Skip to content
CoverwrightStart your own
Sample document set · not your business

Harborview Accounting LLC — document set

This is what a real generation looks like — a 6–15-person Massachusetts accounting firm on Microsoft 365, hybrid remote, MFA only partly rolled out — and inside the FTC Safeguards Rule. The readiness summary and the first section are shown in full; the rest is blurred here. Answer the 21 questions to generate and read your own set.

Coverwright
CW-ES

Security Summary

Harborview Accounting LLC

What this business has told us about its security controls, on one page. Every line is drawn from the same answers that produced the documents — nothing here is stated that the documents do not also state.

Industry
Accounting / bookkeeping / finance
People
6–15
Based in
Massachusetts
Working pattern
Hybrid — some remote work
Email platform
Microsoft 365
IT support
An outside IT company or person
Data handled
Customer names, emails, addresses, Confidential client documents
Card payments
Yes
Prior incident
No
5
controls confirmed in place
3
open items, ranked with a plan
1
not established in the answers
Open, and being dealt with
  1. 01Multi-factor authentication
  2. 02Endpoint protection (AV/EDR)
  3. 03Security awareness training

In priority order. Each one has a first step, an owner and a target date on the action plan below.

Not established in the answers
  • Whether endpoint protection is running on every device

This page is a summary of the business’s own answers, not an audit, an assessment, or a verification of any control. It does not make the business compliant with any regime, does not certify anything, and is not a representation that any insurer will offer cover or accept a claim. Whether a legal regime applies to this business is a determination for the business and its counsel.

Readiness against common carrier questions

Scored from the answers you gave — not a certification.

5/8controls confirmed
3 gaps found
In place
Remote access to the office server

Goes through a VPN or an equally secured connection — your policy states it as standing practice.

Gap
Multi-factor authentication

Many carriers now decline coverage or apply a surcharge where MFA is absent. Your policy includes a rollout clause; finishing it is your top action.

Gap
Endpoint protection (AV/EDR)

Not confirmed on all devices. Your policy includes a remediation clause with the built-in-protection baseline.

In place
Software updates

Installing automatically — your policy states it as standing practice.

In place
Unsupported software

Nothing past end-of-support in use — your policy states the replace-don’t-keep rule.

In place
Automatic backup

Automatic — now pair it with the first restore test your policy commits to.

Gap
Security awareness training

Informal onboarding only. Your policy commits to a structured yearly refresher.

In place
Password manager

In use across the team.

In your docs
Written security policy

Generated from your answers — evidences the written-policy item carriers commonly ask businesses to hold. It documents your practices; it doesn’t substitute for the controls themselves.

In your docs
Incident response plan

Generated from your answers, tailored to your setup, with a first-cycle tabletop-exercise commitment.

In your docs
Breach-notification duties

Your incident response plan names the state-law test — where each affected person lives, not just where you are — the 30-to-60-day outside range, and your state attorney general’s filing step.

In your docs
FTC Safeguards Rule

Work of this kind is commonly within the Rule’s definition of a financial institution. Your program names the responsible individual, the risk assessment, and the 30-day FTC reporting deadline for events affecting 500+ consumers — the applicability call itself stays with your counsel.

In your docs
PCI self-assessment

Your program records the annual self-assessment questionnaire your payment provider asks for. Using a provider narrows which questionnaire applies; it doesn’t remove the obligation.

What to do next, in order

Ordered on published small-business security guidance and on the controls most often asked about in cyber insurance questionnaires — not on how any particular carrier underwrites or prices a risk, which is not something this document can know.

  1. 01
    Multi-factor authentication

    Turn on multi-factor authentication for every account in Microsoft 365, starting with the owner and any administrator accounts, then extend it to online banking and remote access.

  2. 02
    Endpoint protection (AV/EDR)

    Confirm the built-in protection (Microsoft Defender or the macOS equivalent) is switched on and reporting for every device used for work, including personal ones.

  3. 03
    Security awareness training

    Book a short refresher for everyone — spotting phishing, using MFA, and how to report something immediately — and record the date it happened.

Your downloads include this plan with space to write an owner and a date against each item.

Application answer sheet

The questions applications and client questionnaires most often ask, answered from what you told us.

15 answers
AQ-01
Is multi-factor authentication required for email access?

Not enabled for all accounts on Microsoft 365. Your program commits to a rollout, and this is the first item on your action plan.

No
AQ-02
Is multi-factor authentication required for other privileged access — banking, administrator accounts, remote access?

Not yet enabled across banking, administrator and remote access. Extending it there is named in your program.

In part
AQ-03
Are unique passwords enforced, and is a password manager in use?

A password manager is in use across the team, generating a unique password per service.

Yes
AQ-04
Is remote desktop (RDP) exposed directly to the internet?

Remote access to the office server goes through a VPN or an equally secured connection.

No

11 more answers — including backups, patching, training and incident history — are in your download, with the detail line to write into each box.

Coverwright
CW-SP

Written Information Security Program

Information security policy for Harborview Accounting LLC

1. Purpose & scope

SP-PU-01

This program sets out how Harborview Accounting LLC protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.

