Law Firms and Cyber Insurance: Placing the Risks That Keep You Awake at Night

Legal sector cyber submissions are getting harder to place. The problem usually isn't the firm's security: it's the evidence behind it.

Resource: Legal Firms
White Paper: How Cyber Risk Assessments Transform Insurability for Legal Firms
Why underwriters treat legal as a hard-to-place sector

Law firms hold some of the most sensitive data in existence. Client confidences, intellectual property, financial transaction details, dispute strategy. Information that is valuable to criminals, to competitors and, as the NCSC has warned, to state actors. They also conduct high-value financial transactions on behalf of clients, which makes them prime targets for business email compromise fraud. And they tend to operate with lean IT functions relative to the sensitivity of what they handle.

The regulator's own data supports this. The SRA reports that the cybercrime it hears about overwhelmingly involves client money, that three-quarters of all reports in 2024 came from residential conveyancing, and that email remains the most common route in.

It is no surprise, then, that the legal sector has attracted serious underwriting scrutiny. Insurers have seen the losses. They know the threat profile. And they have responded by tightening criteria, asking harder questions, and in some cases declining legal sector risks they would have written without difficulty a few years ago. Firms themselves are alert to it: 92% of the Top 100 told PwC this year that they were somewhat or extremely concerned cyber risk could stop them achieving their strategic ambitions, up from 89% the year before.

If you place cyber insurance for law firms, you're familiar with the challenge. Infoprotect's white paper, How Cyber Risk Assessments Transform Insurability for Legal Firms, explains why the difficulty is often worse than it needs to be, and what brokers can do to change the outcome for their clients.

The compliance-shaped answer to an underwriting-shaped question

The core problem, as the white paper identifies, is that legal firms tend to present their cyber risk through the lens of their regulatory and compliance obligations. They know about data protection. They have client confidentiality obligations built into their professional framework. They may have completed a Cyber Essentials assessment which is genuinely relevant, and no underwriter will disregard it. But it doesn't directly address the questions underwriters are asking when they assess a legal sector submission.

What underwriters actually want to know about a law firm

Insurers are interested in the attack vectors that drive losses in law firms specifically. Business email compromise is the most significant. Fraudulent diversion of client funds through manipulated payment instructions is a recurring claim type in the legal sector, driven as much by human factors as by technical ones.

The numbers are not abstract. In the SRA's thematic review of targeted firms, more than £4m of client money was stolen across 23 firms. Insurers met around £3.6m of it; close to £400,000 came out of firms' own money. That is before the premium increases, the lost time and the damage to client relationships that followed.

So, underwriters want to know how the firm manages that risk. What are the verification procedures for payment instructions? What does the security awareness training look like, and does anyone measure whether it works? What controls are in place around email authentication? A standard compliance assessment often doesn't go anywhere near this level of detail.

There is also the matter of handling confidential information and securing sensitive case files. Legal firms work with highly valuable data, and underwriters want to understand the governance around it. Not just whether data is encrypted, but whether access is properly controlled, whether the firm can demonstrate oversight at leadership level, and whether there are robust procedures for handling the kind of targeted social engineering that lawyers are particularly vulnerable to.

Nor is the sector escaping the more destructive end of the threat. Coveware's data, cited in Gallagher's recent legal sector market commentary, put professional services, which includes legal, as the single most affected sector for ransomware in Q2 2025, accounting for 19.7% of incidents, up from 14.4% the previous quarter.

Why self-attestation costs legal firms’ money

Self-attestation fails legal firms in a particularly expensive way. Partners completing a cyber insurance questionnaire are interpreting their own security controls based on their understanding of the technology and processes involved. They may genuinely believe the controls are better than they are. They may not be aware of gaps that a qualified assessor would identify in an afternoon. The underwriter receives an incomplete picture and discounts their confidence accordingly and that discount is priced in.

The white paper sets out what underwriters probe on a legal sector submission, and the evidence that answers them.

What an independent assessment changes

Infoprotect's Cyber Assess framework provides the independent, validated assessment that changes this. The report covers technical controls, governance maturity, human risk management and business resilience: all of the factors that determine whether a law firm is a well-managed cyber risk.

For brokers, the submission that accompanies this kind of assessment is materially different from a self-attested proposal form. It gives underwriters something they can assess with confidence, and it positions the firm's risk in its best possible light on the basis of evidence rather than assertion. It bridges the gap between security implementation and insurance outcomes.

A word on market conditions

It is worth being straight about where the market is. Cyber has been a buyer's market: capacity is ample, pricing has been broadly stable into 2026, and insurers had loosened requirements at the SME end, although that is subtly changing. This article is not an argument that every legal risk is about to become unplaceable.

It is an argument about differentiation. The best terms are going to the risks that can evidence their controls rather than describe them, and third-party and supplier oversight is now central to how underwriters look at a submission. Commentators are also flagging the potential for hardening as AI-driven attacks mature. A firm that can demonstrate its position now is buying at the best moment it is likely to get, and it will be in a far stronger position if conditions turn.

What this does for the broker relationship

The broker who brings this capability to their legal sector clients is offering something that changes the relationship. Rather than being the person who delivers bad news at renewal - the premium's gone up, the terms are tighter, the underwriter has questions - you become the person who anticipated the challenge and did something about it. The client gets better insurance outcomes. You get a client who understands the value you bring, and who is unlikely to test the market.

The governance dividend

There's a governance dividend too. For law firms operating under SRA requirements and navigating data protection obligations, a thorough cyber risk assessment produces board-level intelligence that has genuine value beyond the renewal. It is not simply an insurance exercise; it is a tool for the firm's leadership to understand and manage the risk properly, and to evidence that they have done so.

How Cyber Risk Assessments Transform Insurability for Legal Firms is free to download here.

If you have a legal sector renewal coming up in the next quarter, speak to Infoprotect UK about how a Cyber Assess report could change the submission.

About Infoprotect UK

Infoprotect helps businesses achieve cybersecurity compliance, maturity and customer satisfaction.

We also have a symbiotic relationship with Insurance Brokers to provide effective “cyber risk management” for their clients, which is critical for organisations of all sizes and types as cyber threats continue to evolve and become more sophisticated. It can help prevent data breaches, reduce the impact of cyber-attacks, and protect an organisation’s reputation and financial stability.

Our agile, personalised human approach differentiates us. We deliver business value to our clients through our commitment and dedication to service delivery.

Our Cyber Assess, Cyber GRC and Cyber Protect solutions are industry-leading cybersecurity services.

We bridge the cyber gap between businesses, brokers, and insurers by offering technical expertise in cyber risk management and compliance.

Infoprotect Services Limited, trading as, Infoprotect UK
Company registration no: 11928161
5 Brayford Square, London, E1 0SG

Stay up to date

Get the latest updates and exclusive tips about cyber resilience

© 2025. All rights reserved Infoprotect Services Limited.

We bridge the cyber gap between businesses, brokers, and insurers by offering technical expertise in cyber risk management and compliance.

Infoprotect Services Limited, trading as, Infoprotect UKCompany registration no: 119281615 Brayford Square, London, E1 0SG

Stay up to date

Get the latest updates and exclusive tips about cyber resilience

© 2025. All rights reserved Infoprotect Services Limited.

We bridge the cyber gap between businesses, brokers, and insurers by offering technical expertise in cyber risk management and compliance.

Infoprotect Services Limited, trading as, Infoprotect UK
Company registration no: 11928161
5 Brayford Square, London, E1 0SG

Stay up to date

Get the latest updates and exclusive tips about cyber resilience

© 2025. All rights reserved Infoprotect Services Limited.