ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Renewal Readiness: A 90-Day Plan for Law Firms

Work backward from your renewal date. This 90-day plan covers the controls to fix, evidence to collect and conversations to have with your broker.

3 min readBy Counsel Cyber Team

Cyber insurance renewals reward firms that prepare and surprise firms that do not. Carriers have become more selective about the controls they expect, and a firm that cannot show multi-factor authentication, tested backups and monitored endpoint protection may see higher premiums, lower limits or added conditions. Waiting for the broker's application to arrive turns improvement into a scramble.

This 90-day plan works backward from your renewal date. The details will vary, so adapt it to your carrier's application and your firm's size.

Days 90 to 75: Orient and assess

  1. Gather last year's application and policy. Note every technical commitment you made.
  2. Meet your broker and ask what the carrier is focusing on this year, whether the carrier has changed its minimum requirements and how your premium might change.
  3. Assign an owner, usually the administrator, with an IT contact and a partner sponsor.
  4. Run a control check against the typical application topics: MFA, endpoint detection and response, backups, email security, patching, training, incident response and payment verification.
  5. List the gaps with estimated effort and cost.

Days 75 to 45: Fix what matters most

Prioritize the items that carriers and attackers care about most.

Authentication

Make sure MFA is enforced, not just offered, on email, remote access, administrator accounts and backup consoles. Close exceptions like shared mailboxes and old service accounts.

Backups

Verify that backups are protected from deletion, ideally with an immutable or offline copy, and run a documented restore test. Save the report.

Endpoint and monitoring

Confirm that endpoint detection and response is deployed on every laptop and server and that someone reviews alerts. List any unmanaged devices and either enroll or retire them.

Email security

Check that filtering is active, external sender warnings are on and that SPF, DKIM and DMARC are published, with enforcement planned or in place.

Patching and end-of-life systems

Update operating systems, firewalls and critical applications. Replace or isolate any system that no longer receives security updates.

Payment controls

Document and enforce your call-back verification procedure for wires and changes to payment instructions, along with dual approval. Carriers commonly ask about this because social engineering losses are frequent.

Days 45 to 30: Train and document

  • Complete security awareness training for all staff and keep the completion record.
  • Run a phishing simulation and record results.
  • Update the written incident response plan with current contacts and your carrier's claim hotline.
  • Review and update policies on passwords, devices, acceptable use and AI tools.
  • Hold a short tabletop exercise with partners, and record the outcome.

Days 30 to 15: Build the evidence file

Assemble one folder with:

  1. Screenshots or exports showing MFA enforcement and conditional access.
  2. Endpoint protection coverage reports.
  3. The latest backup restore test.
  4. Training and simulation records.
  5. The incident response plan.
  6. Network diagram and an asset list.
  7. Policy documents with dates.

This folder helps with the insurance application, client questionnaires and your own planning.

Days 15 to 0: Complete the application accurately

Fill in the application using the evidence, and have the IT lead review the technical answers. A partner or officer who signs it should read the final version. Do not overstate. If a control is partial, say so and describe the plan. Keep a copy of exactly what was submitted.

Questions to confirm with your broker

  • Are the sublimits for social engineering and ransomware adequate for our exposure?
  • What are the notice requirements and who do we call first?
  • Does the policy require us to maintain specific controls throughout the term?
  • Are there discounts or credits for particular security measures?

After the renewal

Set calendar reminders to keep controls in place through the year. Re-verify MFA and backups quarterly. Keep your evidence folder current, because the next questionnaire may come at any time.

Connecting to professional duties

Carriers and clients are asking more because the ethics rules ask lawyers to take reasonable steps to protect client information under Rule 1.6(c), and ABA Formal Opinion 483 discusses obligations after a breach. A well-prepared firm is better positioned for both.

How Counsel Cyber helps

Counsel Cyber runs renewal readiness reviews for law firms, closes control gaps and assembles the evidence folder. If your renewal is within the next quarter, contact us and we will start with a short assessment.