Cyber Insurance for Accounting and Law Firms: The Privilege Problem Most Policies Miss

Reviewed by IT Cares certified technicians · Updated July 2026

Accounting and law firm office with a locked file cabinet illustrating confidential client data protection and cyber insurance
Privileged files and trust accounts make accounting and law firms a distinct cyber insurance risk category — not a generic small-business one.
⚖️
Not sure your firm's current IT setup would satisfy a cyber insurer's underwriting checklist? Our certified technicians will assess your controls honestly before you apply or renew.
Get a Free Assessment →

Accounting and law firms are not ordinary small businesses when it comes to cyber risk, and a cyber insurance policy written for a generic retailer or consultancy will almost always leave a gap that becomes visible only after a real incident. These firms sit on a specific, concentrated combination of client financial data, privileged legal communications, litigation strategy, merger and acquisition details with real-time market value, and — for many law firms — direct control of trust accounts holding client funds. That combination makes them a disproportionately attractive target, and it means the insurance built to protect them needs to be built around that specific risk, not adapted from a template designed for a coffee shop or a marketing agency.

This matters more than most firms initially assume, because the professional obligations layered on top of ordinary data protection law — solicitor-client privilege for lawyers, the duty of confidentiality that governs both legal and accounting professional codes of conduct — create a category of exposure that a standard small-business cyber policy was never designed to address. A breach at a typical retailer means compromised customer emails and maybe credit card numbers. A breach at a law firm can mean a client's confidential litigation strategy sitting in a ransomware group's leak site, or a wire transfer redirected out of a real estate trust account days before closing. The dollar figures and the professional consequences are simply not the same category of event.

This guide covers what actually needs to be true about a cyber insurance policy for an accounting or law firm: why these firms are targeted the way they are, what makes a breach of privileged or confidential client information a distinct risk category insurers and firms both need to think about separately from an ordinary data breach, what a properly built policy should cover (and the specific gaps — regulatory fines, social engineering fraud — that catch firms off guard), what insurers now require before they'll even offer a quote, realistic Canadian premium ranges, and where to go for further guidance. If you want the compliance side of this picture specifically — what PIPEDA requires of accounting and law firms handling client data — our PIPEDA compliance guide for accounting and law firms covers that in depth; this guide focuses on the insurance layer that sits alongside it.

A note before we start

This article is general information to help your firm ask the right questions of a broker or insurer — it is not legal advice, and it is not a substitute for a policy review by a broker who specifically understands professional services and legal/accounting risk. Insurance policy wording varies significantly between insurers and can change year to year; always confirm the specifics of coverage, exclusions, and sub-limits directly in your policy documents before relying on any general description of what a "typical" policy covers.

Why Accounting and Law Firms Are High-Value Targets

Ransomware operators and business email compromise scammers are, at the end of the day, running a numbers game — they go where the payoff-to-effort ratio is best. Professional services firms score unusually well on that calculation for a few structural reasons that have nothing to do with how careful any individual firm is being.

Concentration of high-value data in one place. A single accounting firm's client file server can hold banking details, tax filings, payroll data, and financial statements for dozens or hundreds of businesses and individuals at once — a much richer target than compromising any one of those businesses directly. The same logic applies to a law firm's document management system, which routinely holds financial statements, personal identity documents, medical records (in personal injury or estate files), and litigation strategy across a wide client roster.

A documented willingness to pay to protect reputation. Ransomware groups explicitly study which industries pay ransoms most reliably, and professional services firms — where a public data leak threatens not just operational disruption but the trust relationship the entire business is built on — are known to be more likely to pay than a typical retailer facing the same attack. Attackers price that into who they target.

Trust accounts create a direct financial fraud angle beyond data theft. Real estate transactions, litigation settlements, and estate matters routinely move six- and seven-figure sums through law firm trust accounts, and business email compromise scams specifically targeting real estate closings — where a scammer impersonates the lawyer, the client, or the other side's counsel to redirect a closing wire transfer at the last minute — have become one of the most consistently profitable scams in the professional services space precisely because the transaction context (a large, time-pressured, one-time wire transfer) is exactly the setup social engineering fraud is built to exploit.

