ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Applications: Why Honest Answers Protect the Firm

Cyber insurance applications ask detailed questions about your controls. Inaccurate answers can jeopardize a claim. Here is how to complete one carefully.

3 min readBy Counsel Cyber Team

A law firm's cyber insurance application can look like an IT questionnaire, and many firms hand it to whoever is available, check the boxes quickly, and move on. That is understandable, but it is risky. The application is a set of representations to the insurer, and if a claim arises, the insurer may compare what you said with what was actually in place.

This post explains how to approach the application so that your coverage is more likely to respond when you need it. It is general information, not legal or insurance advice; talk to your broker and counsel about your own policy.

What Insurers Typically Ask

Applications vary, but most carriers focus on the same core controls:

  • Multi-factor authentication for email, remote access and administrator accounts
  • Endpoint detection and response on laptops and servers
  • Backups: frequency, separation from the main network, and whether restores are tested
  • Email security and filtering
  • Patching practices
  • Security awareness training and phishing simulation
  • Incident response planning
  • Controls around funds transfer, such as call-back verification
  • Management of vendors that hold sensitive data
  • Whether you have experienced prior incidents or claims

The Risk of Overstating

It is tempting to answer "yes" to a question when the control is mostly in place. If MFA covers most users but not all, "yes" may be inaccurate. The insurer may treat a material misstatement as grounds to dispute or even rescind coverage. Whether that happens depends on the policy language and the facts, which is exactly why you want counsel and your broker involved early.

The safer approach is to answer precisely. Many applications allow comments or have options such as "partially" or "in progress." Use them.

A Careful Process

1. Assign a single owner

One person, usually the firm administrator, coordinates the application and gathers input from the IT provider, the managing partner and accounting.

2. Verify, do not assume

For each control, ask the IT provider for evidence: a report showing MFA enforcement by user, a coverage report for endpoint protection, a backup summary with last restore test. If you cannot get evidence, treat the answer as unverified.

3. Close gaps before applying when possible

Sometimes the best answer is made true before submission. If a control can be turned on within days, such as MFA for a remaining set of accounts, do it first and then answer accurately.

4. Have two people review

An attorney or partner should read the final application with the administrator. The signature carries weight.

5. Keep a copy

Save the submitted application and your supporting evidence. At renewal, start from the prior answers and update them, rather than copying forward without checking.

Controls That Often Surprise Firms

  • Legacy accounts. Old accounts without MFA, such as shared mailboxes or former employees, can make "MFA for all users" untrue.
  • Backups on the same network. Carriers often ask whether backups are offline or immutable.
  • Personal devices. If staff access client email on personal phones, how is that managed?
  • Remote access. Any remote desktop exposed to the internet will raise concerns.
  • Vendors. If a third party handles your data, carriers may ask about their security.

Reading the Policy as Well as the Application

Beyond the application, read the policy itself. Useful questions for your broker:

  • What exactly triggers coverage, and what are the notice requirements after an incident?
  • Are there sublimits for ransomware, funds transfer fraud or business interruption?
  • Does the policy require you to use the carrier's approved incident response vendors?
  • Are there conditions tied to specific controls, such as MFA, that could limit payment if they are not maintained?
  • Does coverage extend to social engineering and wire fraud?

Keep Controls True All Year

Answering accurately once is not enough. Controls change when staff leave, new systems are added, or IT providers change. Revisit your key controls quarterly so renewals do not reveal surprises.

How Counsel Cyber Helps

Counsel Cyber helps law firms gather evidence for insurance applications, close gaps before renewal, and keep controls documented and current. If your renewal is approaching, we can run a pre-application review so the answers you give match what is actually in place.