ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Security Controls That Help a Law Firm Qualify for Cyber Coverage

Insurers look for a core set of security controls before they offer cyber coverage. Here is what they tend to ask law firms about and how to prepare evidence.

3 min readBy Counsel Cyber Team

Cyber insurance applications have become more detailed over the past several years. Where a form once asked a handful of general questions, many now read like a short security audit. Carriers want to know how likely a firm is to suffer a loss, and they use specific controls as indicators.

Requirements differ by carrier and change over time, so treat this as a map of the common ground rather than a guarantee of what any insurer will require. Your broker can tell you what the market currently expects.

Why Controls Matter to Underwriters

Insurers study claims. Certain failures appear repeatedly in incidents: stolen credentials without a second factor, unpatched systems, absent monitoring and backups that were deleted or encrypted along with everything else. Controls that address those failures tend to appear in applications. A firm that can show them may find coverage easier to obtain and renew, though pricing and availability depend on many factors.

The Controls Most Often Asked About

Multi-factor authentication

Expect questions about MFA on email, remote access, privileged and administrator accounts, and sometimes on backups and cloud applications. Be ready to answer where it is enforced, not just where it is available. An exception, such as one partner who refuses prompts, can make an application answer inaccurate.

Endpoint detection and response

Carriers frequently ask whether devices are protected by more than traditional antivirus, and whether someone monitors alerts around the clock. A managed detection and response service is often how small firms answer this.

Backups

Questions typically cover frequency, offsite or offline storage, immutability, encryption, separation from your main credentials and whether restores are tested. Documentation of a recent restore test is a useful piece of evidence.

Patching and vulnerability management

Applications ask how quickly critical updates are applied and whether unsupported software remains in use. Aging servers and old operating systems are common problems.

Email security

Expect questions about filtering for phishing and malware, authentication records that help prevent domain spoofing, and procedures for verifying payment changes.

Security awareness training

Many applications ask whether staff receive regular training and phishing simulations, and how often.

Incident response planning

Carriers want to know whether you have a written plan, whether it has been tested and who is on the response team.

Access management

Questions address privileged accounts, removal of access when employees leave, and periodic access reviews.

Wire-fraud controls

For law firms, many insurers ask about callback verification, dual approval and how you handle changes to payment instructions. This is often connected to sublimits for funds-transfer fraud.

Preparing Your Evidence

  1. Assemble a control inventory. For each control, record what is deployed, where, and who verified it.
  2. Collect proof. Screenshots or reports showing MFA enforcement, endpoint coverage, patch status and backup tests.
  3. Reconcile gaps honestly. If something is in progress, say so and document the timeline.
  4. Have your IT provider review answers before submission.
  5. Retain a copy of the submitted application and its supporting documents.

Closing Gaps Efficiently

If you are missing controls, prioritize by impact and effort:

  • Turn on MFA everywhere it is available, starting with email and remote access.
  • Retire or isolate unsupported systems.
  • Add managed endpoint detection.
  • Strengthen backups with an immutable or offline copy.
  • Write the incident response plan and run a short tabletop.
  • Adopt a written wire-verification procedure.

None of these requires a massive budget, and they improve security whether or not an insurer is watching.

A Warning About Optimism

It is tempting to answer questions in the most favorable way. Inaccurate answers can create problems when a claim is made. Answer precisely, qualify where needed and ask your broker how to handle partial implementations.

Think Beyond Insurance

Controls that satisfy underwriters also address concerns found in ABA guidance such as Formal Opinion 477R, which discusses reasonable efforts to secure client communications, and Opinion 483 on breach response. A firm that builds a sound baseline serves clients, insurers and its own risk management at once.

How Counsel Cyber Helps

Counsel Cyber helps firms implement and document the controls insurers ask about, and we provide evidence packages you can hand to your broker. If a renewal is coming, we can start with a gap review against the list above.