IT Support for Law Firms · Cyber Security

Cyber Insurance for Law Firms: What Your Insurer Will Actually Check

31 July 2026

Cyber Insurance for Law Firms: What Your Insurer Will Actually Check

Law firms are consistently among the most targeted organisations in the UK for cyber attack. The combination of client money accounts, privileged communications, and high-value transaction data makes a successful breach extraordinarily lucrative for attackers — and extraordinarily damaging for practices.

Cyber insurance is a sensible response to that exposure. But the controls law firms need to have in place to make a claim pay out are more specific than a generic business policy implies, and the SRA's own expectations align closely with what insurers look for.

Why law firms face closer scrutiny at claim time

Cyber insurers assess risk at the point of application and again at the point of claim. For law firms, the scrutiny is heightened because:

  • The value of a successful breach is high — client funds, commercially sensitive matters, and personal data all carry significant potential liability
  • The SRA's Accounts Rules and professional obligations mean there is a higher bar for what constitutes adequate controls
  • Phishing and business email compromise attacks targeting conveyancing firms and client account transfers are sufficiently well-documented that insurers treat them as a known, specific risk rather than a generic one

This means the gap between a firm that will have a claim paid and a firm that will not is often found in the specific controls around email security, client account handling, and identity verification — not in general IT hygiene alone.

What insurers check for legal practices

Email security and anti-spoofing

Business email compromise — where an attacker intercepts or spoofs legitimate email to redirect client funds — is the primary cyber risk for conveyancing and commercial practices. Insurers will look for SPF, DKIM, and DMARC records on your domain, anti-phishing filtering, and whether staff have been trained to verify payment instruction changes through an out-of-band channel (a phone call to a known number, not a reply to the email).

Multi-factor authentication on all access

MFA on case management systems, email, remote access, and any system through which client account instructions flow is a near-universal insurer requirement. A single account without MFA that is used in a breach gives an insurer grounds to question whether controls were in place as represented.

Client account controls

Procedures for verifying payment instructions — particularly changes to account details — are something insurers look at closely for conveyancing practices. Written protocols, dual authorisation for large transfers, and verbal verification steps are all evidence that the firm took reasonable precautions.

Access to matter files and client data

Who can access which matter files, whether former staff accounts are promptly disabled, and whether access to sensitive matters is restricted to those with a need — these are access control questions that appear in policy applications and can be tested by an insurer's forensic team after an incident.

Incident response and SRA notification

Firms have obligations to notify the SRA and, in some cases, the ICO following a breach. Insurers expect those notifications to happen within required timeframes and expect the firm to have followed a documented response plan. Delayed or absent notification is one of the more reliable ways to complicate a claim.

How the SRA's expectations align

The SRA expects firms to have appropriate systems and controls to protect client money and client data. The specific controls insurers look for — MFA, access management, verified payment procedures, staff training, incident response — are not separate from regulatory compliance. They are the same thing. A firm that has robust controls for the SRA is, in most respects, a firm that has robust controls for its insurer.

The risk area is the gap between what the firm believes its controls to be and what they actually are in practice. Annual reviews of who has access to what, whether MFA is genuinely applied everywhere, and whether payment verification procedures are actually followed — not just written down — are what close that gap.

Knowing where you stand

The Technology Resilience Score™ is a free assessment that gives law firms a clear view of their current control posture across the areas insurers and regulators care about: access management, backup and recovery, staff awareness, device and system security, and incident preparedness.

Your score tells you what your environment actually looks like today — the same picture an insurer's forensic team would build after a claim, except you get it in advance. If there are gaps, you have the opportunity to close them before your renewal and before you need to rely on the policy.

Get your free Technology Resilience Score for law firms →

We are not insurance advisers or legal compliance consultants. For advice on your specific policy or SRA obligations, speak to your broker and your compliance officer. What we can tell you is what the controls look like in practice.

Is your firm's technology environment resilient?

Find out how well protected your matter files, client account and email really are, with a free Technology Resilience Score™ written for law firms.

Get your firm's Technology Resilience ScoreTalk to us directly