For accountants
The 12 cyber questions on your PI renewal, decoded.
Published 2026-05-25 · 12 questions · Approx. 15-minute read
Your professional indemnity renewal comes with a cyber-security questionnaire, and the underwriter uses the answers to price your policy. The easy move is to copy last year's answers. It's also the risky one. Some of the wording means something specific to an insurer, and a wrong answer tends to surface at the worst moment, when you make a claim.
The questions aren't random. Each one maps to a way a firm like yours loses money. Phishing arrives from a supplier's hacked email account. Ransomware locks the file server. A partner clicks a link, and a client ends up paying the wrong bank account. Every question on the form is the underwriter asking whether you've closed one of those gaps.
Below are 12 questions that come up on renewal forms from the PI providers used by ICAEW and ACCA practices and CIOT tax advisers (Hiscox, Towergate, Lockton, Markel, Arch). Each one comes with what it means in plain English and why the insurer asks. Then comes the part a vendor would usually skip: whether a Vantyris report helps. Mostly it doesn't. Eight of the twelve are about how your firm runs on the inside, and no outside scan can answer them. The other four are about what your firm shows the internet, and there a dated Vantyris report is quick, cheap evidence.
The 12 questions
- 01
“Do you have a documented information security policy?”
What it means
A written document that says how staff handle client data and who can access what, including how that access is removed when someone leaves. The insurer wants a dated copy that someone has reviewed in the last 12 months.
Why they ask
Without one, the insurer assumes you handle client data ad hoc and prices you as more likely to have a breach. A policy won't stop a breach. It does show the insurer you've thought about the problem.
How Vantyris fits
Outside Vantyris's scope. This is internal paperwork. A Vantyris report can back up one section of it, though. If your policy says the website gets an external check, the report footer (scan ID, date, methodology version) is the evidence that section points to.
- 02
“Have you completed Cyber Essentials certification (or Cyber Essentials Plus)?”
What it means
A government-backed scheme, run for the NCSC by IASME, covering five basic controls: firewalls, secure configuration, security update management, user access control and malware protection. Plain CE is the entry level. CE+ adds a hands-on assessment.
Why they ask
CE is a recognised baseline, so a yes here tells the underwriter the firm has the basics in place. Ask your broker whether your insurer prices it into the premium.
How Vantyris fits
Vantyris is not a CE certification body. The certificate has to come from a certification body licensed through IASME. What every verified Vantyris scan does include is a Cyber Essentials alignment section, which maps each finding to the five control areas. Use it as the starting checklist for a CE submission. It also shows which controls an external scan can speak to (A2 secure configuration, A3 update management) and which need evidence from inside the firm (A1 firewalls, A4 user access, A5 malware). Read the explainer →
- 03
“Do you run regular external vulnerability scans on your public-facing systems?”
What it means
Some insurers want to see one external scan in the last 12 months. Others want monthly or quarterly scans. Check the wording on your own form.
Why they ask
Websites drift. An expired TLS certificate is the loud version. The quiet version is a plugin update that drops a security header, or a DMARC record someone switched off, and nobody at the firm notices either until an outside scan does.
How Vantyris fits
Vantyris monitoring re-scans on the schedule you pick, from daily to monthly, and only emails you when something gets worse, such as a new high-severity finding or a certificate close to expiry. Each scan's dated PDF is your evidence. Switch on the public trust page and the insurer can check it themselves.
- 04
“Do you use multi-factor authentication on all administrative accounts?”
What it means
Email, accounting software, client portals, banking. The insurer asks whether MFA (an authenticator app, a hardware key, or at minimum SMS) is enabled on every account that handles client money or data.
Why they ask
Without MFA, a stolen password is all anyone needs to get into the account. With MFA switched on, the password alone won't open it.
How Vantyris fits
Outside Vantyris's scope. MFA is a setting inside each service. Vantyris does check the email records that stop other people sending mail as your domain (SPF, DKIM, DMARC). That's a kind of impersonation MFA never sees.
- 05
“How often do you patch your software, and what's the policy for emergency updates?”
What it means
The insurer wants to see a patching policy. A common one reads 'high-risk vulnerabilities patched within 14 days, everything else within 30'. Cyber Essentials sets the same 14 days for high and critical updates.
Why they ask
Attackers don't need a new trick when an old hole is still open. The CISA Known Exploited Vulnerabilities catalogue lists holes attackers are known to be using, and each entry comes with a fix. The question is whether you've installed it.
How Vantyris fits
Vantyris adds 15 points to the priority of any finding tied to a CVE on the CISA KEV list, so those patches rise to the top of your list. Where a finding has a CVE, the report's references link straight to the entry.
- 06
“Do you have a documented incident response plan?”
What it means
A written plan that says who decides whether something counts as a breach, who reports it to the ICO (UK GDPR gives you 72 hours from when you become aware of it), who tells affected clients, and what the firm says publicly.
Why they ask
The first 72 hours after a breach decide much of the legal and reputational damage. A firm without a plan spends them improvising.
How Vantyris fits
Outside Vantyris's scope, because this is internal process. What Vantyris does keep is a history on every finding, with each status change and comment and who made it. That's the record you'd cite in a post-incident review to show what you were watching and how you responded.
