Businessman shields office from hackers using a strong lock shield, while coworkers cheer in a law office setting.

What Cybersecurity Controls Do Law Firms Need for Cyber Insurance?

August 05, 2026

Prepare for 12 Common Cyber Insurance Requirements

Law firms seeking cyber insurance should prepare to demonstrate 12 core cybersecurity controls: multi-factor authentication, protected administrator accounts, endpoint detection and response, security updates, email protection, employee training, data encryption, access management, secure backups, 24/7 monitoring, incident response, and vendor-risk management.

Insurer requirements vary by carrier, policy, firm size, claims history, coverage limits, and the type of information the firm handles. However, underwriters increasingly want evidence that security controls are operating across the entire environment—not merely purchased or enabled for selected employees.

For a 25–50 employee law firm, the preparation process should begin 60–120 days before renewal. That window gives the firm time to verify controls, correct coverage gaps, complete recovery testing, update written procedures, and resolve differences between the insurance application and the actual technology environment.

The objective is not simply to obtain a policy. It is to ensure that the statements made on the application can be supported with current, accurate evidence.

1. Enforce Multi-Factor Authentication Across the Complete Environment

Multi-factor authentication, or MFA, requires a user to provide an additional form of verification beyond a password.

A law firm should evaluate MFA for:

  • Microsoft 365
  • Remote network access
  • Practice-management systems
  • Document-management systems
  • Cloud file-sharing platforms
  • Accounting and payroll applications
  • Backup administration
  • Security-tool consoles
  • Website and domain administration
  • Privileged administrator accounts
  • Remote-support tools

Do not answer “yes” because most employees use MFA

An application may ask whether MFA is required for all remote access, all email access, or all privileged accounts.

That statement may be inaccurate when:

  • One partner is permanently excluded.
  • A legacy email application bypasses modern authentication.
  • A vendor account still uses only a password.
  • Administrators access a backup portal without MFA.
  • A remote-access tool uses shared credentials.
  • A service account can sign in interactively.

Before answering, create a system-by-system MFA inventory showing:

  • The application
  • The users with access
  • The authentication method
  • Any exclusions
  • The business reason for each exclusion
  • The remediation date

Use stronger authentication for high-risk users

Partners, finance personnel, executives, administrators, and employees authorized to approve payments should be evaluated for phishing-resistant methods such as:

  • Passkeys
  • Hardware security keys
  • Windows Hello for Business
  • Certificate-based authentication where appropriate

Text messages and approval prompts are better than passwords alone, but stronger methods can provide additional protection against credential phishing and repeated approval attacks.

2. Protect Administrative and Privileged Accounts

Privileged accounts can change security policies, create users, access sensitive information, disable safeguards, or interfere with recovery systems.

A law firm should:

  • Limit the number of highly privileged accounts.
  • Assign only the access required for each role.
  • Use separate daily and administrative accounts.
  • Require strong MFA for administrators.
  • Review privileged access at least quarterly.
  • Monitor administrator sign-ins and role changes.
  • Disable obsolete provider and vendor accounts.
  • Maintain protected emergency-access accounts.

Separate administrative work from ordinary activity

An IT administrator should not use a highly privileged identity for routine email, web browsing, document editing, or general communication.

Each administrator should have:

  • A normal account for daily work
  • A separate identity for administrative tasks
  • Documented role assignments
  • Approved authentication methods
  • Monitored sign-in activity

Review outside-provider access

Managed service providers, software vendors, consultants, and other third parties may hold administrative access.

The firm should know:

  • Which company has access
  • Which individual or account is used
  • What permissions are assigned
  • Whether MFA is enforced
  • How activity is logged
  • When access was last reviewed
  • How access will be removed

Firm leadership should not assume that every technician at an outside provider requires unrestricted access.

3. Deploy Endpoint Detection and Response to Every Supported Device

Endpoint detection and response, often called EDR, monitors computers and servers for suspicious behavior that traditional antivirus may miss.

A cyber insurance application may ask whether EDR or managed detection is deployed throughout the organization.