Smaller firms often carry weaker security than the data they hold would suggest. A five-partner law firm or a twelve-person accounting practice frequently has the same data sensitivity profile as a much larger enterprise, but rarely has a dedicated IT security function, making it a target that combines high payoff with comparatively low defensive friction — a combination attackers actively look for.

📊 IT Cares field note: We've supported firms after both ends of this spectrum — a boutique accounting practice that discovered a compromised email account had been quietly forwarding client tax documents to an external address for weeks, and a real estate law firm that caught a fraudulent wire redirect request the morning of closing because a paralegal called the client directly to confirm rather than trusting the email. The difference between those two outcomes was rarely about budget — it was about whether a verification step existed at all.

The Privilege Problem: Why a Breach of Client Confidentiality Is a Different Risk Category

An ordinary data breach — say, a retailer's customer email list gets exposed — creates real cost and real obligations (notification, credit monitoring, reputational damage). A breach touching privileged or confidential client information at a law or accounting firm creates all of that, plus a second, entirely separate layer of exposure most standard cyber policies were not written with in mind.

Solicitor-client privilege is the client's right, not just the firm's problem

Solicitor-client privilege belongs to the client, and a lawyer has an independent professional and ethical duty to protect it — a duty that exists on top of, and separately from, ordinary data protection law. When privileged communications are exposed in a breach, the consequences can extend well beyond the immediate cost of the incident: opposing counsel may argue privilege has been waived on specific documents, active litigation strategy that leaked can materially damage a client's position in an ongoing matter, and the firm may face a professional conduct complaint to its law society independent of anything a privacy regulator does. None of that is a hypothetical edge case — it's the specific reason cyber insurance for law firms needs to be evaluated against a different risk profile than a standard business policy.

Accountant-client confidentiality carries its own professional stakes

Accounting professional bodies (CPA provincial orders across Canada) similarly impose a duty of confidentiality on member firms that exists independently of privacy legislation. A breach exposing client financial statements, tax positions, or the details of a pending transaction can trigger a professional conduct review by the firm's governing body, even where no regulator finds fault under general privacy law — and the two processes (privacy regulator review and professional conduct review) can run in parallel, each with its own cost, timeline, and reputational exposure.

This creates a coverage gap most firms don't discover until it's too late

Here's the practical consequence: many cyber policies cover breach response costs (notification, forensics, credit monitoring) regardless of the type of data involved, but the professional liability exposure that flows from a breach of privileged or confidential information — a client alleging the firm's negligence in protecting their data caused them specific harm — often falls into a gap between the cyber policy and the professional liability (errors & omissions) policy, unless the two have been deliberately reviewed together. A firm that treats these as two unrelated insurance products, purchased separately without checking how they interact, can end up with a claim that neither policy clearly covers.

The question every firm should ask its broker directly

"If a breach exposes privileged client communications and a client later alleges we were negligent in protecting their information, which policy responds — the cyber policy, the professional liability policy, or both — and is there a gap between them?" If your broker can't answer that clearly, that's the sign the two policies haven't actually been reviewed together.

Want a clear picture of your firm's actual security posture before you talk to a broker?

Our certified technicians assess MFA, backup, endpoint protection, and incident response readiness — the exact things underwriters check — from $119.99.

What Cyber Insurance Should Actually Cover for These Firms

A policy properly sized for an accounting or law firm needs to cover more than the basics, and needs specific attention to two coverages that are commonly under-limited or missing entirely: social engineering fraud and regulatory defense. Here's the fuller picture, and an honest comparison of what's typically included, sub-limited, or excluded.

Coverage Component What It Actually Pays For Common Gap or Exclusion
Breach response & notification Forensic investigation, legal counsel to determine notification obligations, notifying affected clients, credit monitoring/identity protection services Sub-limits on the number of notifications covered; forensic costs can exceed sub-limit on large-scale breaches
Cyber extortion / ransomware Ransom negotiation, ransom payment (where legally permissible), extortion-related business interruption May require insurer pre-approval of negotiator/vendor; some insurers reduce payout if backups weren't tested
Business interruption Lost income and extra expense while systems are down and being restored Waiting period (deductible in time, not just dollars) before coverage kicks in; often 8-24 hours
Data restoration Cost to rebuild or restore systems and data after an incident May not fully cover a full system rebuild if backups were inadequate to begin with
Third-party liability Claims from clients or other parties alleging harm from the firm's data handling Can overlap awkwardly with professional liability coverage if the two policies weren't reviewed together
Regulatory defense Legal costs to respond to a CAI, OPC, or law society/CPA order investigation The regulatory fine or penalty itself is typically NOT insurable and is excluded almost everywhere
Social engineering / funds transfer fraud Loss from an employee tricked into authorizing a fraudulent wire transfer Frequently requires a SEPARATE endorsement with its own, often much lower, sub-limit — this is the single most misunderstood gap for law firm trust accounts

