What Cyber Insurance Questionnaires Actually Ask Accounting Firms

Blog | Understanding Cyber Security · 3 min read | Practice Management | Cyber Security | Compliance | Cyber Insurance

Quick answer: A current cyber insurance questionnaire from an accounting-specific insurance provider asks Australian firms about six technical control areas: multi-factor authentication, backups, critical patching, endpoint and firewall protection, payment verification processes, and prior incident history. Several of these ask whether a control applies across every relevant user, application or device — which means the accurate answer is often partial rather than a simple yes. What you declare at renewal is what your firm may later be asked to stand behind, so accuracy matters more than speed.

Key Takeaways

  • Insurers are working out two things: how likely your firm is to experience an incident, and how serious the consequences would be.
  • Six control areas appear on the questionnaire we reviewed — MFA, backups, patching, endpoints, payment verification, and prior incidents.
  • Answering “no” doesn’t automatically mean cover is declined. It may mean more information, conditions, an adjusted premium, or a control being required.
  • The risk isn’t dishonesty — it’s answering yes without confirming the control applies everywhere.
  • Start at least four weeks before the form is due. If you get your security reviewed close to the deadline, you’ll be answering questions about gaps you haven’t had time to close. Four weeks gives you room to fix what’s found and answer accurately.
  • Practice Protect clients get a free annual security review for exactly this reason — a written report of what’s in place and what isn’t, so the answers on the form are backed by evidence you can produce.

Cyber insurance renewal is one of the few moments a firm is formally asked to describe its own security position.

It arrives as a form. The questions look straightforward, the answers feel obvious, and the whole thing gets completed between other work.

The questions are more specific than they look — and it is easy to reach the day before the form is due still trying to confirm what your firm actually has in place.

What is the form actually for?

Insurers are working out two things: how likely your firm is to experience an incident, and how serious the consequences would be if it does.

Fire prevention and building insurance is a useful comparison. Smoke alarms, safe wiring and extinguishers reduce the likelihood and severity of a fire. Insurance doesn’t stop the fire — it helps you respond financially and practically when prevention wasn’t enough. Neither replaces the other, and insurers are becoming more interested in the specific preventative measures you have in place.

Takeaway: The questionnaire isn’t administrative. Every answer changes the insurer’s understanding of your firm’s risk.

What areas do the questions cover?

Applications ask about your revenue and business activities as well as your controls. On the technical side, most current questionnaires ask about the same six areas:

  • Multi-factor authentication — enforced across remote access and cloud services holding sensitive data, including remote desktops, email, and payroll
  • Backups — run at least weekly, covering all critical data, and held offline or on a separate network
  • Critical patching — whether all critical security patches are installed within 30 days of release
  • Endpoint and firewall protection — antivirus and firewall maintained across all endpoints, including desktops, laptops and servers
  • Payment verification — whether changes to supplier, client or employee bank details are verbally confirmed on a pre-verified number already held on file
  • Prior incidents — what has happened in the past five years, whether or not a claim was made

None of these will surprise anyone, which is part of why they get answered quickly. Recognising the topic isn’t the same as being able to answer the question about it. The endpoint question is a good example: to answer it you also need to know whether personally owned or contractor devices are being used to reach client information, and what protects them.

Takeaway: Six familiar areas. Six questions that are more specific than they appear.

Where a good process still fails

Take payment verification, because it’s the one that looks least technical.

Here is how payment redirection fraud typically works. A criminal gains access to a supplier’s mailbox, finds a real invoice, copies the supplier’s tone, and emails to advise that the bank details have changed. It comes from the supplier’s genuine account, so nothing looks wrong.

A careful staff member doesn’t act on the email alone. She picks up the phone to confirm.

That instinct is right — and depending on which number she rings, it can still put her through to the criminal.

Takeaway: Having a verification process and having one that holds up are different answers to the same question.

