How do law firms insure against phishing and business email compromise attacks?
Short Answer
Cyber liability insurance covers losses from phishing and business email compromise attacks including fraudulent fund transfers, but firms must also implement email authentication, employee training, and verification procedures to satisfy carrier requirements and prevent attacks.
Business email compromise attacks are among the most financially devastating cyber threats targeting law firms. In a typical attack, a criminal impersonates a client, attorney, or title company via email and directs the firm to wire funds to a fraudulent account. Law firms that handle real estate closings, trust disbursements, or settlement payments are particularly vulnerable because they routinely process large wire transfers based on email instructions.
Cyber liability insurance covers several aspects of a business email compromise attack. Social engineering coverage, sometimes called fraudulent instruction coverage, reimburses the firm for funds transferred to a criminal as a result of a fraudulently induced instruction. This coverage is often subject to a sublimit, typically $100,000 to $500,000, that is lower than the overall policy limit. Confirm that your policy includes social engineering coverage and review the sublimit to determine if it is adequate for your firm's typical transaction sizes.
The policy also covers the costs of investigating the attack, notifying affected clients, defending against claims from clients whose funds were misdirected, and regulatory proceedings arising from the breach. If client data was compromised as part of the attack, breach response coverage pays for forensic investigation, notification, and credit monitoring.
Carriers require firms to implement specific controls to qualify for coverage. Verification procedures for wire transfer instructions are essential, including callback verification to a known phone number before processing any change to wiring instructions. Email security controls including DMARC, DKIM, and SPF authentication help prevent email spoofing. Regular phishing simulation training for all employees reduces the likelihood of successful social engineering. Firms that process significant wire transfer volume should consider dedicated fraud insurance or higher social engineering sublimits to ensure adequate protection.
Related coverage
Get a free coverage review
Tell us about your firm and we'll compare your current program against best practices -- no cost, no obligation.