ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

What Cyber Insurance Applications Ask Law Firms to Prove

What cyber insurance applications typically ask law firms about MFA, backups, email security and training, and how to prepare accurate answers before you apply.

3 min readBy Counsel Cyber Team

Cyber insurance applications have become detailed security audits in disguise. Where a form once asked a few yes-or-no questions, many now ask for specifics about multi-factor authentication, endpoint monitoring, backups and incident response. Underwriters ask because claims have taught them which controls tend to separate manageable incidents from catastrophic ones.

For a law firm, the stakes are twofold: getting coverage at a reasonable price, and making sure that what you say on the application is true. This post covers the questions that typically come up and how to prepare.

The Questions You Should Expect

Every carrier's form is different, but these themes appear again and again.

Identity and access

  • Is multi-factor authentication required for email, remote access, VPN and administrator accounts?
  • Is MFA used on cloud applications and backup consoles?
  • How are privileged accounts managed and reviewed?

Endpoint and network protection

  • Do you use endpoint detection and response, and is it monitored around the clock?
  • Is there a firewall, and are remote desktop services exposed to the internet?
  • How quickly are critical patches applied?
  • Are unsupported operating systems or software still in use?

Email security

  • Do you filter email for phishing, malware and impersonation?
  • Is DMARC, SPF and DKIM configured for your domain?
  • Do you have a process for verifying wire instructions or payment changes?

Backups and recovery

  • Are backups regularly performed, encrypted and tested?
  • Is at least one copy offline or immutable?
  • Do you have a documented disaster recovery or incident response plan?

People and process

  • Do employees receive security awareness training, and how often?
  • Do you run phishing simulations?
  • Are vendors that handle sensitive data assessed?

Business facts

Carriers will also ask about revenue, headcount, the types of data you hold, the number of records, and any past incidents or claims.

Why Accuracy Matters

The application is part of the insurance contract. If an answer is wrong, a carrier may contest a claim or, in serious cases, seek to rescind a policy. The risky scenario is a well-meaning administrator answering "yes" to MFA everywhere when it is actually deployed for most but not all accounts. Answer precisely, and where a control is partial, say so.

How to Prepare

  1. Gather facts before you open the form. Collect your MFA coverage, backup configuration, endpoint tools and training records.
  2. Involve your IT provider. Let the person who knows the environment answer technical questions.
  3. Have a partner review and sign. The signer is attesting to the answers.
  4. Fix cheap gaps first. Turning on MFA for the last few accounts or retiring an old server can change both your answers and your risk.
  5. Keep evidence. Save screenshots, reports and policy documents in a folder, since carriers may ask for proof later.
  6. Ask your broker what controls are mandatory for coverage and which ones merely affect price.

Controls That Commonly Affect Coverage

Carriers have increasingly treated the following as baseline expectations: MFA on email and remote access, monitored endpoint protection, tested backups kept separate from the production network, and a plan for incident response. A firm without them may find coverage restricted, more expensive or declined. Requirements vary by carrier and change over time, so ask your broker what applies now.

Review Coverage, Not Just Controls

Read the policy for what is covered: breach response, forensic costs, ransom-related coverage, business interruption, regulatory defense and social engineering or funds transfer fraud. Funds transfer fraud is often sublimited or conditioned on verification procedures, which matters a great deal to firms that move client money. Ask whether coverage applies when a lawyer, not an outside party, makes the transfer.

Make It an Annual Rhythm

Renewal is a good moment to review security, so treat it as a yearly checkpoint rather than an annual scramble.

How Counsel Cyber Can Help

Counsel Cyber helps firms close security gaps and assemble the documentation insurers ask for. If your renewal is approaching, we can review your draft answers with you before you submit them.