Most firms read their cyber insurance application more closely than the policy that results from it. Yet the policy is what decides whether the firm is covered when something goes wrong. Cyber policies vary widely, use dense language, and often contain conditions that only matter on the worst day.
This guide offers a reading plan for the managing partner or administrator. It is not insurance or legal advice, and your broker and counsel should confirm how the terms apply to your firm.
Start with the declarations page
The declarations page summarizes the essentials. Note:
- The policy period and whether coverage is written on a claims-made basis.
- The overall limit and each sublimit.
- The retention, which is the amount the firm pays before coverage applies.
- The retroactive date, if any, which can affect coverage for events that began earlier.
Understand the coverage parts
Cyber policies are usually made up of several coverages, sometimes first party, sometimes third party. Check which are included.
First-party coverages
These address the firm's own losses and response costs. Common categories include:
- Incident response and forensics, including investigators and breach counsel.
- Business interruption, and how the waiting period and calculation work.
- Data restoration, meaning the cost to recover or recreate data.
- Cyber extortion, including ransomware demands and negotiation costs.
- Notification and credit monitoring costs.
- Public relations support.
Third-party coverages
These address claims against the firm:
- Privacy and network security liability.
- Regulatory defense and penalties, where insurable.
- Media liability.
Consider how this coverage coordinates with your lawyers' professional liability policy. Overlaps and gaps are common, and some cyber events could implicate both policies. Ask your broker to explain how they interact.
Pay attention to funds transfer fraud
Law firms are frequent targets of fraudulent transfer schemes. Check:
- Whether social engineering or funds transfer fraud is covered, and its sublimit.
- Whether the coverage requires verification procedures, such as a call-back to a known number, as a condition.
- Whether funds held in trust accounts or belonging to clients are treated differently from the firm's own money.
These details matter, because a policy may include coverage but exclude losses where specified verification steps were skipped.
Read the exclusions and conditions
Look closely for:
- War or state-sponsored attack exclusions. Understand the wording and how it has been applied in the market.
- Failure to maintain security. Some policies exclude or reduce coverage if the firm did not maintain the controls described in the application, such as MFA.
- Unencrypted devices or failure to patch known vulnerabilities.
- Prior knowledge exclusions.
- Contractual liability exclusions, which can affect obligations you assumed in client agreements.
- Betterment language, which may limit paying to upgrade systems after an incident.
If a condition says you must maintain particular controls, ask IT to confirm you meet it and to alert you if that changes.
Know the claims process before you need it
- Notice requirements. Find the deadline and method to report an incident. Many policies require prompt notice, and a delay can threaten coverage.
- The hotline. Save the insurer's incident number in a place you can reach if email is down.
- Panel vendors. Some policies require you to use the insurer's approved forensic firms and breach counsel, or to get consent before engaging others. Calling your own provider first could cause problems.
- Consent to settle or pay a ransom. Know who must approve what.
- Cooperation obligations. Understand what information the insurer may request.
Put these points into your written incident response plan.
Check consistency with the application
Compare the policy to the application you signed. Any inaccuracy, even one made in good faith, can create disputes. If circumstances change between application and policy period, ask the broker whether notice is needed.
Ask your broker pointed questions
- What are the three most likely ways this policy would not respond to a loss at a firm like ours?
- How do social engineering and trust account funds work here?
- How does this coordinate with our professional liability policy?
- What security conditions must we maintain?
- What do other law firms commonly add or change?
Keep it current
Review the policy annually and after major changes such as mergers, new offices, new practice areas, or large increases in sensitive data. Share a summary with partners so that more than one person knows how to respond.
Counsel Cyber does not sell insurance, but we help law firms confirm that their security controls match what their applications and policies promise, and we help prepare for the claims process. If you want a technical read on the conditions in your policy, we can work through them alongside your broker.