Accounting and law firms are not ordinary small businesses when it comes to cyber risk, and a cyber insurance policy written for a generic retailer or consultancy will almost always leave a gap that becomes visible only after a real incident. These firms sit on a specific, concentrated combination of client financial data, privileged legal communications, litigation strategy, merger and acquisition details with real-time market value, and — for many law firms — direct control of trust accounts holding client funds. That combination makes them a disproportionately attractive target, and it means the insurance built to protect them needs to be built around that specific risk, not adapted from a template designed for a coffee shop or a marketing agency.
This matters more than most firms initially assume, because the professional obligations layered on top of ordinary data protection law — solicitor-client privilege for lawyers, the duty of confidentiality that governs both legal and accounting professional codes of conduct — create a category of exposure that a standard small-business cyber policy was never designed to address. A breach at a typical retailer means compromised customer emails and maybe credit card numbers. A breach at a law firm can mean a client's confidential litigation strategy sitting in a ransomware group's leak site, or a wire transfer redirected out of a real estate trust account days before closing. The dollar figures and the professional consequences are simply not the same category of event.
This guide covers what actually needs to be true about a cyber insurance policy for an accounting or law firm: why these firms are targeted the way they are, what makes a breach of privileged or confidential client information a distinct risk category insurers and firms both need to think about separately from an ordinary data breach, what a properly built policy should cover (and the specific gaps — regulatory fines, social engineering fraud — that catch firms off guard), what insurers now require before they'll even offer a quote, realistic Canadian premium ranges, and where to go for further guidance. If you want the compliance side of this picture specifically — what PIPEDA requires of accounting and law firms handling client data — our PIPEDA compliance guide for accounting and law firms covers that in depth; this guide focuses on the insurance layer that sits alongside it.
A note before we start
This article is general information to help your firm ask the right questions of a broker or insurer — it is not legal advice, and it is not a substitute for a policy review by a broker who specifically understands professional services and legal/accounting risk. Insurance policy wording varies significantly between insurers and can change year to year; always confirm the specifics of coverage, exclusions, and sub-limits directly in your policy documents before relying on any general description of what a "typical" policy covers.
Why Accounting and Law Firms Are High-Value Targets
Ransomware operators and business email compromise scammers are, at the end of the day, running a numbers game — they go where the payoff-to-effort ratio is best. Professional services firms score unusually well on that calculation for a few structural reasons that have nothing to do with how careful any individual firm is being.
Concentration of high-value data in one place. A single accounting firm's client file server can hold banking details, tax filings, payroll data, and financial statements for dozens or hundreds of businesses and individuals at once — a much richer target than compromising any one of those businesses directly. The same logic applies to a law firm's document management system, which routinely holds financial statements, personal identity documents, medical records (in personal injury or estate files), and litigation strategy across a wide client roster.
A documented willingness to pay to protect reputation. Ransomware groups explicitly study which industries pay ransoms most reliably, and professional services firms — where a public data leak threatens not just operational disruption but the trust relationship the entire business is built on — are known to be more likely to pay than a typical retailer facing the same attack. Attackers price that into who they target.
Trust accounts create a direct financial fraud angle beyond data theft. Real estate transactions, litigation settlements, and estate matters routinely move six- and seven-figure sums through law firm trust accounts, and business email compromise scams specifically targeting real estate closings — where a scammer impersonates the lawyer, the client, or the other side's counsel to redirect a closing wire transfer at the last minute — have become one of the most consistently profitable scams in the professional services space precisely because the transaction context (a large, time-pressured, one-time wire transfer) is exactly the setup social engineering fraud is built to exploit.
Smaller firms often carry weaker security than the data they hold would suggest. A five-partner law firm or a twelve-person accounting practice frequently has the same data sensitivity profile as a much larger enterprise, but rarely has a dedicated IT security function, making it a target that combines high payoff with comparatively low defensive friction — a combination attackers actively look for.
📊 IT Cares field note: We've supported firms after both ends of this spectrum — a boutique accounting practice that discovered a compromised email account had been quietly forwarding client tax documents to an external address for weeks, and a real estate law firm that caught a fraudulent wire redirect request the morning of closing because a paralegal called the client directly to confirm rather than trusting the email. The difference between those two outcomes was rarely about budget — it was about whether a verification step existed at all.
