Quick Answer: How much does cyber insurance cost for CPAs?
$50 to $750 per month ($600–$9,000/year) depending on firm size, data volume, and security posture. Solo CPAs can get basic cyber coverage starting at just $50/mo.
Why CPAs Need Cyber Insurance
Accounting firms are among the most targeted businesses for cyberattacks. Here's why:
- You store the most sensitive data possible — Social Security numbers, bank accounts, tax IDs, financial statements, payroll records
- Tax season creates urgency — Phishing attacks spike 400% during January-April when CPAs are under deadline pressure
- Wire fraud targeting — Business email compromise (BEC) attacks target CPAs because they handle client funds and financial transactions
- Regulatory exposure — Data breaches trigger notification requirements under state laws, IRS regulations, and potentially GLBA
- Small firms are prime targets — 43% of cyberattacks target small businesses, and CPA firms often lack enterprise-grade security
The average cost of a data breach for a small professional services firm is $120,000–$350,000 when you factor in notification costs, forensic investigation, legal defense, regulatory fines, and lost business. A $50-$200/mo cyber policy is cheap insurance against that exposure.
Cyber Insurance Pricing for CPA Firms
| Firm Size | Monthly Cost | Annual Cost | Typical Limits |
|---|---|---|---|
| Solo CPA | $50–$100/mo | $600–$1,200/yr | $500K–$1M |
| Small firm (2-5 CPAs) | $100–$250/mo | $1,200–$3,000/yr | $1M |
| Mid-size firm (6-20 CPAs) | $250–$500/mo | $3,000–$6,000/yr | $1M–$3M |
| Large firm (20-50 CPAs) | $500–$750/mo | $6,000–$9,000/yr | $3M–$5M |
What Cyber Insurance Covers for CPAs
First-Party Coverage (Your Direct Costs)
- Data breach response — Forensic investigation to determine what happened, who was affected, and how to contain it
- Client notification — Required by law in all 50 states; costs $3-$5 per person including credit monitoring
- Business interruption — Lost income if your systems are down during a ransomware attack or breach
- Ransomware payments — Coverage for ransom demands (though most carriers encourage not paying)
- Data recovery — Costs to restore encrypted or destroyed data from backups
- Crisis management — PR and communication support to manage reputational damage
- Regulatory fines — Coverage for fines from state attorneys general, IRS, or other regulators (where insurable)
Third-Party Coverage (Claims Against You)
- Client lawsuits — Defense costs and settlements if clients sue you for failing to protect their data
- Regulatory defense — Legal representation during regulatory investigations
- Media liability — Claims arising from breach notification communications
- PCI DSS liability — If you process credit cards and violate Payment Card Industry standards
CPA-Specific Cyber Risks
| Threat Type | How It Targets CPAs | Average Cost |
|---|---|---|
| Tax return fraud | Stolen client data used to file fraudulent returns | $75,000–$200,000 |
| Business email compromise | Fake emails impersonating CPAs to redirect payments | $125,000–$500,000 |
| Ransomware | Encrypts client files, demands payment during tax season | $50,000–$300,000 |
| Cloud breach | Unauthorized access to cloud accounting software | $80,000–$250,000 |
| Insider threat | Employee or contractor steals client data | $100,000–$400,000 |
🔒 Protect your firm and your clients. Compare cyber insurance quotes from top carriers →
Top Cyber Insurance Carriers for CPAs Compared
| Carrier | Starting Price | Best For | Key Feature |
|---|---|---|---|
| Hartford | $50/mo | Small CPA firms | $0 retention on breach response |
| Chubb | $120/mo | Large firms, high limits | Broadest coverage, worldwide |
| CNA | $75/mo | AICPA member firms | E&O + cyber bundle discount |
| Hiscox | $55/mo | Solo CPAs | Simple online purchase |
| Travelers | $65/mo | Multi-policy bundling | Strong BOP + cyber packages |
Hartford — Best Value for Small CPA Firms
Hartford offers the most competitive pricing for small accounting firms and includes features that other carriers charge extra for:
- $0 retention on breach response services — You don't pay out of pocket for forensics, notification, or credit monitoring
- Social engineering coverage — Covers losses from wire fraud and business email compromise
- Regulatory defense — Includes coverage for IRS and state regulatory investigations
- 24/7 breach hotline — Immediate access to incident response professionals
- Pre-breach services — Free employee training modules and security assessments
Hartford's cyber policy for CPAs integrates well with their E&O and BOP products, so you can manage all your coverage in one place with multi-policy discounts of 10-15%.
