Buying cyber insurance and understanding it are different things. Many firms renew each year based on a quote and a summary, and first read the policy in earnest after an incident, which is the worst time to learn that funds transfer fraud has a sublimit or that you needed to call a specific hotline before hiring a forensic firm.
This post highlights the terms law firms commonly overlook. It is general education, not insurance or legal advice. Policies differ widely, so sit down with your broker and, where appropriate, counsel to review your own.
Two kinds of coverage: first party and third party
First-party coverage pays for the firm's own costs: forensic investigation, data restoration, business interruption, crisis communications, notification expenses, credit monitoring for affected people and sometimes ransom or extortion payments subject to legal limits.
Third-party coverage responds to claims by others, such as a client alleging that the firm failed to protect its data, along with regulatory proceedings and defense costs.
Know which components your policy actually includes. Not every policy includes all of them.
Terms to read closely
Limits and sublimits
The overall limit may look generous while specific categories carry much lower sublimits. Common candidates include social engineering and funds transfer fraud, ransomware, regulatory fines and business interruption. If a wire fraud loss is likely to be your largest exposure, check what the policy pays for it and what conditions apply.
Retention
The retention is the amount you pay before coverage begins, similar to a deductible. Confirm what it is and whether different coverages carry different amounts.
Business interruption waiting periods
Many policies impose a waiting period before lost income is covered. For a small firm, a multi-day outage may fall largely within the waiting period. Understand how the policy defines lost income and whether it covers extra expenses to keep operating.
Panel vendors and prior consent
Policies often require that you use the carrier's approved breach counsel and forensic vendors, or that you get consent before engaging others. Hiring your own favorite vendor first can jeopardize reimbursement. Write the claim hotline number and panel list into your incident plan.
Notice requirements
Most policies require prompt notice of an incident or a circumstance that may lead to a claim. Know what counts and how quickly you must report. Late notice can affect coverage.
Exclusions
Read them carefully. Typical topics include:
- Failure to maintain minimum security standards described in your application.
- War or state-sponsored attacks, a category that has been the subject of evolving policy language.
- Prior known incidents.
- Bodily injury and property damage, which are usually handled elsewhere.
- Contractual liability assumed beyond what the law would impose.
- Unencrypted devices, in some policies.
Conditions tied to the application
Statements you made on the application can become conditions. If you stated that MFA is enforced for all users and later discover gaps, there may be consequences. Keep the application and verify that the controls described remain true throughout the policy term.
Check for professional liability overlap
Lawyers professional liability policies and cyber policies may overlap or leave gaps, and many professional liability policies exclude or limit cyber-related claims. Ask your broker to compare them side by side and identify whether a cyber event could fall between them.
Retroactive dates and claims-made terms
Many liability coverages are written on a claims-made basis. This means the claim must be made and reported during the policy period, and a retroactive date may limit coverage for earlier events. Changing carriers without attention to this can create a gap.
Dependent business and vendor outages
Ask whether the policy covers losses arising from an outage at a vendor, such as a cloud provider or managed service provider, and under what conditions.
Questions for your broker
- What are our sublimits for funds transfer fraud, ransomware and business interruption?
- Which vendors must we use, and whom do we call first?
- Which statements in our application are conditions of coverage?
- How does this policy interact with our professional liability policy?
- What is excluded that you would expect a law firm to worry about?
- How is a vendor outage treated?
After you read it
Create a one-page summary for your incident plan with the claim hotline, limits, retention, panel vendors and notice rules. Share it with partners and your IT provider so everyone knows it before an incident.
How we help
Counsel Cyber is not an insurance broker, but we help firms verify the controls that policies depend on and prepare for the claim process. If you would like to line up your technical controls with your application, ask us.