The Rising Cost of Cyber Claims Against Law Firms
Summary
Cyber claims against law firms are becoming more frequent and more expensive. Here is what is driving the trend and what it means for your firm's cyber insurance costs.
The frequency and severity of cyber claims against law firms have increased markedly over the past three years, and the trend shows no signs of slowing down. Law firms remain high-value targets for cybercriminals because they hold concentrated volumes of sensitive client data, handle significant financial transactions, and often lack the security infrastructure of comparably sized businesses in other industries. Understanding the current claims landscape is essential for any firm evaluating its cyber insurance program.
Ransomware Targeting Law Firms
Ransomware continues to be the most financially devastating cyber threat facing law firms. Criminal organizations have increasingly targeted legal practices because firms face intense pressure to restore operations quickly. When a firm's document management system, email, and billing platform are encrypted, the business grinds to a halt. Unlike some businesses that can operate in a degraded mode during recovery, law firms face court deadlines, statute of limitations issues, and client emergencies that create urgency to pay ransoms and restore access.
The average ransomware demand against professional services firms exceeded six figures in 2025, and the total cost of a ransomware incident, including business interruption, forensic investigation, data restoration, and legal fees, frequently reaches seven figures. Attackers have also adopted double-extortion tactics, threatening to publish stolen client data on the dark web if the ransom is not paid. For law firms, the prospect of confidential client information being publicly released adds enormous pressure beyond the operational disruption.
Cyber insurers have responded to the ransomware epidemic by requiring specific security controls as conditions of coverage. Multi-factor authentication, endpoint detection and response, offline backups, and privileged access management are now baseline requirements for most carriers. Firms that cannot demonstrate these controls face declinations, exclusions, or dramatically higher premiums.
Business Email Compromise Fraud
Business email compromise remains the most common cyber attack vector targeting law firms. These schemes typically involve an attacker gaining access to an attorney's email account and monitoring communications for opportunities to redirect funds. When the attacker identifies a real estate closing, settlement disbursement, or other financial transaction, they send fraudulent wire instructions from the compromised account or a spoofed lookalike domain.
The losses from BEC attacks can be staggering. A single fraudulent wire redirect can result in hundreds of thousands of dollars in losses. Because the instructions appear to come from a trusted attorney, victims often do not discover the fraud until the funds have been moved through multiple accounts and are unrecoverable.
Get a free coverage review
Tell us about your firm and we'll compare your current program against best practices -- no cost, no obligation.
Cyber policies typically cover BEC losses, but coverage is often sublimited. A firm with a one-million-dollar cyber policy may have only a two-hundred-fifty-thousand-dollar sublimit for social engineering or funds transfer fraud. Firms that regularly handle large financial transactions should negotiate higher sublimits or purchase separate crime coverage to fill the gap.
Data Breach Notification Costs
When a law firm experiences a data breach, the notification and remediation costs can be substantial. State breach notification laws require firms to identify all affected individuals, provide written notice, and in many cases offer credit monitoring services. For a firm that handles thousands of client matters, the process of determining which clients' data was compromised and complying with notification requirements across multiple jurisdictions can take months and cost hundreds of thousands of dollars.
Beyond statutory requirements, firms face potential regulatory investigations from state attorneys general, bar disciplinary proceedings, and civil litigation from affected clients. The legal costs of defending against these actions can exceed the direct costs of the breach itself. Cyber insurance policies typically cover breach notification costs, regulatory defense, and civil liability, but policy limits can be consumed quickly when a breach affects a large client base.
Cyber Premium Trajectory
Cyber insurance premiums for law firms have experienced significant volatility in recent years. After steep increases in 2022 through 2024 driven by ransomware losses, the market began to stabilize in 2025 as carriers benefited from improved underwriting discipline and insureds' adoption of stronger security controls. However, the stabilization has been uneven.
Firms that meet all baseline security requirements and have clean claims histories are seeing flat renewals or modest decreases. Firms with gaps in their security posture, prior claims, or incomplete responses to underwriting questionnaires continue to face challenging renewals. The gap between the best and worst rates in the market has widened, creating a clear financial incentive for firms to invest in security.
Looking ahead, the trajectory of cyber premiums will depend largely on loss experience. If ransomware attacks continue to increase in frequency and severity, the current stabilization could reverse. Carriers are also monitoring the emergence of AI-enabled attacks, which could lower the cost and increase the scale of phishing and social engineering campaigns, potentially driving a new wave of claims.
What Law Firms Should Do Now
Review your cyber insurance program annually, not just at renewal. Ensure your policy limits are adequate for a worst-case scenario involving both operational disruption and client notification. Examine sublimits for social engineering fraud, ransomware payments, and regulatory proceedings. Work with your broker to benchmark your coverage against firms of similar size and practice area.
On the security side, treat the carrier's minimum requirements as a floor, not a ceiling. Implement security awareness training that specifically addresses the threats facing law firms, including BEC schemes targeting trust accounts and wire transfers. Test your incident response plan with tabletop exercises at least annually. The firms that invest in both insurance and prevention will be best positioned to weather the escalating cyber threat landscape.
Frequently asked questions
How much does a typical cyber incident cost a law firm?
Are cyber insurance premiums still increasing for law firms?
What security controls do cyber insurers require from law firms?
Key terms
Need help evaluating your program?
Get a free coverage review -- we'll compare your current insurance against best practices for your firm size and practice areas.