ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Applications: What Underwriters Ask Law Firms

A walkthrough of the questions cyber insurance applications typically ask law firms about MFA, backups, email security and training, and how to prepare.

3 min readBy Counsel Cyber Team

Cyber insurance applications used to be short forms that a firm administrator could complete in ten minutes. Today they are often detailed security questionnaires, and the answers influence whether coverage is offered, on what terms and at what price. For a law firm, a careless answer can also create problems at claim time.

This guide explains the types of questions underwriters commonly ask and how to prepare accurate answers. Forms vary by carrier, so use this as a general map rather than an exact checklist.

Why accuracy matters more than speed

An application is a representation to the insurer. If a firm answers that MFA is enforced for all email accounts and a breach later reveals that several accounts had no MFA, the carrier may dispute coverage. The safest approach is to verify each answer with evidence and to describe partial implementations honestly.

If you are not certain about a technical answer, ask your IT provider to confirm it in writing before you sign. Have a partner review the final application.

Questions you can expect

Multi-factor authentication

Underwriters frequently ask whether MFA is required for:

  • Email access, including webmail.
  • Remote access such as VPN or remote desktop.
  • Administrator and privileged accounts.
  • Access to cloud systems holding client data.
  • Backup systems.

Be precise. "Enabled" and "enforced" are different. If some users are exempt, say so and explain compensating controls.

Backups

Common questions include whether backups are performed regularly, whether at least one copy is offline or immutable, whether backups are encrypted, and whether restores are tested and how often. Have your last restore test documentation ready.

Email security

Carriers ask about spam and phishing filtering, link and attachment scanning, and email authentication such as SPF, DKIM and DMARC. They also ask whether your firm has a process to verify payment instruction changes.

Endpoint protection and monitoring

Expect questions about endpoint detection and response, who monitors alerts, and whether coverage runs around the clock. Some applications ask for the specific product name.

Patching and vulnerability management

How quickly do you apply critical patches? Do you retire unsupported operating systems and software? Is there regular vulnerability scanning?

Training and policies

Applications ask whether staff receive security awareness training, how often, and whether phishing simulations are run. They may also ask about written policies: acceptable use, incident response, and vendor management.

Incident response

Do you have a written plan? Is it tested? Do you have a relationship with a forensic firm or have you identified one? Know where your insurer's required notification steps are documented.

Data handling

Carriers want to know what sensitive data you hold, how much, and how it is protected. Law firms often hold personal data, financial information and health information, which can affect underwriting.

Funds transfer controls

For law firms this section is critical. Expect questions about dual approval, call-back verification and limits on who can change payment details. Some policies treat social engineering fraud as a separate coverage with its own conditions and sublimits, so read what your policy requires.

How to prepare

  1. Gather evidence. Collect screenshots or reports showing MFA enforcement, backup status, patch compliance and training completion.
  2. Appoint a coordinator. One person should own the application, collect inputs and track changes.
  3. Review last year's answers. Note what has changed. Mismatches between years raise questions.
  4. Close easy gaps before submission. If you are missing MFA on a few accounts, fix it first rather than reporting a gap.
  5. Ask the broker. An experienced broker can explain what each question is trying to measure and which improvements matter most to underwriters.

What to do with the policy itself

Do not stop at the application. Read the policy for coverage limits, waiting periods, exclusions, and conditions that require specific security measures. Understand the claims process, including whom to call and how quickly. Keep the insurer's hotline number somewhere accessible offline.

Using the application as a roadmap

A security questionnaire is, in effect, a checklist of widely accepted controls. Firms that treat it as an annual review rather than a hurdle tend to improve steadily. The same evidence also helps with client security questionnaires, which often ask overlapping questions.

Counsel Cyber helps law firms gather the technical evidence for applications, confirm that each answer is supportable, and close gaps before renewal. If your renewal is approaching, we can work with your administrator and broker well ahead of the deadline.