Harborview Accounting LLC — document set
This is what a real generation looks like — a 6–15-person Massachusetts accounting firm on Microsoft 365, hybrid remote, MFA only partly rolled out — and inside the FTC Safeguards Rule. The readiness summary and the first section are shown in full; the rest is blurred here. Answer the 21 questions to generate and read your own set.
Security Summary
Harborview Accounting LLC
What this business has told us about its security controls, on one page. Every line is drawn from the same answers that produced the documents — nothing here is stated that the documents do not also state.
- Industry
- Accounting / bookkeeping / finance
- People
- 6–15
- Based in
- Massachusetts
- Working pattern
- Hybrid — some remote work
- Email platform
- Microsoft 365
- IT support
- An outside IT company or person
- Data handled
- Customer names, emails, addresses, Confidential client documents
- Card payments
- Yes
- Prior incident
- No
- 01Multi-factor authentication
- 02Endpoint protection (AV/EDR)
- 03Security awareness training
In priority order. Each one has a first step, an owner and a target date on the action plan below.
- Whether endpoint protection is running on every device
This page is a summary of the business’s own answers, not an audit, an assessment, or a verification of any control. It does not make the business compliant with any regime, does not certify anything, and is not a representation that any insurer will offer cover or accept a claim. Whether a legal regime applies to this business is a determination for the business and its counsel.
Readiness against common carrier questions
Scored from the answers you gave — not a certification.
Goes through a VPN or an equally secured connection — your policy states it as standing practice.
Many carriers now decline coverage or apply a surcharge where MFA is absent. Your policy includes a rollout clause; finishing it is your top action.
Not confirmed on all devices. Your policy includes a remediation clause with the built-in-protection baseline.
Installing automatically — your policy states it as standing practice.
Nothing past end-of-support in use — your policy states the replace-don’t-keep rule.
Automatic — now pair it with the first restore test your policy commits to.
Informal onboarding only. Your policy commits to a structured yearly refresher.
In use across the team.
Generated from your answers — evidences the written-policy item carriers commonly ask businesses to hold. It documents your practices; it doesn’t substitute for the controls themselves.
Generated from your answers, tailored to your setup, with a first-cycle tabletop-exercise commitment.
Your incident response plan names the state-law test — where each affected person lives, not just where you are — the 30-to-60-day outside range, and your state attorney general’s filing step.
Work of this kind is commonly within the Rule’s definition of a financial institution. Your program names the responsible individual, the risk assessment, and the 30-day FTC reporting deadline for events affecting 500+ consumers — the applicability call itself stays with your counsel.
Your program records the annual self-assessment questionnaire your payment provider asks for. Using a provider narrows which questionnaire applies; it doesn’t remove the obligation.
What to do next, in order
Ordered on published small-business security guidance and on the controls most often asked about in cyber insurance questionnaires — not on how any particular carrier underwrites or prices a risk, which is not something this document can know.
- 01Multi-factor authentication
Turn on multi-factor authentication for every account in Microsoft 365, starting with the owner and any administrator accounts, then extend it to online banking and remote access.
- 02Endpoint protection (AV/EDR)
Confirm the built-in protection (Microsoft Defender or the macOS equivalent) is switched on and reporting for every device used for work, including personal ones.
- 03Security awareness training
Book a short refresher for everyone — spotting phishing, using MFA, and how to report something immediately — and record the date it happened.
Your downloads include this plan with space to write an owner and a date against each item.
Application answer sheet
The questions applications and client questionnaires most often ask, answered from what you told us.
Not enabled for all accounts on Microsoft 365. Your program commits to a rollout, and this is the first item on your action plan.
Not yet enabled across banking, administrator and remote access. Extending it there is named in your program.
A password manager is in use across the team, generating a unique password per service.
Remote access to the office server goes through a VPN or an equally secured connection.
11 more answers — including backups, patching, training and incident history — are in your download, with the detail line to write into each box.
Written Information Security Program
Information security policy for Harborview Accounting LLC
1. Purpose & scope
This program sets out how Harborview Accounting LLC protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.
The controls in this program are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurance carriers, and to satisfy legal obligations around the data the business handles.
Because Harborview Accounting LLC handles personal information, this program also supports the business’s legal obligations for protecting it — the specific regimes that apply are set out under “Legal & regulatory obligations” below. Questions that go beyond day-to-day security practice are escalated to the owner, who takes advice where the answer isn’t obvious.
2. Roles & responsibilities
3. Accounts & access control
4. Devices & endpoint protection
5. Data handling & storage
6. Legal & regulatory obligations
7. Backup & recovery
8. Remote & mobile working
9. Vendors & third-party services
10. Payments & customer transactions
11. Training & awareness
12. Review & maintenance
13. Appendices — templates to keep
That’s the first section — 36 more clauses in this document alone, plus the full Incident Response Plan and (on Complete) the Acceptable Use Policy, Business Continuity Plan, and Vendor Responsibility Matrix, all written for your actual answers.
Incident Response Plan
Prepared for Harborview Accounting LLC
1. Purpose & when to activate this plan
2. Roles & contact points
3. Step 1 — Recognize & report
4. Step 2 — Contain
5. Step 3 — Assess & notify
6. Step 4 — Recover
7. Step 5 — Learn & improve
Acceptable Use Policy
What staff at Harborview Accounting LLC may and may not do with company systems
1. Purpose & who this applies to
2. Accounts & passwords
3. Email, messages & phishing
4. Devices & software
5. Company and customer information
6. AI tools
7. Personal use, monitoring & privacy
8. Electronic monitoring notice
9. Reporting & consequences
Included with the Complete document set —Unlock to read Acceptable Use Policy
Business Continuity Plan
How Harborview Accounting LLC keeps working when systems don’t
1. Purpose & scope
2. What we restore first
3. How quickly, and how much data we can lose
4. Working while systems are down
5. Who to call
6. Keeping this plan real
Included with the Complete document set —Unlock to read Business Continuity Plan
Vendor Responsibility Matrix
Prepared for Harborview Accounting LLC
| Area | Service | Vendor secures | You secure |
|---|---|---|---|
| Email & collaboration | |||
| File storage | |||
| Office server / local files | |||
| Backup | |||
| Devices & endpoint protection | |||
| Card payments | |||
| IT support & administration | |||
| Accounts & identity |
Included with the Complete document set — see pricing.
Ready to build yours?
21 questions, about ten minutes — tailored to your business, not this sample. You’ll see your full set before you pay.