Read as a whole, the pattern is consistent: the coverages a firm assumes are "obviously included" — regulatory fines and social engineering fraud in particular — are exactly the two categories most likely to be excluded or capped at a fraction of the main policy limit. Confirming both explicitly, in writing, before binding a policy is not optional diligence; it's the single highest-leverage thing a firm can do when shopping for cyber coverage.

⚠ The trust account blind spot: Standard "computer fraud" coverage typically pays out when a hacker directly manipulates a computer system to divert funds. It usually does NOT pay out when an employee is socially engineered into approving a wire transfer that looks completely legitimate — which is how the overwhelming majority of real estate and litigation trust account fraud actually happens. If your policy doesn't explicitly name "social engineering fraud" or "funds transfer fraud" as a covered peril with an adequate sub-limit, assume it is not covered.

What Insurers Require Before They'll Bind a Policy

The cyber insurance market has tightened considerably over the past several years, and underwriters for professional services firms specifically now expect a documented, working set of security controls before they'll offer a quote at all — let alone a competitive premium. Firms that show up to the underwriting questionnaire without these in place either get declined, offered materially higher premiums, or approved with exclusions that remove coverage for incidents traceable to the missing control.

1

Multi-factor authentication everywhere it matters

Email, remote access (VPN or remote desktop), document management systems, and any system touching client data. This is now close to a universal underwriting requirement — a firm without MFA on email is likely to be declined outright by most insurers, not just charged more.

2

Endpoint detection and response (EDR), not just antivirus

Traditional signature-based antivirus is increasingly viewed by underwriters as insufficient on its own. EDR tools that can detect and respond to suspicious behaviour in real time are now commonly expected, particularly for firms above a certain revenue or headcount threshold.

3

Backups that are actually tested and ransomware-resilient

Insurers ask specifically whether backups are tested, how frequently, and whether at least one copy is immutable or offline. A firm that can't answer these questions confidently signals exactly the kind of risk that leads to a denied or reduced ransomware claim after the fact.

4

A documented incident response plan

Who gets called first, who has authority to engage a forensic firm or negotiate with an insurer's approved vendor list, and how client notification decisions get made — written down in advance, not improvised during an actual incident.

5

Regular employee phishing and security awareness training

Given how much of the real-world loss in this sector comes from social engineering rather than pure technical exploitation, insurers increasingly ask about training frequency and completion rates as a distinct underwriting question, separate from technical controls.

None of these controls are exotic or enterprise-only — they're achievable for a firm of any size with the right IT partner, and the cost of implementing them properly is consistently smaller than the premium increase (or coverage denial) firms face without them.

📊 IT Cares field note: We've walked more than one firm through an underwriting questionnaire only to discover, mid-form, that "we have backups" meant an unmonitored external drive nobody had tested restoring from in over a year. Getting these five items genuinely in place — not just technically true on paper — before applying consistently produces both better premiums and, more importantly, coverage that actually pays out cleanly if something happens.

Before You Apply for Cyber Insurance: Readiness Checklist

Work through this before your firm's next application or renewal — insurers ask about every one of these, and gaps here directly affect both premium and whether a future claim gets paid in full.

☐ Multi-factor authentication enabled on email, remote access, and document management systems

☐ Endpoint detection and response (EDR) deployed on all workstations and servers

☐ Backups tested with an actual restore in the last 90 days, with at least one immutable or offline copy

☐ Written incident response plan with named roles and an insurer-approved vendor list on file

☐ Phishing/security awareness training completed by all staff within the last 12 months

☐ Client files and email encrypted in transit and at rest

☐ Third-party vendors with access to client data reviewed for their own security posture

☐ Any prior security incident, however minor, documented and ready to disclose honestly on the application

☐ Social engineering / funds transfer fraud coverage confirmed explicitly, with an adequate sub-limit, for firms handling trust accounts or large client wire transfers

Real-World Scenarios: How This Plays Out

The following case studies are composite, fictional scenarios built from patterns common across the professional services sector — they illustrate how these coverage gaps and readiness requirements actually surface in practice, not a specific real firm.

