Law Firm Cybersecurity Insurance: A Practical Guide
Risk Management

Law Firm Cybersecurity Insurance: A Practical Guide

Most firms buy a cyber policy, file it in a drawer, and assume they are covered. Here is what the policy actually pays for, what it does not, and what an underwriter is really checking before your firm ever gets to file a claim.

ABArusarka B.

A law firm's cyber insurance policy usually gets bought once, during a busy renewal season, in about twenty minutes, by whoever happens to be handling the firm's insurance that year. The broker sends a quote, the number looks reasonable next to the malpractice premium, someone signs it, and the policy gets filed away without anyone actually reading past the declarations page. That is a normal way to buy insurance for a business that rarely gets attacked. It is a genuinely dangerous way to buy insurance for a law firm, because firms hold two things almost nobody else in a local business community holds in one place: privileged client information and other people's money sitting in trust.

Attackers know this. A law firm is not just a target because of the client files it holds, it is a target because a compromised law firm email account is often the fastest route to diverting a real estate closing wire, a settlement disbursement, or an escrow payment, and criminal groups that specialize in business email compromise actively look for firms specifically because the payoff per successful attack tends to be larger than almost any other small business target. The insurance industry has caught up to this reality faster than most firms have, which is exactly why so many law firms are discovering, only after they file a claim, that their policy either does not cover what actually happened to them or covers it at a fraction of what they lost.

This guide walks through what a cyber policy for a law firm actually needs to cover, the exclusions and sublimits that catch firms off guard most often, what an underwriter is genuinely checking before they will quote you at all, and how the security posture of your actual practice management system factors into all of it. None of this is theoretical. It is the same set of questions a firm should be asking before signing anything, and most firms are not asking any of them.

Why law firms specifically have become a preferred target

Ransomware groups and business email compromise operators do not attack randomly, they run a cost-benefit calculation like any other business, and a law firm scores well on almost every input that calculation cares about. Firms hold privileged, reputationally sensitive client data that a firm has strong incentive to pay quickly to keep quiet. Firms move large sums of client money through trust accounts, often on tight closing timelines where a fraudulent wire instruction is more likely to get executed without a second phone call to confirm it. And firms, especially small and mid-sized ones, are consistently underinvested in the kind of basic security controls that would make an attack meaningfully harder to pull off.

Real estate closing fraud is the pattern worth understanding in detail because it shows up in claims data more than any other single scenario involving a law firm. An attacker compromises either the firm's email or the client's email, watches the closing timeline quietly for days or weeks, and then sends a wire instruction change at exactly the moment funds are about to move, timed to look completely ordinary against everything the client has already seen in that email thread. The client wires the closing funds to the attacker's account instead of the title company's, and by the time anyone notices, the money has usually already moved through several accounts and is functionally gone. This is not a hypothetical, it is the single most common six and seven figure loss scenario insurers see from law firm policyholders, and it happens because of a compromised inbox, not a sophisticated technical breach.

!
This is not primarily a technology problem Most successful attacks against law firms do not involve breaking through a firewall or exploiting a software vulnerability, they involve a convincing email and a person who does not stop to make a verification call before moving money. A policy, and a firm's actual procedures, need to account for that reality directly.

What cyber insurance actually pays for on your own losses

A cyber policy is really two policies stitched together, and understanding the split matters because firms tend to only think about one half of it. The first-party side pays for the firm's own direct losses when an incident happens, and this is usually the broader, more generous half of the coverage. It typically includes the cost of forensic investigation to figure out what actually happened and how far an attacker got, the cost of notifying affected clients as required by breach notification law, credit monitoring for affected individuals where required, a ransom payment itself in a ransomware scenario along with negotiation services, business interruption losses while systems are down, and the cost of actually restoring or rebuilding systems and data after the incident.

