Cyber Insurance for Accountancy Firms explained
Short answer for a busy partner: most English accountancy practices should carry specialist cyber insurance. A small firm with client personal data and remote access should buy at least £250,000 cover. Practices handling high‑value client funds or many tax agent services should consider £500,000–£1m limits. Confirm the policy includes ransomware extortion and business interruption wording. Expert opinion: buying the cheapest policy without reading exclusions is a false economy.
Who this applies to and who it does not apply to
This guidance applies to English accountancy practices with 1–50 staff. It also applies to sole practitioners who process client personal or financial data. Examples include firms that store payroll records, client bank details or operate client portals. It covers firms that use remote access, cloud practice software or send client documents by email.
That means this advice is less relevant to firms that truly hold no personal data. That situation is very rare for accountants. It is also less relevant to firms with more than 50 staff. Larger firms often have bespoke enterprise cyber programmes arranged by in‑house risk teams. Finally, this does not replace a negotiated cyber schedule attached to a bespoke Professional Indemnity master policy when one exists and is documented.
The factors that matter when deciding
Underwriters base pricing and acceptance on concrete, evidenceable factors. Each item listed below must usually be evidenced during quotation and at renewal. That evidence drives acceptance, exclusions and premium loadings.
- Revenue and payroll: insurers quote by annual turnover bands and staff count. For example, a firm with £250k turnover and five staff sits in a lower premium band than one with £2m and 30 staff.
- Client profile and sensitivity: handling tax returns, payroll and HMRC agent credentials raises risk. Firms with high‑net‑worth clients or large corporate payrolls attract higher premiums.
- Prior incidents: a notified breach or cyber claim in the last 24–36 months often increases premiums sharply. It can also lead to exclusions.
- Technical controls evidence: underwriters typically ask for MFA, endpoint protection, timely patching, tested offline backups and evidence of network segmentation or logical separation. Lack of these controls increases cost or can cause declinature.
- Cyber hygiene policies: a written incident response plan, staff training records and supplier due diligence lower perceived risk.
- Limits and sub‑limits: many policies show a headline limit but then apply sub‑limits for notification, PR, cyber extortion and regulatory defence. Those sub‑limits can materially restrict cover.
These factors explain why two firms with similar turnover can receive quotes that differ by 400%. The controls evidence and client profile drive most of the variance.

Indicative premium ranges and concrete premium drivers
Quotations vary, but indicative UK SME bands help budgeting. A sole practitioner or micro practice with turnover under £150k and strong controls might expect premiums of about £300–£600 pa. Small practices (turnover £150k–£750k, 2–10 staff) typically see £500–£1,200 pa. Larger SMEs (turnover £750k–£3m, up to 50 staff) can be £1,000–£4,000 pa depending on exposure and controls.
Key numerical drivers to budget for:
- A prior cyber incident in the last 24–36 months can uplift premium by 50–200% or trigger higher excesses.
- Absence of MFA or untested/offline backups commonly produces either a declinature or a 30–100% loading.
- Handling high‑value client funds or many HMRC agent services can add 25–100% to the base rate.
- Chosen limit and sub‑limits scale premium roughly linearly; moving from £250k to £1m can multiply the premium 2–4×.
Also budget for excesses, broker fees and remedial actions insurers may require at renewal. Presenting strong dated evidence of controls at quotation materially reduces premium volatility.
Underwriter checklist of exact controls and acceptable evidence
Underwriters for accountancy firms are precise. The list below shows what insurers commonly ask for and the evidence they accept. Presenting this evidence at quotation speeds placement and reduces post‑bind queries.
- Multi‑factor authentication (MFA) for all remote access and admin accounts. Evidence accepted: screenshots from admin console, MFA policy and a dated audit log showing MFA enforced. The NCSC lists MFA as a primary control.
- Up‑to‑date patching regime with a demonstrable 30‑day cadence for OS and common apps. Evidence accepted: patch reports from an RMM or endpoint management console export dated within 30 days.
- Endpoint detection and response or managed AV deployed on all endpoints. Evidence accepted: console screenshot showing active status and alert history for 90 days.
