3 Cyber Insurance Tips for CPAs and Accounting Firms

by Tae Andrews, Esq., and Jeffrey L. Schulman, Esq., Pasich LLP – July 9, 2024
3 Cyber Insurance Tips for CPAs and Accounting Firms

The modern risk management landscape presents numerous areas of potential exposure for professional insureds, including accounting firms and professionals. A first-party policy covers an insured s own losses or damage to the insured s property, such as in the event of cyberattack. In contrast, a third-party policy covers losses resulting from the insured s liability to a third party and arises once the third party has asserted a claim against the insured, which can take many forms.

To maximize recovery in the event of a loss or claim, here are three tips for account ing firms and professionals to consider.

Have a Plan for Cyberattacks

Recent years have seen a massive increase in cyberattacks, which can take many forms, including ransomware, extortion, data breaches, client data theft, wire transfer fraud, social engineering, phishing, spear phishing, email spoofing and other forms of email hacking and account compromise. To make matters worse, the rise of artificial intelligence may only compound these threats by giving bad actors more tools and means of attacking unsuspecting firms. Due to their widespread prevalence, the question has become when, not if, an insured will suffer a cyberattack.

Fortunately for insureds, cyber insurance can cover many of these losses. One way to streamline a firm s coverage is to get their preferred cyber forensics vendor preapproved and listed on their cyber policy. If the firm suffers a cyber-attack, the last thing it needs is a challenge from its insurer regarding the appropriate forensics firm to investigate the loss and whether the rates are reasonable. Similarly, many cyber policies cover notice, crisis and public-relations costs incurred due to cyberattacks. The policyholder can also request preapproval for these preferred firms.

In addition, several other types of policies can cover cyberattacks and similar events, including crime, property, commercial general liability and professional liability policies, sometimes under sublimited coverages in endorsements added to the policies. In the event of a data breach, the best practice is to cast a wide net and report the claim under any and all potential coverages. There is no rule that only cyber policies can cover data breaches   the plain meaning of the coverage is paramount.

Reporting

Cyberattacks can also lead to claims from clients, affected third parties or regulators alleging that the insured failed to adequately safeguard client data. In addition to the aftermath of a cyberattack, third-party claims can also take place in many other contexts and take other forms, including demand letters, subpoenas, civil investigative demands and requests to toll statutes of limitation, among others. Insureds should be aware that there are many types of covered claims, so firms should provide notice to any insurers that may potentially provide coverage for the claim.

Tailor Coverage and Prepare Your Defense

Insureds can tailor their third-party coverage to meet their needs before a potential claim. Many professional liability policies provide coverage for claims alleging wrongful acts by the insured in its rendering or failure to render professional services. CPAs wear many hats and provide a variety of services to their clients. One best practice is to ensure that the description of professional services in your professional liability policy adequately encompasses all the services your firm provides to clients. Like cyber policies, insurers of third-party liability policies may preapprove a firm s preferred defense counsel and its hourly rates. Insureds should also be aware of insurer attempts to change the agreement after the fact, as insurers often try to impose hourly rate caps or litigation management guidelines not included or referenced in the policy.

Forewarned is forearmed — there are a variety of sources of cyber exposure and potential liability in today s risk landscape, but with a bit of prior planning, accounting firms and professionals can better protect themselves in the event of an attack or claim. 


Jeffrey L. Schulman

Jeffrey L. Schulman, Esq., is a managing partner at Pasich LLP.

Tae Andrews

Tae Andrews, Esq., is an insurance policyholder attorney at Pasich LLP.

More content by Tae Andrews:

This article appeared in the Summer 2024 issue of New Jersey CPA magazine. Read the full issue.

PAGE HEADING

Icon_MemberBenefits_MID
CPACharge
CPACharge was developed specifically for CPAs, enrolled agents and accountants, providing a simple, affordable online payment solution that allows you to securely accept credit, debit, and eCheck/ACH payments from anywhere. 
NJCPA_Icn_4C
On-Site Training

NJCPA on-site training programs offer the same outstanding content and expert instruction as our seminars but are led at your location.

Icon_MemberBenefits_MID
Accounting Today
Save 20 percent on an Accounting Today subscription and stay up to date on the latest issues affecting the profession.
Icon_3_people_circle_SKY-04
Join the Accounting Educators Community

Connect and share with other accounting educators about curriculum, trends and the profession. Learn about NJCPA initiatives that are valuable for your students including information on obtaining the CPA designation, student membership, scholarships, volunteer opportunities and events.

Icon_4_cube_connection_SKY-04
Earn an AICPA Robotic Process Automation Certificate
Recognize what RPA is and its business value, with specific focus on accounting and finance functions. Understand how RPA provides a significant competitive advantage.
Icon_MemberBenefits_MID
Guaranteed Rate/Marc Demetriou
Marc Demetriou of Guaranteed Rate is offering NJCPA members a “no lender fee mortgage” ($1,440 lender fee credit), competitive low rates and a dedicated team to deliver world class service.
Icon_3_people_circle_SKY-04
Join the Women's Leadership Forum

Join our online forum that enables female CPAs at all career levels and industries to make meaningful connections with each other and discuss career goals.

Icon_Monitor_magnify_SKY-04
Earn an AICPA Single Audit Certificate
Learn how to plan, perform and evaluate single audits in accordance with the latest requirements of the new Uniform Guidance.
Icon_MemberBenefits_MID
Wolters Kluwer
NJCPA members save 25 percent on CCH CPELink subscriptions, live webinars and on-demand self-study (mobile friendly) CPE courses.
Icon_MemberBenefits_MID
SMI

SMI has negotiated special discounts for the NJCPA members with all the major technology carriers and providers.

Icon_3_people_circle_SKY-04
Join the Business & Industry Professionals Interest Group

Stay connected to your peers and share knowledge on corporate finance topics.

Wolters Kluwer CCH
Save on COVID Tax Resources
NJCPA members save 25 percent on Wolters Kluwer's new book, COVID and Taxpayer Certainty Acts of 2020: Law, Explanation & Analysis.
NJCPA_Icn_4C
Shop the NJCPA store
Are you NJCPA proud? Purchase NJCPA merch to show your pride and help support our scholarship program.
Icon_Shooting_up_arrows_MID-03
Real Estate Classified Ads
View classified ad postings for office space for sale or rent.
Icon_Handshake_MID-03
Mergers & Acquisitions Classified Ads
View classified ad postings from CPA firms looking to be acquired and those looking to acquire or merge with other firms.
Icons_3_gears_midnight-03
Professional Services Classified Ads
View classified ad postings from companies providing services to CPAs.
Icon_3_people_circle_SKY-04
Join the Cannabis Interest Group
New Jerseyans have voted to legalize cannabis. Join the NJCPA's Cannabis Interest Group to gain information, insights and best practices for serving clients in this promising new industry.
NJCPA_Icn_4C
Zoom Backgrounds
Download our virtual backgrounds for Zoom meetings.
Icon_certificate_SKY-04
Earn an AICPA Certificate
When you’re ready to show your competencies, expand your career opportunities or enter new areas of practice, start by earning an AICPA certificate. Choose a certificate that matches your next career goal.
Icon_4_cube_connection_SKY-04
Earn the AICPA Blockchain Fundamentals Certificate
Build a foundation toward becoming a strategic business partner within your organization and with your clients. Learn how to anticipate potential benefits and risks of the technology, structure and functionality, and to translate them into relevant business application and value.