
Cyber Liability for Law Firms and Accounting Practices: What’s Actually at Stake
Law firms and accounting practices sit on some of the most valuable data cyber-criminals can steal — and most are still insured as if that weren’t true.
Ask most managing partners what keeps them up at night, and the answer is usually a client relationship, a lateral hire gone wrong, or a looming deadline. Cybersecurity rarely makes the list — which is precisely why law firms and accounting practices have become such attractive targets. The industry has spent decades building deep expertise in managing client risk and comparatively little in managing its own. Cybercriminals have noticed.
Here’s what’s actually driving the risk, what a breach costs when it happens, and why the professional liability policy sitting in your firm’s file drawer almost certainly won’t help.
Why Law Firms and Accounting Practices Are High-Value Targets
The numbers tell a stark story. In late 2025, professional services — a category that includes law firms — saw the highest share of any industry targeted by ransomware attacks, at nearly 19% of all incidents. More than 200 ransomware attacks have hit law firms since 2025, with one ransomware group alone claiming 20 firms in a single year. Roughly one in five U.S. law firms reported being targeted by a cyberattack in the past year, and more than half of firms that were breached lost sensitive client information in the process.
The legal industry now faces an average of over 1,000 cyberattacks per week — a double-digit increase year over year, with phishing remaining the single most common entry point.
What makes firms so attractive isn’t a mystery. It comes down to concentration and vulnerability, in roughly equal measure.
Concentration of valuable data. A single matter file at a law firm can contain privileged communications, litigation strategy, merger intelligence, financial records, and personal data — all in one place, often tied to high-stakes transactions where the information itself has direct monetary value to an attacker, whether through extortion or resale.
Comparatively light security investment. Despite the scale of the threat, only about a quarter of firms surveyed say they feel highly prepared for a cyber incident, with most citing the sophistication of modern attacks as their top challenge. Firms have historically invested far more in substantive legal or accounting technology than in the security infrastructure protecting the data underneath it.
Leverage built into the business model. A ransomware actor targeting a law firm or accounting practice isn’t just threatening data loss — they’re threatening to expose privileged client information or disrupt a live transaction, which creates exactly the kind of urgency that pressures firms toward paying a ransom quickly rather than risk reputational fallout with clients.
The 3 Types of Data Creating the Most Exposure
Not all data is equally dangerous to lose. For professional services firms, three categories carry the most weight in a breach.
1. Client financial records. Accounting practices routinely hold detailed financial statements, tax returns, banking information, and payroll data for individual and business clients. This is exactly the kind of data that commands a premium on the black market and triggers the broadest set of notification obligations when exposed.
2. Legal strategy and privileged documents. For law firms, the exposure goes beyond financial harm. Litigation strategy, merger and acquisition details, and privileged attorney-client communications carry value to competitors, opposing parties, and in some cases nation-state actors — which is part of why several large firms have reported breaches attributed to sophisticated, targeted intrusions rather than opportunistic attacks.
3. Personally identifiable information (PII). Social Security numbers, dates of birth, addresses, and other PII collected through client intake, HR records, and billing systems create direct regulatory notification obligations the moment they’re exposed — regardless of whether the underlying matter itself was sensitive.
The overlap of all three in a single firm’s systems is what makes professional services such a concentrated target: a single intrusion can expose financial, strategic, and personal data simultaneously, multiplying both the breach response cost and the number of parties with standing to bring a claim.
What a Breach Actually Costs
The dollar figures involved have moved sharply in the wrong direction. The average data breach cost in the legal sector reached $5.08 million in 2026, up 10% year over year — a figure that’s roughly 14% higher than the average breach cost across all industries combined, and one that doesn’t account for long-term reputational damage or client attrition.
Breaking that figure down into its components:
Regulatory fines and notification costs. Breaches involving PII or financial data trigger mandatory notification obligations in all 50 states, plus potential federal requirements depending on the data involved. Notification alone — letters, call center support, credit monitoring for affected individuals — can run into six figures before any regulatory fine is assessed.
Legal defense. Firms facing a breach are frequently sued by affected clients in addition to any regulatory action, generating defense costs independent of whatever the underlying claim is worth.
Business interruption. Ransomware incidents that take systems offline directly halt billable work, delay active transactions, and in several documented cases have disrupted firms during live M&A deals or high-profile litigation — compounding the financial impact well beyond the direct cost of the incident.