Case study: a boutique law firm in Halifax, Nova Scotia

A six-lawyer real estate and litigation practice in Halifax had cyber insurance in place with a $1 million limit, purchased three years earlier and renewed automatically each year without much review. During a residential closing, a paralegal received an email — appearing to come from the firm's own conveyancing lawyer — instructing a change to the wire transfer details for the $487,000 sale proceeds. The email was a near-perfect spoof of the lawyer's writing style and signature block, sent from a domain one character different from the firm's own. The paralegal, trained to verify large transfers by phone rather than email alone, called the lawyer directly and caught the fraud before the transfer was sent — but the firm's broker later confirmed, during the post-incident review the firm requested out of caution, that its policy's social engineering fraud sub-limit was capped at $50,000, a fraction of what would have been needed had the transfer actually gone through. The firm increased its sub-limit to $500,000 at the next renewal, at an additional cost of roughly $650 CAD annually — a small price relative to what the near-miss could have cost.

Case study: a mid-size accounting firm in Calgary, Alberta

A 42-employee accounting firm serving oil and gas sector clients experienced a ransomware attack that encrypted its practice management system and client file server over a weekend. The firm's cyber policy, with a $2 million limit, covered forensic investigation (roughly $85,000), a ransom negotiation that ultimately avoided payment through a clean backup restore, business interruption costs during the six days systems were down (approximately $140,000 in lost billable time and extra staffing costs), and notification to the roughly 1,100 affected clients whose tax and financial records were on the encrypted systems. Total claim payout came to just under $310,000. The firm's premium the following year rose from $9,200 to $14,600 CAD — a substantial increase, but the firm's broker confirmed it would have faced non-renewal entirely at several other carriers had it not been able to demonstrate the EDR deployment and immutable backup configuration it implemented immediately after the incident.

Case study: a small accounting practice in Winnipeg, Manitoba

A four-person accounting practice applied for its first-ever cyber policy after a client asked, as a condition of a new engagement, whether the firm carried cyber coverage. During underwriting, the insurer's questionnaire revealed the firm had no MFA on its email system and no documented backup testing process. The insurer offered a policy, but at a premium roughly 40% higher than the firm's broker had initially estimated, with an explicit exclusion for any claim traceable to a compromised account that lacked MFA. The firm's principal engaged an IT provider to implement MFA and a tested cloud backup over the following six weeks; at renewal the following year, with both controls verifiably in place and documented, the premium dropped from $3,850 to $2,400 CAD and the MFA exclusion was removed.

Budget Reality Check: What Premiums Actually Cost in Canada

Cyber insurance premiums for accounting and law firms vary based on revenue, headcount, data volume and sensitivity, claims history, coverage limits chosen, and — increasingly heavily — the security controls verified during underwriting. Here's how it typically breaks down by rough firm size, as directional guidance rather than a fixed price list:

These ranges are directional for budgeting conversations, not quotes — actual pricing depends on a specific underwriting review of your firm's data volume, controls, claims history, and the limits and endorsements you choose. What's worth internalizing regardless of size: firms that invest in the security controls insurers require BEFORE applying consistently see materially better premiums and broader coverage than firms that treat the insurance application as the first time they think seriously about their security posture.

If you're weighing where cyber insurance fits into a broader IT and compliance budget, our PIPEDA compliance guide for accounting and law firms and our guide on how ransomware actually works both help frame the full picture — insurance is one layer of a broader risk management approach, not a substitute for the underlying security controls.

Working With a Broker Who Actually Understands Professional Services Risk

Not every commercial insurance broker has deep experience placing cyber coverage for accounting and law firms specifically, and the difference shows up in exactly the gaps this guide has been describing. A generalist broker may place a technically valid policy that still leaves the firm exposed on social engineering fraud, regulatory defense, or the professional liability coordination question — not because the broker is careless, but because those specific gaps only become visible to someone who has placed and, ideally, seen a claim on this exact type of risk before.