The law firm should verify coverage for:

  • Attorney laptops
  • Employee desktops
  • Remote computers
  • Servers
  • Temporary replacement devices
  • Computers kept at secondary offices
  • Approved virtual desktops

Measure coverage, not license purchases

Buying 40 licenses does not prove that 40 computers are protected.

The provider should produce a current report showing:

  • Every known device
  • Whether the security agent is installed
  • Whether it is actively reporting
  • The last check-in time
  • The assigned user
  • The operating-system status
  • Any unresolved health issue

Unprotected or inactive devices should have assigned owners and remediation deadlines.

Confirm who responds to alerts

Technology that identifies suspicious behavior is useful only when qualified personnel review and respond.

Ask:

  • Who monitors endpoint alerts?
  • Is monitoring active outside business hours?
  • Can the responder isolate a device?
  • Can compromised credentials be disabled?
  • How quickly are critical alerts reviewed?
  • When is firm leadership notified?
  • How are response actions documented?

Explore cybersecurity services for coordinated endpoint protection, threat monitoring, identity security, and incident response.

4. Maintain Supported Systems and a Measurable Patching Process

Cyber insurance underwriters may ask whether the firm regularly installs security updates or remediates critical vulnerabilities within a specified period.

A defensible patching program should cover:

  • Windows and macOS
  • Servers
  • Microsoft 365 applications
  • Web browsers
  • PDF software
  • Remote-access applications
  • Firewalls
  • Wireless equipment
  • Backup appliances
  • Legal applications
  • Third-party utilities

Define correction targets by risk

The firm may use target ranges such as:

  • Critical actively exploited issues: Immediate review and expedited correction
  • Critical vulnerabilities: Remediation within 7–14 days where operationally possible
  • High-risk vulnerabilities: Remediation within 14–30 days
  • Routine updates: Installation through the standard monthly process

These are example ranges. The firm should select targets based on its risk, systems, operational constraints, and insurer requirements.

Track exceptions

Some legal applications may require compatibility testing before updates are installed. When a patch is delayed, document:

  • The affected system
  • The vulnerability
  • The business reason for delay
  • The temporary safeguards
  • The responsible person
  • The expected correction date

Replace unsupported technology

Systems that no longer receive security updates may create underwriting concerns and operational risk.

Maintain a replacement plan showing:

  • Device or application
  • Support expiration
  • Business impact
  • Replacement approach
  • Estimated cost
  • Target completion date

5. Protect Email Against Phishing and Impersonation

Email is a primary pathway for credential theft, fraudulent payment requests, malicious attachments, and unauthorized access to confidential information.

A law firm’s email protections should address:

  • Spam and phishing filtering
  • Malicious attachment inspection
  • Malicious link protection
  • Executive and partner impersonation
  • Lookalike domains
  • Suspicious mailbox rules
  • Automatic external forwarding
  • Unusual sign-ins
  • Third-party application access
  • Sender authentication

Configure SPF, DKIM, and DMARC

The firm should identify every authorized service that sends email using its domain, including:

  • Microsoft 365
  • Practice-management platforms
  • Billing systems
  • Marketing applications
  • Electronic signature services
  • Website forms
  • Document-sharing applications

SPF, DKIM, and DMARC should then be configured and monitored to reduce unauthorized use of the firm’s domain.

Block automatic external forwarding by default

An attacker may create a hidden rule that sends copies of messages outside the firm.

External forwarding should be prohibited or restricted to approved and documented business cases.

Use verification procedures for financial requests

Email security tools cannot determine whether every payment instruction is legitimate.

The firm should require employees to verify high-risk requests through a separate, known communication method when messages involve:

  • Wire transfers
  • Settlement payments
  • Vendor bank changes
  • Payroll changes
  • Gift card purchases
  • Password resets
  • Unexpected document requests

6. Provide Recurring Security Training and Phishing Tests

Employees need practical training that reflects the messages, workflows, and decisions they encounter.