Chubb — Premium Protection for Larger Firms
Chubb's cyber policy is the Cadillac option — comprehensive coverage with the highest available limits:
- Limits up to $25M — For firms that need maximum protection
- Worldwide coverage — Protects international operations and overseas data
- Full social engineering coverage — Industry-leading limits on wire fraud losses
- Reputation recovery — Dedicated PR support and brand rehabilitation
- Board-level reporting — Cyber risk dashboards for partners and leadership
- Voluntary notification coverage — Covers notification costs even when not legally required
Chubb is worth the premium for firms handling high-net-worth client data or managing complex multi-entity engagements.
CNA — Best for AICPA Members
CNA's partnership with the AICPA gives them unique advantages for CPA firms:
- AICPA program discounts — 5-10% premium reduction for active AICPA members
- E&O + cyber bundle savings — Up to 15% discount when combining policies
- Accounting-specific risk tools — Free access to CPA-focused cybersecurity resources
- Claims expertise — Adjusters who understand accounting firm operations
- Identity theft response — Comprehensive support for clients whose data is compromised
Hiscox — Simplest Option for Solo CPAs
Hiscox makes it easy to get basic cyber protection:
- Online application — Quote and bind in under 10 minutes
- Monthly billing — No annual commitment required
- Basic coverage — Good for solos handling individual tax clients
- Simple claims process — Streamlined reporting and response
Hiscox's cyber policies are more standardized, so larger firms with complex needs may find the coverage too basic.
Travelers — Best Multi-Policy Value
Travelers excels at packaging cyber with other business coverages:
- CyberFirst Essentials — Entry-level cyber product included with BOP
- Multi-policy savings — 10-15% discount across bundled policies
- Strong financial rating — A++ AM Best
- Good for growing firms — Easy to upgrade coverage as your firm expands
💡 Compare all 5 carriers side-by-side. Get your personalized cyber insurance quotes →
IRS Requirements & WISP Compliance
The IRS requires all tax professionals to have a Written Information Security Plan (WISP) under the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. While the IRS doesn't specifically require cyber insurance, having one demonstrates compliance with several WISP requirements:
What the IRS Requires
- Designate a security coordinator — Someone responsible for your firm's data protection
- Conduct a risk assessment — Identify where client data is stored and what threats exist
- Implement safeguards — Technical, physical, and administrative protections
- Monitor and test — Regular security testing and incident response procedures
- Train employees — Annual cybersecurity awareness training
How Cyber Insurance Helps With WISP Compliance
Many cyber insurance carriers provide free tools that satisfy WISP requirements:
- Risk assessments — Hartford and Chubb include free annual security assessments
- Employee training — Most carriers offer free online training modules
- Incident response plans — Carriers provide templates and guidance
- Breach notification procedures — Built into the policy
Failing to comply with WISP requirements can result in IRS penalties and increased scrutiny. Having cyber insurance doesn't replace WISP compliance, but it provides many of the tools you need and a financial backstop if something goes wrong.
Cyber Insurance + E&O Bundles for CPAs
Most CPA firms should consider bundling cyber and E&O insurance. Here's why:
Why Bundle?
Coverage gap elimination — Standalone policies can leave gaps between E&O and cyber coverage. A client sues you for a data breach that exposed their financial data — is that a cyber claim or an E&O claim? Bundled policies eliminate the argument.
Cost savings — Expect 10-15% bundle discounts from most carriers.
Simplified claims — One carrier, one point of contact, no finger-pointing between policies.
Broader coverage — Bundled policies often include coverage enhancements not available in standalone products.
