A cyber-insurance acquisition review connects the practice’s incident history, actual policy wording, applications, and proposed buyer coverage. Its purpose is to determine what evidence and funding the buyer needs before closing, rather than treating an insurance certificate as proof that inherited cyber exposure has been transferred.
What should a buyer examine first?
Examine the complete current policy and the history behind it. A certificate usually answers a narrower identification question than the buyer needs to answer about covered entities, events, dates, conditions, and available limits.
The buyer hub places this review alongside operating and financial diligence. Connect it with the malpractice and claims acquisition guide while preserving the distinction between professional-service allegations and cyber events.
Request declarations, forms, endorsements, applications, renewal submissions, relevant notices, loss information, and correspondence about incidents or coverage. Have the appropriate insurance adviser identify missing periods and explain what the documents establish.
Access should be limited to permitted reviewers. Incident reports may contain client information, employee data, privileged analysis, or sensitive descriptions of vulnerabilities. Agree on a review method rather than circulating the full archive to everyone involved in the acquisition.
How should the buyer compare the coverage components?
Compare each operational exposure with the specific policy response. First-party recovery costs and liability to other people are different categories; a large headline limit may not apply equally to both.
The FTC cyber insurance guidance distinguishes first-party and third-party coverage and recommends discussing suitable coverage with an insurance agent. It identifies matters such as vendor-held data, recovery, interruption, notification, and legal assistance for consideration.
Use those categories to ask questions, not to claim that a particular policy covers them. Read definitions, exclusions, retentions, sublimits, waiting periods, notice requirements, approved-provider conditions, and any relevant endorsements together.
| Exposure | Policy question | Operating evidence |
|---|---|---|
| Lost or inaccessible files | Which recovery expenses and providers qualify? | Restoration tests and vendor agreements |
| Interrupted tax production | How is covered interruption measured? | Work queues and recovery dependencies |
| Client data exposure | Which notification and defense costs apply? | Data locations and incident records |
| Payment instruction fraud | Is this event within the relevant insuring agreement? | Verification procedures and bank controls |
| Acquired entity or assets | Who is insured after the transaction? | Entity structure and insurer confirmation |
A comparison sheet should record the adviser’s interpretation and unresolved questions. The buyer should not turn ambiguous wording into a precise insured recovery amount merely to make a financing model balance.
How should incidents and loss information be reconciled?
Reconcile the timeline of known incidents with internal logs, vendor records, insurer notices, remediation evidence, and management explanations. Different documents may describe different stages of the same event.
An incident that produced no paid claim may still matter operationally. Perhaps costs fell below a retention, the policy did not respond, the event was never reported, or the matter remains unresolved. Investigate the explanation rather than assuming a blank loss history proves there were no problems.
Distinguish an attempted phishing message, unauthorized access, confirmed data exposure, lost availability, and a reported insurance claim. These labels carry different evidence requirements. Record what is established and what still requires technical or legal assessment.
The IRS tax professional data protection guidance provides tax-practice security resources and instructions for responding to data theft. A buyer reviewing an event should identify whether relevant reporting and remediation questions were addressed, using qualified advisers for the actual facts.
Preserve dates. The event date, discovery date, reporting date, policy period, and remediation date may each affect a different question. An acquisition does not erase that history or establish that an existing policy will respond to a later allegation.
What should be tested in insurance applications?
Test important security representations against the actual operating environment and proposed post-closing changes. A checkbox about authentication, backups, access, or training should have identifiable support.
Ask who answered each relevant question, which systems were included, when the answer was tested, and whether exceptions were disclosed. A seller may have accurately described one environment while the buyer intends to replace it with another.
For example, an application discussing protected remote access should be reconciled with contractor access methods, vendor accounts, and administrator privileges. This is an evidence review, not a claim that any specific mismatch automatically voids coverage.
The current Safeguards Rule regulations require covered institutions to develop, implement, and maintain an information security program, with specified requirements and limited exceptions. Insurance is a separate risk-financing tool; its purchase does not establish compliance with those obligations.
Track remediation that must occur before binding the proposed coverage or before closing. Obtain the actual insurer and adviser position about representations and conditions rather than interpreting a quote as permission to postpone required controls.
How should a buyer model retained financial exposure?
Model total operating cost and assumed insurance reimbursement separately. Recovery timing and coverage uncertainty can require buyer cash even when some costs may ultimately be reimbursed.
