Policy comparison for solicitors
Compare headline limits, sub‑limits and incident panels to see real protection fast. Read the schedule, not the brochure.
What to check first
Check sub‑limits for regulatory fines, notification and extortion. A £1,000,000 headline limit can hide small sub‑limits that leave gaps.
Check whether forensics and PR sit as first‑party costs or under a capped notification sub‑limit. That determines if the insurer pays urgent work that stops downtime.
Check retroactive dates and prior‑acts wording to ensure historic incidents are covered. If the retro date is after the incident, the claim is declined.
Quick decision sentence
If a policy shows low sub‑limits for notification or extortion, treat it as partial cover and negotiate an endorsement.
| Insurer / Product |
Total limit |
Regulatory fines sub‑limit |
Notification / PR |
Ransom/extortion |
Business interruption |
Incident responder |
Common exclusions |
| Market A (syndicate) |
£1,000,000 |
£50,000 |
Included (sub‑limit £25,000) |
Sub‑limit £100,000 |
Yes, 30‑day indemnity |
Approved panel only |
No cover if MFA absent |
| Hiscox‑style product |
£500,000–£2,000,000 |
£100,000 |
Included (no separate sub‑limit) |
Included |
Yes, loss of fees cover |
Choice of responders |
Prior incidents limit applies |
| Direct insurer product |
£250,000–£1,000,000 |
£25,000 |
Often capped |
Often excluded |
Limited |
Panel only |
Exclusions for unpatched systems |
Legal firms should document MFA, backup tests and patch logs. When such evidence exists, insurers accept claims more quickly.
One simple habit reduces underwriting friction for most firms.
24h
First 24 hours
Isolate systems, call insurer, preserve logs.
72h
72 hours
Decide ICO notification, prepare client message.
30d
30 days
Containment done, remediation plan in place, update insurers.
Policy wording for solicitors needs a sector lens. For law firms, the headline limit alone can be misleading.
Aim to secure a regulatory fines sub‑limit of at least £150,000 to £250,000. Set notification and PR cover at £50,000 to £150,000.
Ransom cover should be at least £100,000 where the firm holds sensitive client files. Loss of fees should be measured in months, not days.
A sensible minimum is 90 to 180 days cover for practices handling litigation or property completions.
Check retroactive date wording and an express carve‑in for regulatory defence costs. Watch exclusions such as absent MFA, no backup tests or deliberate partner crime.
Option A: use a specialist cyber broker
A specialist broker negotiates wording, explains sub‑limits and matches incident responders to firm needs. For small practices that expertise usually offsets the broker fee.
When to choose a broker
Choose a broker when the firm has prior claims, higher turnover or complex PI interactions. Brokers can secure endorsements for legal professional privilege and regulatory defence.
Broker advantages and limits
Brokers draft bespoke clauses and test retro dates with underwriters. This works well in theory, but in practice the broker must show documented security controls to persuade insurers.
A clear mistake is relying on verbal assurances alone and failing to provide proof of controls.
Pause briefly to gather documentation and evidence before negotiations.
Option B: buy direct from insurer
Buying direct can be faster and cheaper for very small firms with simple needs. Direct buying often lacks negotiation of wordings and limits.
When to buy direct
Buy direct if the firm wants a fast quote, has no prior claims and accepts standard wording. This suits sole practitioners with limited client data.
Limitations of direct purchase
Direct sales typically use standard schedules with low sub‑limits for notification and extortion. The error most frequent at this point is buying on price and missing sub‑limits.
Option C: rely on PI or add‑on cover
Relying on PI or a PI add‑on for cyber carries risk. PI often excludes forensic, ransomware and regulatory costs.
When PI might help
PI may cover negligent advice that caused loss, for example wrong legal advice on a data sale. PI rarely covers heavy first‑party breach costs.
Why PI falls short
PI wordings commonly exclude cyber extortion and have no notification budget. Many firms discover this after a claim and face uninsured costs.
How to choose according to your situation
Match cover to firm size, client sensitivity and case mix. Use the table and checklist to prioritise clauses that protect clients and keep the firm running.
