Many law firms carry a cyber insurance policy and assume that settles the question of financial risk from a breach. Often it does not, because the details of what the policy covers, and how much, vary widely. The time to find the gaps is before a claim, not after.
This post highlights areas to discuss with your broker. Policies differ, and nothing here describes any particular carrier. Always rely on your actual policy language and your broker's advice.
Understand the structure first
Cyber policies typically have two kinds of coverage:
- First-party coverage pays for your own costs: forensic investigation, data restoration, business interruption, ransom negotiation or payment where permitted, notification and credit monitoring, and public relations.
- Third-party coverage responds to claims against you: lawsuits or regulatory actions alleging that you failed to protect data.
Each has its own limits, retentions and conditions, and they may share an aggregate limit.
Gap 1: Funds-transfer fraud and social engineering
Business email compromise is among the most financially damaging threats to law firms handling settlement funds, closings and trust accounts. Yet coverage for fraudulent transfers is frequently sub-limited, meaning capped well below the main policy limit, or conditioned on verification procedures. Some policies exclude it unless a specific endorsement is added.
Ask: Is funds-transfer fraud covered? What is the sub-limit? Does it include money held in trust for clients? What verification steps does the carrier expect you to follow?
Gap 2: Client funds
A loss of money belonging to clients may be treated differently from a loss of the firm's own funds. Clarify how the policy treats trust account losses and whether your professional liability policy or crime policy interacts.
Gap 3: Interaction with other policies
Your lawyers professional liability, crime, general liability and cyber policies may overlap or leave seams. Ask your broker for a map showing which policy responds to which scenario, such as ransomware, wire fraud or a stolen laptop, and whether any of them exclude the others' territory.
Gap 4: Vendor and cloud incidents
If your document management provider or IT vendor is breached, does your policy respond? Look for "dependent business interruption" and coverage for losses arising from third-party systems, and note any sub-limits.
Gap 5: Waiting periods and retentions
Business interruption coverage often starts only after a waiting period measured in hours. Retentions, the amount you pay before coverage kicks in, can be significant for a small firm. Make sure the numbers are ones you can absorb.
Gap 6: Conditions and warranties
Policies may condition coverage on maintaining controls described in the application, such as MFA or tested backups. If you stated it, you need to maintain it. Review your application answers each year against reality.
Gap 7: Exclusions
Read the exclusions for items such as:
- Failure to maintain minimum security standards
- Unencrypted devices
- War or state-sponsored attacks, which some policies define broadly
- Prior known incidents
- Betterment, meaning improvements beyond restoring your systems to their earlier state
Gap 8: Required vendors and consent
Many policies require using a panel of approved breach response firms or require carrier approval before you hire anyone. Hiring your own forensic firm in the first panic could jeopardize reimbursement. Keep the notice contact information outside your own network.
Gap 9: Limits that fit the firm
A limit that seemed adequate when you purchased it may not reflect a growing client roster or more sensitive matters. Ask your broker what typical incident costs look like for firms your size, and for scenarios rather than a one-size recommendation.
Questions to ask your broker
- Walk me through what happens, step by step, if we suffer ransomware.
- Is social engineering coverage included, and at what limit?
- Are there conditions we must maintain to keep coverage?
- Do we have a required response vendor?
- How does this policy coordinate with our malpractice and crime coverage?
Insurance is not security
Even the best policy cannot restore client trust or erase reputational harm. Controls that prevent incidents still matter most.
How Counsel Cyber helps
We can map your actual controls against what your carrier expects, and support your broker conversation with accurate technical detail. Ask us for a short coverage-readiness review.