The Privilege Problem: Why a Breach of Client Confidentiality Is a Different Risk Category
An ordinary data breach — say, a retailer's customer email list gets exposed — creates real cost and real obligations (notification, credit monitoring, reputational damage). A breach touching privileged or confidential client information at a law or accounting firm creates all of that, plus a second, entirely separate layer of exposure most standard cyber policies were not written with in mind.
Solicitor-client privilege is the client's right, not just the firm's problem
Solicitor-client privilege belongs to the client, and a lawyer has an independent professional and ethical duty to protect it — a duty that exists on top of, and separately from, ordinary data protection law. When privileged communications are exposed in a breach, the consequences can extend well beyond the immediate cost of the incident: opposing counsel may argue privilege has been waived on specific documents, active litigation strategy that leaked can materially damage a client's position in an ongoing matter, and the firm may face a professional conduct complaint to its law society independent of anything a privacy regulator does. None of that is a hypothetical edge case — it's the specific reason cyber insurance for law firms needs to be evaluated against a different risk profile than a standard business policy.
Accountant-client confidentiality carries its own professional stakes
Accounting professional bodies (CPA provincial orders across Canada) similarly impose a duty of confidentiality on member firms that exists independently of privacy legislation. A breach exposing client financial statements, tax positions, or the details of a pending transaction can trigger a professional conduct review by the firm's governing body, even where no regulator finds fault under general privacy law — and the two processes (privacy regulator review and professional conduct review) can run in parallel, each with its own cost, timeline, and reputational exposure.
This creates a coverage gap most firms don't discover until it's too late
Here's the practical consequence: many cyber policies cover breach response costs (notification, forensics, credit monitoring) regardless of the type of data involved, but the professional liability exposure that flows from a breach of privileged or confidential information — a client alleging the firm's negligence in protecting their data caused them specific harm — often falls into a gap between the cyber policy and the professional liability (errors & omissions) policy, unless the two have been deliberately reviewed together. A firm that treats these as two unrelated insurance products, purchased separately without checking how they interact, can end up with a claim that neither policy clearly covers.
The question every firm should ask its broker directly
"If a breach exposes privileged client communications and a client later alleges we were negligent in protecting their information, which policy responds — the cyber policy, the professional liability policy, or both — and is there a gap between them?" If your broker can't answer that clearly, that's the sign the two policies haven't actually been reviewed together.
Want a clear picture of your firm's actual security posture before you talk to a broker?
Our certified technicians assess MFA, backup, endpoint protection, and incident response readiness — the exact things underwriters check — from $119.99.
What Cyber Insurance Should Actually Cover for These Firms
A policy properly sized for an accounting or law firm needs to cover more than the basics, and needs specific attention to two coverages that are commonly under-limited or missing entirely: social engineering fraud and regulatory defense. Here's the fuller picture, and an honest comparison of what's typically included, sub-limited, or excluded.
| Coverage Component | What It Actually Pays For | Common Gap or Exclusion |
|---|---|---|
| Breach response & notification | Forensic investigation, legal counsel to determine notification obligations, notifying affected clients, credit monitoring/identity protection services | Sub-limits on the number of notifications covered; forensic costs can exceed sub-limit on large-scale breaches |
| Cyber extortion / ransomware | Ransom negotiation, ransom payment (where legally permissible), extortion-related business interruption | May require insurer pre-approval of negotiator/vendor; some insurers reduce payout if backups weren't tested |
| Business interruption | Lost income and extra expense while systems are down and being restored | Waiting period (deductible in time, not just dollars) before coverage kicks in; often 8-24 hours |
| Data restoration | Cost to rebuild or restore systems and data after an incident | May not fully cover a full system rebuild if backups were inadequate to begin with |
| Third-party liability | Claims from clients or other parties alleging harm from the firm's data handling | Can overlap awkwardly with professional liability coverage if the two policies weren't reviewed together |
| Regulatory defense | Legal costs to respond to a CAI, OPC, or law society/CPA order investigation | The regulatory fine or penalty itself is typically NOT insurable and is excluded almost everywhere |
| Social engineering / funds transfer fraud | Loss from an employee tricked into authorizing a fraudulent wire transfer | Frequently requires a SEPARATE endorsement with its own, often much lower, sub-limit — this is the single most misunderstood gap for law firm trust accounts |
Read as a whole, the pattern is consistent: the coverages a firm assumes are "obviously included" — regulatory fines and social engineering fraud in particular — are exactly the two categories most likely to be excluded or capped at a fraction of the main policy limit. Confirming both explicitly, in writing, before binding a policy is not optional diligence; it's the single highest-leverage thing a firm can do when shopping for cyber coverage.