A training program should include:

  • New-employee training
  • Annual or recurring awareness education
  • Phishing simulations
  • Targeted follow-up for employees who need help
  • Procedures for reporting suspicious activity
  • Training records

Teach law-firm-specific scenarios

Training should address examples such as:

  • A client requesting an urgent wire change
  • A partner apparently sharing a confidential document
  • A court notice containing a malicious link
  • A fake Microsoft 365 password-expiration message
  • A vendor asking an employee to approve a new application
  • An unexpected MFA prompt
  • A request to move a conversation to personal email

Make reporting simple

Employees should know exactly how to report:

  • Suspicious email
  • An unexpected authentication prompt
  • A lost device
  • A mistaken file share
  • A password entered into a suspicious website
  • Unusual computer behavior

The reporting process should reach a monitored team rather than an inbox checked only during normal business hours.

Measure completion and improvement

Evidence may include:

  • Training completion reports
  • Simulation participation
  • Reported phishing messages
  • Targeted coaching records
  • Recurring risk themes

The purpose is risk reduction, not embarrassing employees who make mistakes.

7. Encrypt Confidential Information on Devices and in Transit

Encryption can reduce the exposure created by lost devices, stolen equipment, intercepted connections, and unauthorized access to stored information.

A law firm should verify encryption for:

  • Laptops
  • Desktop computers where appropriate
  • Servers
  • Mobile devices
  • Backup media
  • Portable drives
  • Cloud connections
  • Remote access

Verify disk encryption rather than relying on policy

A written policy stating that laptops must be encrypted does not prove that encryption remains active.

The provider should produce a report showing:

  • The device
  • The assigned user
  • The encryption status
  • The recovery-key location
  • The last verification date

Control portable storage

USB drives and portable disks should be:

  • Blocked when unnecessary
  • Approved before use
  • Encrypted when permitted
  • Tracked when containing confidential information
  • Securely erased or destroyed when retired

Secure remote connections

Remote access should use encrypted connections, MFA, approved devices, current software, and active monitoring.

Employees should not expose internal systems directly to the internet or use unapproved remote-control applications.

8. Apply Least Privilege and Complete Access Reviews

Least privilege means employees receive the minimum access required to perform their responsibilities.

Access should reflect:

  • Job role
  • Practice group
  • Assigned matters
  • Ethical walls
  • Financial responsibilities
  • Administrative duties
  • Client requirements

Standardize onboarding

A new-employee checklist should identify:

  • The approved job role
  • The manager or attorney authorizing access
  • Microsoft 365 licensing
  • Practice-management access
  • Document permissions
  • Email groups
  • Remote-access requirements
  • Equipment assignment
  • MFA enrollment
  • Training requirements

Disable access promptly during offboarding

The offboarding process should include:

  • Disabling user accounts
  • Revoking active sessions
  • Removing authentication methods
  • Removing remote access
  • Transferring email and files
  • Removing third-party application access
  • Recovering devices
  • Changing shared credentials
  • Preserving required information

Review access quarterly

The review should include:

  • Former employees
  • Inactive accounts
  • Privileged administrators
  • Outside vendors
  • Guest users
  • Shared mailboxes
  • Restricted matters
  • Remote-access accounts

Document who completed the review, which exceptions were found, and when corrections were completed.

9. Maintain Isolated Backups and Test Restoration

Cyber insurance applications frequently ask about backup frequency, isolation, immutability, retention, and recovery testing.

A defensible backup strategy should include:

  • Multiple copies of critical information
  • At least one isolated or immutable copy
  • Separate backup credentials
  • Encryption
  • Monitored job status
  • Defined retention
  • Protection for local and cloud systems
  • Documented restoration procedures
  • Recurring recovery tests

Define recovery targets

Each critical system should have:

  • Recovery Time Objective: The maximum acceptable period of downtime
  • Recovery Point Objective: The maximum acceptable amount of recent data loss

These targets should be approved by firm leadership and supported by the actual recovery design.

