Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Contact Us
  • Verito
  • Home

  • Applications

    • Managed IT

      • Cloud Hosting KB

        • Home
        • Managed IT

        Cyber Insurance, Monitoring, and What Happens If You Have a Breach

        Discover how cyber insurance and proactive monitoring can mitigate risks and what steps to take in the event of a data breach.

        Table of Contents

        1. Three things that are often confused 2. Does my Verito service include cyber insurance? 3. What we can do for your insurer 4. Security controls, and the human layer 5. If you think you have had a breach What happens after you call us 6. Responsibility for losses 7. Getting help

        Cyber Insurance, Monitoring, and What Happens If You Have a Breach

        Last Updated on 1st September  |  Published by Parnav Dagar

        Firms ask us about this in three different ways that sound like one question. Is insurance part of my service. What happens if something goes wrong. Who pays. They are separate questions with separate answers, and running them together is what leads firms to assume they are protected in ways they are not.

        This article separates them. If you would rather talk it through, call us and we will go through it with you.

        1. Three things that are often confused

        What it is Who it protects Who arranges it
        Your firm's cyber liability policy Your firm, against your own losses and your obligations to your clients Your firm, through your own broker or insurer
        Verito's own insurance Verito, in respect of Verito's own liability Verito
        The security controls, monitoring, and training in your plan Nobody financially. These reduce the chance of an incident and shorten the time it takes to spot one. Verito, as part of your service

        The third row is the one worth sitting with. Security controls change how likely an incident is and how quickly it is caught. They do not function as insurance, and no amount of them removes the need for a policy.

        2. Does my Verito service include cyber insurance?

        No. Cyber liability insurance is not included in any Verito plan, and we are not an insurance broker. Your firm carries its own policy, arranged through your own broker or insurer.

        If you do not currently hold one, that is worth addressing regardless of what your IT arrangements look like. A policy covers things no security control can: notification costs, credit monitoring for affected clients, legal fees, regulatory response, business interruption, and the cost of forensic investigation. Those are the expenses that make an incident at a small firm expensive, and they arrive whether or not the underlying breach was preventable.

        3. What we can do for your insurer

        Most cyber policies now ask detailed questions about the controls you have in place, and the answers affect both whether you are offered cover and what you pay. Several of those questions are about things we manage for you, so send the questionnaire to us and we will go through it with you line by line.

        Two points we will always be precise about, because an inaccurate answer on an insurance form is your exposure rather than ours. Our SOC 2 report covers our cloud data center. It does not extend to managed IT services or to our support organization, which is covered separately by ISO 27001. We will tell you exactly which certification applies to which part of the service rather than letting a general answer stand.

        Where an insurer wants something in writing, tell us and we will provide it as a documentation request rather than an answer given on a call.

        4. Security controls, and the human layer

        Security controls and monitoring do two things well. They make an incident less likely, and they shorten the gap between something happening and someone noticing it. That gap is where most of the damage in a breach accumulates, so closing it quickly matters a great deal.

        What no security control can do is make a decision on behalf of a member of your team. We apply commercial best practice across the environment we manage. We cannot stop someone clicking a link they should not, downloading a file they should not, or typing their password into a page that looks exactly like the one they use every day. A firm is only as strong as its weakest link, and that link is almost always human rather than technical.

        This is why employee security awareness training carries as much weight as the tooling, and why it is included on VeritGuard Pro and Elite. Regular training changes what your people notice: the sender address that is one character different, the invoice from a familiar name but an unfamiliar domain, the urgent payment request that skips your normal process. Those are the moments where an incident is either avoided or created, and they happen at somebody's desk rather than in a console.

        So the security controls, the training, and your insurance policy each cover something the others cannot. That is the case for treating them as three layers rather than as alternatives.

        5. If you think you have had a breach

        Call 844-629-9899 immediately. Do not email, and do not wait until you are certain. Speed matters more than confirmation at this stage, and there is no penalty for calling about something that turns out to be nothing.

        Things worth calling about straight away: someone entered credentials into a page that turned out to be fake, an unexpected file was opened or run, client data appears to have been sent somewhere it should not have been, or an account is behaving in a way nobody at the firm can explain.