⚠ The trust account blind spot: Standard "computer fraud" coverage typically pays out when a hacker directly manipulates a computer system to divert funds. It usually does NOT pay out when an employee is socially engineered into approving a wire transfer that looks completely legitimate — which is how the overwhelming majority of real estate and litigation trust account fraud actually happens. If your policy doesn't explicitly name "social engineering fraud" or "funds transfer fraud" as a covered peril with an adequate sub-limit, assume it is not covered.
What Insurers Require Before They'll Bind a Policy
The cyber insurance market has tightened considerably over the past several years, and underwriters for professional services firms specifically now expect a documented, working set of security controls before they'll offer a quote at all — let alone a competitive premium. Firms that show up to the underwriting questionnaire without these in place either get declined, offered materially higher premiums, or approved with exclusions that remove coverage for incidents traceable to the missing control.
Multi-factor authentication everywhere it matters
Email, remote access (VPN or remote desktop), document management systems, and any system touching client data. This is now close to a universal underwriting requirement — a firm without MFA on email is likely to be declined outright by most insurers, not just charged more.
Endpoint detection and response (EDR), not just antivirus
Traditional signature-based antivirus is increasingly viewed by underwriters as insufficient on its own. EDR tools that can detect and respond to suspicious behaviour in real time are now commonly expected, particularly for firms above a certain revenue or headcount threshold.
Backups that are actually tested and ransomware-resilient
Insurers ask specifically whether backups are tested, how frequently, and whether at least one copy is immutable or offline. A firm that can't answer these questions confidently signals exactly the kind of risk that leads to a denied or reduced ransomware claim after the fact.
A documented incident response plan
Who gets called first, who has authority to engage a forensic firm or negotiate with an insurer's approved vendor list, and how client notification decisions get made — written down in advance, not improvised during an actual incident.
Regular employee phishing and security awareness training
Given how much of the real-world loss in this sector comes from social engineering rather than pure technical exploitation, insurers increasingly ask about training frequency and completion rates as a distinct underwriting question, separate from technical controls.
None of these controls are exotic or enterprise-only — they're achievable for a firm of any size with the right IT partner, and the cost of implementing them properly is consistently smaller than the premium increase (or coverage denial) firms face without them.
📊 IT Cares field note: We've walked more than one firm through an underwriting questionnaire only to discover, mid-form, that "we have backups" meant an unmonitored external drive nobody had tested restoring from in over a year. Getting these five items genuinely in place — not just technically true on paper — before applying consistently produces both better premiums and, more importantly, coverage that actually pays out cleanly if something happens.
Before You Apply for Cyber Insurance: Readiness Checklist
Work through this before your firm's next application or renewal — insurers ask about every one of these, and gaps here directly affect both premium and whether a future claim gets paid in full.
☐ Multi-factor authentication enabled on email, remote access, and document management systems
☐ Endpoint detection and response (EDR) deployed on all workstations and servers
☐ Backups tested with an actual restore in the last 90 days, with at least one immutable or offline copy
☐ Written incident response plan with named roles and an insurer-approved vendor list on file
☐ Phishing/security awareness training completed by all staff within the last 12 months
☐ Client files and email encrypted in transit and at rest
☐ Third-party vendors with access to client data reviewed for their own security posture
☐ Any prior security incident, however minor, documented and ready to disclose honestly on the application
☐ Social engineering / funds transfer fraud coverage confirmed explicitly, with an adequate sub-limit, for firms handling trust accounts or large client wire transfers
Real-World Scenarios: How This Plays Out
The following case studies are composite, fictional scenarios built from patterns common across the professional services sector — they illustrate how these coverage gaps and readiness requirements actually surface in practice, not a specific real firm.
