What Cyber Insurance Now Requires of LA Law Firms
The Short Answer For Managing Partners
Cyber insurance underwriting has become a security-control review, not a paperwork exercise. For a Los Angeles law firm, the controls most likely to affect whether a carrier writes or renews a policy are multifactor authentication, endpoint detection and response, secure backups, patch management, email security, least-privilege access, employee security training, incident response planning, and evidence that those controls are actually operating.
That shift matters because law firms hold privileged communications, settlement strategy, entertainment contracts, employment records, trust-account workflows, tax materials, medical facts, and personally identifiable information. The American Bar Association reported that 29% of respondents said their firm had experienced a security breach in its legal technology survey ABA TechReport. For small and midsize LA firms, that statistic maps directly to client confidentiality, malpractice exposure, downtime, reputational damage, and renewal friction.
The practical answer is this: do not treat the cyber insurance application as something your office manager, broker, or outsourced IT vendor can guess through at the last minute. Treat it like an operational snapshot of your technology environment. If the application says MFA is enforced, EDR is deployed, backups are tested, and an incident response plan exists, your firm should be able to produce evidence for each statement.
What Carriers Usually Want To See Before Renewal
Most carriers ask about the same control families because most severe cyber claims follow familiar paths: stolen credentials, phishing, unpatched software, compromised remote access, ransomware, business email compromise, and backup failure. The exact wording varies by carrier, broker, revenue band, and claim history, but the questions are predictable.
A cyber application from Beazley asks about MFA, endpoint protection, EDR or MDR, hardened device baselines, cloud backup design, incident response planning, end-of-life software, firewall defaults, local administrator rights, and critical patching Beazley cyber insurance application. Coalition separately describes MFA, cybersecurity training, good data backups, identity access management, and data classification as essential cyber insurance requirements Coalition requirements.
For a law firm buyer, that means the carrier is not merely asking, “Do you have cybersecurity?” It is asking whether the firm can prevent credential theft from becoming a mailbox takeover, stop malware from spreading across laptops and servers, restore matters without paying extortion, remove former employees and vendors quickly, and prove that sensitive client data is handled with reasonable care.
The Control Checklist Your Firm Should Validate
1. Multifactor Authentication
MFA is now one of the most important underwriting controls. At minimum, a Los Angeles law firm should enforce MFA for email, Microsoft 365 or Google Workspace, remote access, VPN, cloud document systems, case management platforms, accounting systems, administrator accounts, and any system containing client or financial data.
The weak version is optional MFA that attorneys can skip. The stronger version is enforced MFA through conditional access policies, with separate controls for administrator accounts and no unmanaged exceptions. Carriers increasingly care about the difference.
Evidence to keep includes MFA policy screenshots, conditional access rules, identity-provider reports, admin-account lists, and exception logs.
2. Endpoint Detection And Response
Traditional antivirus is often not enough for underwriting conversations. Many carriers now ask whether the firm uses EDR or MDR on workstations and servers. The point is not just malware blocking; it is detection, containment, alerting, and response.
For a law firm, coverage should include attorney laptops, staff desktops, file servers, remote users, and any cloud-managed endpoints. If partners use personal devices for firm email or document access, that needs to be addressed before the application is completed.
Evidence to keep includes endpoint inventory, EDR deployment reports, alert-handling procedures, and proof that no active machines are missing protection.
3. Backups That Are Secure, Offline Or Immutable, And Tested
Ransomware underwriting focuses heavily on backups because a backup that attackers can delete is not much of a recovery plan. Firms should maintain backups that are encrypted, access-controlled, monitored, and protected from ordinary domain compromise. Immutable or offline backup copies are especially important.
Testing matters. A carrier may ask whether backups are tested, but the operational question is more specific: can the firm restore the document management system, billing data, email, and matter files within a tolerable timeframe?
Evidence to keep includes backup architecture, backup success reports, restore-test records, retention settings, and administrative-access controls for the backup platform.
4. Patch Management And End-Of-Life Software Removal
Carriers commonly ask how quickly critical vulnerabilities are patched and whether the firm runs unsupported systems. This includes Windows servers, laptops, firewalls, VPN appliances, remote desktop tools, practice-management software, document-management systems, and line-of-business applications.
Unsupported software creates both security and claims problems. If an application says the firm does not use end-of-life systems, the firm should verify that statement across servers, endpoints, and network devices.
Evidence to keep includes vulnerability scans, patch compliance reports, asset inventory, firewall firmware records, and remediation tickets.
