You hold other people’s money and other people’s data.
Which makes a professional firm one of the most targeted businesses in Canada. The attack is rarely sophisticated. It is an email asking you to change payment details during your busiest week of the year.
Build the firm file See what’s covered Talk to a brokerCyber, professional liability and directors’ cover for advisory firms
Accountants, bookkeepers, tax preparers, law firms and advisors
Your current policies and your email security setup
Do accounting and professional firms need cyber insurance?
Yes. A professional firm holds client financial records, tax data, banking details and identity documents in one place, and moves money on client instructions. That combination is exactly what criminals look for. Cyber cover pays for the incident response, the forensic work, the legal advice on what you must disclose, notifying affected clients, and money lost to fraudulent transfers.
A breach at a professional firm is not only your loss. Clients whose financial records were exposed have their own claim, and the regulator has its own questions, both arriving in your busiest month. The Canadian Anti-Fraud Centre describes how the fraud works: “Spear phishing frauds involve fraudsters pretending to be from legitimate sources to convince businesses or individuals to send them money.” One convincing email and the funds are gone, with no hack anywhere. Read the Anti-Fraud Centre on spear phishing (opens in a new tab).
It sits alongside your professional liability, not instead of it. One covers a mistake in your work; the other covers a breach of your systems.
Cover for firms that hold sensitive things.
Funds transfer fraud
Money sent on a convincing fake instruction. No system is broken into, and the money is gone.
Client data breach response
Notifying clients, legal advice, credit monitoring and dealing with regulators.
Ransomware
Getting your systems and your client files back, and the income lost while you cannot work.
Regulatory and privacy
The costs that follow when personal information you held is exposed.
Three habits worth more than the policy.
Insurers now ask about all three, and every one of them is free. Adopt them whether or not you buy cover from anyone.
Call before you change a payment
Any change to bank details gets verified by phone on a number you already had. This alone stops it.
Two-factor on email
A compromised email account is the route this control closes.
A backup you have restored
Held away from your main network, and actually tested. Untested backups fail exactly when needed.
Tax season is when this happens.
Not because criminals are clever. Because you are busy.
The pattern is consistent: high volume, unfamiliar clients, urgent requests, and staff working late. An email that would look wrong in July looks ordinary in April. That is the whole method.
So the useful time to arrange this is now, not in the middle of it, and the useful conversation is as much about the verification habit as it is about the policy. We will send you the insurer’s own security questions and go through them with you, free, whether you buy or not.
How this can play out.
In April, a staff member opens an attachment while working late. Client tax files and banking details are exposed. The cost is not the computers. It is the forensics, the legal advice, and telling every client what happened.
Firms that hold client trust.
What cyber cover expects from a financial practice.
Cyber policies for firms that touch client money are underwritten on the controls you describe. The description becomes the deal.
Controls ticked but not lived
Multi-factor sign-in on every mailbox, including the bookkeeper’s. If the application says yes and one shared login says no, the breach will find that login.
Money moved without a callback
Funds-transfer cover routinely expects verification on a known number before payment changes destination. Many of these emails say there is no time for that. The dangerous ones are calm and patient and sound just like your supplier. So make the call every time the destination changes, not only when you feel rushed.
Client notification done late
Privacy law and the policy both expect fast notice after a breach. Waiting to see if it blows over spends the response window the cover was built to buy.
The vendor with your keys
Portals, processors and IT providers hold access to client data on your behalf. A breach that starts at a vendor still lands on the trust between you and the client, and the policy should contemplate it.
Answer the renewal like an affidavit and rehearse the callback rule once. Check that your systems still match your answers.
What professional firms ask us.
We are a small firm. Are we really a target?
Small firms are targeted precisely because their defences are lighter and they still hold valuable data and move client money. Most attacks are automated and indiscriminate.
Is money lost to a fake email covered?
Under a cyber policy with the right section, generally yes. Under a standard business policy, generally no. It is the clearest gap between the two.
Does our professional liability policy cover a data breach?
Usually not, or only narrowly. Professional liability responds to errors in your work; a breach of your systems is a different exposure needing cyber cover.
Our clients are starting to ask whether we carry cyber insurance. Why?
Because their own insurers and auditors increasingly require it of their advisors. Send us the requirement and we will check what we arrange against it, line by line, and tell you where it falls short.
We use cloud accounting software. Is that not their responsibility?
Their platform is theirs. Your accounts, your client data and your payment instructions remain yours, and an attacker inside your email is inside your firm regardless of who hosts the software.
What should we do first if we think we have been breached?
Call us. If a cyber policy is in place there is an incident response team you are entitled to use, and engaging it early materially improves the outcome.
Not an accounting firm? consultants & professional services covers other advisory work.
The questions behind the questions.
Ask for the security questions.
We will send the insurer’s questionnaire and work through it with you. No obligation, and you end up safer either way. Send us your current policies and your email security setup.