ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Who Pays When a Law Firm Is Breached? Cyber Insurance Basics

Cyber insurance can help cover breach costs, but coverage varies widely. Learn the main components, common exclusions, and what to ask your broker.

3 min readBy Counsel Cyber Team

After a breach, the bills arrive quickly: forensic investigators, outside counsel, notification costs, restoration work, lost billings, and sometimes a ransom or a diverted wire. Cyber insurance exists to help with these costs, but policies differ enough that two firms with "cyber coverage" may have very different protection. This post explains the basics so you can ask better questions. It is general information, not insurance or legal advice.

Two Kinds of Coverage

Cyber policies often divide coverage into first-party and third-party.

First-party coverage

These cover the firm's own costs. Typical components include:

  • Incident response: forensic investigation and breach counsel
  • Data restoration: recovering or rebuilding systems and data
  • Business interruption: lost income while systems are down, often with a waiting period
  • Cyber extortion: negotiation and payment related to ransomware, subject to the policy terms and applicable law
  • Notification and monitoring: notifying affected people and providing credit monitoring where required
  • Funds transfer fraud and social engineering: coverage for payments sent to criminals, often with a lower sublimit

Third-party coverage

These cover claims against the firm, such as lawsuits or regulatory proceedings arising from a data breach. Legal liability coverage may sit in a cyber policy, in your professional liability policy, or both, with different rules about what is covered.

Questions to Ask Your Broker

  1. What are the limits and sublimits? A policy with a large overall limit may cap ransomware or wire fraud payments much lower.
  2. What are the retentions? The retention is what the firm pays before coverage applies.
  3. How is business interruption calculated? Waiting periods and definitions of lost income vary.
  4. Does coverage include social engineering? Many policies require specific call-back verification procedures as a condition.
  5. Are there required controls? Some policies tie coverage to maintaining MFA, backups or other measures.
  6. Who must we call first? Many carriers require notice within a stated time and may require use of panel vendors.
  7. How does it interact with our professional liability policy? Gaps and overlaps can be significant.
  8. What are the exclusions? Look for war or nation-state language, unencrypted devices, prior known incidents, and failure to maintain security.

Common Misunderstandings

  • "We have cyber insurance, so we are protected." Insurance pays after something goes wrong; it does not stop it, and it does not undo reputational harm.
  • "The policy covers everything IT-related." Hardware failure and ordinary outages may not qualify.
  • "We can call the carrier later." Late notice can complicate claims. Know the notice process now.
  • "Our application was a formality." Answers on the application matter. Accuracy is essential.

What Insurers Want to See

Carriers have tightened underwriting in recent years and generally want evidence of core controls: MFA, endpoint detection, tested backups, email security, patching, training and an incident plan. Meeting these baseline controls often improves both eligibility and pricing, though results vary by carrier.

Before an Incident

  • Keep the carrier's claim hotline and policy number in your incident response plan, printed and stored offline
  • Know whether you must use specific vendors
  • Brief partners on what to do and what not to do, such as not paying a ransom or contacting criminals without guidance
  • Practice a tabletop exercise so that decisions are not made for the first time during a crisis

After an Incident

Call your carrier and counsel promptly, preserve evidence, and avoid wiping systems before forensic experts have examined them. ABA Formal Opinion 483 discusses a lawyer's obligations after a data breach, including client communication, so involve counsel early.

Insurance Is One Layer

Policies work best alongside prevention, detection and recovery. Spending on insurance without investing in controls leaves a firm with more risk and, often, a higher premium.

How Counsel Cyber Can Help

Counsel Cyber does not sell insurance, but we help firms prepare for underwriting, document their controls, and build incident response plans that align with their policies. If you are reviewing a renewal, we can help you understand which controls your carrier expects.