Test real recovery

A quarterly test may restore:

  • A matter folder
  • An email message or mailbox
  • A SharePoint library
  • A OneDrive folder
  • A server
  • A database
  • A legal application

The test report should record:

  • What was restored
  • Which backup copy was used
  • How long recovery took
  • Whether the information was complete
  • Whether permissions were correct
  • Whether an attorney or business owner validated it
  • Whether the approved target was met

A dashboard showing successful backup jobs is not equivalent to a demonstrated restoration.

Explore business continuity services for backup protection, disaster recovery, recovery testing, and continuity planning.

10. Monitor Security Events 24/7

Attacks do not occur only during business hours. Law firm systems remain online during evenings, weekends, holidays, and employee vacations.

Continuous monitoring may include:

  • Endpoint alerts
  • Microsoft 365 sign-ins
  • Administrator role changes
  • Suspicious mailbox activity
  • Firewall events
  • Backup failures
  • Security-tool health
  • Malicious application consent
  • Unusual downloads or deletions
  • Repeated authentication failures

Clarify what “24/7 monitoring” means

Ask whether:

  • A qualified person reviews alerts at all times.
  • The monitoring team can take containment action.
  • The firm has an after-hours escalation contact.
  • Response times are defined by severity.
  • Actions are documented.
  • Monitoring includes cloud identity as well as computers.

A tool sending alerts to an inbox is not the same as continuous human review and response.

Maintain an escalation matrix

Severity Example Expected action
Critical Active ransomware, confirmed account takeover, widespread outage Immediate containment and leadership escalation
High Malware detection, suspicious administrator activity, backup failure Rapid investigation and documented response
Medium Repeated login failures, risky application, missing security agent Same-day investigation and correction planning
Low Routine policy deviation or informational alert Review through the normal operating process

The actual response targets should be defined in the firm’s service agreement and incident procedures.

11. Maintain a Written Incident Response Plan

A cyber insurance application may ask whether the firm has a documented and tested incident response plan.

The plan should address:

  • Incident declaration
  • Technical containment
  • Leadership authority
  • Evidence preservation
  • Business continuity
  • Insurance notification
  • Outside counsel coordination
  • Forensic support
  • Client communication
  • Regulatory and contractual review
  • System restoration
  • Post-incident improvement

Assign specific roles

The plan should identify:

  • Executive incident leader
  • Technical response lead
  • Legal and compliance lead
  • Operations lead
  • Communications lead
  • Insurance coordinator
  • System business owners

Maintain offline contact information

The contact list should include:

  • Cyber insurer
  • Insurance broker
  • Breach counsel
  • Forensic provider
  • Managed IT provider
  • Critical software vendors
  • Firm leadership
  • Alternate employee contacts

Do not store the only copy of the plan inside the environment that may become unavailable.

Test the plan annually

A tabletop exercise should require leadership to respond to a realistic scenario.

For example:

At 7:30 a.m. on a Monday, several employees cannot open matter documents. One attorney reports an unexpected MFA prompt, the backup dashboard is unavailable, and a filing deadline is four hours away.

The exercise should test:

  • Who declares the incident
  • Who contacts the insurer
  • How affected systems are isolated
  • How court deadlines are handled
  • How employees receive instructions
  • How clients are informed
  • Which systems are restored first

12. Evaluate Vendors and Third-Party Technology Risk

Law firms rely on software providers, cloud platforms, consultants, payment processors, filing services, researchers, experts, and outsourced technology companies.

A vendor may create risk through:

  • Administrative access
  • Weak authentication
  • Stored client information
  • Remote-support tools
  • Unreviewed integrations
  • Inadequate incident notification
  • Unclear data-return procedures

Create a vendor inventory

For each significant vendor, document:

  • The service provided
  • The type of information accessed or stored
  • The business owner
  • The technical owner
  • The authentication method
  • The level of administrative access
  • The contract renewal date
  • The incident contact
  • The data-return and deletion process

Review critical vendors before renewal

Questions may include:

  • Is MFA available and enforced?
  • How is data encrypted?
  • Which subcontractors are involved?
  • How are incidents reported?
  • How is information backed up?
  • Can the firm export its data?
  • How is access removed when the contract ends?
  • Does the vendor carry appropriate insurance?