SP-PU-02

The controls in this program are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurance carriers, and to satisfy legal obligations around the data the business handles.

SP-PU-03

Because Harborview Accounting LLC handles personal information, this program also supports the business’s legal obligations for protecting it — the specific regimes that apply are set out under “Legal & regulatory obligations” below. Questions that go beyond day-to-day security practice are escalated to the owner, who takes advice where the answer isn’t obvious.

2. Roles & responsibilities

SP-RO-02
SP-RO-03

3. Accounts & access control

SP-AC-02
Multi-factor authentication
SP-AC-09
MFA beyond email
SP-AC-03
Passwords
SP-AC-05
Administrator accounts
SP-AC-06
Joiners & leavers

4. Devices & endpoint protection

SP-DV-02
SP-DV-04
Endpoint protection
SP-DV-05
Updates
SP-DV-08
Unsupported software

5. Data handling & storage

SP-DA-01
SP-DA-02
SP-DA-04
SP-DA-05

6. Legal & regulatory obligations

SP-RG-01
State breach-notification law
SP-RG-02
State breach-notification law
SP-RG-06
Customer financial information (FTC Safeguards Rule)
SP-RG-07
Customer financial information (FTC Safeguards Rule)
SP-RG-09
Card payments (PCI DSS)
SP-RG-10
State privacy laws
SP-RG-11
States with their own program duty

7. Backup & recovery

SP-BK-01
SP-BK-06

8. Remote & mobile working

SP-RM-01
SP-RM-03
Remote access to the office server

9. Vendors & third-party services

SP-VN-01
SP-VN-02
SP-VN-03

10. Payments & customer transactions

SP-PY-01
SP-PY-02

11. Training & awareness

SP-TR-03

12. Review & maintenance

SP-RV-01

13. Appendices — templates to keep

AP-01
Appendix A — Vendor & service register (template)
AP-02
Appendix B — Leaver checklist (template)
AP-03
Appendix C — Security training log (template)
Unlock to read the rest

That’s the first section — 36 more clauses in this document alone, plus the full Incident Response Plan and (on Complete) the Acceptable Use Policy, Business Continuity Plan, and Vendor Responsibility Matrix, all written for your actual answers.

Coverwright
CW-IR

Incident Response Plan

Prepared for Harborview Accounting LLC

1. Purpose & when to activate this plan

IR-PU-01
IR-PU-02

2. Roles & contact points

IR-RO-02
IR-RO-03

3. Step 1 — Recognize & report

IR-DT-01
IR-DT-02

4. Step 2 — Contain

IR-CN-01
IR-CN-03
IR-CN-05

5. Step 3 — Assess & notify

IR-AS-01
IR-AS-02
IR-AS-07
IR-AS-06
IR-AS-03

6. Step 4 — Recover

IR-RC-01
IR-RC-02

7. Step 5 — Learn & improve

IR-RV-01
IR-RV-02
Coverwright
CW-AU

Acceptable Use Policy

What staff at Harborview Accounting LLC may and may not do with company systems

1. Purpose & who this applies to

AU-PU-01
AU-PU-02

2. Accounts & passwords

AU-AC-01
AU-AC-02
AU-AC-03

3. Email, messages & phishing

AU-EM-01
AU-EM-02
AU-EM-03

4. Devices & software

AU-DV-01
AU-DV-02
AU-DV-03
AU-DV-04

5. Company and customer information

AU-DA-01
AU-DA-02
AU-DA-04

6. AI tools

AU-AI-01
AU-AI-02
AU-AI-03
AU-AI-04
Tax return information specifically

7. Personal use, monitoring & privacy

AU-PE-01
AU-PE-02
AU-PE-03

8. Electronic monitoring notice

AU-MN-01
Issued to each employee at hire, and posted where staff can see it

9. Reporting & consequences

AU-RP-01
AU-RP-02

Included with the Complete document set —Unlock to read Acceptable Use Policy

Coverwright
CW-BC

Business Continuity Plan

How Harborview Accounting LLC keeps working when systems don’t

1. Purpose & scope

BC-PU-01
BC-PU-02

2. What we restore first

BC-PR-01
BC-PR-02
BC-PR-03
BC-PR-04

3. How quickly, and how much data we can lose

BC-TG-01
BC-TG-02

4. Working while systems are down

BC-WA-01
BC-WA-02
BC-WA-03

5. Who to call

BC-CT-01
BC-CT-02

6. Keeping this plan real

BC-TS-01
BC-TS-02

Included with the Complete document set —Unlock to read Business Continuity Plan

Coverwright
CW-VM

Vendor Responsibility Matrix

Prepared for Harborview Accounting LLC

AreaServiceVendor securesYou secure
Email & collaboration
File storage
Office server / local files
Backup
Devices & endpoint protection
Card payments
IT support & administration
Accounts & identity

Included with the Complete document set — see pricing.

Ready to build yours?

21 questions, about ten minutes — tailored to your business, not this sample. You’ll see your full set before you pay.

Answer the 21 questions