Your insurance broker calls about the cyber policy renewal. Partway through the usual questions, she asks who reviews your security policy and how recently that happened. You don’t answer straight away. You know there’s a policy somewhere, and you’re fairly sure someone looks at it now and then. Whether that’s true, and whether you could prove it if she asked twice, is a different question.
A renewal that can’t be backed with documentation rarely gets an outright no. More often it gets slower and pricier, and sometimes a rider ends up excluding the exact scenario you couldn’t prove you’d covered. The broker is just filling in a form that increasingly decides what you pay and what’s there for you if you ever need it.
For a long time, professional services firms could lean on relationships to carry that weight. If a client had worked with the same partner for a decade, that history did the convincing. These days the person asking is just as likely to be an underwriter who’s never met you or an examiner working through a checklist, treating your firm exactly the way they’d treat a stranger.
Why the question keeps landing
A recent American Bar Association Cybersecurity TechReport found that more than a quarter of law firms surveyed had already been asked by a client to produce their firm’s written security requirements, a request that was uncommon a decade ago and is common enough now to plan for.
Firms that count as financial institutions under the Gramm-Leach-Bliley Act – accountants, tax preparers, mortgage brokers, and non-SEC-registered investment advisors – are required to hold a written information security program under the FTC Safeguards Rule, with one named individual accountable for it and a documented annual review behind it. Tax preparers face a related requirement from the IRS, which asks preparers to certify, on their PTIN renewal, that a written data security plan genuinely exists before they can keep filing. A lot of firms handling financial or legal client data already fall under some version of this, whether they think of themselves as regulated or not.
Underneath the technical language, what’s being tested is whether a firm can produce, on request, proof of how it governs itself. Across the DMV’s regulated professional services firms, that responsibility usually lands informally with whoever happens to manage IT, whether that’s an internal hire or an outside vCIO arrangement brought in for exactly this kind of oversight.
Five questions to ask before someone else does
These are the five that tend to come up, in the order most people get asked them.
Ownership
Who owns this, specifically enough that you could give a regulator or an insurer a person’s name if they asked? Ask three people in your firm right now and see if they name the same one.
Review cadence
When was it last reviewed, and does anyone know the specific date without checking? Insurers assessing renewal risk and regulators conducting examinations both treat a policy that has never been revisited as functionally unreviewed, however sound it looked the day it was written.
Documentation
Does it exist in writing, or only as informal practice that everyone assumes is being followed? A client’s due diligence questionnaire or a regulator’s request is asking for a document. If it landed in your inbox tomorrow, would you be sending something that already exists?
Accessibility
Could the right person find or produce it today if a client’s questionnaire or a regulator’s request landed in the next hour? Documentation that cannot be located quickly behaves, in any real examination, exactly like documentation that was never written.
Audit trail
Could you show that this was followed a year or eighteen months ago, not just that a policy exists today? That earlier window is usually the exact period an insurer or regulator examines most closely once something has already gone wrong.
The answer matters less than knowing it
Most firms end up here for an unremarkable reason. They spent their time and energy on client work, since that’s what pays the bills, and the systems that would let them answer these five questions with confidence were never anyone’s priority until something outside the business made them one.
There’s also a practical reason to know before you’re asked. A firm that has to build documentation from scratch under a deadline, mid-renewal or mid-examination, tends to produce something rushed and thin. A firm that already knows where it stands, even if the answer is uncomfortable, has time to decide what to do about it on its own timing.
Working through the five questions above, honestly and without reaching for a fix, tends to be revealing on its own. It’s also usually the first thing a client ends up asking for once due diligence starts, or an insurer once a renewal stops being a formality and becomes a real look at documented audits and assessments.
Which of the five would be hardest for your firm to answer right now?




