Cyber insurance renewals used to be a one-page form and a quick signature. Today, many carriers ask for detailed answers about multi-factor authentication, backups, endpoint monitoring and incident response before they will quote coverage, and some ask for supporting evidence. For a law firm, the application is also a legal document: inaccurate answers can create trouble at the exact moment you need the policy.
Starting preparation 60 to 90 days before renewal gives you time to fix gaps rather than simply disclose them.
Why accuracy matters more than speed
Whoever signs the application is attesting that the answers are true. If a firm says MFA is enforced on all email accounts and a handful of legacy accounts were exempt, a carrier could raise that discrepancy after a claim. Policies and carriers differ, so ask your broker how misstatements are treated, but the safe rule is simple: answer only what you have verified.
Controls that applications commonly ask about
While every carrier's form is different, the same themes appear again and again:
- Multi-factor authentication on email, remote access, and privileged accounts
- Endpoint detection and response, and whether someone monitors it around the clock
- Backups: how often, whether copies are offline or immutable, and whether restores have been tested
- Patching practices for operating systems and internet-facing systems
- Email security filtering and how you handle payment-change requests
- Security awareness training and phishing simulations
- A written incident response plan, and whether it has been exercised
- Limits on administrator accounts
- End-of-life software still in use
A step-by-step preparation process
- Get last year's application. Compare what you promised then with what is true now. Anything that slipped needs attention.
- Build an evidence folder. Screenshots or reports showing MFA enforcement, a backup restore test log, training completion records, and your incident response plan.
- Run a gap review with your IT provider. For each question, mark it Yes, Partial or No, then decide what can be fixed before the renewal date.
- Address the cheap, fast fixes first. Enforcing MFA on remaining accounts, retiring unused administrator accounts, and scheduling a restore test are examples that often take days, not months.
- Document exceptions honestly. If a legacy system cannot support MFA, record the compensating controls and raise it with your broker.
- Have a partner review before signing. The person with authority to bind the firm should understand what is being attested.
Work with your broker, not around them
A broker who knows the legal sector can tell you how different carriers treat law firms, what coverage limits are typical for firms your size, and what the policy actually covers. Ask specifically about:
- Coverage for funds-transfer fraud or social engineering, which is often sub-limited or excluded in basic policies
- Whether you must use a carrier-approved incident response firm
- How the policy responds to a breach involving client data held by a vendor
- What notification and claims-reporting deadlines apply
Common mistakes
- Letting the person who fills out the form guess at technical answers
- Answering based on what the firm intends to do rather than what is deployed
- Forgetting satellite offices, remote attorneys or acquired practices
- Not telling the broker about a material change, such as a new office or a merger
Treat the form as a free security roadmap
Many carriers' questions line up with what national guidance, such as CISA's recommendations and the NIST Cybersecurity Framework 2.0, would tell you to do anyway. If answering a question makes you uncomfortable, that is useful information.
Finally, keep a dated copy of the submitted application and your evidence folder. When the next renewal arrives, you will start from a verified record instead of from memory, and you will be able to show your carrier and your clients a consistent story about the controls the firm maintains year over year.
How Counsel Cyber can help
We help firms assemble the evidence, close gaps and complete the technical sections of renewal applications accurately. If your renewal is coming up, reach out and we can run a readiness review before the deadline.