- Offline, tested backups retained for both system and client data, with at least one offline copy. Evidence accepted: backup job logs, a restoration test report within 12 months and a backup retention policy.
- Network segmentation or logical separation between user workstations and servers/backups. Evidence accepted: a network diagram or firewall screenshots, or a VLAN configuration export.
- Email protection such as SPF, DKIM and DMARC and anti‑phishing controls. Evidence accepted: public DNS records or an email security gateway report.
- Administrator account controls: separate admin accounts, a privileged access manager or strict logon processes. Evidence accepted: user account lists showing disabled local admin or PAM screenshots.
- Incident response plan and tabletop evidence: a written plan and a record of at least one tabletop exercise or staff training in the last 12 months.
Underwriters commonly refuse verbal claims of controls. They want dated, exportable evidence. If evidence is missing, insurers may add warranty conditions, exclude specific cover such as ransomware, or decline the risk.
💡 Tip
Present a single zipped evidence pack at quotation: MFA screenshots, a backup test report, an EDR console export and a one‑paragraph incident response summary. That reduces underwriter follow‑up and speeds placement.
Is cyber insurance worth it for accountancy firms?
Yes for the majority of UK accountancy practices. The immediate costs of breach response often exceed the annual policy cost. For example, a simple ransomware incident can cost a small practice £20,000–£70,000 in immediate response and lost fees. Policies in the £300–£1,500 pa range can transfer that risk.
Dicho de otro modo, policies vary in what they pay. Many standard cyber policies have sub‑limits for notification and PR. Some policies carve out regulatory fines. That means firms must balance premium with appropriate limits. They must confirm sub‑limits meet plausible worst‑case costs. When a practice handles large volumes of sensitive tax or payroll data, the expert recommendation is to choose higher overall limits. Also increase notification and PR sub‑limits.
There are cases where insurance offers little benefit. If a firm has a bespoke professional body master policy that includes tailored cyber cover, an off‑the‑shelf SME policy may duplicate cover or leave gaps. If a firm truly holds no personal data and has no online access to client systems, the economics shift against purchase. Such situations are rare.
Real case studies and lessons learned
Practical, anonymised examples sharpen the risks and insurance outcomes. A five‑partner Kent practice suffered a ransomware attack after a contractor’s remote access credential was phished. Forensics identified the vector within 48 hours. The insurer appointed a negotiator. After negotiation a ransom of £18,000 was paid. The firm also incurred £12,500 in forensics and about £8,000 in business interruption. Lesson: insist on supplier access controls and log monitoring. Keep offline backups tested. Ensure the policy’s ransom and BI sub‑limits match plausible costs.
Another case involved an internal data leak where an ex‑employee exfiltrated payroll files. The claim failed initially because the firm could not produce dated backup logs and HR leaver records. Lesson: retain dated artefacts such as backup test reports and leaver checklists to satisfy post‑incident enquiries. Use short, structured case summaries in board briefings. Include vector, immediate response, insurer actions, outcome and key remedial step. That approach makes protection investments and policy choices tangible.
Cyber insurance vs professional indemnity for accountants
A common mistake is assuming Professional Indemnity (PI) covers cyber incidents. PI covers negligent professional advice and errors that cause client loss. It does not usually cover first‑party breach response costs. Those costs include forensics, notification expenses and ransomware payments.
Conversely, cyber insurance covers those first‑party costs. It often includes third‑party liability for data protection claims and defence costs. For accountancy firms both covers are complementary.
A typical scenario clarifies the difference. A payroll error caused by a software bug that harms a client is a PI claim. A stolen payroll file exfiltrated via a compromised login is a cyber claim. It can also become a data protection claim and run alongside PI. Firms must check whether their PI policy has cyber extensions. If it does, verify limits, retroactive dates and whether cyber extortion or regulatory defence are included.
Experienced brokers recommend holding both a PI policy sized for professional liability and a standalone cyber policy sized to incident response and regulatory risk. That combination reduces overlap. It also ensures access to specialist incident management vendors used by cyber insurers.
Which cyber policy covers GDPR fines for accountants
Most UK SME cyber policies exclude statutory regulatory fines as an insured loss because fines can be punitive. However, many insurers will cover defence costs for regulatory investigations and, in a minority of