Remove unused integrations

Applications connected to Microsoft 365 or other legal systems may retain access long after employees stop using them.

Review connected applications at least quarterly and remove permissions that no longer have a documented purpose.

Create a Cyber Insurance Evidence Package

The strongest renewal preparation produces a collection of current evidence rather than a set of assumptions.

The package may include:

  1. MFA coverage report
  2. Privileged-access review
  3. Device and EDR coverage report
  4. Patch and vulnerability report
  5. Email-security configuration summary
  6. Security-training completion report
  7. Encryption status report
  8. User-access review
  9. Backup and restoration test results
  10. Monitoring and escalation summary
  11. Incident response plan
  12. Tabletop exercise record
  13. Vendor inventory
  14. Open cybersecurity risk register

Date every artifact

Evidence from two years ago may not reflect the current environment.

Each report should show:

  • The date
  • The systems reviewed
  • The person or provider completing the review
  • The findings
  • The unresolved exceptions
  • The next review date

Preserve the completed application

Keep:

  • The submitted application
  • Supporting evidence
  • Clarifications provided to the broker or insurer
  • The final policy
  • Endorsements
  • Security-control warranties or conditions

Firm leadership, the broker, qualified counsel, and the technology team should resolve unclear questions before submission rather than guessing.

Use a 90-Day Cyber Insurance Readiness Process

Days 1–30: Verify

  • Collect the prior application and current insurer questions.
  • Inventory systems, users, devices, vendors, and administrators.
  • Verify MFA coverage.
  • Verify EDR and encryption coverage.
  • Review backup protection.
  • Identify unsupported technology.
  • Review incident-response documentation.

Days 31–60: Correct

  • Remove MFA exclusions.
  • Deploy missing security agents.
  • Disable inactive accounts.
  • Separate administrator access.
  • Correct critical vulnerabilities.
  • Protect backup credentials.
  • Update the incident response plan.
  • Resolve high-risk vendor access.

Days 61–90: Test and document

  • Complete a backup restoration test.
  • Run a phishing simulation.
  • Conduct a privileged-access review.
  • Perform an incident-response tabletop exercise.
  • Prepare the evidence package.
  • Review answers with leadership and the broker.
  • Assign owners to remaining exceptions.

Starting three months ahead reduces the pressure to make major security changes during the final week before renewal.

A Practical Example for a 35-Employee Law Firm

Consider a Salt Lake City law firm with 35 employees, Microsoft 365, remote attorneys, a cloud practice-management platform, a local document server, and an outsourced IT provider.

The renewal application asks whether the firm has:

  • MFA for email and remote access
  • EDR on every computer
  • Encrypted laptops
  • Offline or immutable backups
  • Annual security training
  • A tested incident response plan
  • 24/7 security monitoring

Leadership initially believes the firm can answer “yes” to all seven questions.

The evidence review finds:

  • Two partners are excluded from an MFA policy.
  • Three remote laptops have stopped reporting to the EDR console.
  • One replacement laptop is not encrypted.
  • Backups are completing, but no restoration test has been documented.
  • Five new employees have not completed security training.
  • The incident plan lists two former employees.
  • Microsoft 365 alerts are reviewed only during business hours.

30-day remediation plan

  1. Remove the MFA exclusions.
  2. Repair or replace the missing endpoint agents.
  3. Enable encryption and record the recovery key.
  4. Restore a representative matter folder and mailbox.
  5. Complete training for all outstanding employees.
  6. Update the response plan and contact list.
  7. Establish after-hours alert monitoring and escalation.

The firm then answers the insurance questions using current evidence rather than its original assumptions.

What Cyber Insurance Does Not Replace

A cyber policy may help fund approved legal, forensic, notification, restoration, interruption, and liability costs after a covered event.

It does not replace:

  • Secure configuration
  • Employee training
  • Active monitoring
  • Incident response planning
  • Protected backups
  • Access reviews
  • Technology maintenance
  • Leadership decision-making

Coverage also depends on the policy’s terms, conditions, exclusions, limits, deductibles, and reporting requirements. The firm should review those matters with its broker and qualified counsel.