See what actually went wrong

Our session Cyber Insurance: Is Your Firm Ready? walks through this in full — which number to verify against and why it matters — along with the rest of the questionnaire, using real questions that we see accounting-specific insurance providers commonly asking clients.

It also unpacks what several of these questions are really asking — and why that changes how you answer them.

WATCH THE ON-DEMAND WEBINAR

What if the honest answer is no?

Answering no doesn’t automatically mean cover is declined. It may mean supplying additional information, or the insurer applying conditions, adjusting the premium, or requiring a control to be implemented.

The greater risk runs the other way. Answering yes because a control exists somewhere in your environment, without confirming it applies consistently, creates a gap between what your insurer believes and what your firm actually has. That gap only surfaces at the worst possible moment.

Takeaway: A considered no is a stronger position than an unverified yes.

What should you hold alongside your answers?

Whatever you answer, keep something that supports it: a record of which users are covered by MFA and your other security policies, evidence of endpoint protection, backup scope and retention documentation, a written bank detail change procedure, and records of any incidents previously reported or assessed.

Separately, insurers may expect you to hold certain written policies, or take them into account when assessing risk — a privacy policy, a data retention and disposal policy, a data breach response plan. For our clients, these sit in our Cyber Security Compliance Hub™.

For firms on Practice Protect Core™, we help answer the questions covering password protection, managed access, security policies such as MFA and geo-locking, staff onboarding and offboarding, and single sign-on access to your email system where applicable. For Complete™ clients that extends to email protection and endpoint questions, including antivirus and patching. If you have our optional Backup add-on, we can also help with questions on data retention and where your data is held. Where a question falls outside what we manage — a separate server, your internal payment verification process, your incident history — we say so rather than guess.

Renewal is also a natural catalyst for clients to book their annual Security Audit Review. We recommend booking it at least four weeks before your renewal forms are due, so that any improvements the review identifies can be implemented and reflected in the answers you give.

Takeaway: A renewal form is a poor document to complete the day before it’s due.

Frequently Asked Questions

What does cyber insurance cover for an accounting firm?

+

Policies commonly combine first-party and third-party cover. First-party covers costs your firm experiences directly — digital forensics, data restoration, system recovery, legal advice, crisis communications, business interruption. Third-party covers claims involving another person or organisation, such as allegations that client information wasn’t adequately protected, privacy-related claims, or network security liability. Optional extras vary considerably between policies, so the fine print matters.

Does cyber insurance replace having security controls in place?

+

No, and the reverse is also true. Security controls reduce the likelihood and severity of an incident. Insurance addresses the financial, legal and operational consequences when one happens anyway. Insurance providers often make the point that there is no foolproof solution against cybercrime, and they are becoming more interested in the specific preventative measures a firm has in place — which is why the two are more connected than they used to be.

Does answering “no” mean we won’t get cover?

+

Not necessarily. A no may mean the insurer asks for more information, applies conditions, adjusts the premium, or requires a control to be implemented. The more common problem is the opposite — answering yes without confirming the control applies consistently.

How far ahead of renewal should we start?

+

Early enough to check what’s actually in place, close anything that needs closing, and have your answers reflect the fixed position rather than the one you found. For our clients, we recommend booking their annual Security Audit Review at least four weeks before the renewal forms are due, so that any improvements it identifies can be implemented in time.

Practice Protect is the only cyber security service built exclusively for Australian accounting and bookkeeping firms — giving every practice the compliance confidence, client protection, and operational simplicity that protecting client data now demands. Trusted by 28,000+ accounting professionals.

Disclaimer: This article is general in nature and provided for educational purposes only. It does not constitute legal, financial or insurance advice. For questions about your specific policy, wording or cover, speak with your insurance provider or broker.

Renewing your cyber insurance soon?

If you would like a clearer picture of what your firm could actually evidence before your next renewal form is due, book a security consultation with our team. We only work with accounting and bookkeeping firms, so the conversation starts with your Xero, your practice management system, and your staff access — not general IT theory.

BOOK A SECURITY CONSULTATION