Consider an illustrative tabletop event with $30,000 of system recovery, $25,000 of forensic work, $45,000 of legal and notification expense, and $80,000 of interruption loss. Total assumed economic impact is $180,000. These are invented planning inputs, not an observed claim or severity forecast.
For a simplified hypothetical policy calculation, suppose only $100,000 is eligible, a $20,000 retention applies, and there are no other limiting terms. Assumed insurer payment is $80,000; retained impact is $180,000 minus $80,000, or $100,000.
If a relevant payment cap instead limits insurer reimbursement to $40,000 under the assumed wording, retained impact becomes $140,000. Real policies may apply limits and retentions differently; the adviser must calculate the actual response.
Neither calculation assigns a probability to the event or proves coverage. Use the thirteen-week acquisition forecast to test when invoices would need payment and which unrestricted funds could meet them before reimbursement.
How should the buyer perform the review?
Perform the review as a sequence that connects historical evidence with the proposed insured operation. Resolve significant coverage and readiness questions before relying on them in the closing plan.
- Collect policy periods, complete forms, applications, endorsements, and relevant incident records through permitted access.
- Reconcile known events and notices into a timeline with unresolved factual questions.
- Have qualified advisers compare actual operating exposures with policy wording and insured entities.
- Test material security representations against current systems and planned post-closing changes.
- Obtain written decisions on buyer coverage, conditions, historical exposure, and transaction-related questions.
- Fund retained exposure and response liquidity, then assign remediation and ongoing reporting owners.
A coverage decision should identify who supplied the interpretation and which documents it used. Record an unresolved matter as unresolved rather than filling the gap with the seller’s statement that insurance has always been adequate.
When a proposed acquisition changes entity, services, vendors, or access practices, show those facts to the relevant adviser. Do not infer coverage continuity from the practice retaining its trade name or using the same office.
Which findings should change the acquisition plan?
Findings should change the plan when they alter operating readiness, available coverage, retained cost, or the evidence needed to allocate historical responsibility. The response depends on the actual problem.
A funded authentication improvement may be manageable. An unresolved incident affecting key records or a coverage uncertainty that leaves essential costs unfunded may require additional diligence, a delayed closing, or a different transaction arrangement.
Keep operational remediation distinct from purchase agreement allocation. An indemnity can describe responsibility between parties, but it does not restore inaccessible records, create immediate cash, or determine an insurer’s obligation.
Compare the review with remote-contractor diligence, particularly where production depends on third-party access. The relevant question is whether the insured and controlled environment matches the workflow the buyer will operate.
Maintain a closing register showing each finding, evidence, responsible reviewer, agreed action, cost, and remaining limitation. A useful result is a supported coverage and response plan that the buyer can actually implement after closing.
A few common questions
What else should you know?
Does a cyber insurance certificate establish acquisition coverage?
A certificate identifies limited information and does not replace the complete policy, endorsements, and relevant insurer decisions. The buyer needs to determine which entities, dates, events, and expenses are addressed after the transaction. Have a qualified adviser examine the actual wording and obtain confirmation of unresolved acquisition-related questions before relying on coverage.
What does a clean loss run tell a buyer?
It provides evidence about the claims and losses reported in the particular record and period. It does not establish that no incidents occurred, no expenses were retained, or every event was reported. Reconcile it with management explanations, technical records, notices, and remediation evidence, while preserving appropriate confidentiality and access controls.
Should a buyer assume the policy limit will cover an interruption?
No. Examine the relevant insuring agreement, covered cause, measurement method, waiting period, retention, sublimits, and other applicable terms. A headline limit is not a forecast of recovery. Model the operating impact separately, then ask the insurance adviser to calculate the potential response for clearly stated hypothetical facts and actual wording.
Can insurance replace a practice security program?
Insurance addresses defined financial risks under its terms, while data protection obligations and operating controls require their own implementation. Review applicable requirements, access practices, recovery capability, and incident response separately. The acquisition budget should support both a suitable coverage decision and any necessary security work rather than treating a premium as proof of readiness.
Which sources support this guide?
Primary rules and guidance support the factual statements in this article. The worked examples and decision frameworks are original educational analysis.
- Cyber Insurance — Federal Trade Commission
- Protect your clients; protect yourself — Internal Revenue Service
- 16 CFR Part 314: Standards for Safeguarding Customer Information — Electronic Code of Federal Regulations