The scale of these costs surprises firms that have never priced it out. Forensic investigation alone from a qualified incident response firm commonly runs into five figures before anyone has even confirmed the scope of what happened, and that is before notification costs, before any ransom consideration, before a single hour of the downtime the firm experiences while its practice management system, email, and document storage are all offline. A firm running entirely on paper files and a single shared inbox might get through a short outage relatively unscathed. A firm running matters, deadlines, billing, and trust accounting through digital systems that suddenly go dark for a week is looking at a very different order of magnitude in lost billable time and missed deadlines, on top of the direct incident costs.

3K+
attorneys running their firm on Casely
98%
customer satisfaction
$0
to start, on the Free plan

What it covers when someone else comes after you

The third-party side of the policy is what pays when a client, a regulator, or a bar association comes after the firm as a result of the incident, and this is the half most firms underestimate the value of until they actually need it. It typically covers the legal defense costs and any settlement or judgment arising from a lawsuit filed by clients whose data was exposed, regulatory investigation costs and fines where the jurisdiction allows insurance to cover them, and liability arising from a breach of a client's data that the firm was responsible for protecting.

For a law firm specifically, this matters more than it would for a typical small business because the underlying data is privileged, and clients whose confidential matter details end up exposed have a genuine, provable harm that is easier to litigate than a typical consumer data breach where the exposed information is comparatively low stakes. A firm that handles family law, criminal defense, or anything involving genuinely sensitive personal circumstances is exposed to third-party claims that carry real reputational and financial weight if the underlying policy limit is too thin to actually absorb them.

FeatureWithout MFA enforced firm-wideWith MFA enforced firm-wide
Underwriting outcomeHigher premium or declined coverage outrightStandard premium, broader terms offered
Social engineering sublimitOften capped very low, sometimes $50K or lessFrequently raised to match the primary policy limit
Claim investigationInsurer may argue failure to maintain controlsStraightforward claim process, no coverage dispute
Renewal pricingIncreases sharply after any incidentMore stable, insurer has documented risk reduction

The exclusions and sublimits that catch firms off guard

The gap between what a firm assumes its policy covers and what it actually covers almost always lives in the exclusions and the sublimits, and this is the part of the policy nobody reads until they are filing a claim. Social engineering and funds transfer fraud, the exact category that covers a fraudulent wire instruction during a real estate closing, is very often carved out into a separate sublimit that is dramatically lower than the primary policy limit, sometimes twenty-five or fifty thousand dollars against a primary limit of a million or more. A firm that assumes its full policy limit applies to a wire fraud loss can be in for a genuinely painful surprise when the claim comes back capped at a fraction of what was actually lost.

The other exclusion worth understanding closely is the failure to maintain minimum required safeguards clause, which appears in some form in almost every modern cyber policy. If the application asked whether the firm has multi-factor authentication enabled on email and remote access, and the firm answered yes when the actual answer was "mostly, except for a few partners who found it annoying," the insurer has real grounds to deny or reduce a claim after the fact if the incident traces back to an account that did not actually have MFA enabled. Insurers have gotten considerably more aggressive about enforcing this exclusion over the past several renewal cycles, precisely because so many claims trace back to exactly this kind of gap between what the application said and what was actually true.

Read the retention amount, not just the limit The retention is what the firm pays out of pocket before coverage kicks in, and it is easy to focus entirely on the headline coverage limit while missing that the retention on a smaller firm's policy can run five figures on its own, money that has to come from firm operating funds the moment an incident happens, well before any insurance payout arrives.

What underwriters are actually checking before they quote you

The cyber insurance application has gotten considerably more detailed over the last several renewal cycles, and it is worth treating the questionnaire as a genuine security assessment rather than a formality to get through quickly. Underwriters are specifically checking whether multi-factor authentication is enforced on email, remote access, and any privileged administrative accounts, not just available as an option employees can turn on themselves. They are checking whether the firm runs endpoint detection and response software rather than relying on basic antivirus alone, whether backups are stored somewhere genuinely separate from the firm's main network so a ransomware attack cannot encrypt the backups along with everything else, and whether those backups are actually tested for successful restoration rather than just assumed to be working.