        Two things to do in parallel. Notify your insurer promptly, because most policies require early notification and some restrict which forensic and legal providers you may use. Engaging your own people first can affect cover. And follow your firm's own incident response procedure, which under the FTC Safeguards Rule you are required to maintain as part of your written information security program. If you hold a VeritShield WISP, that procedure is in it.

        What happens after you call us

        Where we become aware of, or reasonably suspect, that your data has been compromised, we notify you in writing. That notice describes what we know at the time: the nature of the incident, the categories of data affected, and the steps taken or proposed. Information may come to you in stages as an investigation develops, which is normal and better than waiting for a complete picture before telling you anything.

        We then take commercially reasonable steps to contain, investigate, and remediate within the systems we manage, and we cooperate with your own notification obligations. Supporting you through an incident is part of your service. If anything ever fell outside that, we would talk it through with you at the time rather than afterwards.

        What stays with your firm is the decision making. Whether to notify the FTC, a state authority, or your clients, and the execution of those notifications, is yours to decide, not ours. Your agreement is explicit on this point. The same applies to designating your Qualified Individual and giving final approval to your WISP, your risk assessment, and your incident response plan. We support those, we do not own them.

        6. Responsibility for losses

        Your service agreement sets out how responsibility is shared between your firm and Verito. Like any managed services agreement, it places limits on what we are liable for, and it identifies the situations where responsibility sits with your firm. The full terms are on our website, and we are glad to walk through them with you at any point.

        The question underneath this one is usually the more useful one. If a breach happened next week, what would it actually cost your firm, and is your policy sized for that? The expenses that hurt a firm your size tend to arrive regardless of who was at fault: client notification, credit monitoring, legal and forensic support, and the weeks your team spends on the incident instead of on client work.

        That is a conversation we would rather have with you now than during an incident. Your account contact can set it up, or call the support line and we will arrange it.

        7. Getting help

        Managed IT support is available 24 hours a day, 7 days a week.

        • Email: itsupport@verito.com
        • Phone: 844-629-9899

        For a suspected security incident, call rather than email.

        cybersecurity breach response

        Was this article helpful?

        Yes
        No
        Give feedback about this article

        RELATED QUESTIONS

        • Protecting Your Computer with Endpoint Security
        • How to Use Task Manager to Manage and Monitor Your Computer
        • How to Uninstall Any Application from Your Computer
        • How to Check Your Internet Speed & Understand Why It’s Slow

        Table of Contents

        1. Three things that are often confused 2. Does my Verito service include cyber insurance? 3. What we can do for your insurer 4. Security controls, and the human layer 5. If you think you have had a breach What happens after you call us 6. Responsibility for losses 7. Getting help
        Verito Logo

        Secure Cloud Solutions for
        Tax & Accounting Professionals

        3524 Silverside rd. Suite 35B,
        Wilmington, Delaware 19810

        1-855-583-7486
        sales@verito.com

        Services

        • Dedicated Hosting
        • Managed IT Services
        • VeritComplete
        • IT for Law Firms
        • Tax Software Hosting
        • QuickBooks Hosting

        Company

        • About Us
        • Our Data Centers
        • Success Stories
        • Partners
        • Contact Us

        Pricing

        • VeritSpace Pricing
        • VeritGuard Pricing
        • VeritComplete Pricing
        • Free Hosting Trial
        • Hosting Demo

        Resources

        • Blogs
        • FAQs
        • Knowledge Base
        • Our Support Channels
        • Privacy Policy

        Compare

        • vs. Rightworks
        • vs. ACE Cloud
        • vs. Cetrom
        • vs. In-House
        • View All
        4.9 

        125+ Reviews on G2

        G2 High Performer
        AICPA SOC

        Proud Affinity
        Partner of:

        natp logo
        nea logo
        nstp logo
        4.9 

        125+ Reviews on G2

        G2 High Performer
        AICPA SOC

        Proud Affinity Partner of:

        natp logo
        nea logo
        nstp logo

        © 2026 Verito Technologies. All Rights Reserved  |  Privacy Policy  |  Terms & Conditions

        Knowledge Base Software powered by Helpjuice

        Expand