Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-21By Securing Your Law Firm

Cyber Insurance for Law Firms: Can You Actually Prove You Have These 6 Controls?

Law firms are being asked to prove MFA, endpoint protection, backups, email authentication, patching, and an incident response plan. Learn what insurers expect and what evidence actually matters.

Blog post - By Securing Your Law Firm

Get your free review | See pricing | Contact us

Every cyber insurance application asks the same six questions in one form or another: Do you have multifactor authentication? Endpoint protection? Tested backups? Email authentication? A patching process? A written incident response plan?

Almost every firm answers yes to all six. That is the problem.

Insurers are no longer treating those answers as a simple check-the-box exercise. They are evaluating whether the firm can actually prove the control exists, is enforced in the right places, and has been maintained over time. More than 40% of cyber insurance claims filed in recent years were denied because the firm's actual environment did not match what it attested to on the application, not because the loss itself was uncovered by the policy.

For law firms, that gap matters more than most industries. Firms hold client trust accounts, confidential litigation strategy, and private financial data. They also face pressure from corporate clients, cyber insurers, and ABA technology expectations at the same time. A firm can have coverage on paper and still be in a weak position if it cannot produce evidence that the controls are active and enforced.

The real question is not simply, "Do we have these six controls?" The real question is, "If the carrier's forensic team showed up tomorrow, could we hand them evidence?"

In this article:

  • Why insurance carriers are treating applications like evidence, not a box-checking exercise
  • The six controls that get challenged most often at renewal and after a claim
  • What proof looks like for MFA, EDR, backups, email authentication, patching, and incident response
  • Why a law firm with a policy can still be exposed if it cannot show the controls are active
  • How the free Exposure Review and fixed-scope services help firms close the gap before renewal

Why carriers are reading applications differently now

The legal industry is not immune to the insurance underwriting shift. Carriers have moved from accepting a firm's attestation at face value to evaluating whether the answer holds up under scrutiny. A policy application is increasingly treated like a continuing warranty, not just a one-time form filled out at renewal.

If a firm says it has MFA but only enabled it for email, not for the VPN, the practice management system, or privileged admin accounts, the answer is incomplete. If it says it has business email protection but DMARC is set to monitor-only, that is not the same as enforcement. If it says it has backups but cannot show a tested restoration, the insurer will see a weak control, not a working one.

That is why the gap between "we have it" and "we can prove it" is now one of the most important conversations a law firm can have before renewal.

The six controls underwriters focus on most

Here are the six areas that get scrutinized most closely, and what real proof looks like in practice.

1. Multifactor authentication

The first question is often not whether the firm uses MFA at all. It is whether MFA is enforced in the places that matter most: Microsoft 365, VPN, remote access, privileged accounts, and the firm's business-critical systems.

A firm with MFA on email but not on the domain admin portal or a legacy billing tool has a gap. An underwriter may treat partial enforcement as non-enforcement. That is the exact kind of issue that can show up after a loss, even when the firm thought it was compliant.

What evidence helps:

  • A current MFA status report showing which systems require second-factor authentication
  • An admin console export or screenshot confirming enforcement for privileged users
  • A device or user access review showing no exempted admin accounts without MFA

This is one area where law firms often need help. Many firms have modern security enabled for standard users but not for administrative or remote access pathways. That is a problem for carriers and a common reason claims get denied after a breach.

2. Endpoint detection and response

Underwriters increasingly expect more than signature-based antivirus. They want to know whether firm endpoints are monitored in real time for suspicious behavior, especially on laptops used remotely or on home networks.

A legal practice can easily have a mix of desktops, laptops, and mobile devices, and insurers want coverage across that environment. If a firm says it has EDR but the licensing does not match its active device count, or if new laptops were added without corresponding coverage, that is a documentation issue that can surface during a claim.

What evidence helps:

  • An up-to-date device inventory matched against EDR coverage
  • Console screenshots showing active protection and health status
  • A summary of excluded devices, if any, and why they are excluded

This is also where a law firm's technology stack can drift over time. New staff, new laptops, or contractor access can produce a coverage gap without anyone noticing. The result is not just a technical weakness. It is also a compliance weakness.

3. Backups that are protected and tested

Backups are one of the most misunderstood areas of cyber insurance underwriting. A backup that can be encrypted or deleted by ransomware is not the same as a secure backup.

Carriers often want to see that backups are immutable, protected from unauthorized modification, and tested for restoration. In practical terms, they want proof that the firm can recover data after a ransomware event and that the backup process is not just scheduled but actually functioning.

What evidence helps:

  • A dated restoration test showing files were recovered successfully
  • Backup retention and immutability settings from the platform
  • Logs or reports showing periodic backup verification

A common issue is that firms have backups enabled but cannot show that they have ever restored a file or tested a system image. The wording matters. "We run nightly backups" is a policy statement. "We restored a test file on [date] and confirmed integrity" is evidence.

