ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

How to Prepare for a Cyber Insurance Renewal at Your Law Firm

Cyber insurance applications keep getting more detailed. Use this 60-day preparation plan to gather evidence, close gaps and avoid costly misstatements.

3 min readBy Counsel Cyber Team

Cyber insurance renewals used to be a one-page form and a quick signature. Many carriers now ask for detailed answers about multi-factor authentication, backups, endpoint protection and incident response, and some run external scans of your domain before quoting. Law firms, which hold confidential client information and large trust balances, get close attention.

The good news is that preparation is mostly organization. Start about 60 days before renewal and work through the steps below.

Days 60 to 45: gather the facts

Pull your current policy

Review limits, retention (deductible), sublimits for items such as social engineering or funds-transfer fraud, and any conditions that require specific controls. Note exclusions. If you do not understand a clause, ask your broker to explain it in writing.

Collect last year's application

Your answers are statements the carrier relied on. Compare them with reality today. If something changed, such as a new office, a new system or a lapse in a control, be prepared to explain.

Days 45 to 30: verify your controls

Carriers commonly ask about the following areas. Confirm each one rather than assuming.

  1. Multi-factor authentication on email, remote access, administrator accounts and, ideally, all cloud applications.
  2. Endpoint detection and response on laptops, desktops and servers, with someone monitoring alerts.
  3. Backups that are tested, kept offsite and protected from deletion by ransomware.
  4. Email security such as filtering for phishing and spoofing, and published SPF, DKIM and DMARC records.
  5. Patching on a regular schedule for operating systems and key applications.
  6. Security awareness training with documented completion.
  7. Written incident response plan that names contacts and has been reviewed.
  8. Funds-transfer procedures that require call-back verification and dual approval.

For each, gather proof you could show: a screenshot, a report or a policy document. Evidence turns a hopeful answer into a defensible one.

Days 30 to 15: close gaps

If you find a missing control, fix it before you apply where possible. Turning on MFA or documenting a procedure often costs little. If a gap cannot be closed in time, tell your broker early. Carriers react better to a disclosed gap with a remediation plan than to a surprise.

Days 15 to 0: complete the application carefully

  • Have the person who knows the answer complete each section, rather than guessing.
  • Do not round up. Answering "yes" to a control that is only partly deployed can cause problems if you ever file a claim.
  • Keep a copy of the submitted application and the supporting evidence together.
  • Have a partner review and sign.

Mistakes to avoid

  • Treating the form as a formality.
  • Letting the broker or an assistant answer technical questions without IT input.
  • Ignoring the funds-transfer or social engineering coverage until a wire goes wrong.
  • Not knowing your carrier's notification process. Many policies require prompt notice of a suspected incident and may require using the carrier's approved response vendors.

Questions to ask your broker

  • What controls do you expect carriers to require this cycle?
  • Are our social engineering and funds-transfer fraud sublimits adequate for our trust activity?
  • Does the policy cover regulatory notification costs, forensics and business interruption?
  • What is the claims reporting procedure, and who should we call first?

A note on honesty

Hypothetically, a firm that overstates its controls on an application may find a claim contested later. Accuracy protects you. Insurance is a backstop, not a substitute for the controls themselves.

Keep the evidence file alive

After the policy binds, do not let the evidence file go stale. Save the application, the broker correspondence and your control screenshots in one folder, and set a calendar reminder to update it each quarter. When a client questionnaire arrives or an incident occurs, that folder will answer most of the questions immediately. It also makes the next renewal far less painful, since you will be updating a record instead of reconstructing one from memory.

How we help

Counsel Cyber helps law firms assemble the evidence carriers ask for and close the gaps that cost the most at renewal. If you would like us to review your draft application against your actual environment before it goes out, we are glad to do so.