Ransom payments themselves. Ransom demands against law firms and professional services firms have climbed dramatically, with average initial demands now in the millions and amounts actually paid averaging several hundred thousand dollars per incident when firms choose to pay — a decision that itself carries legal and ethical complications most firms are unprepared to navigate in real time.
Reputational damage and client attrition. Perhaps the hardest cost to price, but often the most lasting. A publicized breach at a firm handling sensitive client matters can stall new business development and strain existing relationships well beyond the direct financial cost of the incident itself.
Why Your E&O Policy Almost Certainly Won’t Cover This
Here’s the misconception that catches the most firms off guard: assuming a professional liability (E&O) policy — sometimes called Lawyer Professional Liability for law firms — extends to cover a cyber incident. In the vast majority of cases, it doesn’t, and the reason is structural rather than incidental.
E&O insurance is built to respond to a specific trigger: a claim that your firm’s professional advice, work product, or service fell below the applicable standard of care and caused a client financial harm. A cyber incident is a fundamentally different kind of event — unauthorized access, ransomware, a data breach — and standard E&O policies simply aren’t written to respond to it, even when the breach is directly connected to a client matter.
This holds even in the scenario where a breach leads to a professional error claim. Consider a law firm whose systems are breached, and in the aftermath, a client alleges the firm’s negligent data handling practices caused the exposure of their privileged information, resulting in financial harm. That claim — the client alleging the firm failed to meet its professional obligations — may indeed trigger the E&O policy. But the breach response itself — forensic investigation, notification costs, credit monitoring, regulatory defense, ransom negotiation — falls outside what E&O was ever designed to fund. Those costs require a separate, dedicated cyber liability policy, and without one, the firm pays for breach response and legal defense from two different exposures, with only one of them backed by insurance.
Some insurers have responded to this gap by adding limited cyber endorsements to E&O policies, or offering blended products that combine professional liability with first- and third-party cyber coverage in a single form. These can be a reasonable fit for smaller firms, but they typically provide meaningfully less protection than standalone E&O and cyber policies purchased separately — a tradeoff worth understanding clearly before assuming a bundled endorsement is sufficient.
How to Choose the Right Cyber Liability Limits
Sizing cyber coverage correctly starts with an honest look at two variables: how much client data your firm actually holds, and how sensitive that data is.
Start with client volume. A larger active client roster means more individuals and entities with standing to be notified — and billed for — in the event of a breach. A firm serving a few dozen high-net-worth clients has a different notification cost profile than one serving several thousand individual tax clients, even if the underlying systems are similarly vulnerable.
Weight for data sensitivity, not just volume. A firm handling a smaller number of extremely high-stakes matters — major litigation, complex M&A, high-net-worth estate planning — may carry disproportionate cyber risk relative to its size, because the value of what could be exposed or exploited is unusually high per record, even if the total record count is modest.
Account for regulatory complexity. Firms operating across multiple states, or handling data subject to specific regulatory frameworks, face more complex and more expensive notification and compliance obligations in a breach — a factor that should push coverage limits higher even without a corresponding increase in raw data volume.
Confirm coverage addresses both first- and third-party costs. Your policy needs to fund your own breach response (forensics, notification, business interruption) as well as claims brought against you by affected clients. Confirm both are addressed, either in a single comprehensive policy or through coordinated standalone coverage.
Review limits as the firm grows — not just at renewal. As your firm adds attorneys or partners, takes on larger engagements, or expands into new practice areas handling more sensitive data, your cyber exposure grows with it. A limit set three years ago, calibrated to a smaller firm with a narrower client base, is likely behind where your actual risk sits today.
The Bottom Line
Law firms and accounting practices have become some of the most targeted organizations in the current threat landscape, precisely because of what makes them valuable to clients in the first place: concentrated, sensitive information, handled with trust and discretion. That same concentration is what makes a breach so expensive when it happens — and what makes a standard E&O policy so inadequate to respond to one on its own.
The firms best protected aren’t necessarily the largest or the most technically sophisticated. They’re the ones who’ve recognized that professional liability and cyber liability answer two different questions, and who’ve made sure both are covered — with limits that reflect the data they actually hold, not the data they held when the policy was first purchased.
This article is for educational purposes only and does not constitute legal or insurance advice. Consult our licensed insurance agents to review your firm’s specific coverage needs.
