This note summarises unforeseen bills and policy gaps small law firms face. It explains how PII and cyber insurance split perils and where exclusions leave liability. It targets owners, directors and practice managers in England.
Quick comparison for small law firms
| Criteria |
Professional indemnity (PII) |
Standalone cyber |
When to choose |
| Covers regulatory fines |
Often excluded or restricted |
Usually excluded unless endorsed |
Buy endorsement if facing ICO risk |
| Funds transfer fraud |
Often excluded as criminal act |
May have sublimit or social engineering cover |
Standalone if firm handles client funds online |
| First-party incident costs |
Limited for IT forensics and breach response |
Designed to cover forensics, notification, PR |
Choose standalone for operational recovery needs |
| Business interruption |
PII covers negligent advice losses |
Covers IT outage losses if included |
Add cyber BI if you bill hourly or lose income |
| Excesses and sublimits |
Typical excesses £1k–£10k |
Sublimits common for social engineering £10k–£100k |
Check per-claim and aggregate limits carefully |
Choose a standalone cyber policy when the firm relies on email for funds transfers. Opt for standalone cover when the firm stores large volumes of special category client data. Choose PII extensions only if an insurer offers a broad cyber endorsement.
Terms should be competitive; combined cover is rare without negotiation.
Plan for weeks of disruption in worst cases.
Is cyber insurance worth it for small law firms?
As a cover choice, cyber insurance is usually worth it for firms that process transfers. It also suits firms that hold special category client data or use cloud case management. Cyber insurance covers first-party costs such as forensics, notification and PR. PII often excludes these costs.
Expect recovery to take several days to several weeks. Many incidents require 7–28 days for forensic investigation and operational restoration. Complex ransomware or cross-jurisdiction incidents take longer. Use conservative planning estimates of at least two weeks when modelling business interruption and backlog costs.
A typical small law firm spends between £1,000 and £10,000 on policy excesses per claim. Market data show excesses commonly sit in that range for SME policies.
Policy exclusions small law firms must check
In the context of exclusions, check four areas first. Firms often miss them on renewal. The four are fraud, acts of war exclusions, regulatory fines and third-party contractual liabilities.
Fraud and social engineering exclusions are common. Many PII policies explicitly exclude criminal acts and transfer-of-funds fraud. Standalone cyber policies may include social engineering cover. They often apply a sublimit of £10,000–£100,000 under current market terms.
Regulatory fines are often excluded. Insurers argue fines are punitive and uninsurable in some markets. Some insurers offer an endorsement to cover ICO fines. That endorsement raises premium and imposes extra conditions.
Contractual liabilities from supplier or client contracts can be excluded. If a firm accepts wide liability in a retainer, insurers may decline that part of a claim. Read client and panel firm clauses carefully.
Check whether social engineering cover is a per-claim sublimit. If it is, quantify the worst-case loss before renewal.
Ransomware cover vs data breach response for law firms
Ransomware cover is part of cyber response. Ransom cover pays negotiated ransom and some ancillary costs if included. Data breach response pays forensic, notification, legal and PR costs irrespective of ransom.
Ransom payments often trigger additional conditions. Insurers usually require an approved incident response firm.
Insurers may refuse cover if the firm did not keep offline backups. The Law Society and ICO expect actions to mitigate harm. See ICO guidance on personal data breaches.
If backups are not segregated, many ransomware claims will be declined. This changes the insurer’s view of mitigation.
RansomwarePay ransom? Risk of criminality and no guarantee.
ForensicsIdentify intrusion, scope and client data exposure.
NotificationICO reporting within 72 hours if likely high risk.
What GDPR liabilities might small law firms still face?
GDPR liabilities refer to fines, enforcement and compensation claims from data subjects. Firms must note that insurers sometimes exclude regulatory fines or require conditions for indemnity. The ICO requires reporting a breach without undue delay and, where feasible, within 72 hours.
Compensation claims for distress and material loss are third-party losses. PII might cover negligence-based compensation, but cyber policies often handle immediate breach costs. A recent DCMS Cyber Security Breaches Survey found 39% of small businesses reported cyber incidents. See DCMS Cyber Security Breaches Survey 2023 for sector context.
Third-party claims and PII overlaps for small law firms
The principal difference between PII and cyber policies is the type of loss they cover. PII covers professional negligence and third-party claims for bad advice. Cyber covers first-party response and third-party privacy claims caused by a breach.
Overlap creates disputes over which policy responds first. Insurers may argue subrogation, apportionment or that one policy excludes the other. Always obtain a joint loss protocol or a lead insurer clause at placement.
Practical clause example for retainer and panel requirements:
-
"The firm will maintain standalone cyber insurance with a minimum aggregate limit of £250,000 and social engineering cover of at least £50,000."
-
"The firm will notify clients and the insurer within 24 hours of suspicion of unauthorised access and will use an insurer-approved incident responder."
Contracts with clients, panel firms and suppliers are a major control. They are rarely shown in practical form. Use template clauses to set expectations and reduce coverage disputes.
Supplier security clause — "The supplier shall maintain technical and organisational measures equivalent to ISO 27001 and permit annual security questionnaires and one audit per annum on reasonable notice; the supplier shall notify the firm of any incident within 24 hours."
Subcontractor flow-down — "The supplier shall ensure that all subcontractors are bound to the same data protection and insurance obligations as set out herein."
