ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Myths Law Firm Administrators Still Believe

Seven common misunderstandings about cyber insurance for law firms, from assuming ransomware is covered to thinking small firms are not targets.

3 min readBy Counsel Cyber Team

Cyber insurance is part of risk management for many law firms, but it is surrounded by assumptions. Some are comforting and wrong. Others are cynical and also wrong. Getting them straight before you renew, or before you file a claim, can save significant time and money.

This post covers seven common myths. It is general information, not insurance or legal advice; your broker and counsel should address your specific policy.

Myth 1: "We have cyber insurance, so we are covered for everything"

Policies cover defined events under defined conditions, subject to limits, sublimits, retentions and exclusions. A policy might pay for forensic investigation but cap social engineering losses at a small amount. Read the declarations and endorsements, and ask your broker to summarize in plain language what is and is not covered.

Myth 2: "Our general liability or professional liability policy already covers cyber events"

Many general liability policies exclude or limit data and cyber losses, and lawyers' professional liability policies may address some claims but not first-party costs like data restoration or business interruption. Some carriers now add specific cyber exclusions or sublimits. Ask each carrier directly what is and is not included, and get the answer in writing.

Myth 3: "Wire fraud is covered automatically"

Funds transfer fraud and social engineering coverage is often a separate insuring agreement with its own limit and conditions, which may include requiring a call-back verification procedure. If you hold client funds in trust, ask whether losses involving those funds are treated differently from firm funds.

Myth 4: "The insurer will just pay the ransom and make it go away"

Policies may address extortion payments, but they typically require consent, may involve sanctions screening and are not guaranteed. The FBI discourages ransom payments in general guidance, noting that payment does not guarantee data will be returned and may encourage further attacks. Insurance does not replace tested backups, which are your most reliable path to recovery.

Myth 5: "Our application is just paperwork"

The application is often treated as a representation about your security. If you said MFA is on for all users and it is not, a carrier may argue misrepresentation after a claim. Treat the application as a formal statement, and have IT verify each answer before signing. Keep the evidence.

Myth 6: "We are too small to be a target"

Attackers frequently use automation to find exposed systems and stolen passwords regardless of size. Small firms hold valuable data, often have fewer defenses and handle large transactions. The question is rarely whether a firm is targeted individually, but whether its defenses stop a routine attempt.

Myth 7: "If we have good security, we do not need insurance"

Good controls reduce the likelihood and impact of incidents, but nothing eliminates them. Insurance transfers part of the financial risk, and carrier-provided breach coaches and forensic partners can be valuable in an emergency. Security and insurance are complements. Insurers increasingly price based on controls, so stronger security often means better terms.

Other misunderstandings worth correcting

  • "Claims are paid quickly." Investigations and coverage determinations take time. Plan for cash flow while waiting.
  • "We can choose our own forensic firm." Many policies require panel vendors.
  • "Notice can wait until we know more." Policies often require prompt notice of incidents and circumstances. Delay can jeopardize coverage.
  • "Our IT provider's insurance covers us." Their policy protects them, not necessarily you, and may have limits that do not match your exposure.

What a sensible approach looks like

  1. Read your policy and keep a one-page summary of limits, retentions and conditions.
  2. Verify that every control described in the application is in place and evidenced.
  3. Record notice procedures and phone numbers where the whole incident team can find them without firm systems.
  4. Ask your broker annually whether coverage matches your risk, including how much client money moves through your accounts.
  5. Invest in controls insurers value: MFA, endpoint detection and response, tested backups, email security and training.

Renewal as a review

Treat the renewal questionnaire as a free annual audit. The questions reflect what carriers see in claims. If you cannot answer one confidently, that is a gap worth closing regardless of the policy.

How Counsel Cyber can help

Counsel Cyber helps law firms prepare for cyber insurance applications by verifying controls and assembling evidence. If you are approaching renewal and want a second set of eyes, we would be glad to help.