Harborview Accounting Ltd — document set
This is what a real generation looks like — a 6–15-person accounting firm on Microsoft 365, hybrid remote, MFA only partly rolled out. The readiness summary and the first section are shown in full; the rest is blurred here. Answer the 20 questions to generate and read your own set.
Readiness against common insurer questions
Scored from the answers you gave — not a certification.
Goes through a VPN or an equally secured connection — your policy states it as standing practice.
Many insurers now decline cover or apply a surcharge where MFA is absent. Your policy includes a rollout clause; finishing it is your top action.
Not confirmed on all devices. Your policy includes a remediation clause with the built-in-protection baseline.
Installing automatically — your policy states it as standing practice.
Nothing past end-of-support in use — your policy states the replace-don't-keep rule.
Automatic — now pair it with the first restore test your policy commits to.
Informal onboarding only. Your policy commits to a structured yearly refresher.
In use across the team.
Generated from your answers — evidences the written-policy item insurers commonly ask businesses to hold. It documents your practices; it doesn't substitute for the controls themselves.
Generated from your answers, tailored to your setup, with a first-cycle tabletop-exercise commitment.
Information Security Policy
Prepared for Harborview Accounting Ltd
1. Purpose & scope
This policy sets out how Harborview Accounting Ltd protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.
The controls in this policy are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurers, and to satisfy legal obligations around the data the business handles.
Because Harborview Accounting Ltd handles personal data, this policy also supports the business's data protection obligations. Data protection questions that go beyond day-to-day security practice are escalated to the owner or designated data protection lead.
2. Roles & responsibilities
3. Accounts & access control
4. Devices & endpoint protection
5. Data handling & storage
6. Backup & recovery
7. Remote & mobile working
8. Vendors & third-party services
9. Payments & customer transactions
10. Training & awareness
11. Review & maintenance
12. Appendices — templates to keep
That's the first section — 29 more clauses in this document alone, plus the full Incident Response Plan and (on Complete) the Vendor Responsibility Matrix, all written for your actual answers.
Incident Response Plan
Prepared for Harborview Accounting Ltd
1. Purpose & when to activate this plan
2. Roles & contact points
3. Step 1 — Recognise & report
4. Step 2 — Contain
5. Step 3 — Assess & notify
6. Step 4 — Recover
7. Step 5 — Learn & improve
Vendor Responsibility Matrix
Prepared for Harborview Accounting Ltd
| Area | Service | Vendor secures | You secure |
|---|---|---|---|
| Email & collaboration | |||
| File storage | |||
| Office server / local files | |||
| Backup | |||
| Devices & endpoint protection | |||
| Card payments | |||
| Website / online store | |||
| IT support & administration | |||
| Accounts & identity |
Included with the Complete document set — see pricing.
Ready to build yours?
Fifteen questions, about ten minutes — tailored to your business, not this sample. You'll see your full set before you pay.