Pillar guide

Cyber-insurance requirements for small financial firms

Cyber-insurance applications and the FTC Safeguards Rule ask about the same handful of controls, because both are trying to answer one question: can this firm protect client data, and prove it? An application is a legal representation. Answer 'yes' only to a control you can actually show — a written policy that a control 'shall' exist is not evidence that it does. A WISP with a proof checklist keeps your answers and your evidence in one place, which is exactly what an underwriter, and later a claims adjuster, wants to see.

Key facts

  • Underwriters price evidence, not intentions — the fastest way to a clean quote is being able to prove each control.
  • MFA is the question that appears most, usually broken into remote access, admin, email, and cloud (16 CFR 314.4(c)(5)).
  • Answering 'yes' to a control you cannot prove is a misrepresentation that can void a claim later.

Key takeaways

  • Underwriters price evidence, not intentions — the fastest way to a clean quote is being able to prove each control.
  • MFA is the question that appears most, usually broken into remote access, admin, email, and cloud (16 CFR 314.4(c)(5)).
  • Answering 'yes' to a control you cannot prove is a misrepresentation that can void a claim later.
  • The WISP, IRP, AUP, and Access Control Policy answer these questions with one source-cited packet and a proof checklist.

What do cyber insurers ask small firms?

The core set is predictable: multi-factor authentication, encryption, tested backups, endpoint protection (EDR), email security, staff training, access controls, vendor management, and incident response. A few — MFA and encryption above all — are treated as make-or-break by nearly every carrier.

These questions overlap with the Safeguards Rule on purpose. Both are asking whether customer information is protected by reasonable administrative, technical, and physical controls (16 CFR 314.4(c)).

Keep the answer and the evidence aligned. If MFA is enabled for email but not for your remote-access tool, do not let the application imply it covers everything. Specificity is not a weakness here; it is what an honest, defensible application looks like.

How does a WISP help with insurance?

It puts the facts an application asks for in one document: who owns security (314.4(a)), which systems hold client data (314.4(c)(2)), which controls are in place, which gaps are being remediated, and where the evidence lives.

Underwriters rarely read the whole WISP at quoting, but the same facts drive the application — and if a claim ever happens, the firm that can show its answers were made carefully is in a far better position.

Policywright includes proof-of-implementation prompts, so each control points to the screenshot, export, log, or contract that backs it up.

The insurer-question map

Below is how the most common carrier questions line up with the Safeguards Rule element behind them and the evidence to keep. Use it to answer an application without treating insurance and compliance as substitutes for each other.

This mapping is drawn from real applications (AIG, Travelers, Hudson/Encore) compared against 16 CFR 314.4. It is a practical crosswalk, not a promise of coverage or compliance.

The value is having the two languages — the carrier's and the regulator's — in one table, so a small firm answers once and can defend it twice.

Carrier question mapped to the Safeguards Rule element and the evidence to keep
Carrier question themeSafeguards Rule elementProof to collect
MFA (remote, admin, email, cloud)Access controls & MFA - 16 CFR 314.4(c)(5)Admin screenshots per system, exception log
Encryption at rest and in transitEncryption - 16 CFR 314.4(c)(3)Disk-encryption and TLS configuration evidence
Tested, offline/immutable backupsRecovery readiness - 16 CFR 314.4(h)Backup schedule, last restore-test date
EDR / next-gen antivirusLogging & monitoring - 16 CFR 314.4(c)(8)EDR console showing coverage
Security-awareness trainingTraining - 16 CFR 314.4(e)Training roster, completion dates
Vendor oversight by contractService-provider oversight - 16 CFR 314.4(f)Vendor inventory, contract safeguards clauses
Incident responseWritten IRP - 16 CFR 314.4(h)IRP, contact list, tabletop notes

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

Can Policywright answer my insurance application for me?

No. Policywright helps document your controls, but the firm must answer insurance applications truthfully based on its actual environment.

What is the most common control gap?

For small firms, MFA coverage and backup testing are common gaps because they require both configuration and evidence.

Sources

Document the controls insurers ask about.

Build a cited policy packet with a proof checklist and gap remediation language.

Build my plan
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.