5. Email Security And Business Email Compromise Controls
Law firms are high-value targets for invoice redirection, settlement-wire fraud, credential phishing, and mailbox rule abuse. Carriers know this. Expect questions about email filtering, phishing protection, SPF, DKIM, DMARC, external sender warnings, mailbox auditing, and wire-transfer verification procedures.
Technical controls help, but workflow controls matter too. A firm should have a documented out-of-band verification process for changes to payment instructions, trust-account transfers, vendor banking information, and settlement disbursements.
Evidence to keep includes email security configuration, DMARC records, phishing simulation results, mailbox audit settings, and written payment-verification procedures.
6. Least Privilege And Administrator Account Control
Carriers often ask whether users have local administrator rights and whether privileged accounts are protected. The desired answer is that attorneys and staff do not operate daily with local admin rights, administrator accounts are separate from normal user accounts, privileged access is limited, and former employees are removed promptly.
This is especially important in firms where vendors, bookkeepers, contract attorneys, and outside IT providers have access to systems. Access should be named, traceable, reviewed, and removed when no longer needed.
Evidence to keep includes administrator group membership, offboarding records, access review results, vendor account lists, and privileged-account MFA settings.
7. Security Awareness Training
Most carriers expect employee security awareness training because phishing remains a common entry point. For law firms, training should cover phishing, malicious attachments, credential prompts, payment fraud, document-sharing mistakes, and incident reporting.
Training should not be a once-a-year checkbox with no records. The firm should be able to show completion rates and follow-up for users who did not complete training.
Evidence to keep includes training completion reports, phishing simulation results, policy acknowledgments, and onboarding checklists.
8. Incident Response Planning
An incident response plan is now a practical insurance asset. It should identify who makes decisions, who contacts the broker, who contacts breach counsel, who manages forensic vendors, who handles client communications, and how the firm operates if email or document systems are unavailable.
For California law firms, the plan should also account for privacy and breach-notification obligations. The California Attorney General provides guidance on data security and breach reporting expectations California DOJ data breach guidance.
Evidence to keep includes the written incident response plan, tabletop exercise notes, contact lists, escalation procedures, and after-action items.
Why Accuracy On The Application Matters
Cyber insurance applications are not harmless questionnaires. If a firm overstates its controls, the issue may surface when a claim is filed. That can create coverage disputes, delays, or rescission arguments depending on the policy language and facts.
The safer process is to answer based on evidence. If a control is partially implemented, say so internally, fix it where possible before submission, and coordinate the final answer with the broker. A rushed “yes” to MFA, backups, EDR, or patching can create avoidable risk if the technical reality is messier.
A Practical 60-Day Renewal Plan
Sixty days before renewal, collect the application and map every security question to evidence. Identify the systems in scope: email, endpoints, servers, case management, document management, accounting, remote access, backup, and cloud storage.
Forty-five days before renewal, close the most important gaps: enforce MFA, remove stale accounts, deploy missing endpoint protection, patch critical systems, verify backup isolation, and review administrator access.
| Control Area | Status Before Renewal | Action Items for Improvement |
|---|---|---|
| Multifactor Authentication (MFA) | Partially Implemented | Enforce MFA for all critical systems; review exception logs regularly |
| Endpoint Detection & Response | Limited Deployment | Ensure EDR coverage on all endpoints; review alert response |
| Backups | Tested Monthly | Verify immutability/isolation; conduct full restore tests |
| Patch Management | Within 30 days | Expedite patching for critical vulnerabilities; scan for EOL software |
| Email Security | Basic Filters Active | Implement DMARC; enhance phishing training; review wire transfer procedures |
| Least Privilege | Some Admin Rights | Reduce local admin rights; conduct access reviews for vendors |
| Security Training | Annual Completion | Increase frequency; track completion rates; phishing simulation |
| Incident Response Plan | Document Exists | Conduct tabletop exercises; update contact lists; review BCDR |
Thirty days before renewal, run a restore test, export security reports, complete training, review incident response contacts, and confirm that the broker understands any remaining exceptions.
Before submission, have firm leadership, IT, and the broker review the application together. The goal is not to make the application sound perfect. The goal is to make it accurate, defensible, and aligned with the firm’s actual operating controls.
Bottom Line
Cyber insurance carriers now expect law firms to operate a baseline cybersecurity program, not just buy a policy. For a Los Angeles law firm, the most important controls are enforced MFA, EDR, secure and tested backups, patch management, email protection, least-privilege access, security training, and incident response planning.
The firms that handle renewal best are the ones that prepare early, validate their answers, and keep evidence. That approach improves insurability, reduces claim friction, and gives the firm a stronger security posture whether or not an incident occurs.
We Solve Problems by helping you navigate the complexities of cybersecurity and cyber insurance. Contact us today for a tailored assessment.