Decision criteria
Rank these items: forensic cover, notification costs, regulatory defence, business interruption. If any are limited, consider higher sub‑limits or a higher total limit.
Practical scoring system
Score each clause 0 to 3 where 0 means missing and 3 means full cover. If the total score is nine or less, upgrade the policy or add endorsements.
Scoring makes a quick, evidence-based buying decision.
What no one tells you
Insurers require minimum cyber hygiene as a condition for many policies. Firms that cannot show MFA, recent backups and a patching schedule risk higher excess or declined claims.
Common underwriting traps
Many policies silently exclude known vulnerabilities or lack of backups. Documenting controls in writing often resolves underwriting queries faster than switching insurers.
Real‑world example
An anonymised case: a small Manchester firm faced ransomware. The insurer paid £50,000 for forensics and client notifications.
The ICO reviewed the response and closed the case after the firm showed backup tests and staff training records. This example shows why quick evidence matters.
This guidance is less relevant for very large firms (100+ staff), practices operating mainly outside England, or firms already engaged with specialist regulators and counsel after a large breach.
A specialist broker can review a policy schedule and provide a short memo on key gaps.
Frequently asked questions
What is the difference between cyber insurance and PI?
Cyber insurance covers first‑party costs like forensics, notification and business interruption. Professional Indemnity covers negligent advice and third‑party claims.
PI often excludes ransomware and notification costs.
Do I have to tell the ICO about every data breach?
A notifiable breach must be reported to the ICO within 72 hours if it risks individuals' rights. Firms should assess severity and record the decision to notify or not.
How much does cyber insurance cost for a small firm?
Typical premiums vary widely by firm size, turnover and security controls. Sole practitioners often see about £300 to £700 in common cases.
Small firms with 2 to 10 staff commonly pay about £600 to £2,000. Medium firms with 11 to 49 staff commonly fall in the £1,500 to £5,000 band.
These bands assume documented controls like MFA, backup testing and patch logs.
What evidence do insurers want during a claim?
Insurers expect logs, backup test results, MFA records, patch schedules and staff training records. Early documentation speeds claims and supports regulatory defence.
Can a broker help coordinate PI and cyber?
Yes. A specialist broker can negotiate coordination clauses, carve‑outs and endorsements so PI and cyber do not conflict. Use a broker when the policies interact.
Premium guidance tailored to solicitors helps budgeting.
- As a rough UK market guide in 2025: sole practitioners with limited client data and basic controls commonly see premiums around £300 to £700.
- Small firms (2–10 staff) with standard controls typically pay about £600 to £2,000.
- Medium firms (11–49 staff) handling higher volumes or sensitive matters commonly fall in the £1,500 to £5,000 band.
- Regional firms approaching 50 to 100 staff can expect premiums from about £4,000 upwards depending on turnover and casemix.
Lack of controls or prior claims can push premiums substantially higher.
Next steps and resources
The ICO provides clear breach notification guidance and templates on its website. See ico.org.uk for official steps.
Client notification template
Subject: Important: data security incident affecting your matter
Dear [Client name],
On [date] the firm discovered unauthorised access to some case files relating to [matter]. The firm contained the issue and engaged specialists.
Data involved: [brief list]. Our steps: isolated systems, called insurer, started forensic review.
Potential impact: [brief risk]. What we ask you to do: [change passwords, monitor accounts].
For questions contact: [Partner name] at [email] or call [number].
Yours sincerely,
[Partner]
Sample internal incident checklist
- Isolate affected devices.
- Preserve logs and evidence.
- Call insurer and incident responder.
- Assess need to notify ICO within 72 hours.
- Prepare client notifications and update the SRA file.
Keep one copy of policy schedules and evidence of security controls in a safe, dated folder. This folder proves diligence to underwriters and regulators.
Will insurers pay ransomware ransom?
Some policies cover ransom payments within a defined sub‑limit and subject to legal and ethical checks. Always confirm the ransom sub‑limit and whether payment needs law enforcement approval.