4. Email authentication

Spam, spoofing, and impersonation remain major risk areas for law firms. Underwriters want to see that the firm's domain is configured correctly through SPF, DKIM, and DMARC, and that DMARC is actually enforcing policy rather than simply monitoring it.

This part matters because business email compromise is not a hypothetical issue. It is one of the highest-impact fraud vectors for professional services firms. If a hacker spoofs a partner's email or impersonates a closing counsel, the firm can lose real money without a traditional breach or malware infection.

What evidence helps:

  • A live DNS record check showing SPF, DKIM, and DMARC values
  • Proof that DMARC is set to quarantine or reject, not just monitor
  • A review of sender alignment and any misconfiguration that leaves the domain exposed

This is also one of the fastest wins for firms. Many law firms have a DMARC record, but it is set to p=none, which means it exists but does not protect the domain. That is a red flag during underwriting and a real operational risk in the wild.

5. Patch management and vulnerability response

Carriers do not want a verbal promise that IT patches things when it gets around to it. They want evidence of a defined process and a track record of timely action.

This is especially relevant for firms that rely on third-party software, remote access tools, or outdated devices. A legal office might not feel exposed by one unpatched application, but a carrier sees a risk profile and a potential claim trigger. The underwriting question is not whether the firm is perfectly secure. It is whether the firm has a documented path to identify and close known vulnerabilities.

What evidence helps:

  • A patching policy or SLA for critical and high-risk vulnerabilities
  • Ticketing or reporting history showing recent updates and time to remediate
  • An asset inventory that ties software versions to patch status

A defined patch cadence is far stronger than a general statement that someone handles updates. Insurers want process and proof, not memory.

6. Written incident response plan

A law firm can have no dedicated cyber plan and still tell itself it has a general idea of what to do when something goes wrong. That answer does not satisfy a carrier, a client questionnaire, or a regulator after the fact.

Carriers and clients want to see that roles are assigned, decision-makers are named, and the firm has a real process for triage, notification, forensic review, and client communication. A document saved in a shared folder without clear ownership or a recent tabletop exercise is not the same as a plan that works under pressure.

What evidence helps:

  • A dated incident response plan with named roles and escalation steps
  • A tabletop or mock exercise record showing the plan is understood by staff
  • A contact list for legal, communication, insurer, and external vendor response

This is another area where many small and mid-sized firms are underprepared. They do not need a complex framework. They need a usable playbook, and they need to be able to show it exists and has been tested.

What happens if a firm cannot produce the evidence

Two outcomes are possible, and neither is good.

At renewal, a firm may face higher premiums, added exclusions, or a declined renewal. After a claim, gaps can turn into a denied claim even when the firm had a policy in place. The issue is not always that the breach was caused by the specific missing control. The issue is that the application was inaccurate, incomplete, or unsupported by evidence.

That is why our work with clients is designed around evidence, not just technical checklists. A firm does not need a massive transformation before it can start. It needs a clear view of what exists, what is missing, and what needs documentation so the insurer or client can see it clearly.

The practical way law firms should approach this

Most firms do not need a multi-year overhaul to improve their position. They need a fixed-scope review of the actual risk areas that underwriters care about.

That is exactly where our services fit.

The free Zero-Access Exposure Review™ gives a law firm a read-only snapshot of public exposure before it ever moves to a paid engagement. It checks the public signals attackers and insurers look at first: exposure of email infrastructure, lookalike domains, public web posture, and weak sender authentication.

Our Email Hardening service focuses on the controls that protect the firm's reputation and ability to trust inbound and outbound email: SPF, DKIM, DMARC, and delivery security that reduces impersonation risk.

Our Microsoft 365 & Workstation Security service addresses the access and device controls that carriers care about most: MFA enforcement, legacy authentication reduction, admin privilege review, external sharing controls, and workstation security.

Our Compliance Documentation Assistance service helps firms turn technical reality into clear, evidence-based answers for cyber insurance applications and client security questionnaires. It is not about writing a generic checklist. It is about documenting what is true, identifying what is missing, and translating that into language an underwriter or client can actually evaluate.

The takeaway

Cyber insurance is not just about buying a policy. It is about proving the controls the insurer expects to exist and to be maintained. For law firms, that means the gap between what appears to be secure and what can actually be demonstrated is where risk usually shows up.

If your firm cannot show MFA status by system, device coverage for EDR, tested backups, email authentication enforcement, documented patching, and an incident response plan, you are leaving the renewal conversation and the claims process to chance.

The better question is not whether your firm has these controls. It is whether your firm can prove them before an insurer asks.

Get your free review | See pricing | Contact us