The Beginners Guide To Cyber Insurance for Law Firms

The COVID-19 pandemic has impacted everyone in one way or another. A section of society that has benefited hugely from the pandemic is cybercriminals. Cybercrime has shot up by almost 300% since the start of the pandemic.

The top 100 UK law firms are more likely to see cyber-attacks as a threat to their ambitions than Covid-19, a survey by Big Four accountants PwC has found. In its annual top-100 survey, PwC said 90% were “extremely or somewhat concerned” about the impact of cyber threats on their ability to achieve their ambitions over the next 12 months.

But it would be wrong to think that cybercrime only affects the big law firms. That’s why you must take necessary measures to protect your business. One of these measures is to have Cyber Insurance. This might also be called Cyber Liability Insurance or Cyber Risk Insurance.

Cyber Insurance covers the financial loss that results from cyber events such as data breaches. However, cyber liability is not typically included within general liability insurance and must be purchased separately. Also, each company offering a policy has different coverage options available and exclusions included.

Our Beginner’s Guide to Cyber Insurance for Law Firms is not meant to be a comprehensive buyers guide. But it will give you an overview of why you should consider cyber insurance and what it could cover.

Why Invest in Cyber Liability Insurance?

Experts estimate that the damage inflicted by cybercrimes will add up to about $6 trillion globally in 2021. That’s higher than the GDP of the world’s third-largest economy, Japan!

These statistics show why SMBs in particular should have cyber liability insurance:

  • Over 40% of cyberattacks target small businesses.
  • More than 60% of SMBs have experienced a cyberattack in the past 12 months.
  • Over 45% of SMBs say that their processes are ineffective at mitigating attacks.

Having cyber insurance could be the difference between your business sinking or staying afloat after a security incident. Without cyber insurance, the various expenses you might have to bear after an incident could financially harm your business in the short term. In the worst case, it could result in permanent closure.

Here are a few expenses that a practice would have to manage following a severe data breach incident:

  • Downtime
  • Investigation
  • Data Recovery
  • Legal Proceedings
  • Cost of notifying stakeholders about the incident
  • Cost of restoring the personal identities of those affected

Good cyber insurance would usually cover these expenses. But always remember that before you commit to a policy, you must get clarity from your insurer about what they do and do not cover.

Does your business need it?

Every business should consider having cyber liability insurance. Law firms are increasingly an attractive target for cyber criminals because of the nature of their business. In the course of corporate legal and M&A work, litigation and other legal services they perform, law firms and in-house legal teams collect tons of confidential corporate information and sensitive data like tax returns. They can suffer reputational and financial losses if they are breached, especially if data is exposed. Therefore, cyber liability insurance should be a priority.

Make sure your cyber liability insurance has the following essential coverages:

First-party coverage:

  • Network security and privacy liability

Covers breach response costs like forensic investigations, public relations, credit monitoring, legal fees and fines/penalties

  • Business interruption losses and extra expenses

Covers lost revenue and added costs to continue business

  • Digital data recovery and cyber extortion expenses

Covers losses such as ransom paid due to ransomware

Third-party coverage:

  • Cyber liability

Covers claims of lawsuit expenses resulting from breaches in client systems or networks

  • Media liability

Covers claims of libel, copyright/trademark infringement, etc., resulting from media use

Cybercrime coverage:

  • Covers losses from digital theft of money or securities and social engineering fraud

Who Are the Top Cyber Liability Insurance Carriers?

Finding the right cyber insurance provider is not easy. While most general insurance providers offer general liability coverage, they don’t always offer comprehensive cyber coverage.

You can visit the Association of British Insurers for independent advice on Cyber Insurance and The National Cyber Security Centre (NCSC) also provide their own Cyber Insurance Guidance

The following insurance companies are some of the leading cyber insurance providers in the UK:

But remember, just committing to a policy is not enough. You will also have to track/measure compliance with the agreement to make sure your contract is always valid, and will therefore, pay out in the event of an issue.

One of the best ways to do this is through Cyber Essentials or Cyber Essentials Plus certification. Indeed, you can apply for free cyber insurance upon completion of the Cyber Essentials certification. However the level of this is unlikely to be sufficient for all but the smallest firm.

How We Can Help 

Hopefully our Beginner’s Guide to Cyber Insurance for Law Firms has been useful.

Whether you are looking to find a cyber insurance policy that is right for your business or trying to find and measure your policy’s compliance with cyber insurance contracts, we are here to help.

We can organise a video call with expert for the legal sector, Mike Birt.

There is no obligation to move to a full IT Assessment following this call, Mike can just answer your most burning questions. And, of course, there is no obligation to buy anything, ever.

0/5 (0 Reviews)
  • FAST RESPONSE

    15-minute response time

  • NO LONG-TERM CONTRACTS

    Low Risk & Complete Flexibility

  • CLIENT FOCUSED

    An Extension of Your Business