ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Reading Your Cyber Policy: Conditions and Exclusions to Check

A cyber insurance policy only helps if its conditions are met. These are the sections law firm administrators should read closely before a claim ever happens.

3 min readBy Counsel Cyber Team

Most firms buy cyber insurance through a broker, skim the summary page and file the policy. The first time many administrators read it closely is after an incident, which is the worst time to discover that a condition was not met or that a type of loss was excluded.

You do not need to be an insurance expert to read a policy usefully. You need to know which sections matter, what questions to ask your broker and which operational commitments you made when you applied. This post highlights the areas to read. It is general information and not insurance or legal advice; your broker and counsel should interpret your specific policy.

Coverage grants: what the policy says it will pay for

Cyber policies are usually built from several parts, and the names vary by carrier. Look for how each is described.

  • First-party costs: your own expenses after an incident, such as forensic investigation, restoring data, business interruption and sometimes extortion payments.
  • Third-party liability: claims from clients or others alleging harm from a breach or privacy failure.
  • Regulatory and notification costs: legal advice, notification letters, credit monitoring and regulatory defense where applicable.
  • Crime or social engineering coverage: funds transfer fraud and business email compromise losses, which are frequently subject to separate limits or require a separate endorsement.

Ask your broker specifically about wire fraud. Many firms assume they are covered and discover the sublimit is small compared with the amounts that pass through their trust account.

Limits, sublimits and retentions

A headline limit can be misleading when individual coverages carry lower sublimits. Make a one-page summary: the overall limit, each sublimit, the retention (the amount you pay before coverage starts) and any waiting period for business interruption. Check whether defense costs erode the limit.

Conditions and warranties

This is the section that most often surprises policyholders. The application you signed describes the controls your firm has in place, such as MFA, backups, endpoint protection and training. Carriers may rely on those statements. If a claim arises and the controls were not actually in place as described, the carrier may dispute coverage.

Read your application alongside the policy and ask whether each answer is still true today. If you said MFA is required on all email accounts, confirm that is true for every account, including shared mailboxes and legacy protocols.

Exclusions worth noticing

Exclusions vary, but ask about:

  • War or state-sponsored attack exclusions. Their scope has been the subject of discussion in the industry, so ask how your carrier's wording applies.
  • Failure to maintain security. Language about failing to keep minimum controls in force.
  • Unencrypted devices or data.
  • Prior known incidents.
  • Infrastructure and vendor outages.
  • Betterment, meaning the carrier may pay to restore systems to their prior state but not to improve them.

Notice and claims procedures

Policies typically require prompt notice of an incident or circumstances that could lead to a claim, and some require using the carrier's panel of breach counsel or forensic firms. Using an unapproved vendor can jeopardize reimbursement.

Write down, on one page, the claim reporting number, the policy number, the broker's contact and the carrier's required first steps. Give copies to the managing partner, the administrator and your IT provider. A breach at two in the morning is no time to hunt through email.

Consent before settling or paying

Many policies require the carrier's consent before you agree to pay a ransom or settle a claim. Know the rule in advance.

Questions to ask your broker

  1. Is social engineering and wire fraud covered, and at what limit?
  2. Which security controls are conditions of coverage?
  3. Do we have to use specific vendors after an incident?
  4. How does the policy treat funds held in trust?
  5. Is regulatory coverage included for our states?
  6. What would reduce our premium or improve terms at renewal?

Align operations with the paper

Once you know the conditions, assign owners. If MFA is a condition, someone should be monitoring MFA coverage monthly. If backups are tested, someone should file the results. Insurance should not be a promise your IT environment quietly stops honoring.

How Counsel Cyber can help

Counsel Cyber helps firms verify that the controls described in insurance applications are actually in place, and documents the evidence for renewal. If you would like help comparing your policy conditions to your real environment, we are happy to assist.