represents a significant project. Usually it doesn’t.
Enforcing MFA across a twenty-person practice is generally an afternoon’s work, including the conversation with whoever objects. Getting backups replicated off-site and properly tested is a short project measured in days rather than months. Endpoint detection deploys remotely. Patch management runs automatically once configured, and produces the compliance figure the application asks for as a by-product.
The items that take longer — a documented incident response plan, a written security plan, a training programme with records — are documentation exercises rather than technical ones, and they’re straightforward when someone knows what carriers expect to see.
Our cybersecurity services and managed IT services are built around exactly this set of controls, with backup and disaster recovery that produces a tested result on a schedule. The documentation an application requires comes out of the arrangement rather than being assembled separately when a form arrives.
The benefit nobody mentions
There’s an outcome worth noting that has nothing to do with insurance.
The same questions carriers ask are the questions institutional clients increasingly ask. Larger businesses now send security questionnaires to the professionals handling their money, and some require evidence before engagement.
A firm that closed these gaps for its insurance renewal discovers it can also answer a client’s due diligence questionnaire in an afternoon — with dates, percentages, and documentation rather than reassurances. Firms that can’t answer aren’t told they lost on security. They simply aren’t shortlisted.
So the work gets done once and serves two purposes: it satisfies an underwriter, and it removes an obstacle to winning the kind of client most practices want more of.
Looking ahead
The direction of this market is reasonably clear, and worth planning around rather than reacting to.
Requirements have tightened every year for the past five, and there’s no indication of that reversing. Controls that were recommended in 2022 became required by 2024. Controls being recommended now — continuous monitoring, formal incident response testing, vendor risk assessment — are the likely requirements of the next renewal cycle.
Firms that treat each application as a one-time hurdle find themselves scrambling annually. Firms that maintain the underlying controls properly find each renewal easier than the last, because the evidence already exists.
The second approach is also, over any reasonable timeframe, considerably cheaper.
Before your next renewal
Take the checklist above to whoever manages your technology and get honest answers to each line. Do it now rather than in the week the application is due, because that’s when assumptions get ticked as facts.
If several boxes give you pause, that’s useful information — and every one of them is closable well within a renewal cycle.
Book an appointment with RJ PRO Tech Group and we’ll work through the checklist with you properly, verify what’s actually in place rather than what’s assumed, and give you a written summary you can use directly on your application. Call 209-920-4077 to arrange a time that suits your schedule.