Questions to Ask the Insurance Broker

  1. Which security controls are mandatory for coverage?
  2. Which answers create continuing obligations during the policy period?
  3. Are there separate requirements for ransomware coverage?
  4. Are social-engineering and funds-transfer losses covered?
  5. What are the sublimits for those events?
  6. Does the policy require approved forensic or legal providers?
  7. How quickly must the carrier be notified?
  8. Which costs require advance approval?
  9. Are voluntary shutdown costs covered?
  10. How is business interruption calculated?
  11. Are cloud-provider incidents covered?
  12. Are vendor incidents covered?
  13. What exclusions apply to unsupported technology?
  14. What records should the firm preserve?
  15. What changes must be reported during the policy term?

Questions to Ask the IT Provider

  1. Can you produce evidence for every cyber insurance control?
  2. Which employees or systems are excluded from MFA?
  3. Are all devices actively reporting to EDR?
  4. Who monitors security alerts after hours?
  5. When was the last restoration test?
  6. Can you show the written result?
  7. Are backup credentials separated from normal administrators?
  8. Which systems are unsupported?
  9. When was privileged access last reviewed?
  10. Which former employee or vendor accounts remain active?
  11. Is every firm laptop encrypted?
  12. When was the incident response plan last tested?
  13. Which insurer requirements are not currently satisfied?
  14. What will remediation cost?
  15. Who owns each correction and when will it be completed?

Read the six questions that reveal whether an IT provider is actually protecting the firm for additional ways to evaluate evidence and accountability.

What Law Firm Clients Value During Insurance Preparation

Customer feedback collected by 911 IT repeatedly highlights the value of clear answers, proactive guidance, rapid support, and confidence that security requirements are being handled.

Clients value a provider that:

  • Identifies gaps before renewal deadlines
  • Explains requirements without unnecessary technical language
  • Produces evidence instead of verbal reassurance
  • Coordinates security, Microsoft 365, backups, and user access
  • Responds quickly when problems are discovered
  • Creates a prioritized remediation plan
  • Remains accountable until corrections are verified

One recurring concern among law firms is discovering during renewal that required controls were never fully deployed, even though leadership believed they were in place.

A stronger process gives partners a current control report that distinguishes among:

  • Fully implemented controls
  • Partially implemented controls
  • Unsupported assumptions
  • Open remediation work

That clarity supports more accurate communication with brokers, insurers, clients, and firm leadership.

30-Point Cyber Insurance Readiness Checklist

  • MFA is enforced for every employee.
  • MFA protects remote access.
  • MFA protects privileged accounts.
  • High-risk users have been evaluated for stronger authentication.
  • Administrative accounts are separate from daily accounts.
  • Privileged access was reviewed within the last quarter.
  • EDR is installed on every supported computer and server.
  • Every security agent is actively reporting.
  • Critical security updates follow defined remediation targets.
  • Unsupported systems have replacement plans.
  • Email filtering addresses phishing and impersonation.
  • Automatic external forwarding is restricted.
  • SPF, DKIM, and DMARC have been reviewed.
  • All current employees completed security training.
  • Phishing simulations are performed.
  • Employees have a simple incident-reporting process.
  • Firm laptops are encrypted.
  • Encryption recovery keys are securely retained.
  • Onboarding and offboarding follow written checklists.
  • Inactive and former employee accounts are disabled.
  • Guest and vendor access is reviewed.
  • Backups include isolated or immutable protection.
  • Backup credentials are separated.
  • A real restoration test has been completed.
  • Security alerts are monitored after hours.
  • Critical escalation procedures are documented.
  • The incident response plan is current.
  • Leadership completed a tabletop exercise.
  • Critical vendors are inventoried.
  • Application answers are supported by current evidence.

Any answer of “no,” “probably,” or “our provider handles that” should become a documented action item before the application is submitted.

