A cyber insurance policy is a contract with many moving parts, and the headline limit rarely tells the whole story. When a law firm has an incident, the questions that matter are specific. Will the policy pay for a forensic investigation? For notifying clients? For a fraudulent wire? Does it require you to use particular vendors? Reading the policy with a broker before an incident is far better than discovering gaps afterward.
This is general information, not insurance or legal advice. Policies differ, so rely on your broker and counsel for your specific coverage.
Common coverage components
First-party costs
These are the firm's own losses and expenses:
- Incident response and forensics: investigators to determine what happened and contain it
- Data restoration: costs of recovering or recreating data
- Business interruption: lost income during an outage, often with a waiting period
- Extortion: negotiation and, depending on the policy, ransom payments subject to legal limits
- Notification and credit monitoring: costs of notifying affected individuals
- Public relations: crisis communications support
Third-party liability
Coverage for claims brought by others, such as clients alleging that their information was exposed, along with defense costs and regulatory proceedings.
Cyber crime coverage
Many policies treat social engineering and funds-transfer fraud separately, often with lower sublimits and specific conditions. For a firm that moves client money, this section deserves close attention.
Questions to ask about funds-transfer fraud
- Is social engineering fraud covered, and under what sublimit?
- Are there conditions, such as a requirement that the firm verified payment instructions by callback?
- Does coverage apply to client funds held in trust, not only the firm's own money?
- How quickly must the loss be reported?
Where verification procedures are a condition, follow them every time and keep records.
Gaps that commonly surprise firms
Sublimits
A policy with a large aggregate limit may cap ransomware, social engineering or regulatory coverage at much lower amounts.
Waiting periods and time limits
Business interruption coverage usually begins after a waiting period, and may be limited to a defined period of restoration.
Exclusions and conditions
Read carefully for exclusions relating to unpatched known vulnerabilities, failure to maintain represented security controls, war or state-sponsored acts, infrastructure failures and prior known incidents. Some policies make coverage depend on maintaining controls described in the application, such as MFA.
Vendor and cloud outages
Check whether coverage extends to losses caused by an outage or breach at a vendor, such as a cloud provider. This is sometimes called dependent business interruption.
Panel vendors
Many insurers require or strongly encourage using their approved incident response firms and counsel. Using someone else without consent may reduce reimbursement.
Claims-made and retroactive dates
Cyber policies are often claims-made, so the timing of the claim, the report and the policy period matters.
Professional liability overlap
Your lawyers' professional liability policy may exclude or limit cyber events. Ask how the two policies interact and whether there are gaps between them.
How to review your policy
- Request a full copy, including endorsements, not just the declarations page.
- Have your broker walk through the coverage grid line by line.
- List the controls the policy depends on and confirm they are in place.
- Note notice deadlines and the claims reporting number.
- Share a one-page summary with partners and IT.
- Put key contacts into your incident response plan.
Adjusting limits
There is no universal rule for how much coverage to buy. Consider the number of client records, the volume of money handled, the firm's revenue and the cost of downtime, and discuss options with your broker. Avoid choosing limits solely on price.
Keep your side of the bargain
Insurance does not replace security. Insurers increasingly expect MFA, backups, monitoring and training, and a firm that cannot show them may face higher premiums, narrower coverage or a refusal to renew.
Next steps
Review your policy once a year in advance of renewal, and again after any material change in the firm. Counsel Cyber can help you map policy conditions to your actual controls and prepare evidence for underwriters, working alongside your broker.