ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Exclusions Law Firms Should Read Before Signing

A good cyber policy can still leave gaps. Review common exclusions, sublimits and conditions that law firms should understand before a claim happens.

3 min readBy Counsel Cyber Team

Most law firms read the declarations page of an insurance policy, note the limit and the premium, and file the document. The surprises show up after an incident, when the details of exclusions, sublimits and conditions determine what the carrier will actually pay.

Policies differ widely, and this post is not insurance or legal advice. Treat it as a list of questions to bring to your broker, who can explain how your specific policy language works.

Understand the structure first

Cyber policies are often built from separate coverage parts, each with its own limit, retention and conditions. Common parts include:

  • First-party costs: forensics, restoration, business interruption, extortion payments and notification expenses
  • Third-party liability: claims from clients or others alleging harm from a breach
  • Regulatory defense and penalties where insurable
  • Funds-transfer fraud or social engineering coverage, often with a lower sublimit

Do not assume a large headline limit applies to every part.

Exclusions and limitations to look for

Funds-transfer and social engineering fraud

Wire fraud is a leading risk for law firms, yet coverage for it is often limited to a small sublimit and may require specific verification steps. Read the conditions closely. Some policies pay only if you followed documented call-back procedures.

Failure to maintain security controls

Some policies contain conditions or exclusions tied to representations on the application, such as having MFA or maintained backups. If those statements were inaccurate or the controls lapse, a carrier may dispute coverage. This is why accuracy on the application matters.

War, state-sponsored attack and infrastructure exclusions

Many policies carry exclusions for acts of war or attacks attributed to nation-states, plus exclusions for widespread infrastructure outages. Ask how the policy language defines these and how attribution works.

Unencrypted devices or unpatched systems

Certain policies reduce or deny coverage when losses stem from known unpatched vulnerabilities or unencrypted devices. Ask whether any such conditions apply.

Prior acts and retroactive dates

If a breach occurred before the retroactive date, or an intruder was inside your network before the policy began, coverage can be limited.

Contractual liability

Liability assumed by contract, such as indemnities in outside counsel guidelines, may be excluded or limited. Review client agreements alongside your policy.

Betterment

Policies often will not pay to make systems better than before the incident. Ask how upgrade costs are treated during recovery.

Professional liability overlap

Your malpractice policy and cyber policy may each assume the other responds. Ask your broker how they interact, and whether a gap exists.

Conditions that affect claims

  • Notice requirements. Many policies require prompt notice of a suspected incident. Know the deadline and the hotline.
  • Panel vendors. Some carriers require you to use their approved forensics and breach counsel. Using someone else without approval may jeopardize reimbursement.
  • Consent to settle or pay ransoms. Policies often require carrier approval before you make payments or admissions.

Questions to ask your broker

  1. What are the sublimits for social engineering and funds-transfer fraud, and what conditions apply?
  2. Which security controls are conditions of coverage?
  3. How does the policy treat business interruption and the waiting period?
  4. Does coverage include notification costs for clients, and is there a cap?
  5. Are we required to use specific vendors?
  6. How does this policy coordinate with our professional liability policy?

Match coverage to exposure

Compare limits to what an incident could realistically involve for your firm: number of client records, trust account balances, revenue dependence on systems. ABA Formal Opinion 483 discusses a lawyer's obligations after a breach, including notice to current clients, and notification costs can accumulate.

Insurance does not replace controls

A policy transfers some financial risk. It does not restore a client's trust or return lost files. Basic controls reduce the chance you ever file a claim, and carriers increasingly reward them with better terms.

Next steps

Request the full policy, not only the summary, and mark every exclusion and condition. Counsel Cyber can help you compare those conditions against the controls actually in place, so what you promised an insurer matches what is true.