A few practical signs a broker genuinely understands this space: they ask, unprompted, how your professional liability and cyber policies would interact in a breach involving privileged information; they specifically raise social engineering fraud coverage if your firm handles trust accounts or large client wire transfers, rather than waiting for you to ask; they can name which insurers in the current market are actively writing professional services cyber risk well versus which have pulled back or gotten meaningfully more restrictive; and they walk you through the underwriting questionnaire in advance so there are no surprises about what controls you'll be asked to confirm.

It's also worth asking a broker directly about claims experience — not just how many policies they've placed, but how many claims they've actually helped a client navigate, and what that process looked like. A broker who has been through a real ransomware or wire fraud claim with a client understands, in a way a broker who has only ever placed policies doesn't, where the friction points tend to show up: which forensic vendors an insurer prefers versus insists on, how quickly claims payments actually move once approved, and where policy language that reads clearly in the abstract turns out to be ambiguous in an actual dispute over coverage.

Reviewing your policy annually, not just at renewal

Cyber risk and the insurance market covering it both move quickly enough that a policy purchased two or three years ago may no longer reflect either your firm's actual risk profile or what a well-structured policy in the current market looks like. Firms that have grown headcount, added new practice areas, started handling larger transactions, or adopted new technology (a new practice management platform, a client portal, an AI-assisted drafting tool) since their last policy review are frequently carrying coverage that no longer matches their actual exposure. An annual check-in with your broker — not just a rubber-stamp renewal — is worth the hour it takes.

What Actually Happens When You File a Claim

Understanding the claims process before you need it changes how well a firm navigates an actual incident, because the first 24-72 hours after discovering a breach or ransomware attack are exactly when panic and unfamiliarity with the process cause the most costly mistakes.

1

Notify your insurer immediately — before you do anything else technical

Most cyber policies require prompt notification as a condition of coverage, and many also require using the insurer's approved forensic and legal vendors rather than a firm's own IT provider acting unilaterally. Engaging outside help before calling the insurer can, in some policies, jeopardize coverage for costs incurred before notification — call the insurer's claims hotline first, every time.

2

The insurer assigns a breach coach or claims counsel

This is typically a lawyer, appointed by the insurer but working on the firm's behalf, who coordinates the response, manages privilege over the investigation (breach investigations conducted under legal counsel's direction can themselves be privileged, which matters if litigation follows), and directs which forensic vendor gets engaged.

3

Forensic investigation determines scope and cause

An approved forensic firm investigates what happened, what data was actually accessed or exfiltrated versus merely exposed to risk, and how the attacker got in — findings that directly shape both the notification obligations that follow and any negotiation with a ransomware group if extortion is involved.

4

Notification obligations get triggered based on findings

Breach coach and legal counsel determine what must be reported to the CAI, OPC, affected clients, and — separately — whether the firm's law society or CPA order requires notification under professional conduct rules, which is not automatically the same trigger as the privacy regulator notification requirement.

5

Claim costs get tracked against policy limits and sub-limits

This is where firms discover, sometimes for the first time, exactly how their sub-limits work in practice — a $2 million overall limit doesn't mean $2 million is available for every category of cost if individual coverages (like social engineering fraud) carry their own much lower sub-limit.

The single most consistent piece of feedback from firms that have been through this process: having a documented incident response plan in place before an incident — even a simple one naming who calls the insurer, who has authority to make time-sensitive decisions, and where the policy documents and insurer contact information are actually kept — measurably reduces both the stress and the cost of the first 48 hours, which is often when the most consequential decisions get made under the most pressure.

Canadian Government and Institutional Resources

A few Canadian institutional resources are worth knowing about as you build out both your security posture and your understanding of the compliance landscape cyber insurance sits alongside:

Want an honest read on whether your firm would pass an insurer's underwriting review?

IT Cares' security audits check the exact controls cyber insurers now expect — MFA coverage, EDR, tested backups, and documented incident response — and translate the gaps into a concrete plan before you apply or renew. For firms that want these controls actively maintained rather than assessed once and left to drift, our cybersecurity services and managed IT services can keep your posture insurer-ready on an ongoing basis.

