Cyber insurance for law firms has changed. Years ago, an application might have been a short form. Today carriers commonly ask detailed questions about security controls and may decline coverage, raise premiums or add restrictions when answers show weaknesses. Preparing in advance is the most effective way to keep coverage available and affordable.
This article describes common themes in underwriting. Questions and requirements vary by carrier and change over time, so your broker is the right source for your specific application. Nothing here is insurance or legal advice.
Why Accuracy Matters
An application is a statement of fact on which the insurer relies. If you answer "yes" to a control that is only partly in place, a later claim could be complicated by a dispute over the application. Answer carefully, verify with IT and keep records of your answers.
Controls Underwriters Commonly Ask About
Multi-factor authentication
Probably the most emphasized control. Expect questions about MFA on email, remote access, privileged and administrator accounts, and sometimes backups and cloud applications. Partial coverage is a common cause of difficulty. "Everyone except a few partners" is not a yes.
Endpoint detection and response
Carriers frequently ask whether managed detection and response or an equivalent tool is on laptops and servers, and who monitors it. Traditional antivirus alone may no longer satisfy some underwriters.
Backups
Expect questions about frequency, whether backups are encrypted, kept offline or immutable, stored separately from the main network and tested. Be ready to say when you last performed a restore test.
Patching and vulnerability management
How quickly are critical updates applied? Do you retire unsupported software? Are internet-facing systems scanned?
Email security
Filtering, protection against phishing and spoofing, and DMARC enforcement are common topics.
Security awareness training and phishing simulations
How often is training offered, who attends and how are results tracked?
Incident response planning
Do you have a written plan, a contact list and a practice of testing it?
Privileged access and administrator accounts
Do admins have separate accounts, is access reviewed and are shared passwords prohibited?
Wire-transfer controls
For law firms specifically, questions about callback verification and dual approval for payments are common, since funds-transfer fraud is a leading source of claims. Ask your broker how social-engineering and funds-transfer coverage is handled, because some policies limit or sublimit it.
Data and vendors
Volume of sensitive records, encryption practices and how third-party providers are managed.
Build a Renewal Package
Start 90 to 120 days before renewal if you can.
- Gather evidence. MFA settings reports, backup logs and restore tests, training records, policies and vendor lists.
- Close easy gaps. Turn on MFA where it is missing, install missing tools and retire obsolete systems before the application is due.
- Prepare a short narrative. A one-page summary of your security program can help a broker present your firm favorably.
- Review coverage, not just price. Check limits, retentions, exclusions, sublimits for social engineering, whether breach response services are included and whether the policy requires insurer approval of response vendors.
- Align with other applications. Answers on questionnaires, client agreements and insurance forms should agree.
Know Your Policy Before You Need It
Read the notice requirements. Many policies require you to report incidents quickly and to use approved response providers. Keep the claims hotline number in your incident plan, printed. Ask your broker to walk you through what is and is not covered.
Related Coverage
Cyber insurance usually does not replace professional liability coverage. Ask how the two policies interact, and whether either covers claims arising from technology errors or from fraud. A broker experienced with law firms can help.
Improvement Pays Twice
Controls that satisfy underwriters also reduce the odds of needing the policy. Multi-factor authentication, monitored endpoint protection and tested backups are not just checkboxes. They are some of the most useful defenses against the incidents that produce claims.
Counsel Cyber helps law firms prepare for cyber-insurance applications by verifying controls, gathering evidence and closing gaps. We do not sell insurance, but we can work alongside your broker so your answers are accurate and well supported.