A law firm’s cyber exposures include confidential matters, document access and payment communications. Policy comparison needs to reflect the firm’s actual workflow, including remote access and the way sensitive instructions are independently verified.

The decision that deserves the closest review

Map matter-management systems, shared files and payment authorisation. Ask how business email compromise, outsourced service failure and confidentiality-related allegations are addressed. Discuss professional indemnity interaction with a specialist adviser rather than assuming one product fills every gap.

A hypothetical example

A fraudulent message appears to change completion-payment instructions. The firm follows an independent verification process and reports the incident through the agreed channel. Insurance enquiry questions should test both attempted fraud and an actual financial loss.

Incident response and cyber cover

Cyber policies can address different combinations of response services, the insured business’s own losses and third-party allegations. Check each section rather than relying on the product name. Security obligations and consent before spending can be important parts of the comparison.

Premiums, excesses and usable cover

Request quotations using the same business description, required limits and relevant dates. Put the annual premium, any instalment charges, excesses and important sublimits in one comparison. A cheaper premium can represent a different transfer of risk rather than the same cover at a better price.

Comparison item Question to resolve
Payment-authorisation exposure Are fraud and breach costs separately limited?
Matter-management and document systems What verification procedures are conditions of cover?
Confidentiality responsibilities and recovery needs How is recovery coordinated with professional insurers?

Request the proposed wording and schedule, not just a price or certificate. Mark any difference that affects a real activity before deciding whether the premium saving is worthwhile.

Prepare an accurate insurance enquiry

Give each adviser a consistent description of the activities being insured. Include important contracts, changes since the previous enquiry and matters the insurer asks you to disclose. Do not guess answers merely to obtain a faster or cheaper quote; ask for clarification when the proposal wording is unclear.

Test payment instructions as well as file recovery

A law firm’s cyber enquiry should distinguish confidential records from client-payment processes. Explain who can change payment details, approve transfers and administer email accounts. Include outsourced systems and the steps used to verify an instruction that appears to come from a client or colleague.

Ask how the offered sections address an intrusion, a misdirected payment and interrupted access to matter files. Review notification and consent procedures against the firm’s incident plan. The practical comparison should identify the people available to help, not simply list a large overall limit.

Include overseas work or sales in the UK business’s enquiry and confirm the accepted territories and jurisdictions.

A mistake to avoid

Treating a cyber policy as a substitute for payment verification and access controls.

Check what happens after the policy starts

Ask who to contact when activities change or a potential claim arises. Understand the notification and consent process before arranging repairs, appointing specialists or settling a complaint. At renewal, compare the new documents with the accepted business description; continuity of a familiar brand does not prove continuity of every term.

Questions before choosing

Can cyber insurance guarantee recovery of stolen money?

No quotation should be read that way; ask for the exact insured events, sublimits and exclusions.

Will every fraudulent transfer fall within the cyber section?

Ask for the relevant wording and conditions to be explained. Do not infer the answer from the fact that an email or online account was involved.

Sources and further reading

Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.