Common Mistakes Firms Make When Choosing Coverage

A handful of patterns show up repeatedly when firms discover, after the fact, that their cyber policy didn't do what they assumed it would. Recognizing these ahead of time is far cheaper than learning them during an actual claim.

Buying on price alone. The cheapest quote in a stack of proposals is frequently the cheapest because it carries lower sub-limits, narrower definitions of covered events, or exclusions the other quotes don't have — not because the insurer is simply more efficient. Comparing policies purely on the headline premium, without laying the actual coverage terms side by side, is one of the most common and most costly mistakes a firm can make.

Assuming last year's policy still fits this year's firm. A firm that has grown from 8 to 22 employees, started handling larger real estate closings, or added a new office in another province since its last policy renewal may be carrying coverage limits and terms sized for a firm that no longer exists. Auto-renewing without a substantive annual review is a quiet but common way firms end up underinsured exactly when they can least afford to be.

Not reading the retroactive date. Cyber policies often include a retroactive date — coverage only applies to incidents that occurred (or, more precisely, that the wrongful act underlying the claim occurred) after that date, even if the claim itself is made during the current policy period. A firm that switches insurers without confirming the new policy's retroactive date matches or precedes its prior coverage can create a gap where an incident that technically began under the old policy isn't covered by either one.

Treating the underwriting questionnaire as a formality. Answers on a cyber insurance application are representations the insurer relies on to price and, ultimately, to pay a claim. Rushing through the questionnaire, guessing at answers about MFA coverage or backup testing frequency rather than actually confirming them with IT, or having different people at the firm answer similar questions inconsistently across renewal years, all create material misrepresentation risk that can surface — and be used to deny a claim — at the worst possible moment.

Not involving IT in the renewal conversation. The person renewing the policy (often a managing partner, office manager, or firm administrator) and the person who actually knows the technical answers to underwriting questions (an internal IT lead or outsourced IT provider) are frequently not the same person, and not always in the same conversation. Building a habit of looping in whoever manages your actual IT environment before every renewal — so the answers on the application reflect what's technically true, not what someone assumes is true — closes one of the most avoidable gaps in this entire process.

Forgetting that coverage decisions ripple into everyday operations. A policy's sub-limits and exclusions aren't just paperwork — they should shape how a firm actually operates day to day. If your social engineering fraud sub-limit is modest, that's a direct argument for a strict, non-negotiable phone-verification rule on any wire transfer instruction change, regardless of how urgent or legitimate the request appears in writing. Treating the policy purely as a financial backstop, disconnected from the operational habits that determine whether a claim happens at all, leaves value on the table that better internal process would have captured for free.