Bundle Pricing Comparison
| Carrier | E&O Only | Cyber Only | Bundle Price | Savings |
|---|---|---|---|---|
| Hartford | $67/mo | $50/mo | $100/mo | 15% |
| CNA | $85/mo | $75/mo | $136/mo | 15% |
| Chubb | $125/mo | $120/mo | $208/mo | 15% |
| Hiscox | $75/mo | $55/mo | $117/mo | 10% |
| Travelers | $90/mo | $65/mo | $132/mo | 15% |
How to Reduce Your Cyber Insurance Premium
1. Implement Multi-Factor Authentication (MFA)
This is the number one premium reducer — and many carriers now require it. MFA on email, remote access, and cloud accounting software can reduce premiums 10-15%. Some carriers won't even quote you without it.
2. Use Endpoint Detection & Response (EDR)
Traditional antivirus isn't enough anymore. EDR tools like CrowdStrike, SentinelOne, or Microsoft Defender for Business actively monitor for threats. Having EDR can reduce premiums 5-10%.
3. Encrypt Everything
- Encrypt laptops and desktops (BitLocker, FileVault)
- Use encrypted email for client communications
- Encrypt cloud storage
- Encrypt backup systems
4. Regular Employee Training
Phishing is the #1 attack vector for CPA firms. Annual (or quarterly) security awareness training demonstrates to carriers that you're managing your biggest risk. Many carriers provide free training modules as part of the policy.
5. Maintain Offline Backups
The 3-2-1 backup rule: 3 copies of data, on 2 different media types, with 1 copy offline/offsite. Carriers love this because ransomware attacks become recovery exercises rather than ransom negotiations.
6. Have an Incident Response Plan
Document what happens when (not if) you have a breach. Who do you call? How do you contain it? Who notifies clients? Carriers view firms with documented IR plans as lower risk.
Real-World Cyber Claims for CPA Firms
Case 1: Tax Season Phishing — $185,000
A staff accountant clicked a phishing link during busy season. Attackers accessed the firm's tax software and filed 47 fraudulent returns using client SSNs. The cyber policy covered $85,000 in forensics, $60,000 in client notification and credit monitoring, and $40,000 in regulatory defense costs.
Case 2: Ransomware Attack — $275,000
A 12-person CPA firm was hit by ransomware two weeks before the April 15 deadline. All client files were encrypted. The cyber policy covered the $50,000 ransom payment (after the carrier's incident response team negotiated it down from $200,000), $75,000 in data recovery, $100,000 in business interruption losses, and $50,000 in extended deadline penalty coverage.
Case 3: Business Email Compromise — $320,000
Attackers compromised a partner's email account and sent fake wire instructions to three business clients. Total losses: $320,000. The social engineering coverage paid $250,000 (policy sublimit), and the E&O portion covered the remaining $70,000 in client claims.
Case 4: Cloud Software Breach — $150,000
A CPA firm's cloud accounting platform was breached, exposing 2,300 client records. Even though the breach was the vendor's fault, the CPA firm was responsible for notifying affected clients. The cyber policy covered $90,000 in notification costs and $60,000 in legal defense when three clients filed suit.
Cyber Insurance Application Tips for CPAs
Carriers ask detailed security questions. Here's how to prepare:
What They'll Ask
- Do you have MFA enabled on email and remote access? (Required by most carriers)
- What antivirus/EDR solution do you use? (Name the product)
- Do you encrypt laptops and portable devices? (Yes/no — yes is better)
- How often do you back up data? (Daily minimum, with offline copies)
- Do you have an incident response plan? (Written plan preferred)
- Do you conduct employee security training? (Annual minimum)
- What cloud services do you use? (QuickBooks, Xero, Drake, ProConnect, etc.)
- Have you had any cyber incidents in the past 3 years? (Be honest — lying voids coverage)
- Do you have a WISP? (Required by IRS for tax preparers)
- How many client records do you store? (Affects pricing)
Red Flags That Increase Premiums or Cause Declination
- No MFA on email
- No regular backups
- Prior ransomware incident
- Storing unencrypted SSNs on local machines
- No employee training
- Using end-of-life software
🎯 Ready to protect your firm? Compare cyber insurance quotes from 5+ carriers →
Cyber Insurance vs. E&O: What's the Difference?
| Feature | E&O Insurance | Cyber Insurance |
|---|---|---|
| What it covers | Professional mistakes & negligence | Data breaches & cyber events |
| Trigger | Professional error or omission | Cyber event or data breach |
| Example | Tax filing error costs client $50K | Hacker steals 1,000 client SSNs |
| First-party costs | Limited | Extensive (forensics, notification, recovery) |
| Ransomware | Not covered | Covered |
| Business interruption | Not covered | Covered |
| Recommended? | Essential for all CPAs | Essential for all CPAs |
Bottom line: You need both. E&O covers professional mistakes; cyber covers data breaches and cyber events. They protect against different risks, and neither fully covers what the other does.
