A bookkeeper at a four person accounting firm nearly wired $48,000 to the wrong account last spring. The email looked like it came from a longtime client, right down to the signature and the friendly tone. It asked her to send the quarterly payment to a “new” bank because the old one was “under review.” She only paused because the client had never once changed banks in nine years. That pause saved the firm. Most firms do not get one.
If you run a law practice or an accounting office, you already hold the exact information criminals want most: client financial records, Social Security numbers, tax filings, case files, and in many firms, money moving through trust or escrow accounts. That combination makes a small firm a bigger target than its size suggests. Cyber insurance for law firms and accountants exists to keep one bad email or one locked server from becoming a business ending event.
This guide walks through what that coverage actually does, what it costs in 2026, the one policy detail that trips up firms the most, and what insurers now require before they will sign you up.
Why law firms and accountants are prime targets
It is not personal. It is math. A single law firm file can hold privileged communications, medical records, financial statements, and identity documents for dozens or hundreds of people. An accounting client folder holds tax IDs, bank details, and payroll data. To an attacker, that is a warehouse of resellable information behind a door that is often only lightly locked.
The numbers back it up. The American Bar Association’s 2025 technology report found that 29 percent of law firms had experienced a security breach, with firms of 10 to 49 attorneys reporting the highest rates. Yet only about 40 percent of firms carry cyber liability insurance, down from 46 percent a few years earlier, and just 34 percent have a written incident response plan. In other words, exposure is rising while protection is slipping.
Accounting firms face the same pressure from a slightly different angle. Business email compromise, where an attacker spoofs or hijacks an email account to redirect a payment, is the dominant threat to CPA and tax practices. In 2026, criminals are using AI to write flawless messages and even clone a partner’s voice on a phone call, which makes the old advice to “just look for typos” close to useless.

What cyber insurance for law firms covers
A good policy splits into two halves, and you want both. The first half, sometimes called first party coverage, pays for your own costs when something goes wrong. The second half, third party coverage, pays for the claims other people bring against you afterward. You can read the full breakdown in our guide to what cyber insurance covers, but here is the version that matters for a firm.
On the first party side, a policy typically pays for the forensic investigation to find out what happened, the cost of notifying affected clients, credit monitoring for those clients, data restoration, and lost income while your systems are down. If ransomware locks your case management software, this is the coverage that funds the recovery. Our explainer on ransomware insurance goes deeper on that piece.
On the third party side, coverage handles the legal defense and settlements when a client sues because their data leaked, plus regulatory fines and the cost of responding to a bar association or state licensing inquiry. For a law firm, a breach of privileged material is not just expensive, it is an ethics problem, and the defense costs alone can run into six figures.
One more piece to look for: coverage for the fallout when the breach happens at a vendor you rely on, like your cloud document host or your practice management platform. Plenty of firm breaches start at a third party, and you want the policy to follow.
The wire fraud trap that catches firms off guard
Here is the detail that surprises even careful buyers. Losing money to a fraudulent wire transfer, the exact scenario that nearly hit the bookkeeper above, is often not covered under the main policy limit. Many carriers tuck social engineering and funds transfer fraud under a separate, much smaller sublimit, sometimes as low as $25,000, even on a policy with a $1 million overall limit.
That gap is a serious problem for a firm that routinely moves client money. If a partner gets tricked into approving a $200,000 wire and the policy only covers $25,000 of it, the firm eats the rest.

