ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Exclusions Law Firms Overlook Until a Claim

Cyber policies contain exclusions and conditions that can shrink or void a claim. Learn which terms law firm administrators should read closely before a loss.

3 min readBy Counsel Cyber Team

A cyber insurance policy can look comprehensive on the cover page and then narrow considerably in the definitions, sublimits, and exclusions. Firms generally discover the difference after an incident, when a claim is disputed or paid at a fraction of what they expected. Reading the policy carefully with your broker, before renewal and before a loss, is time well spent.

This post is general information, not insurance or legal advice. Policies differ widely, so rely on your own policy language and your broker for specifics.

Sublimits that surprise people

Many policies state a headline aggregate limit, then apply smaller limits to specific types of loss. Ask your broker to list every sublimit in plain terms.

  • Funds transfer or social engineering fraud. Coverage for a fraudulent wire may be subject to a much lower limit, and may be conditioned on verification procedures.
  • Ransomware or extortion. Some policies apply a sublimit or a higher retention, or co-insurance, so the firm shares a percentage of the loss.
  • Business interruption. Check the waiting period before coverage begins, how lost income is measured, and whether it includes outages at a vendor.
  • Regulatory fines and penalties. Coverage may depend on whether such fines are insurable under applicable law.
  • Reputational harm. Some policies cover limited public relations costs, others do not.

Conditions that can undermine coverage

Representations in the application

The answers on your application are statements the insurer relies on. If a policy requires MFA on all remote access and you attested to it, a gap discovered after a claim may lead the carrier to dispute coverage or, in serious cases, seek to rescind. This is why accuracy matters more than a quick signature.

Minimum security requirements

Some policies make coverage depend on maintaining specific controls throughout the policy period. Ask:

  • Which controls are described as conditions of coverage?
  • What happens if one lapses mid-term, for example if endpoint protection is not installed on a new laptop?
  • Does the carrier require notice of material changes?

Notice requirements

Policies commonly require prompt notice of a claim or incident, sometimes within a specific number of days. Late notice can jeopardize coverage. Know where the hotline number is and who calls it.

Panel vendors and consent

Many carriers require the use of their approved breach counsel and forensic firms, and require consent before incurring costs or engaging others. Hiring your own responders in a panic, without checking, may leave you with unreimbursed costs.

Common exclusions to examine

  • War and state-backed attack exclusions. Wording varies widely, and some are broad. Ask how attribution would be decided.
  • Failure to maintain security. An exclusion for failure to follow minimum required practices can be broadly worded.
  • Prior acts or known circumstances. If an intrusion began before the policy period or before the retroactive date, it may not be covered.
  • Unencrypted devices. Some policies limit coverage for losses involving unencrypted laptops or media.
  • Contractual liability. Obligations you took on by contract, such as a client indemnity, may be excluded or limited.
  • Betterment. The policy may not pay to upgrade systems beyond restoring what you had.
  • Infrastructure outages. Failures of power, internet, or a cloud provider may be excluded or covered only in limited ways.
  • Professional services. Coverage overlaps with, and may be excluded from, your professional liability policy. Ask how the two policies interact if a cyber incident harms a client.

Questions to put to your broker

  1. What would be paid, in order, if we had a ransomware incident that took us offline for a week?
  2. Is a wire fraud loss caused by a compromised vendor email covered, and under what conditions?
  3. Does the policy cover incident response costs that exceed the limit, or do they erode it?
  4. How are retroactive dates set, and do we have full prior acts coverage?
  5. Does coverage extend to data held by our vendors?
  6. What notice must we give, to whom, and how fast?
  7. Are limits shared with other policy sections?

Keep your evidence

If a claim happens, you will need to show the controls you represented. Keep copies of your application, MFA reports, backup tests, training records, and logs. Having this organized in advance helps both claims and renewals.

Revisit the coverage annually

Your firm changes, and so do policies and market conditions. Review limits against realistic loss scenarios, including the cost of notifying clients, forensic investigation, restoration, and downtime.

Our role

Counsel Cyber does not sell insurance, but we help firms confirm that the controls they attested to are actually in place and documented. If you want to compare your policy requirements to your real environment, we can help with that review.