Case study: a boutique law firm in Halifax, Nova Scotia
A six-lawyer real estate and litigation practice in Halifax had cyber insurance in place with a $1 million limit, purchased three years earlier and renewed automatically each year without much review. During a residential closing, a paralegal received an email — appearing to come from the firm's own conveyancing lawyer — instructing a change to the wire transfer details for the $487,000 sale proceeds. The email was a near-perfect spoof of the lawyer's writing style and signature block, sent from a domain one character different from the firm's own. The paralegal, trained to verify large transfers by phone rather than email alone, called the lawyer directly and caught the fraud before the transfer was sent — but the firm's broker later confirmed, during the post-incident review the firm requested out of caution, that its policy's social engineering fraud sub-limit was capped at $50,000, a fraction of what would have been needed had the transfer actually gone through. The firm increased its sub-limit to $500,000 at the next renewal, at an additional cost of roughly $650 CAD annually — a small price relative to what the near-miss could have cost.
Case study: a mid-size accounting firm in Calgary, Alberta
A 42-employee accounting firm serving oil and gas sector clients experienced a ransomware attack that encrypted its practice management system and client file server over a weekend. The firm's cyber policy, with a $2 million limit, covered forensic investigation (roughly $85,000), a ransom negotiation that ultimately avoided payment through a clean backup restore, business interruption costs during the six days systems were down (approximately $140,000 in lost billable time and extra staffing costs), and notification to the roughly 1,100 affected clients whose tax and financial records were on the encrypted systems. Total claim payout came to just under $310,000. The firm's premium the following year rose from $9,200 to $14,600 CAD — a substantial increase, but the firm's broker confirmed it would have faced non-renewal entirely at several other carriers had it not been able to demonstrate the EDR deployment and immutable backup configuration it implemented immediately after the incident.
Case study: a small accounting practice in Winnipeg, Manitoba
A four-person accounting practice applied for its first-ever cyber policy after a client asked, as a condition of a new engagement, whether the firm carried cyber coverage. During underwriting, the insurer's questionnaire revealed the firm had no MFA on its email system and no documented backup testing process. The insurer offered a policy, but at a premium roughly 40% higher than the firm's broker had initially estimated, with an explicit exclusion for any claim traceable to a compromised account that lacked MFA. The firm's principal engaged an IT provider to implement MFA and a tested cloud backup over the following six weeks; at renewal the following year, with both controls verifiably in place and documented, the premium dropped from $3,850 to $2,400 CAD and the MFA exclusion was removed.
Budget Reality Check: What Premiums Actually Cost in Canada
Cyber insurance premiums for accounting and law firms vary based on revenue, headcount, data volume and sensitivity, claims history, coverage limits chosen, and — increasingly heavily — the security controls verified during underwriting. Here's how it typically breaks down by rough firm size, as directional guidance rather than a fixed price list:
- Solo practitioner or very small firm (1-10 people): Annual premiums typically range from roughly $1,500 to $5,000 CAD for a policy with a $1 million limit, assuming baseline controls (MFA, tested backups) are in place. Firms without these controls can see quotes 30-60% higher, or outright declines from some carriers.
- Small-to-mid firm (10-30 people): Commonly falls in the $5,000-$15,000 CAD range for limits between $1-2 million, with social engineering fraud sub-limits and regulatory defense coverage adding to the base premium.
- Growing firm (30-75 people): Typically lands between $15,000 and $40,000+ CAD annually for limits in the $2-5 million range, with pricing increasingly sensitive to demonstrated security maturity and any claims history.
These ranges are directional for budgeting conversations, not quotes — actual pricing depends on a specific underwriting review of your firm's data volume, controls, claims history, and the limits and endorsements you choose. What's worth internalizing regardless of size: firms that invest in the security controls insurers require BEFORE applying consistently see materially better premiums and broader coverage than firms that treat the insurance application as the first time they think seriously about their security posture.
If you're weighing where cyber insurance fits into a broader IT and compliance budget, our PIPEDA compliance guide for accounting and law firms and our guide on how ransomware actually works both help frame the full picture — insurance is one layer of a broader risk management approach, not a substitute for the underlying security controls.