Beyond the technical controls, underwriters increasingly ask about documented incident response procedures, whether staff receive regular security awareness training specifically covering phishing and business email compromise tactics, and whether the firm has a specific, written procedure requiring a phone call to a known number before any wire instruction is acted on, especially one that changed recently. Firms that can answer these questions with genuine, current detail rather than a vague sense of "yes, probably" consistently get quoted lower premiums, higher sublimits on the coverage categories that actually matter, and fewer coverage disputes if a claim ever gets filed.

  • Is multi-factor authentication enforced on every email and remote access account, with no exceptions for partners
  • Are backups stored somewhere genuinely separate from the main network and tested for restoration at least quarterly
  • Does every wire instruction change require a phone call to a previously known number before funds move
  • Has staff received security awareness training on phishing and business email compromise within the last twelve months
  • Is there a written incident response plan naming who does what in the first 24 hours of a suspected breach

Business email compromise deserves its own line of defense

Because business email compromise is the single most common real-world claim category for law firms, it is worth treating separately from general cybersecurity hygiene rather than lumping it in as one item on a broader list. The core defense is procedural, not technical: no wire instruction, and no change to an existing wire instruction, gets acted on without a verification phone call placed to a number the firm already had on file before the email arrived, never a number provided in the suspicious email itself. This single habit, applied without exception, stops the overwhelming majority of successful wire fraud attempts against law firms, because the attacker's entire plan depends on the request looking routine enough that nobody picks up the phone.

The technical side matters too, because a compromised inbox is usually how the attacker gets visibility into the closing timeline in the first place. Email accounts need MFA that cannot be bypassed by a forwarded SMS code, unusual login activity from new locations or devices needs to trigger an actual alert someone looks at rather than a notification that gets ignored, and firms handling real estate or high-value transactional work specifically should consider a dedicated secure channel for exchanging wire instructions rather than relying on plain email for the single most exploitable moment in the entire transaction.

AES-256
encryption on every document, per-firm key
0
extra logins needed for e-signatures
98%
customer satisfaction

Sizing the right coverage limit for your firm

Coverage limits get chosen far too often by picking whatever number the broker's default quote suggested, rather than by actually working backward from the firm's real exposure. The better starting point is the largest single trust transaction the firm regularly handles, because a wire fraud loss scales with transaction size, not with firm revenue. A firm doing occasional five million dollar commercial real estate closings has a fundamentally different exposure profile than a firm doing routine residential closings in the low six figures, even if both firms bill roughly the same amount in a given year.

The second input is the volume and sensitivity of the client data the firm holds, since a breach notification obligation scales with the number of affected individuals, not with the size of any single transaction. A firm with a large personal injury or class action practice holding tens of thousands of client records has a notification cost exposure that a small estate planning practice with a few hundred active clients simply does not carry, regardless of how similar the two firms might look on paper in terms of headcount or revenue. Working through both of these numbers with a broker who actually understands legal practice, rather than someone quoting a generic small business cyber policy, tends to produce a limit that reflects the firm's real risk instead of a number picked because it was the middle option on a rate sheet.

  1. 01File the claim and notify the insurer within the policy's required reporting window
  2. 02Insurer assigns a breach coach and approved forensic investigation firm
  3. 03Forensics determines scope, what was accessed, and whether client notification is triggered
  4. 04Firm sends required notifications to affected clients and any applicable regulator
  5. 05Insurer reimburses covered costs and the firm implements the corrective controls the incident exposed

What actually happens when you file a claim

Most firms have never gone through a cyber claim and genuinely do not know what the process looks like, which makes an already stressful moment considerably worse. The first step after discovering an incident is notifying the insurer within the specific window the policy requires, which is often much shorter than firms expect, sometimes as little as 24 to 72 hours, and missing that window can itself become grounds for a coverage dispute regardless of how legitimate the underlying claim is. The insurer then typically assigns a breach coach, usually an attorney who specializes in data breach response, along with an approved forensic investigation firm from the insurer's own panel, and the firm generally does not get to pick its own forensic vendor and expect full reimbursement unless that vendor is already on the insurer's approved list.

