Cyber-Insurance for Law Firms: What Your Malpractice Carrier Now Requires
What does cyber insurance now require from a law firm?
Cyber and legal-malpractice carriers now require law firms to prove specific security controls before they will bind or renew a policy: multi-factor authentication (MFA) on email and remote access, endpoint detection and response (EDR) on every device, tested offline backups, email filtering, and staff phishing training. If your firm can't attest to these, expect higher premiums, coverage exclusions, or a flat decline.
Why are carriers demanding this from law firms right now?
Law firms are a favorite target. They hold settlement funds, IOLTA trust accounts, merger details, sealed filings, and client secrets protected by privilege—all in one place, often behind aging IT. After a wave of ransomware and business-email-compromise claims drained the market, insurers stopped treating cybersecurity as optional. The application is no longer a formality; it's an underwriting audit.
The shift matters most at renewal. A policy that renewed on a one-page form two years ago now comes with a detailed technical questionnaire, and the answers you give become binding representations. That's why the controls below aren't "nice to have"—they're the price of admission. A qualified cybersecurity services provider can close these gaps before your application lands on an underwriter's desk.
What is on the insurer's questionnaire?
Underwriters send a supplemental application built almost entirely around whether you have concrete controls in place. Expect direct yes/no questions on:
- MFA on email, VPN/remote access, and any admin or cloud account
- EDR or managed detection deployed and monitored across all endpoints and servers
- Backups that are encrypted, kept offline or immutable, and—critically—test-restored on a schedule
- Email security: spam/phishing filtering, and external-sender banners
- Patch management and end-of-life software timelines
- Security awareness training and documented incident-response planning
- Privileged access controls and prompt offboarding of departed staff
Every "yes" is a representation the carrier relies on to price and issue your policy. A managing partner who checks boxes without confirming them with IT is exposing the firm—not just to hackers, but to the insurer.
Why do MFA and EDR come up on every application?
Because they stop the two most common claims. MFA blocks the credential theft behind business email compromise—the fake wire instructions and hijacked partner inboxes that cost firms client funds and trust. EDR catches ransomware early, isolating a device before an intruder can spread across your file server and encrypt every open matter. Underwriters have the loss data, so these two controls now function as a hard gate. Firms without them are frequently declined outright, regardless of how clean their history looks.
The practical problem: most firms think they already have both. "We use Microsoft 365" doesn't mean MFA is enforced on every account, and traditional antivirus is not EDR. Verifying the difference is exactly the kind of work managed cybersecurity handles day to day, and it's why our deeper guide on cyber insurance MFA and EDR requirements is worth reading before you fill anything out.
How does malpractice coverage connect to cyber coverage?
For law firms the two are entangled in a way most other businesses never face. A breach that exposes privileged client data isn't only a cyber incident—it can trigger a legal-malpractice claim for failing to safeguard confidences, plus bar-discipline exposure under your duty of competence and confidentiality. Some malpractice carriers now bundle or condition coverage on the same security posture cyber underwriters demand, and a gap on one side can undercut the other. Firms in regulated matters or handling sensitive verticals should treat this as a whole-firm risk. Our legal IT services overview walks through the confidentiality obligations that make this different from a typical business.
What happens if you attest to controls you don't actually have?
This is the quiet danger. Cyber policies are issued on the representations in your application. If you attest that MFA is enforced everywhere and a breach investigation later shows it wasn't on the account that got compromised, the carrier can deny the claim or rescind the policy—leaving the firm to absorb the loss, notification costs, and any resulting malpractice exposure with no coverage at all.
That turns an honest-but-sloppy answer into an uninsured catastrophe, and the cost of getting it wrong dwarfs the cost of implementing the controls—far less than a single denied ransomware claim. The safe path is simple: don't attest to anything until an IT partner has verified it's genuinely in place, enforced, and documented. Ongoing managed IT services keep that attestation true between renewals, not just on application day.
How should a firm prepare before its renewal?
Start the security work well before the renewal deadline, not the week the application is due. Map every control on the questionnaire to reality, close the gaps, and gather the evidence—MFA enforcement reports, EDR coverage, backup-restore test logs—so your answers are provable, not hopeful. Firms that show up to underwriting with clean, documented controls routinely see better terms and fewer exclusions. Those that scramble get penalized or declined.
Does small-firm size get us a pass on these requirements?
No. Underwriters apply the same core controls—MFA, EDR, tested backups—regardless of headcount, because attackers target small firms precisely for weaker defenses. A solo or small practice holding trust funds and privileged files is squarely in scope.
Is cyber insurance a substitute for actually securing the firm?
No. Insurance transfers financial risk after an incident; it doesn't prevent one or repair the client-trust damage. Carriers now require the controls precisely because they'd rather you never file a claim. Treat the questionnaire as a baseline security checklist, not a paperwork hurdle.
What if our current IT can't answer the questionnaire?
That's a red flag worth acting on. If no one can confirm whether MFA is enforced or backups are test-restored, the controls likely aren't reliably in place. A provider focused on law-firm cybersecurity can assess your posture, close gaps, and produce the documentation underwriters want.
Renewing soon? Compare vetted managed IT & cybersecurity providers—free and walk into underwriting with controls you can honestly attest to.
