Cyber Insurance

Covers the costs when your firm gets hacked, your client data gets stolen, or your systems go down. I make sure the policy actually covers the way your practice works.

What it covers

  • Data breach response. Forensic investigation, legal counsel, customer notification, credit monitoring, and crisis management.
  • Ransomware. Ransom payments (where legal), negotiation costs, and getting your systems back online.
  • Business interruption. Lost income when your systems go down, whether from an attack, a system failure, or a cloud provider outage.
  • Regulatory defense. Legal costs if a regulator investigates after a breach. Fines and penalties where insurable.
  • Social engineering. An employee gets tricked into wiring money to a fraudulent account. More common than most people think.
  • Third-party claims. A client sues you because their data was exposed through your systems.

Why professional services firms are targets

Accounting firms hold client tax returns, financial statements, and Social Security numbers. Law firms hold privileged communications and confidential case files. Consulting firms hold strategic plans, M&A details, and proprietary client data.

Professional services firms are targeted because they hold high-value data for many clients at once. One breach affects every client whose data you hold.

What I check that other brokers skip

I read your full policy document and flag problems. Here's what usually comes up:

Does the policy cover cloud outages? If the policy defines "computer system" as hardware you own, and your business runs on cloud services, a cloud outage might not be covered.
Are the sublimits real? A $2M cyber policy with a $100K sublimit on business interruption gives you $100K of BI coverage. That detail is often buried in the endorsements.
Is social engineering actually covered? Some policies include it, some exclude it, some cover it with a limit so low it's meaningless. You have to read the policy to know.
What security do you need to keep coverage? Some policies require MFA, endpoint detection, or encrypted backups. If you don't have those at claim time, the carrier can deny.

Cyber vs E&O: they don't overlap

A common question: "My E&O covers data loss. Do I really need separate cyber?" The short answer is yes. Most E&O policies explicitly exclude data breaches, cyberattacks, and failure to protect electronic data. These are two different policies covering two different risks.

Read the full breakdown: Your E&O Policy Doesn't Cover Cyber. Here's Why That Matters.

Cyber insurance by industry

  • Law firms -- Privileged communications and case files make law firms high-value targets. Bar regulatory proceedings can follow a breach.
  • Accounting firms -- SSNs, tax returns, and financials for every client. Tax season creates a peak exposure window.
  • Consultants -- Client strategic plans, M&A details, and proprietary data across multiple engagements.

Want to know what your cyber policy actually covers?

I'll read it and tell you. No cost for the review.