Data breach insurance for a Kentucky CPA firm should cover breach response, client notification costs, regulatory defense, and funds-transfer fraud — because accounting firms hold the data criminals want most: Social Security numbers, tax returns, and bank account details. Here's what that coverage should include, what the rules require of your firm, and what it costs a small office.
_Current as of July 2026. This is general information from an insurance agency, not legal advice. Breach obligations depend on facts specific to your firm — confirm yours with counsel._
## Why CPA firms are a top target
A tax preparation office holds more sensitive personal data per client than almost any other small business. One workstation compromised during filing season can expose hundreds of clients' Social Security numbers, dependents' information, and direct-deposit details.
The IRS has repeatedly warned tax professionals about this. Its Security Summit series and a 2024 alert both flag spear-phishing campaigns aimed at stealing Electronic Filing Identification Numbers (EFINs) and client files. Our own read is that smaller practices draw attention precisely because they rarely have enterprise-grade defenses — the IRS stops short of saying that, but it does single out smaller firms when it reminds preparers to keep a written security plan.
## What's actually required of your firm
Two things matter here, and they are commonly confused.
First, the written plan. Under the FTC Safeguards Rule, an accountant or tax preparation service that completes income tax returns is treated as a financial institution (16 CFR 314.2(h)(2)(viii)). That means 16 CFR 314.3(a) applies: you must develop and maintain a comprehensive information security program written in one or more readily accessible parts — what the IRS and the profession call a WISP.
There is a partial exemption at 16 CFR 314.6 for firms holding information on fewer than 5,000 consumers, and it is widely misunderstood. It relieves four specific provisions, including the written risk assessment and the written incident response plan. It does not relieve the requirement to have a written security program at all. A two-person tax office still needs one.
Second, breach notification. Since May 13, 2024, 16 CFR 314.4(j) requires notifying the Federal Trade Commission within 30 days of discovering a breach affecting 500 or more consumers. Kentucky also has a breach notification statute, KRS 365.732, which requires notice to affected Kentucky residents — though it contains an exemption at subsection (8) for firms already subject to the Gramm-Leach-Bliley Act, which is the same federal framework the Safeguards Rule sits under.
How those two regimes interact for any particular firm is a legal question, and one your counsel should answer for your practice rather than a blog. The practical planning point does not depend on the answer: whether you notify clients because a statute compels it, because your engagement letter does, or because you intend to keep the client, the forensic work, the mailing, and the credit monitoring all cost real money. That's what the insurance is for.
## What data breach insurance for a CPA firm should include
### 1. Breach response and notification
Pays for forensic investigation, client notification, call-center support, and credit monitoring for affected clients. This is the core of the policy — confirm the limit is per-event and covers all affected records, not just Kentucky residents.
### 2. Cyber extortion and ransomware
Covers ransom negotiation, payment where lawful, and system restoration. Ask specifically whether restoration of data from backups is included.
### 3. Funds-transfer fraud and social engineering
CPA firms move money — payroll files, estimated tax payments, client refunds. Social engineering coverage responds when an employee is tricked into wiring funds to a criminal. Many base cyber policies exclude this; it is often a rider you have to request. Across the market as a whole, business email compromise and funds-transfer fraud together account for the majority of cyber claims, which is why we treat this endorsement as close to essential rather than optional.
### 4. Regulatory defense and fines
Covers legal defense for state or federal regulatory actions following a breach, including FTC Safeguards Rule inquiries, where insurable by law.
### 5. Business interruption
If ransomware locks your systems the first week of April, the lost billable work is real money. Cyber business interruption reimburses lost income during downtime. Check the waiting period — 6 to 12 hours is typical, and some forms run 24.
### 6. Third-party liability
Defends the firm if clients sue over the exposure of their data. For a firm with business clients this matters even more, because a breached CPA can become the entry point into a client's own systems.
## What cyber insurance costs a small Kentucky CPA firm
Published benchmarks for accounting firms with one to four employees put a $1M standalone cyber policy in the range of roughly $900 to a few thousand dollars a year, depending on revenue, record count, and security controls. Carriers now underwrite business data security directly — expect questions about multi-factor authentication, backups, and email security before anyone quotes you. Firms with MFA enabled and tested backups generally see better pricing.
A cyber endorsement on a business owners policy is cheaper, but read the structure before relying on it. The headline limit is often $25,000 to $50,000, and inside it sit smaller sublimits — a $10,000 ransom sublimit within a $25,000 cyber limit is a common shape. A firm holding thousands of client tax records generally needs a standalone policy.