The forensic investigation determines exactly what happened, which systems were accessed, and critically, whether client data was actually viewed or exfiltrated rather than simply exposed to potential access, because that distinction often determines whether formal notification obligations are triggered at all under most breach notification frameworks. Only once that scope is established does the firm move to actual client notification and any required regulatory reporting, and the insurer reimburses the covered costs across the whole process according to the policy's specific sublimits, which is exactly why understanding those sublimits before an incident happens matters so much more than reading them for the first time in the middle of one.

Building the security posture that makes the policy actually work

A cyber insurance policy is a financial backstop, not a substitute for the underlying security of the systems a firm actually runs its practice on every day, and the two need to work together rather than being treated as separate concerns handled by different people at different times of year. The practice management system a firm uses is itself either reducing the firm's real exposure or quietly adding to it, and the honest test is not whether the system has a security page on its marketing site, it is whether the specific controls an insurer asks about on the application are actually true of how the system works underneath.

This is where the architecture of the system a firm runs on genuinely matters, not as a feature checklist but as the literal difference between a claim that pays out cleanly and one that gets disputed. Casely encrypts every document with AES-256 using a key unique to each firm rather than shared infrastructure across every customer on the platform, which is a meaningfully different security posture than a generic file storage layer bolted onto a case management tool. Ethical walls are enforced at the server itself, at the data access layer, so a walled staff member genuinely cannot reach a restricted matter through a search bar, a shared calendar entry, or a forwarded document link, which matters directly when an underwriter or a forensic investigator is trying to establish exactly who could have accessed what during an incident. And because trust disbursements are blocked at the database transaction level the moment they would exceed what is actually sitting in a matter's balance, with every correction voided rather than deleted and visible on the ledger permanently, a firm can produce a complete, defensible record of exactly what happened to client funds if a claim or a bar inquiry ever asks for one.

None of this replaces a cyber policy, and no firm should treat strong software as a reason to skip coverage entirely. But a firm that can answer an underwriting questionnaire honestly and specifically, because the systems it runs on actually enforce the controls being asked about rather than merely offering them as optional settings, is a firm that gets quoted better terms, faces fewer coverage disputes, and recovers faster when something does go wrong.

Making the actual decision

Cyber insurance for a law firm is not a box to check once during renewal season and forget about for the next twelve months. It is a policy that needs to be read closely, particularly the social engineering sublimit and the failure to maintain safeguards exclusion, matched against the firm's real exposure rather than a generic small business default, and backed by security practices and procedures that make the application's answers actually true rather than aspirational. The firms that get burned are rarely the firms with no policy at all, they are the firms with a policy they assumed covered more than it actually did.

The broader lesson underneath all of this is that insurance and infrastructure are not separate line items, they are two halves of the same risk management decision. A firm running trust accounting, document storage, and client communication on a system that enforces real controls at the architecture level, not just in a settings menu somebody has to remember to configure correctly, walks into every renewal conversation with a genuinely stronger hand, and walks into an actual incident with a genuinely better chance of the claim paying out the way the firm expected it to.

If trust account security specifically is the piece of this you want to shore up first, given how often a compromised wire instruction is the actual event that triggers a claim, our trust accounting software page walks through exactly how disbursements get blocked before they can exceed a matter's balance, and why that structural guarantee matters as much for an insurance underwriter's questionnaire as it does for a bar audit.

AB

WRITTEN BY

Arusarka B.

Covers legal technology, compliance workflows, and how firms actually adopt new practice management software.

More about the team