ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

What Your Cyber Policy Covers for a Law Firm and Where Gaps Hide

Cyber policies vary widely. Review coverage for response costs, ransomware, funds-transfer fraud, business interruption and vendor failures before you need it.

3 min readBy Counsel Cyber Team

A cyber insurance policy is a contract with many moving parts, and the headline limit rarely tells the whole story. When a law firm has an incident, the questions that matter are specific. Will the policy pay for a forensic investigation? For notifying clients? For a fraudulent wire? Does it require you to use particular vendors? Reading the policy with a broker before an incident is far better than discovering gaps afterward.

This is general information, not insurance or legal advice. Policies differ, so rely on your broker and counsel for your specific coverage.

Common coverage components

First-party costs

These are the firm's own losses and expenses:

  • Incident response and forensics: investigators to determine what happened and contain it
  • Data restoration: costs of recovering or recreating data
  • Business interruption: lost income during an outage, often with a waiting period
  • Extortion: negotiation and, depending on the policy, ransom payments subject to legal limits
  • Notification and credit monitoring: costs of notifying affected individuals
  • Public relations: crisis communications support

Third-party liability

Coverage for claims brought by others, such as clients alleging that their information was exposed, along with defense costs and regulatory proceedings.

Cyber crime coverage

Many policies treat social engineering and funds-transfer fraud separately, often with lower sublimits and specific conditions. For a firm that moves client money, this section deserves close attention.

Questions to ask about funds-transfer fraud

  1. Is social engineering fraud covered, and under what sublimit?
  2. Are there conditions, such as a requirement that the firm verified payment instructions by callback?
  3. Does coverage apply to client funds held in trust, not only the firm's own money?
  4. How quickly must the loss be reported?

Where verification procedures are a condition, follow them every time and keep records.

Gaps that commonly surprise firms

Sublimits

A policy with a large aggregate limit may cap ransomware, social engineering or regulatory coverage at much lower amounts.

Waiting periods and time limits

Business interruption coverage usually begins after a waiting period, and may be limited to a defined period of restoration.

Exclusions and conditions

Read carefully for exclusions relating to unpatched known vulnerabilities, failure to maintain represented security controls, war or state-sponsored acts, infrastructure failures and prior known incidents. Some policies make coverage depend on maintaining controls described in the application, such as MFA.

Vendor and cloud outages

Check whether coverage extends to losses caused by an outage or breach at a vendor, such as a cloud provider. This is sometimes called dependent business interruption.

Panel vendors

Many insurers require or strongly encourage using their approved incident response firms and counsel. Using someone else without consent may reduce reimbursement.

Claims-made and retroactive dates

Cyber policies are often claims-made, so the timing of the claim, the report and the policy period matters.

Professional liability overlap

Your lawyers' professional liability policy may exclude or limit cyber events. Ask how the two policies interact and whether there are gaps between them.

How to review your policy

  1. Request a full copy, including endorsements, not just the declarations page.
  2. Have your broker walk through the coverage grid line by line.
  3. List the controls the policy depends on and confirm they are in place.
  4. Note notice deadlines and the claims reporting number.
  5. Share a one-page summary with partners and IT.
  6. Put key contacts into your incident response plan.

Adjusting limits

There is no universal rule for how much coverage to buy. Consider the number of client records, the volume of money handled, the firm's revenue and the cost of downtime, and discuss options with your broker. Avoid choosing limits solely on price.

Keep your side of the bargain

Insurance does not replace security. Insurers increasingly expect MFA, backups, monitoring and training, and a firm that cannot show them may face higher premiums, narrower coverage or a refusal to renew.

Next steps

Review your policy once a year in advance of renewal, and again after any material change in the firm. Counsel Cyber can help you map policy conditions to your actual controls and prepare evidence for underwriters, working alongside your broker.