- 07
“Are your backups kept offline and encrypted, and have you tested a restore?”
What it means
Offline, or in immutable cloud storage such as AWS Glacier with object lock, so ransomware can't encrypt them too. Encrypted at rest. And tested, which means actually restoring from them at least once a year.
Why they ask
Ransomware encrypts every file it can reach. With tested offline backups you restore and get back to work. Without them, the conversation turns to whether to pay.
How Vantyris fits
Outside Vantyris's scope. Your backups live with your accounting software vendor and your file storage provider. What Vantyris does scan is the public side of your firm, client portal included, and that's one of the routes ransomware takes in.
- 08
“Do you train staff on phishing and social engineering?”
What it means
An annual training session, with simulated phishing tests at least quarterly. Some insurers explicitly ask for evidence of phishing-simulation results.
Why they ask
One convincing email is enough to start a breach, and an accounting firm is full of what phishers go after, from payment instructions to client tax records.
How Vantyris fits
Outside Vantyris's scope. The email checks Vantyris does run (DMARC, SPF, DKIM) cover the other direction, where someone emails your clients pretending to be you. Training stops your staff clicking. An enforced DMARC policy stops mail that forges your exact domain from reaching your clients' inboxes. Read the explainer →
- 09
“Are you using cloud services for any client data, and which ones?”
What it means
The insurer wants a list of every cloud service that touches client data: accounting software (Xero, QuickBooks, Sage), document storage (Dropbox, Google Drive, OneDrive), email (Google Workspace, Microsoft 365), file portals (your own, or your software's), MFA tooling, password manager.
Why they ask
Every cloud service is one more way in. The insurer wants to know each one is a reputable vendor with at least a SOC 2 report or ISO 27001 certification.
How Vantyris fits
Outside Vantyris's scope. We scan what your firm shows the internet, not your vendor list. If you need a format, our own privacy policy lists its processors one line per vendor, with what each one does. Copy that and add where each vendor keeps the data.
- 10
“Have you had any cyber-related incidents in the last 12 months?”
What it means
Anything from a successful phishing attempt against a partner's email to a malware infection on a workstation to a ransomware attempt. The insurer asks for full disclosure.
Why they ask
Honesty matters here. If the insurer finds out later you concealed an incident, they can refuse to pay a claim citing material non-disclosure.
How Vantyris fits
Outside Vantyris's scope. It's a question of remembering and disclosing. Vantyris helps with the timeline, because each finding's history shows when a scan first raised it and when someone marked it fixed or accepted, with their reason.
- 11
“Do you have cyber insurance separately from PI?”
What it means
PI cover is built around claims about your professional work, so it may not fully cover a cyber incident. Check your wording. A dedicated cyber policy covers ransomware payments, breach notification costs, regulatory fines, and business interruption.
Why they ask
The insurer is checking your overall risk exposure, not selling you cyber cover (though some carriers offer both).
How Vantyris fits
Outside Vantyris's scope. It's a question about what cover you've bought. If you do buy a separate cyber policy, that insurer may well ask about external scanning too, and the same report answers it.
- 12
“Can you provide evidence of recent security testing?”
What it means
A penetration test report (if you've had one), a vulnerability scan report, or an internal audit. The insurer wants something dated within the last 12 months on letterhead.
Why they ask
Writing 'we take security seriously' is worth nothing on this form. A dated document is something the underwriter can actually weigh.
How Vantyris fits
Every verified Vantyris scan produces a PDF with your domain in the header and a footer carrying the scan date, the methodology version and a unique scan ID. It comes in three layouts. The full report opens with a one-page executive summary, so the same file works for your records and for the underwriter. A single-issue work order answers a follow-up question about one finding. The compliance report maps your findings to the Cyber Essentials controls, A1 to A5. If you switch on the public trust page (
vantyris.com/trust/your-firm), the insurer can check the same data without you forwarding a PDF.
The short version
Vantyris produces real evidence for four of the twelve: Cyber Essentials alignment (Q2), external scanning (Q3), known-vulnerability patching (Q5) and recent security testing (Q12). On the other eight it has nothing to say. They cover policy, MFA, backups, staff training, incident response, your cloud vendors, past incidents and other insurance, all of which live inside the firm where no outside scan can see.
That split is fine. You write the incident response plan yourself, and no scanner should pretend otherwise. What Vantyris does is answer the four outward-facing questions with something dated: a PDF for the file, and a public trust page the insurer can open without asking you for anything. Whether that changes your premium is the insurer's call. It does mean those four answers rest on evidence instead of a tick box.
None of this is unique to Vantyris. An enterprise platform like Qualys will give you the same evidence, priced for companies with their own security team. We don't see the case for a small practice paying for that.
Run a free check on your firm's website before the next renewal.
Create a free account and run the teaser. It checks your certificate and security headers in seconds, and it needs no card. A verified scan costs one credit, from a starter pack of five for $10€10£10A$15¥1,500AED 40, and gives you the dated PDF to hand to the underwriter.
Vantyris editorial team · methodology v1.0.0 · references: NCSC Cyber Essentials · ICO guidance · CISA KEV catalog