## How data breach insurance and professional liability insurance fit together
This is the part most CPA firm insurance conversations skip, and it's where firms get surprised.
If your firm carries accountants' professional liability insurance — E&O — you already have some protection touching client data. The AICPA's program policy, for instance, reaches certain third-party claims brought by a client over theft or misuse of confidential information in the course of professional services. That's real coverage, and it's worth knowing you have it.
What that policy generally does not reach is your own first-party cost when a breach actually happens: forensic investigation, notifying every affected client, credit monitoring, and the billable hours lost while systems are down. The program says as much itself — which is exactly why it sells a separate cyber endorsement carrying its own limits.
So the useful frame isn't "covered or not covered." It's first-party versus third-party:
- Professional liability insurance answers "did the firm fail its client?"
- Data breach insurance answers "what does it cost this firm to respond?"
The gap between those two questions is where a real bill lands.
One thing to check rather than assume: some standalone cyber forms carry a professional services exclusion — occasionally with a carve-back for cyber events — and some carry none at all. It genuinely varies by form. If a client alleges your firm failed in its professional duty to safeguard their data, which policy responds can turn on wording in two different contracts. Have both read together, by someone who will actually read both.
## What Kentucky requires
Short answer: nothing.
Kentucky does not require CPAs or CPA firms to carry professional liability or cyber coverage as a condition of licensure or a firm permit. The licensure criteria are enumerated in KRS 325.261 for individuals and KRS 325.301 for firms, and the firm application under 201 KAR 1:081 is a form and a $100 fee. Insurance appears nowhere in them. Kentucky's peer review requirement is a quality-control review of engagement workpapers, and it doesn't reference insurance either.
So coverage here is a business decision, not a compliance box to tick. The obligations that actually bind come from somewhere else — the federal FTC Safeguards Rule for your written security program, and, increasingly, your own clients' engagement letters and contracts.
## How an independent agent helps
Comparing KY insurance providers on cyber liability insurance is harder than comparing them on property, because the forms are less standardized. Social engineering limits, ransomware sublimits, and breach-response services differ significantly from one carrier to the next. As an independent agency in Owensboro, Elite Risk Advisors quotes cyber coverage across multiple carriers and explains the differences in plain language, so you know what a policy will and won't do before you need it. We place and service coverage for CPA and professional firms across Owensboro, Daviess County, and western Kentucky; the carrier underwrites and pays the claim.
## Frequently asked questions
### Is cyber insurance required for CPA firms in Kentucky?
No law requires you to buy the insurance. But the FTC Safeguards Rule does require tax preparers to maintain a written information security program, and client engagement letters increasingly ask about coverage. Practically, it has become standard practice.
### Does a business owners policy (BOP) cover data breaches?
Usually only through an endorsement, often with a headline limit around $25,000 to $50,000 and smaller sublimits inside it that a single event can exhaust quickly. Firms holding large volumes of client tax data generally need a standalone policy.
### What's the difference between first-party and third-party cyber coverage?
First-party pays your own costs — forensics, notification, ransom, lost income. Third-party defends you when someone else, usually a client, holds you responsible. A good CPA-firm policy includes both.
### Do I need a written security plan even if I'm a two-person office?
Yes. The under-5,000-consumer exemption in 16 CFR 314.6 relieves several specific requirements, but not the underlying obligation to maintain a written information security program.
_Want a plain-language review of your firm's cyber exposure? [Contact Elite Risk Advisors](https://www.eliteriskagent.com) in Owensboro for a no-pressure quote comparison across multiple carriers._
Post by Amber Dennis
Jul 27, 2026 11:32:27 AM
Jul 27, 2026 11:32:27 AM
Amber Dennis is co-owner and principal advisor at Elite Risk Advisors, an independent insurance agency in Owensboro, Kentucky. Before insurance, she spent 12 years in Daviess County Public Schools as an ELA teacher and instructional coach — and that background shows up in everything she does. Amber owns every client relationship at ERA from the first call through every renewal, approaching coverage the same way she approached the classroom: with patience, clarity, and the belief that people make better decisions when they actually understand what they're choosing. When she's not working, she's keeping five kids alive, tending to her plants, and — if she's being honest — has never once finished a movie as an adult. Owensboro has been home her entire life, and so have the people she now protects.