Common Cyber Insurance Application Mistakes

Answering from memory

Leadership may reasonably believe a control is active without knowing about exclusions, disconnected devices, inherited accounts, or failed tools.

Using vague definitions

Terms such as MFA, EDR, offline backup, encryption, and 24/7 monitoring can have precise meanings. Confirm what the application is asking before answering.

Assuming a purchased tool is fully deployed

A license does not prove installation, configuration, coverage, monitoring, or response.

Ignoring cloud systems

Applications may ask about all critical information, including Microsoft 365 and hosted legal platforms—not only local servers.

Failing to report exceptions

One unprotected administrator or remote computer may make a broad “all users” statement inaccurate.

Waiting until the renewal deadline

Major improvements such as MFA enforcement, backup redesign, device replacement, or monitoring changes may require weeks to complete safely.

Letting the IT provider complete the application alone

The technology provider can verify technical controls, but firm leadership, the broker, and qualified counsel should review the representations and policy implications.

Failing to preserve evidence

The firm should retain the reports and documentation supporting its answers.

Frequently Asked Questions

Is multi-factor authentication required for cyber insurance?

Many insurers evaluate MFA for email, remote access, privileged accounts, and other critical systems. The exact requirement depends on the insurer and policy. The firm should confirm scope rather than assuming partial deployment is sufficient.

Does every law firm need endpoint detection and response?

EDR is commonly evaluated because it can identify and contain suspicious behavior on computers and servers. Insurers may ask whether it is deployed and monitored across the full environment.

What is an immutable backup?

An immutable backup is protected from alteration or deletion for a defined period. It can reduce the likelihood that ransomware or a compromised administrator will destroy every recovery copy.

How often should a law firm test backup recovery?

Critical recovery processes should be tested on a recurring schedule, often quarterly. The test should restore usable information and document whether the recovery target was met.

Does Microsoft 365 provide everything needed for cyber insurance?

Microsoft 365 includes significant security and recovery capabilities, but the firm remains responsible for licensing, configuration, monitoring, access, employee behavior, third-party applications, and recovery planning.

Does cyber insurance cover ransomware payments?

Coverage depends on the policy, endorsements, exclusions, applicable law, insurer approval, and the circumstances of the event. The firm should review this issue with its broker and qualified counsel.

Can a claim be affected by an inaccurate application?

Application accuracy can be important to underwriting and coverage. Firm leadership should ensure that answers are supported by evidence and obtain legal guidance when questions or policy consequences are unclear.

Who should complete the cyber insurance application?

The process should involve firm leadership, the insurance broker, the technology provider, and qualified counsel as appropriate. No single participant may have complete knowledge of the technical, operational, and legal issues.

How early should a firm prepare for renewal?

Beginning 60–120 days before renewal provides time to assess controls, correct gaps, perform tests, gather evidence, and clarify questions with the broker or insurer.

What should a firm do when it cannot satisfy a requirement?

Document the gap, determine whether a compensating safeguard is available, create a remediation plan, and discuss the issue accurately with the broker and insurer. Do not make an unsupported affirmative statement.

Build Insurability on Verifiable Security Controls

Cyber insurance readiness should be based on 12 verified control areas:

  1. Multi-factor authentication
  2. Protected administrator accounts
  3. Endpoint detection and response
  4. Security updates
  5. Email protection
  6. Employee training
  7. Encryption
  8. Access management
  9. Protected backups
  10. 24/7 monitoring
  11. Incident response
  12. Vendor-risk management

The firm should be able to support every material application answer with a current report, test result, written procedure, or documented review.

That evidence does more than support insurance renewal. It gives partners clearer visibility into whether the systems protecting confidential client information are working as intended.

911 IT helps Utah law firms assess cybersecurity controls, secure Microsoft 365, monitor threats around the clock, protect backups, test recovery, prepare incident procedures, and remediate insurance-readiness gaps.

Explore our cybersecurity services, review our business continuity services, learn about managed IT services, or schedule a 10-minute discovery call to evaluate your firm’s cyber insurance readiness before the next renewal.