Skip to main content
Law Firm Insurance
Market Trends

The Rising Cost of Cyber Claims Against Law Firms

Summary

Cyber claims against law firms are becoming more frequent and more expensive. Here is what is driving the trend and what it means for your firm's cyber insurance costs.

The frequency and severity of cyber claims against law firms have increased markedly over the past three years, and the trend shows no signs of slowing down. Law firms remain high-value targets for cybercriminals because they hold concentrated volumes of sensitive client data, handle significant financial transactions, and often lack the security infrastructure of comparably sized businesses in other industries. Understanding the current claims landscape is essential for any firm evaluating its cyber insurance program.

Ransomware Targeting Law Firms

Ransomware continues to be the most financially devastating cyber threat facing law firms. Criminal organizations have increasingly targeted legal practices because firms face intense pressure to restore operations quickly. When a firm's document management system, email, and billing platform are encrypted, the business grinds to a halt. Unlike some businesses that can operate in a degraded mode during recovery, law firms face court deadlines, statute of limitations issues, and client emergencies that create urgency to pay ransoms and restore access.

The average ransomware demand against professional services firms exceeded six figures in 2025, and the total cost of a ransomware incident, including business interruption, forensic investigation, data restoration, and legal fees, frequently reaches seven figures. Attackers have also adopted double-extortion tactics, threatening to publish stolen client data on the dark web if the ransom is not paid. For law firms, the prospect of confidential client information being publicly released adds enormous pressure beyond the operational disruption.

Cyber insurers have responded to the ransomware epidemic by requiring specific security controls as conditions of coverage. Multi-factor authentication, endpoint detection and response, offline backups, and privileged access management are now baseline requirements for most carriers. Firms that cannot demonstrate these controls face declinations, exclusions, or dramatically higher premiums.

Business Email Compromise Fraud

Business email compromise remains the most common cyber attack vector targeting law firms. These schemes typically involve an attacker gaining access to an attorney's email account and monitoring communications for opportunities to redirect funds. When the attacker identifies a real estate closing, settlement disbursement, or other financial transaction, they send fraudulent wire instructions from the compromised account or a spoofed lookalike domain.

The losses from BEC attacks can be staggering. A single fraudulent wire redirect can result in hundreds of thousands of dollars in losses. Because the instructions appear to come from a trusted attorney, victims often do not discover the fraud until the funds have been moved through multiple accounts and are unrecoverable.

Get a free coverage review

Tell us about your firm and we'll compare your current program against best practices -- no cost, no obligation.

Cyber policies typically cover BEC losses, but coverage is often sublimited. A firm with a one-million-dollar cyber policy may have only a two-hundred-fifty-thousand-dollar sublimit for social engineering or funds transfer fraud. Firms that regularly handle large financial transactions should negotiate higher sublimits or purchase separate crime coverage to fill the gap.

Data Breach Notification Costs

When a law firm experiences a data breach, the notification and remediation costs can be substantial. State breach notification laws require firms to identify all affected individuals, provide written notice, and in many cases offer credit monitoring services. For a firm that handles thousands of client matters, the process of determining which clients' data was compromised and complying with notification requirements across multiple jurisdictions can take months and cost hundreds of thousands of dollars.

Beyond statutory requirements, firms face potential regulatory investigations from state attorneys general, bar disciplinary proceedings, and civil litigation from affected clients. The legal costs of defending against these actions can exceed the direct costs of the breach itself. Cyber insurance policies typically cover breach notification costs, regulatory defense, and civil liability, but policy limits can be consumed quickly when a breach affects a large client base.

Cyber Premium Trajectory

Cyber insurance premiums for law firms have experienced significant volatility in recent years. After steep increases in 2022 through 2024 driven by ransomware losses, the market began to stabilize in 2025 as carriers benefited from improved underwriting discipline and insureds' adoption of stronger security controls. However, the stabilization has been uneven.

Firms that meet all baseline security requirements and have clean claims histories are seeing flat renewals or modest decreases. Firms with gaps in their security posture, prior claims, or incomplete responses to underwriting questionnaires continue to face challenging renewals. The gap between the best and worst rates in the market has widened, creating a clear financial incentive for firms to invest in security.

Looking ahead, the trajectory of cyber premiums will depend largely on loss experience. If ransomware attacks continue to increase in frequency and severity, the current stabilization could reverse. Carriers are also monitoring the emergence of AI-enabled attacks, which could lower the cost and increase the scale of phishing and social engineering campaigns, potentially driving a new wave of claims.

What Law Firms Should Do Now

Review your cyber insurance program annually, not just at renewal. Ensure your policy limits are adequate for a worst-case scenario involving both operational disruption and client notification. Examine sublimits for social engineering fraud, ransomware payments, and regulatory proceedings. Work with your broker to benchmark your coverage against firms of similar size and practice area.

On the security side, treat the carrier's minimum requirements as a floor, not a ceiling. Implement security awareness training that specifically addresses the threats facing law firms, including BEC schemes targeting trust accounts and wire transfers. Test your incident response plan with tabletop exercises at least annually. The firms that invest in both insurance and prevention will be best positioned to weather the escalating cyber threat landscape.

Frequently asked questions

How much does a typical cyber incident cost a law firm?
A significant ransomware attack on a law firm can easily reach seven figures when you include ransom payments, forensic investigation, data restoration, business interruption losses, notification costs, and legal fees. Even a business email compromise incident can result in six-figure losses from a single fraudulent wire transfer.
Are cyber insurance premiums still increasing for law firms?
The market has stabilized compared to the steep increases of 2022-2024. Firms with strong security controls and clean claims histories are seeing flat renewals or modest decreases. However, firms with security gaps or prior claims continue to face above-average rate pressure.
What security controls do cyber insurers require from law firms?
Most carriers now require multi-factor authentication on all remote access and email, endpoint detection and response tools, regular offline backups, privileged access management, and documented security awareness training. These are considered baseline requirements, and firms lacking them may face declinations or coverage restrictions.

Need help evaluating your program?

Get a free coverage review -- we'll compare your current insurance against best practices for your firm size and practice areas.

Free coverage review for law firms.