Law firms buy malpractice coverage obsessively and then run trust accounts over email. Attackers noticed years ago: the wire-diversion email that redirects a closing, the ransomware note that locks case files a week before trial. Here's what law-firm cyber coverage actually needs to include in 2026, what it costs, and the five controls carriers now require before they'll quote at all.
| Coverage | The law-firm scenario it pays |
|---|---|
| Breach response | Forensics, client notification, credit monitoring, PR — discovery databases are PII warehouses |
| Funds-transfer fraud + social engineering | The diverted closing wire; confirm BOTH your funds and client funds you control are covered, at real sublimits |
| Ransomware / extortion | Negotiation, payment where lawful, restoration — and lost billable time via business interruption |
| Third-party privacy liability | Client suits over exposed privileged/PII data |
| Regulatory / bar defense | State AG privacy actions; some forms extend to disciplinary proceedings arising from the breach |
Two boundary notes: your LPL policy may cover a malpractice CLAIM that follows a cyber event (missed deadline because systems were down) but not the event itself — and cyber forms exclude professional services, so the two policies must meet without a gap. Check both sides' exclusions against the wire-fraud scenario specifically: money lost from a TRUST account lands in the seam unless someone endorsed it.
Small firms (under ~25 attorneys): $1,500–$7,500/yr per $1M limit, driven by revenue, practice mix (real estate and trust-heavy practices price higher — the wire exposure), controls, and claims. Mid-size firms scale up with revenue and data volume. Compare that to the median wire-diversion loss — six figures, unrecovered — and cyber sits beside LPL as the second mandatory line, with the same claims-made mechanics (refresher here) — mind retroactive dates when switching carriers, same as prior acts on your LPL.
A law firm's cyber policy is wire-fraud coverage first, ransomware coverage second, and breach response third — buy it in that order of scrutiny, implement the five controls before the application (they're the price of admission now), and make sure the cyber form and the LPL meet at every seam a trust account can fall through.
Law Firm Insurance Pros places cyber built for firms: social engineering at real sublimits including client funds, coordinated seams with your LPL, and applications prepped so the controls questions price in your favor.
Get a free quoteGeneral information only, not legal or coverage advice. Class codes, rates, and statutory requirements change and vary by carrier, state, and policy period. Law Firm Insurance Pros is operated by Thrive Risk Management Insurance Solutions, Inc., CA License #6012320. Confirm current requirements with a licensed agent.