Here’s the uncomfortable question we ask firms: the morning after a ransomware note appears on your screens, which policy responds? Most lawyers reach for their malpractice policy — the big one, the one they’ve paid faithfully for years. And for most of what a breach costs, that policy was never designed to answer.
The short answer
Lawyers professional liability covers claims that you performed legal services negligently. A cyber incident mostly generates costs that aren’t professional-negligence claims at all — forensic investigation, system restoration, client notification, credit monitoring, regulatory response, extortion payments, wire-fraud losses, business interruption while you’re locked out. Those are first-party and privacy-liability costs, and they’re the province of cyber coverage. A firm carrying LPL alone isn’t “mostly covered” for a breach; it’s mostly bare — which is why cyber has been the fastest-growing coverage in the professional suite.
Why law firms specifically
A law firm’s data isn’t ordinary data. Client files carry privilege, deal information, trust-account details, litigation strategy. That makes firms attractive targets — and makes breach response legally delicate: the forensic and notification process itself has to respect privilege, which is exactly why SafeLaw™ was built for legal practices rather than adapted from retail templates.
The costliest pattern we see isn’t even the dramatic breach — it’s wire fraud via social engineering: a spoofed email in a real estate closing or settlement disbursement, funds sent to a criminal’s account. Depending on facts, that loss can fall in the seam between policies — this is precisely where coverage curation earns its keep, aligning the crime, cyber, and LPL pieces so the seam is closed before the wire moves.
What goes where: the two-column test
- LPL responds: a client alleges your legal work was negligent — including, say, a missed deadline that happened during a system outage. The malpractice consequences of an incident stay with LPL.
- Cyber responds: the incident’s own costs — forensics, restoration, notification, monitoring, regulatory defense, extortion, fraud-instruction losses, lost billings during downtime.
- Both, coordinated: the bad week where a breach causes client harm. Two policies, one event — and the reason buying them as a curated pair, not from two unrelated vendors, prevents the finger-pointing that delays payment.
The Texas small-firm reality
Solo and small firms tell us they’re too small to target. The data says the opposite: small firms are targeted because defenses are thin, and as we covered for solos, client data doesn’t scale down its sensitivity with your headcount. Cyber premiums for small firms are modest relative to the exposure — and relative to what you already pay for LPL.
Want to know exactly where your current policies would leave you the morning after? That review is free — and it’s a lot cheaper before the wire transfer than after.
FAQ
Does malpractice insurance cover a data breach?
Generally no — LPL covers professional-negligence claims. Breach costs (forensics, notification, restoration, extortion, fraud losses) belong to cyber coverage.
Do small law firms really need cyber insurance?
Yes — small firms are frequent targets precisely because defenses are lighter, and privileged client data is high-value regardless of firm size.
What is social engineering / wire-fraud coverage?
Protection for funds lost to fraudulent payment instructions — a top loss scenario for firms handling closings and settlements, and one that can fall between standard policies if not deliberately covered.
What does SafeLaw™ include?
LawPAK’s legal-practice cyber program: breach response with privilege-aware counsel, client-data liability and regulatory defense, ransomware and wire-fraud coverage, and trust-account exposure review — details here.
Companions: Insurance Coverage · Solo to five · Texas cost guide
