We’re open until 6pm tonight

Your Professional Indemnity Policy Will Not Pay for a Cyber Attack

Law firms hold exactly what criminals want: client money, confidential case files, identity documents, and the trust that makes a fraudulent email look ordinary. A single compromised inbox can expose years of privileged correspondence or divert a completion payment that never comes back. Cyber insurance is the cover that responds when that happens, and for most solicitors it sits alongside professional indemnity rather than inside it.

The Highlights

  • Your SRA professional indemnity policy is not a substitute for cyber cover.
  • Payment diversion fraud during conveyancing remains the single most costly threat.
  • A reportable breach must reach the ICO within 72 hours of you becoming aware of it.
  • Incident response support is often worth more than the limit on the policy.

01 Why Law Firms Are Targeted

Criminals do not choose targets at random. They choose organisations that move large sums at predictable moments, hold sensitive personal data, and operate under deadlines that discourage people from pausing to check. Legal practices tick every one of those boxes.

Conveyancing is the obvious example. Completion dates are public knowledge between the parties, the sums involved are life changing for the client, and the payment instruction arrives by email. Litigation, probate, and family work carry a different exposure: the files themselves are damaging if published, which makes a practice a candidate for extortion even when no money moves.

Client money

Client account balances and completion payments make a practice worth attacking on a single transaction.

Sensitive files

Case papers hold health records, financial affairs, and family detail that clients expect to stay private.

Deadline pressure

Court dates and completion deadlines push staff to act quickly on instructions that look routine.

Assumed authority

An email that appears to come from a partner or a lender carries weight that few people question.

02 Where Professional Indemnity Stops and Cyber Begins

This is the point most firms get wrong. Every practice regulated by the Solicitors Regulation Authority must hold professional indemnity insurance that meets the SRA minimum terms and conditions, currently £2 million for most firms and £3 million where the practice is incorporated. That policy responds to civil liability arising from the legal services you provide.

It was never designed to pay for your own losses. If ransomware encrypts your case management system, professional indemnity does not fund the recovery, the specialists, or the fee income lost while you cannot work. Those are first party costs, and cyber insurance is where they belong.

Scenario Typically responds
A client sues after you miss a limitation date Professional indemnity
Ransomware locks your case management system Cyber
Fee income lost while systems are down Cyber
Notifying clients and the ICO after a data breach Cyber
A client claims your negligence let their data leak Both may be engaged
Funds diverted by a fraudulent payment instruction Cyber, or crime cover

Read the overlap carefully: where a breach also produces a client claim, both policies can be triggered. Insurers handle that differently, so tell your broker who provides your professional indemnity before you buy cyber cover.

03 What Cyber Insurance Covers

Policies vary, but a cyber policy written for a professional practice usually brings together the following.

  • Incident response: access to breach specialists, IT forensics, and legal advice from the moment you report, usually through a 24 hour helpline.
  • Data restoration: the cost of rebuilding systems, recovering files, and getting the practice working again.
  • Business interruption: fee income lost while you cannot bill, including the period of disruption after systems return.
  • Cyber extortion: negotiation support and, subject to sanctions checks and insurer consent, the ransom itself.
  • Breach notification: the cost of telling affected clients, providing monitoring, and managing the reputational fallout.
  • Regulatory defence: legal costs of an ICO investigation and, where insurable, the resulting fines.
  • Funds transfer fraud: money lost through a fraudulent instruction, which is frequently an extension rather than a standard inclusion.

Check the funds transfer wording first. For conveyancing practices this is the clause that matters most, and it is the one most often capped well below the main policy limit or excluded altogether.

04 The Threats Solicitors Meet Most Often

Four patterns account for the majority of incidents reported by legal practices.

Payment diversion fraud

Widely known in the profession as Friday afternoon fraud. A criminal monitors an email thread, waits until completion is imminent, then sends the client revised bank details from an address that differs from the genuine one by a single character. The client pays, the money is moved within minutes, and recovery is rare.

Business email compromise

Rather than sending a fake email, the attacker gets into a real mailbox. From there they read everything, set quiet forwarding rules, and pick their moment. Because the messages genuinely originate from your firm, the usual warning signs are absent.

Ransomware

Files are encrypted and a payment is demanded. Modern attacks also copy the data first and threaten to publish it, which turns a technical problem into a confidentiality breach and a regulatory one at the same time.

