Law firms hold exactly what criminals want: client money, confidential case files, identity documents, and the trust that makes a fraudulent email look ordinary. A single compromised inbox can expose years of privileged correspondence or divert a completion payment that never comes back. Cyber insurance is the cover that responds when that happens, and for most solicitors it sits alongside professional indemnity rather than inside it.
The Highlights
- Your SRA professional indemnity policy is not a substitute for cyber cover.
- Payment diversion fraud during conveyancing remains the single most costly threat.
- A reportable breach must reach the ICO within 72 hours of you becoming aware of it.
- Incident response support is often worth more than the limit on the policy.
01 Why Law Firms Are Targeted
Criminals do not choose targets at random. They choose organisations that move large sums at predictable moments, hold sensitive personal data, and operate under deadlines that discourage people from pausing to check. Legal practices tick every one of those boxes.
Conveyancing is the obvious example. Completion dates are public knowledge between the parties, the sums involved are life changing for the client, and the payment instruction arrives by email. Litigation, probate, and family work carry a different exposure: the files themselves are damaging if published, which makes a practice a candidate for extortion even when no money moves.
Client money
Sensitive files
Deadline pressure
Assumed authority
02 Where Professional Indemnity Stops and Cyber Begins
This is the point most firms get wrong. Every practice regulated by the Solicitors Regulation Authority must hold professional indemnity insurance that meets the SRA minimum terms and conditions, currently £2 million for most firms and £3 million where the practice is incorporated. That policy responds to civil liability arising from the legal services you provide.
It was never designed to pay for your own losses. If ransomware encrypts your case management system, professional indemnity does not fund the recovery, the specialists, or the fee income lost while you cannot work. Those are first party costs, and cyber insurance is where they belong.
| Scenario | Typically responds |
| A client sues after you miss a limitation date | Professional indemnity |
| Ransomware locks your case management system | Cyber |
| Fee income lost while systems are down | Cyber |
| Notifying clients and the ICO after a data breach | Cyber |
| A client claims your negligence let their data leak | Both may be engaged |
| Funds diverted by a fraudulent payment instruction | Cyber, or crime cover |
Read the overlap carefully: where a breach also produces a client claim, both policies can be triggered. Insurers handle that differently, so tell your broker who provides your professional indemnity before you buy cyber cover.
03 What Cyber Insurance Covers
Policies vary, but a cyber policy written for a professional practice usually brings together the following.
- Incident response: access to breach specialists, IT forensics, and legal advice from the moment you report, usually through a 24 hour helpline.
- Data restoration: the cost of rebuilding systems, recovering files, and getting the practice working again.
- Business interruption: fee income lost while you cannot bill, including the period of disruption after systems return.
- Cyber extortion: negotiation support and, subject to sanctions checks and insurer consent, the ransom itself.
- Breach notification: the cost of telling affected clients, providing monitoring, and managing the reputational fallout.
- Regulatory defence: legal costs of an ICO investigation and, where insurable, the resulting fines.
- Funds transfer fraud: money lost through a fraudulent instruction, which is frequently an extension rather than a standard inclusion.
Check the funds transfer wording first. For conveyancing practices this is the clause that matters most, and it is the one most often capped well below the main policy limit or excluded altogether.
04 The Threats Solicitors Meet Most Often
Four patterns account for the majority of incidents reported by legal practices.
Payment diversion fraud
Widely known in the profession as Friday afternoon fraud. A criminal monitors an email thread, waits until completion is imminent, then sends the client revised bank details from an address that differs from the genuine one by a single character. The client pays, the money is moved within minutes, and recovery is rare.
Business email compromise
Rather than sending a fake email, the attacker gets into a real mailbox. From there they read everything, set quiet forwarding rules, and pick their moment. Because the messages genuinely originate from your firm, the usual warning signs are absent.
Ransomware
Files are encrypted and a payment is demanded. Modern attacks also copy the data first and threaten to publish it, which turns a technical problem into a confidentiality breach and a regulatory one at the same time.
Insider error
Not every incident is malicious. A bundle emailed to the wrong recipient or an unprotected attachment sent to a third party is still a personal data breach, and still reportable.
05 How Much Cover Should a Practice Buy
There is no fixed rule, and the right limit depends on the size of your client account, the volume of personal data you hold, and how quickly the practice would stop earning if systems went down. The tiers below are a starting point for that conversation rather than a recommendation.
£1 Million
Suited to small practices with modest client account activity and limited conveyancing.
- Sole practitioners and small teams
- Incident response and data restoration
- Breach notification costs
£2 Million
The level most established high street firms settle on, particularly where property work is regular.
- Regular conveyancing and probate work
- Business interruption for fee income
- Funds transfer fraud extension
£5 Million
Appropriate for larger practices, high value transactions, or firms holding substantial personal data.
- Multi office and multi department firms
- Higher sub limits on extortion and fraud
- Wider regulatory defence cover
Look past the headline limit. Sub limits on funds transfer fraud, extortion, and business interruption decide what you actually recover. A £2 million policy with a £50,000 fraud sub limit will not replace a diverted completion payment.
06 Your Duties When Something Goes Wrong
A cyber incident at a law firm creates obligations that run in parallel, and the clocks start at different moments.
- The ICO: a personal data breach that poses a risk to individuals must be reported within 72 hours of you becoming aware of it. Where the risk is high, you must also tell the individuals affected.
- The SRA: report promptly where the incident is serious, particularly if client money is involved or your ability to act for clients is affected.
- Your bank and Action Fraud: speed decides whether diverted funds can be frozen, so make these calls before anything else.
- Your insurers: notify cyber and professional indemnity insurers early. Late notification is one of the most common reasons a valid claim is reduced.
Use the helpline before you act. Most cyber policies require insurer consent before you engage IT specialists or lawyers. Paying for your own response first can leave those costs outside the claim.
07 Preparing for the Questions Insurers Ask
Cyber underwriting has tightened considerably. Firms that can answer clearly tend to secure both better terms and wider extensions, so it is worth gathering the following before you approach the market.
- Authentication: whether multi factor authentication is enforced on email, remote access, and administrator accounts.
- Backups: how often you back up, whether a copy is held offline, and when you last tested a restore.
- Payment controls: the process for verifying bank details and the authorisation steps for outgoing payments.
- Training: how often staff receive security training and whether you run phishing simulations.
- Incident plan: whether a written response plan exists and who holds authority to act at two in the morning.
08 Arranging Cover With Nova Insurance
We arrange cyber insurance for professional practices across the UK, and we understand how it needs to sit beside the solicitors insurance you already hold. That means checking the funds transfer wording, comparing sub limits rather than headline figures, and making sure nothing important falls between your two policies.
If you would like to review your current arrangements, or you are buying cyber cover for the first time, speak to our team and we will talk it through with you.
The Short Version
- Professional indemnity covers claims made against you. Cyber covers your own losses. You need both.
- Payment diversion fraud is the threat most likely to cost a conveyancing practice serious money.
- Sub limits, not the headline limit, decide what you actually recover.
- Report a qualifying data breach to the ICO within 72 hours, and tell your insurers straight away.
- Multi factor authentication, tested backups, and verified payment details improve both your risk and your terms.
Cyber cover built around how your firm actually works
Speak to a specialist broker who understands SRA obligations, client account risk, and where your professional indemnity policy stops.
Nova Insurance has been proudly serving clients across the UK since 1995. This article is general information and not legal or regulatory advice. Cover varies between insurers, so always read the policy wording and speak to your broker about your firm’s circumstances.