Working With a Broker Who Actually Understands Professional Services Risk
Not every commercial insurance broker has deep experience placing cyber coverage for accounting and law firms specifically, and the difference shows up in exactly the gaps this guide has been describing. A generalist broker may place a technically valid policy that still leaves the firm exposed on social engineering fraud, regulatory defense, or the professional liability coordination question — not because the broker is careless, but because those specific gaps only become visible to someone who has placed and, ideally, seen a claim on this exact type of risk before.
A few practical signs a broker genuinely understands this space: they ask, unprompted, how your professional liability and cyber policies would interact in a breach involving privileged information; they specifically raise social engineering fraud coverage if your firm handles trust accounts or large client wire transfers, rather than waiting for you to ask; they can name which insurers in the current market are actively writing professional services cyber risk well versus which have pulled back or gotten meaningfully more restrictive; and they walk you through the underwriting questionnaire in advance so there are no surprises about what controls you'll be asked to confirm.
It's also worth asking a broker directly about claims experience — not just how many policies they've placed, but how many claims they've actually helped a client navigate, and what that process looked like. A broker who has been through a real ransomware or wire fraud claim with a client understands, in a way a broker who has only ever placed policies doesn't, where the friction points tend to show up: which forensic vendors an insurer prefers versus insists on, how quickly claims payments actually move once approved, and where policy language that reads clearly in the abstract turns out to be ambiguous in an actual dispute over coverage.
Reviewing your policy annually, not just at renewal
Cyber risk and the insurance market covering it both move quickly enough that a policy purchased two or three years ago may no longer reflect either your firm's actual risk profile or what a well-structured policy in the current market looks like. Firms that have grown headcount, added new practice areas, started handling larger transactions, or adopted new technology (a new practice management platform, a client portal, an AI-assisted drafting tool) since their last policy review are frequently carrying coverage that no longer matches their actual exposure. An annual check-in with your broker — not just a rubber-stamp renewal — is worth the hour it takes.
What Actually Happens When You File a Claim
Understanding the claims process before you need it changes how well a firm navigates an actual incident, because the first 24-72 hours after discovering a breach or ransomware attack are exactly when panic and unfamiliarity with the process cause the most costly mistakes.
Notify your insurer immediately — before you do anything else technical
Most cyber policies require prompt notification as a condition of coverage, and many also require using the insurer's approved forensic and legal vendors rather than a firm's own IT provider acting unilaterally. Engaging outside help before calling the insurer can, in some policies, jeopardize coverage for costs incurred before notification — call the insurer's claims hotline first, every time.
The insurer assigns a breach coach or claims counsel
This is typically a lawyer, appointed by the insurer but working on the firm's behalf, who coordinates the response, manages privilege over the investigation (breach investigations conducted under legal counsel's direction can themselves be privileged, which matters if litigation follows), and directs which forensic vendor gets engaged.
Forensic investigation determines scope and cause
An approved forensic firm investigates what happened, what data was actually accessed or exfiltrated versus merely exposed to risk, and how the attacker got in — findings that directly shape both the notification obligations that follow and any negotiation with a ransomware group if extortion is involved.
Notification obligations get triggered based on findings
Breach coach and legal counsel determine what must be reported to the CAI, OPC, affected clients, and — separately — whether the firm's law society or CPA order requires notification under professional conduct rules, which is not automatically the same trigger as the privacy regulator notification requirement.
Claim costs get tracked against policy limits and sub-limits
This is where firms discover, sometimes for the first time, exactly how their sub-limits work in practice — a $2 million overall limit doesn't mean $2 million is available for every category of cost if individual coverages (like social engineering fraud) carry their own much lower sub-limit.
The single most consistent piece of feedback from firms that have been through this process: having a documented incident response plan in place before an incident — even a simple one naming who calls the insurer, who has authority to make time-sensitive decisions, and where the policy documents and insurer contact information are actually kept — measurably reduces both the stress and the cost of the first 48 hours, which is often when the most consequential decisions get made under the most pressure.
Canadian Government and Institutional Resources
A few Canadian institutional resources are worth knowing about as you build out both your security posture and your understanding of the compliance landscape cyber insurance sits alongside:
- Business Development Bank of Canada (BDC): BDC publishes cybersecurity and risk management guidance specifically aimed at Canadian SMBs and professional services firms, including practical steps for improving security posture in ways that also tend to align with what cyber insurers look for at underwriting.