Frequently Asked Questions

Do accounting and law firms really need cyber insurance separate from their professional liability policy?
In almost every case, yes. Professional liability (errors & omissions) insurance is built around claims of professional negligence in the advice or service you provided — it was never designed around the specific costs of a data breach: forensic investigation, breach notification to every affected client, credit monitoring, ransomware negotiation, system restoration, and regulatory defense. Some professional liability policies include a small cyber sub-limit or endorsement, but it's frequently far too low to cover a real incident at a firm holding financial records, litigation files, or trust account access. A dedicated cyber policy, reviewed alongside your professional liability coverage so the two don't leave a gap between them, is the standard recommendation for any firm handling sensitive client data.
Will cyber insurance cover a breach of solicitor-client privileged information?
It depends heavily on the specific policy wording, which is exactly why this needs to be reviewed with a broker who understands legal and accounting risk rather than assumed. Most well-structured cyber policies will cover the breach response costs (notification, forensics, credit monitoring, legal costs to assess privilege implications) regardless of whether the compromised data was privileged. What often is NOT covered, or is only partially covered, is the downstream professional liability exposure if a client alleges the firm's negligence in protecting their information caused them harm — that exposure typically needs to be addressed through professional liability coverage or a policy that explicitly bridges the two. Ask directly: does this policy cover claims arising from a breach of privileged or confidential client information, and how does it coordinate with our professional liability policy?
How much does cyber insurance cost for a small accounting or law firm in Canada?
For a solo practitioner or small firm of 2-10 people, annual premiums typically range from roughly $1,500 to $5,000 CAD depending on coverage limits, revenue, and the security controls already in place. A firm of 10-30 people commonly falls in the $5,000-$15,000 range, and larger firms of 30-75 people with higher revenue and larger data volumes often land between $15,000 and $40,000 or more. These are directional ranges — actual premiums depend heavily on claims history, security posture at underwriting, coverage limits chosen, and the insurer's current appetite for professional services risk, which has tightened significantly in recent years.
What security controls do insurers require before they'll bind a cyber policy for a firm like ours?
Most cyber insurers now require, at minimum: multi-factor authentication on email, remote access, and any system holding client data; endpoint detection and response (EDR) rather than basic antivirus; regularly tested backups that are immutable or offline; a documented incident response plan; and periodic employee phishing training. Firms that can't confirm these controls are in place either get declined outright, offered a policy with significantly higher premiums and lower limits, or approved with exclusions that remove coverage for incidents traceable to a missing control — for example, a ransomware claim denied or reduced because MFA wasn't enabled on the compromised account.
Does cyber insurance cover regulatory fines under Law 25 or PIPEDA?
Generally, no — or only partially. Administrative monetary penalties and regulatory fines are, in most Canadian jurisdictions, considered against public policy to insure, meaning insurers cannot legally indemnify a firm for the fine itself even if they wanted to. What cyber policies typically DO cover is the legal defense costs of responding to a regulatory investigation or proceeding, which can themselves run into tens of thousands of dollars. Read the regulatory defense and fines/penalties sections of any policy carefully, and don't assume a policy that mentions "regulatory coverage" means the fine itself is covered — ask specifically.
Is wire fraud targeting a law firm's trust account covered by cyber insurance?
Sometimes, but this is one of the most commonly misunderstood gaps in cyber coverage for law firms. Many standard cyber policies cover "computer fraud" (unauthorized access causing a fraudulent transfer) but exclude "social engineering fraud" (where an employee is tricked into authorizing a legitimate-looking wire transfer, which is how most trust account fraud actually happens). Social engineering fraud typically needs its own endorsement or sub-limit, often capped much lower than the main policy limit. Given that fraudulent wire transfers targeting real estate and litigation trust accounts are a leading cyber claim category for law firms, confirming this specific coverage exists — and at an adequate limit — is essential, not optional.
What's the difference in cyber risk between an accounting firm and a law firm?
Both hold highly sensitive data, but the specific exposure differs. Accounting firms typically hold concentrated financial data across many clients — banking details, tax records, payroll information, sometimes access to client accounting systems — making them attractive for both direct fraud and business email compromise schemes impersonating the firm to redirect client payments. Law firms, in addition to similarly sensitive financial and personal data, hold privileged litigation strategy, M&A deal information with real-time market value, and often direct control of trust accounts holding client funds, which adds a wire fraud dimension that's less central to most accounting firm exposure. Both should build their cyber coverage around their specific data and workflow risk rather than a generic small-business policy.
Should our firm disclose a past minor security incident when applying for cyber insurance?
Yes, always disclose honestly and completely. Cyber insurance applications typically include specific questions about prior incidents, and insurers can investigate a claim's history during underwriting or after a loss occurs. If an application misrepresents or omits a known prior incident, insurers have grounds to deny a future claim or rescind the policy entirely — which means the firm could discover, in the middle of an actual crisis, that the policy it paid for doesn't actually apply. A prior minor incident, honestly disclosed along with the remediation steps taken afterward, is far less damaging to coverage than a nondisclosure discovered later.

Want an Honest Read on Your Firm's Cyber Insurance Readiness?

IT Cares reviews the exact controls insurers check — MFA, EDR, backups, incident response — and gives you a clear, right-sized plan before you apply or renew.

Comments (3)

MK
Michael K., Winnipeg
July 22, 2026

Our insurer's questionnaire had a full page just on MFA and backup testing. Wish we'd read something like this before we applied the first time — would have saved us a much higher premium.

RL
Rachel L., Halifax
July 21, 2026

The social engineering fraud sub-limit point is exactly what our broker flagged after a close call with a fake wire instruction email. Increased our coverage the same week.

DT
David T., Calgary
July 19, 2026

Appreciated the clarity on regulatory fines not being insurable. Our broker mentioned it briefly but this laid out exactly what "regulatory defense" actually covers versus not.

Leave a Comment

Need Help?