Yes, and it is now part of the core stack rather than an add on. You hold privileged client files, and a professional liability policy will not pay for forensics, notification, ransomware, or a fraudulent wire. Client contracts increasingly require it too. Who this is for: Law firms handling client data or client money.
The short version
- Cyber pays for incident response, business interruption, ransomware, and third party claims. Professional liability does not.
- Funds transfer fraud and social engineering are the most frequent losses, and they usually carry the lowest sublimits.
- Expect $1,200 to $6,000 a year for a small to midsize firm.
- Multifactor authentication and tested backups are now underwriting gates, not suggestions.
- Enterprise client contracts commonly require $1M in cyber liability before you can start work.
What you are holding
A law firm typically holds privileged client files, settlement funds in trust, medical and financial records produced in discovery. That is exactly the inventory a cyber policy exists to protect, and it is also what makes you a target. Attackers go after professional firms because you hold client data without a client's security budget.
What a cyber policy actually pays for
| Coverage part | What it does | Typical sublimit |
|---|---|---|
| Incident response | Forensics, legal counsel, and notification after a breach | Often the full limit |
| Business interruption | Lost income while systems are down | Full limit, with a waiting period of 6 to 12 hours |
| Ransomware and extortion | Ransom payment and negotiation, where lawful | $100K to full limit |
| Funds transfer fraud | Money you send because of a fraudulent instruction | $100K to $250K, often lower than you expect |
| Social engineering | Fraud where an employee is deceived into paying | $50K to $250K, frequently a separate sublimit |
| Third party liability | Claims by clients whose data you exposed | Full limit |
| Regulatory defense | Investigations and fines where insurable | Full limit or a sublimit |
The sublimits are where firms get surprised. A $1M cyber policy with a $100K social engineering sublimit pays $100K on a $340K wire fraud, and that is the most common cyber loss for professional services firms by frequency.
Where cyber and professional liability overlap
The same event can be both. If a breach at your firm exposes client data, the notification and forensics sit on cyber, while the client's claim that your negligence caused it can hit professional liability. For law firms specifically, a wire fraud email spoofing a closing instruction is exactly the sort of event that involves both towers.
Buying both from one carrier, or at least aligning the retentions and the reporting requirements, avoids a coverage fight while you are already in the middle of an incident.
What carriers now require before they will quote
- Multifactor authentication on email and remote access. Without it, many carriers will not offer terms at all.
- Backups that are tested and stored separately from the production network.
- Endpoint detection and response on workstations and servers.
- Email filtering and a documented process for verifying payment instructions by phone.
- Timely patching, particularly of anything internet facing.
These are not best practice suggestions any more. They are underwriting gates, and putting them in place before you apply is usually worth more than shopping the price.
What this looks like in practice
Illustrative example. Numbers are typical of claims we see and are not a promise of how any specific claim would be handled.
The setup: A law firm with a $1M cyber policy that carried a $100,000 social engineering sublimit.
The claim: The matter started with a wire fraud email spoofing a closing instruction. $180,000 of escrowed funds left the trust account and the buyer sued the firm.
The cost: $52,000 in defense costs and $180,000 in settlement, $232,000 in total, paid inside the policy limit after the retention.
The lesson: The forensic and legal costs were covered in full, but the fraudulently transferred funds were capped at the sublimit. Reading the sublimits, not just the headline limit, is what makes a cyber policy useful.
Frequently asked questions
Q: Does a law firm really need cyber insurance?
Yes, if you hold privileged client files. Professional firms are targeted precisely because they hold valuable client data with smaller security budgets than their clients.
Q: Does my professional liability policy cover a data breach?
Rarely in full. Some forms include a small privacy sublimit, but incident response, notification, ransomware, and business interruption belong on a cyber policy.
Q: What does cyber insurance cost?
Commonly $1,200 to $6,000 a year for a small to midsize law firm. Security controls now affect both price and whether a carrier will quote at all.
Q: What is the most common cyber claim for professional firms?
Funds transfer fraud and social engineering, where someone is deceived into wiring money to a fraudster. It is more frequent than ransomware and the sublimits for it are often much lower than the policy limit.
Q: Will my carrier require multifactor authentication?
Almost certainly. Multifactor authentication on email and remote access is now a baseline condition for most cyber quotes, and misrepresenting it on an application can void the coverage.
Q: Do my client contracts require cyber coverage?
Increasingly yes. Enterprise agreements and vendor security reviews commonly require $1M in cyber liability, and healthcare, financial, and public sector clients often require more.
How Morrow helps law firms
Morrow is a licensed independent commercial insurance brokerage that specializes in law firms & attorneys. Matching cyber sublimits to how your firm actually loses money is exactly the kind of question we answer every week, and because we place this coverage every day we know which carriers write it well, which forms are broad, and which contract language actually needs an endorsement behind it.
- We read the contract clause and tell you what your current policy already does and does not do.
- We market your account to carriers that have real appetite for law firms rather than whoever answers first.
- We issue certificates the same day a client asks, with the endorsements listed correctly.
- We stay on the file at renewal so limits, retroactive dates, and contract requirements do not quietly drift.
Get in touch and we will see how we can help. Tell us what you do, send over any contract that is driving the requirement, and send us the question and we will tell you where you stand. Start at morrowinsure.com or reach the team through the contact options on that page.
One more thing. This article is general information for law firms and is not legal advice, tax advice, or a statement of coverage. Policy wording controls in every case, and forms vary by carrier and by state. Have a licensed advisor review your own policy and your own contract before you rely on any of it.
Last updated: Reviewed by the Morrow commercial lines team. Last updated August 2026.