- Innovation, Science and Economic Development Canada (ISED): ISED provides cybersecurity guidance and resources for Canadian businesses, including sector-relevant material for professional services firms handling sensitive client data.
- Office of the Privacy Commissioner of Canada (OPC, priv.gc.ca): The OPC oversees PIPEDA compliance and breach reporting obligations for firms operating outside Quebec (or handling data across provincial/international lines), and is a key resource for understanding the regulatory reporting side of a breach that a cyber policy's regulatory defense coverage would apply to.
Want an honest read on whether your firm would pass an insurer's underwriting review?
IT Cares' security audits check the exact controls cyber insurers now expect — MFA coverage, EDR, tested backups, and documented incident response — and translate the gaps into a concrete plan before you apply or renew. For firms that want these controls actively maintained rather than assessed once and left to drift, our cybersecurity services and managed IT services can keep your posture insurer-ready on an ongoing basis.
Common Mistakes Firms Make When Choosing Coverage
A handful of patterns show up repeatedly when firms discover, after the fact, that their cyber policy didn't do what they assumed it would. Recognizing these ahead of time is far cheaper than learning them during an actual claim.
Buying on price alone. The cheapest quote in a stack of proposals is frequently the cheapest because it carries lower sub-limits, narrower definitions of covered events, or exclusions the other quotes don't have — not because the insurer is simply more efficient. Comparing policies purely on the headline premium, without laying the actual coverage terms side by side, is one of the most common and most costly mistakes a firm can make.
Assuming last year's policy still fits this year's firm. A firm that has grown from 8 to 22 employees, started handling larger real estate closings, or added a new office in another province since its last policy renewal may be carrying coverage limits and terms sized for a firm that no longer exists. Auto-renewing without a substantive annual review is a quiet but common way firms end up underinsured exactly when they can least afford to be.
Not reading the retroactive date. Cyber policies often include a retroactive date — coverage only applies to incidents that occurred (or, more precisely, that the wrongful act underlying the claim occurred) after that date, even if the claim itself is made during the current policy period. A firm that switches insurers without confirming the new policy's retroactive date matches or precedes its prior coverage can create a gap where an incident that technically began under the old policy isn't covered by either one.
Treating the underwriting questionnaire as a formality. Answers on a cyber insurance application are representations the insurer relies on to price and, ultimately, to pay a claim. Rushing through the questionnaire, guessing at answers about MFA coverage or backup testing frequency rather than actually confirming them with IT, or having different people at the firm answer similar questions inconsistently across renewal years, all create material misrepresentation risk that can surface — and be used to deny a claim — at the worst possible moment.
Not involving IT in the renewal conversation. The person renewing the policy (often a managing partner, office manager, or firm administrator) and the person who actually knows the technical answers to underwriting questions (an internal IT lead or outsourced IT provider) are frequently not the same person, and not always in the same conversation. Building a habit of looping in whoever manages your actual IT environment before every renewal — so the answers on the application reflect what's technically true, not what someone assumes is true — closes one of the most avoidable gaps in this entire process.
Forgetting that coverage decisions ripple into everyday operations. A policy's sub-limits and exclusions aren't just paperwork — they should shape how a firm actually operates day to day. If your social engineering fraud sub-limit is modest, that's a direct argument for a strict, non-negotiable phone-verification rule on any wire transfer instruction change, regardless of how urgent or legitimate the request appears in writing. Treating the policy purely as a financial backstop, disconnected from the operational habits that determine whether a claim happens at all, leaves value on the table that better internal process would have captured for free.
Frequently Asked Questions
Want an Honest Read on Your Firm's Cyber Insurance Readiness?
IT Cares reviews the exact controls insurers check — MFA, EDR, backups, incident response — and gives you a clear, right-sized plan before you apply or renew.
Comments (3)
Our insurer's questionnaire had a full page just on MFA and backup testing. Wish we'd read something like this before we applied the first time — would have saved us a much higher premium.
The social engineering fraud sub-limit point is exactly what our broker flagged after a close call with a fake wire instruction email. Increased our coverage the same week.
Appreciated the clarity on regulatory fines not being insurable. Our broker mentioned it briefly but this laid out exactly what "regulatory defense" actually covers versus not.
Leave a Comment