Insurance and indemnity clause — "The supplier will maintain professional indemnity and standalone cyber insurance with minimum limits of £250,000 per annum and email/social engineering cover of at least £50,000, naming the firm as an interested party for notification purposes."
Retainer clause for clients — "The firm will notify clients and insurers within 24 hours of suspected unauthorised access and will appoint an insurer-approved incident responder where required by the insurer."
These clauses can be adapted into panel tenders. They help create clear conditions insurers recognise at claim stage.
Uninsured business interruption hidden costs for small law firms
Uninsured business interruption often dwarfs direct forensic bills. Lost billable time, temporary staff and client relocation add up quickly. A small five-person firm can lose between £20,000 and £150,000 in revenue during a multi-week outage depending on caseload.
Example: a typical funds-transfer fraud totalling £48,000. The firm paid the client compensation after court action while the insurer denied the claim for criminal act. The firm faced an extra £12,000 in legal fees and suffered six weeks of lost billing worth £28,000. Final out-of-pocket cost approached £88,000.
Expect initial recovery tasks to take three to seven days.
Many articles list categories of hidden cost but stop short of an itemised, numeric breakdown that a managing partner can budget against. For a typical five‑partner or five‑person small firm, build a simple incident budget with clear line items. Presenting these items side by side lets a firm compare likely uninsured spend against higher limits or specific endorsements.
Suggested incident budget for a five-person firm:
-
Policy excess/retention commonly £1,000–£10,000.
-
Immediate forensics and IT recovery £3,000–£25,000.
-
Client notification and legal advice £1,000–£10,000.
-
PR and reputational management £2,000–£20,000.
-
Temporary staffing and backlog recovery £5,000–£40,000.
-
Potential compensation or uninsured liabilities variable; example funds-transfer fraud £10,000–£100,000.
Add an overlay for lost billable income. A four-week outage for a small caseload can cost £20,000–£60,000.
How to quantify gaps before renewal
Start with a simple loss run. Add the cost of one incident scenario such as forensic, notification, PR, legal, temporary staff and lost fees. Use conservative ranges when estimating.
Typical UK market figures for a small law firm incident:
-
Forensics and IT recovery £3,000–£25,000.
-
Client notification and legal advice £1,000–£10,000.
-
PR and reputational work £2,000–£20,000.
-
Temporary staffing and backlog recovery £5,000–£40,000.
Add potential regulatory and compensation exposures as realistic worst-case numbers. If the combined estimate exceeds intended limit, increase cover or tighten retentions.
What no one tells you about renewals
Insurers often change wordings between renewals. A coverage that existed one year may be narrowed the next. Brokers sometimes fail to highlight new sublimits or warranties. Read the renewal schedule and compare wording line by line.
For firms with repeated panel work, get endorsements placed in writing. Ask for a clear statement on whether regulatory fines are covered before accepting a retainer.
A practical, step-by-step renewal and buying checklist helps avoid last-minute surprises.
- 90 days before renewal run an internal risk inventory covering data flows, funds transfers and cloud providers.
- 60 days request full policy wordings and recent loss runs from your broker and two insurer wordings for comparison.
- 45 days carry out a one-page scenario test to estimate costs and identify insufficient sublimits or BI indemnity period.
- 30 days negotiate endorsements such as social engineering, ICO fines and ransom; agree excesses and request a lead insurer clause.
- 14 days obtain written confirmation of bespoke wording and have panel and retainer clauses approved by your insurer.
- At renewal store the exact warranty and endorsement texts in the firm’s compliance file and agree an annual review date.
Small law firms Hidden costs and exclusions checklist
-
Confirm whether PII excludes criminal acts and funds transfer fraud.
-
Check whether cyber policy has social engineering sublimit and its amount.
-
Verify whether regulatory fines and penalties are covered or excluded.
-
Confirm business interruption cover includes cyber BI and specify indemnity period.
-
Ask for prospective lead insurer handling wording to manage overlaps.
FAQ
Does PII cover cyber attacks for firms?
Short answer: sometimes, but often not. PII typically covers negligent advice, not cybercrime. Many PII policies exclude criminal acts and funds transfer fraud. Ask the broker for the precise wording and examples of paid claims from that insurer.
What is the cyber exclusion in PII?
Short answer: a clause removing cover for cyber incidents. It usually excludes unauthorised access, malicious code and criminally induced losses. Some insurers include an endorsement to restore cover for a premium. Read the exclusion text line by line.
Do small law firms need separate cyber insurance?
Short answer: yes if they handle online transfers or hold special category data. Standalone cyber covers first-party costs that PII generally does not. For many small firms this cover is cost-effective compared with out-of-pocket recovery bills.
Short answer: social engineering, criminal acts, war and regulatory fines. Also watch for per-claim sublimits for social engineering. Check if the policy requires approved responders for ransom payments.
How much does cyber insurance cost for a small law firm?
Short answer: typical annual premiums range from £300 to £3,000 for basic cover. Premiums vary by turnover, exposures and claims history. Excesses commonly sit between £1,000 and £10,000.
What is the difference between first-party and third-party cyber losses?
Short answer: first-party covers the firm’s own costs like forensics and PR. Third-party covers claims from clients or regulators. Both can apply in the same incident and cause insurer disputes.
Small law firms hidden costs and exclusions
Short answer: hidden costs include client notification, temporary staff, reputational PR and lost future instructions. These often exceed forensic costs and are sometimes uninsured. Quantify them before renewing cover.