Why Use a Brokerage Platform Instead of Buying Direct?
When a carrier offers instant quote-and-bind on their website, it's convenient — but you're only seeing one carrier's rates. A brokerage platform like Insura changes that equation:
- One application, multiple quotes. Fill out one form and get compared across 10+ A-rated carriers including Hartford, Chubb, Hiscox, and more. No need to re-enter your business info on five different websites.
- The price is the same — or lower. Carriers pay the broker's commission directly. Your premium is identical to what you'd pay buying direct, and often lower because a broker can find a carrier that prices your specific risk more competitively.
- We work for you, not the carrier. A direct carrier's website is designed to sell you their policy. A brokerage platform is designed to find you the best policy — we have no incentive to push one carrier over another.
- Automated comparison shopping, year after year. When your policy renews, a brokerage platform automatically re-shops your coverage across carriers to make sure you're still getting the best rate. Buy direct, and you're locked into one carrier's renewal pricing with no leverage.
- Licensed experts when you need them. Have a coverage question or need help with a claim? You get access to real brokers — not a carrier's customer service line reading from a script.
→ Get your free multi-carrier quote
Frequently Asked Questions
How much does cyber insurance cost for a solo CPA?
Basic cyber coverage for solo CPAs starts at $50/mo ($600/year) with $500K limits. If you handle more than 500 client records, expect $75-$100/mo.
Is cyber insurance required for CPAs?
Not legally required in most states, but the IRS requires a WISP, and many clients require proof of cyber coverage. It's effectively necessary for any CPA handling client data electronically.
Does my E&O policy include cyber coverage?
Some E&O policies include limited cyber coverage (usually $25,000-$50,000 in data breach response). This is rarely sufficient. A standalone cyber policy or comprehensive bundle is recommended.
What's the most common cyber claim for CPA firms?
Phishing attacks leading to tax fraud are the most frequent cyber claim for CPA firms, followed by ransomware attacks and business email compromise.
Should I get standalone cyber or bundle with E&O?
Bundle if your carrier offers it. You'll save 10-15% and eliminate coverage gaps between the two policies. Hartford, CNA, and Chubb all offer strong bundle options.
What cyber security measures reduce my premium most?
MFA is #1 (10-15% reduction), followed by EDR (5-10%), encryption (5%), employee training (5%), and documented incident response plans (3-5%).
How quickly can I get cyber coverage?
Most carriers can bind within 24-48 hours for standard CPA firms. Hartford and Hiscox offer same-day coverage for straightforward applications.
Does cyber insurance cover ransomware payments?
Yes, most policies cover ransom payments, though carriers strongly encourage not paying. The coverage also includes the forensic investigation, business interruption losses, and data recovery costs that typically far exceed the ransom itself.
Related Guides
- Complete Accountant & CPA Insurance Guide — Our comprehensive pillar guide covering all insurance types for accounting professionals
- How Much Does CPA E&O Insurance Cost? — Detailed pricing breakdown for professional liability coverage
- Insurance for Tax Preparers & Seasonal CPAs — Specialized coverage for tax season professionals
- Best CPA Insurance Carriers Compared — Independent carrier rankings
Don't limit yourself to one carrier's price. Insura compares Hartford, Chubb, Hiscox, and 20+ other carriers — the price is the same or less, and you'll know you got the best deal. Get your free multi-carrier quote →
Related Coverage Pages
- Cyber insurance — Compare cyber policies from top carriers
- Data breach insurance — Forensics and notification for client data breaches
- Cyber security insurance — Ransomware and phishing protection for accounting firms
Protect your CPA practice — compare quotes in under 2 minutes →
