Sample document set · not your business

Harborview Accounting Ltd — document set

This is what a real generation looks like — a 6–15-person accounting firm on Microsoft 365, hybrid remote, MFA only partly rolled out. The readiness summary and the first section are shown in full; the rest is blurred here. Answer the 20 questions to generate and read your own set.

Readiness against common insurer questions

Scored from the answers you gave — not a certification.

5/8controls confirmed
3 gaps found
In place
Remote access to the office server

Goes through a VPN or an equally secured connection — your policy states it as standing practice.

Gap
Multi-factor authentication

Many insurers now decline cover or apply a surcharge where MFA is absent. Your policy includes a rollout clause; finishing it is your top action.

Gap
Endpoint protection (AV/EDR)

Not confirmed on all devices. Your policy includes a remediation clause with the built-in-protection baseline.

In place
Software updates

Installing automatically — your policy states it as standing practice.

In place
Unsupported software

Nothing past end-of-support in use — your policy states the replace-don't-keep rule.

In place
Automatic backup

Automatic — now pair it with the first restore test your policy commits to.

Gap
Security awareness training

Informal onboarding only. Your policy commits to a structured yearly refresher.

In place
Password manager

In use across the team.

In your docs
Written security policy

Generated from your answers — evidences the written-policy item insurers commonly ask businesses to hold. It documents your practices; it doesn't substitute for the controls themselves.

In your docs
Incident response plan

Generated from your answers, tailored to your setup, with a first-cycle tabletop-exercise commitment.

Coverwright · draft for review
CW-SP · 21 Jul 2026

Information Security Policy

Prepared for Harborview Accounting Ltd

1. Purpose & scope

SP-PU-01

This policy sets out how Harborview Accounting Ltd protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.

SP-PU-02

The controls in this policy are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurers, and to satisfy legal obligations around the data the business handles.

SP-PU-03

Because Harborview Accounting Ltd handles personal data, this policy also supports the business's data protection obligations. Data protection questions that go beyond day-to-day security practice are escalated to the owner or designated data protection lead.

2. Roles & responsibilities

SP-RO-02
SP-RO-03

3. Accounts & access control

SP-AC-02
Multi-factor authentication
SP-AC-09
MFA beyond email
SP-AC-03
Passwords
SP-AC-05
Administrator accounts
SP-AC-06
Joiners & leavers

4. Devices & endpoint protection

SP-DV-02
SP-DV-04
Endpoint protection
SP-DV-05
Updates
SP-DV-08
Unsupported software

5. Data handling & storage

SP-DA-01
SP-DA-02
SP-DA-04
SP-DA-05

6. Backup & recovery

SP-BK-01
SP-BK-06

7. Remote & mobile working

SP-RM-01
SP-RM-03
Remote access to the office server

8. Vendors & third-party services

SP-VN-01
SP-VN-02
SP-VN-03

9. Payments & customer transactions

SP-PY-01
SP-PY-02

10. Training & awareness

SP-TR-03

11. Review & maintenance

SP-RV-01

12. Appendices — templates to keep

AP-01
Appendix A — Vendor & service register (template)
AP-02
Appendix B — Leaver checklist (template)
AP-03
Appendix C — Security training log (template)
Unlock to read the rest

That's the first section — 29 more clauses in this document alone, plus the full Incident Response Plan and (on Complete) the Vendor Responsibility Matrix, all written for your actual answers.

Coverwright · draft for review
CW-IR · 21 Jul 2026

Incident Response Plan

Prepared for Harborview Accounting Ltd

1. Purpose & when to activate this plan

IR-PU-01
IR-PU-02

2. Roles & contact points

IR-RO-02
IR-RO-03

3. Step 1 — Recognise & report

IR-DT-01
IR-DT-02

4. Step 2 — Contain

IR-CN-01
IR-CN-03
IR-CN-05

5. Step 3 — Assess & notify

IR-AS-01
IR-AS-02
IR-AS-03

6. Step 4 — Recover

IR-RC-01
IR-RC-02

7. Step 5 — Learn & improve

IR-RV-01
IR-RV-02
Coverwright · draft for review
CW-VM · 21 Jul 2026

Vendor Responsibility Matrix

Prepared for Harborview Accounting Ltd

AreaServiceVendor securesYou secure
Email & collaboration
File storage
Office server / local files
Backup
Devices & endpoint protection
Card payments
Website / online store
IT support & administration
Accounts & identity

Included with the Complete document set — see pricing.

Ready to build yours?

Fifteen questions, about ten minutes — tailored to your business, not this sample. You'll see your full set before you pay.

Answer the 20 questions