Insider error

Not every incident is malicious. A bundle emailed to the wrong recipient or an unprotected attachment sent to a third party is still a personal data breach, and still reportable.

Verify every change of bank details by phone, using a number you already held.

Turn on multi factor authentication for email, remote access, and your case management system.

Warn clients in writing at the outset that your bank details will never change by email.

Keep offline backups and test that you can actually restore from them.

Train every fee earner and support staff member, not only the IT contact.

Work towards Cyber Essentials, which many insurers now expect to see.

05 How Much Cover Should a Practice Buy

There is no fixed rule, and the right limit depends on the size of your client account, the volume of personal data you hold, and how quickly the practice would stop earning if systems went down. The tiers below are a starting point for that conversation rather than a recommendation.

Entry

£1 Million

Suited to small practices with modest client account activity and limited conveyancing.

  • Sole practitioners and small teams
  • Incident response and data restoration
  • Breach notification costs
Full

£5 Million

Appropriate for larger practices, high value transactions, or firms holding substantial personal data.

  • Multi office and multi department firms
  • Higher sub limits on extortion and fraud
  • Wider regulatory defence cover

Look past the headline limit. Sub limits on funds transfer fraud, extortion, and business interruption decide what you actually recover. A £2 million policy with a £50,000 fraud sub limit will not replace a diverted completion payment.

06 Your Duties When Something Goes Wrong

A cyber incident at a law firm creates obligations that run in parallel, and the clocks start at different moments.

  • The ICO: a personal data breach that poses a risk to individuals must be reported within 72 hours of you becoming aware of it. Where the risk is high, you must also tell the individuals affected.
  • The SRA: report promptly where the incident is serious, particularly if client money is involved or your ability to act for clients is affected.
  • Your bank and Action Fraud: speed decides whether diverted funds can be frozen, so make these calls before anything else.
  • Your insurers: notify cyber and professional indemnity insurers early. Late notification is one of the most common reasons a valid claim is reduced.

Use the helpline before you act. Most cyber policies require insurer consent before you engage IT specialists or lawyers. Paying for your own response first can leave those costs outside the claim.

07 Preparing for the Questions Insurers Ask

Cyber underwriting has tightened considerably. Firms that can answer clearly tend to secure both better terms and wider extensions, so it is worth gathering the following before you approach the market.

  • Authentication: whether multi factor authentication is enforced on email, remote access, and administrator accounts.
  • Backups: how often you back up, whether a copy is held offline, and when you last tested a restore.
  • Payment controls: the process for verifying bank details and the authorisation steps for outgoing payments.
  • Training: how often staff receive security training and whether you run phishing simulations.
  • Incident plan: whether a written response plan exists and who holds authority to act at two in the morning.

08 Arranging Cover With Nova Insurance

We arrange cyber insurance for professional practices across the UK, and we understand how it needs to sit beside the solicitors insurance you already hold. That means checking the funds transfer wording, comparing sub limits rather than headline figures, and making sure nothing important falls between your two policies.

If you would like to review your current arrangements, or you are buying cyber cover for the first time, speak to our team and we will talk it through with you.

The Short Version

  • Professional indemnity covers claims made against you. Cyber covers your own losses. You need both.
  • Payment diversion fraud is the threat most likely to cost a conveyancing practice serious money.
  • Sub limits, not the headline limit, decide what you actually recover.
  • Report a qualifying data breach to the ICO within 72 hours, and tell your insurers straight away.
  • Multi factor authentication, tested backups, and verified payment details improve both your risk and your terms.

Cyber cover built around how your firm actually works

Speak to a specialist broker who understands SRA obligations, client account risk, and where your professional indemnity policy stops.

Get a cyber insurance quote

Nova Insurance has been proudly serving clients across the UK since 1995. This article is general information and not legal or regulatory advice. Cover varies between insurers, so always read the policy wording and speak to your broker about your firm’s circumstances.

Contents

    Not sure what you need?

    Not sure what you need?
    Talk to a Nova Insurance Specialist, they are here to help.
    Prefer to speak to an advisor?

    Quick Contact

    Quick Contact

    Please complete the form and one of our staff will contact you.

    Quick contact

    This field is hidden when viewing the form