So before you sign anything, ask three questions. What is the social engineering and wire fraud sublimit, and can it be raised to match how much you actually move? What does the policy require you to do to qualify, which is usually out of band verification, meaning you confirm any payment change by calling a known number, not replying to the email? And what is the deductible on that specific coverage? Getting clear answers here is worth more than any other single step in the buying process.
What cyber insurance costs for a firm in 2026
Most small and midsize firms pay somewhere between $1,500 and $5,000 a year for a solid policy, with solo practitioners sometimes starting closer to $95 a month. Larger firms holding big trust accounts and volumes of sensitive files can run past $10,000. For comparison, the median premium across all small businesses sits near $1,740 in 2026, so professional firms pay a real premium for the data they hold.
That premium reflects risk. Law firms, CPA practices, and financial advisers typically pay two to four times what a comparable construction company or manufacturer pays, because regulated and privileged data costs far more to clean up after a breach. To put that in perspective, IBM pegs the average law firm data breach at about $5.08 million, well above the cross industry average.
Your own price comes down to a handful of factors: your revenue, how many records you hold, your specific practice area, and the security controls you have in place. That last one is the lever you actually control. Firms with strong controls pay less, and firms without them may not get a quote at all. Our full breakdown of cyber insurance cost shows how the pieces add up, and if you want to see real numbers for your firm you can check your coverage and pricing in a few minutes.
One note on the market: after several years of steep increases, pricing has largely leveled off in 2026. Some firms still see hikes of 15 to 20 percent, but many are renewing at flat rates, especially the ones that can prove they have tightened security.
What insurers require before they will cover you
Cyber insurance is not something you can buy your way into while ignoring security. In 2026, carriers will not bind or renew a policy for a law or accounting firm without proof of specific controls. Miss them and you face steep sublimits, a much higher price, or a flat decline. Our cyber insurance requirements checklist covers all of this in detail, but for firms the core list looks like this.

Insurers now expect multi factor authentication on every account, meaning email, your practice or tax software, client portals, remote access, and any cloud tools. They want endpoint detection and response running on every device, tested backups that cannot be altered by an attacker, a written incident response plan, regular security awareness training for staff, and some oversight of the vendors who touch your data. A growing number also ask for quarterly vulnerability scans.
The good news is that these controls do double duty. They lower your odds of a breach and they lower your premium. Firms that document multi factor authentication across their systems commonly earn discounts of around 18 to 22 percent. Setting up that protection is the single most cost effective thing a firm can do, and it is worth reviewing our plain English glossary if any of these terms are new.
How to choose a policy that fits a firm
Once you know a firm needs coverage, a few habits separate a policy that protects you from one that disappoints you at claim time. Match the wire fraud sublimit to the amounts you actually move. Confirm the policy includes both first party and third party coverage, not just one. Check that regulatory defense and bar or licensing inquiry costs are included. And make sure the limit is large enough to survive a real event, given that a single firm breach can cost millions.
It also helps to think of this as one part of a broader small business plan rather than a standalone purchase. If you want the wider view first, our complete small business guide puts firm coverage in context alongside the rest of what a growing practice needs.
Key takeaways
Law firms and accountants are high value targets because they hold privileged, regulated, and financial data, and often move client money. Cyber insurance for law firms covers both your own recovery costs and the claims clients bring afterward, but the wire fraud sublimit is the detail most likely to leave a gap, so confirm it and raise it if needed. Expect to pay roughly $1,500 to $5,000 a year for a small or midsize firm, driven mostly by your data and your security controls. And plan to meet insurer requirements like multi factor authentication and tested backups, because they decide both whether you get covered and how much you pay.
Frequently asked questions
Do small law firms and solo practitioners really need cyber insurance?
Yes, and often more than big firms do. Small practices hold the same sensitive data but usually have thinner defenses and less cash to absorb a loss. A single breach at a solo practice can wipe out a year of profit, while a policy costs a few thousand dollars or less.
Does my malpractice or general liability policy already cover a data breach?
Almost never. Professional liability and general liability policies were not built for cyber events and typically exclude them or cover only a sliver. You need a dedicated cyber policy, or a cyber endorsement with real limits, to be protected.
What is the most common way firms get hit?
Email. Business email compromise and phishing lead to both wire fraud and ransomware. An attacker either tricks someone into sending money or into clicking a link that lets them in. That is why insurers focus so heavily on multi factor authentication and staff training.
Will cyber insurance pay if we get tricked into wiring money to a scammer?
Often only up to a small sublimit, unless you specifically buy higher social engineering coverage and follow the policy’s verification rules. This is the single most important thing to confirm before you buy, especially for a firm that handles trust or escrow funds.
How fast can a firm get covered?
If your controls are in place, a straightforward small firm policy can often be quoted and bound within a few days. The slow part is usually documenting your security, so getting multi factor authentication and backups sorted first speeds everything up.



