# THE POLICY YOU PAID FOR BUT CANNOT USE Cyber Insurance, Compliance Gaps, and the Documentation Trap Hamilton, Ontario did everything right after the ransomware hit. The city refused to pay the $18.5 million ransom. It contained the attack within 48 hours. It hired forensic specialists, engaged law enforcement, and rebuilt its systems from backups. By every measure of incident response execution, Hamilton performed well under pressure. Then the insurance company denied the entire claim. In July 2025, Hamilton disclosed that its cyber insurer rejected the city’s claim for the full $18.3 million in recovery costs. The insurer did not question the city’s response. It pointed to a single compliance gap: multi-factor authentication had not been fully deployed at the time of the breach. The policy excluded coverage for losses where the absence of MFA contributed to the compromise. Hamilton had known since late 2022 that its insurer required full MFA deployment. City staff acknowledged in 2023 that they had not achieved compliance. The ransomware hit in February 2024. The policy did exactly what it said it would do. It did not pay. Hamilton is not a law firm. But the gap between buying a policy and collecting on it mirrors a gap that exists in most law practices today. The ABA’s 2023 Legal Technology Survey found that only 40% of law firms carry cyber insurance. Of those that do, the number that can demonstrate ongoing compliance with every condition in their policy is almost certainly far smaller. And the consequences of that gap, as Hamilton’s taxpayers learned, are not theoretical. ## The Direct Answer Your cyber insurance policy is a contract, not a guarantee. The conditions that determine whether a claim gets paid are contractual obligations requiring ongoing compliance, contemporaneous documentation, and verifiable evidence that the security controls you attested to on your application are actually in place. Fitch Ratings data indicates that nearly one in four cyber insurance claims filed in 2024 failed to meet coverage requirements. Industry analyses tracking all denial categories place the figure higher, with multiple sources reporting denial rates exceeding 40%. The most common reasons: misrepresented security controls, missing documentation, and failure to meet policy conditions that the insured agreed to when the carrier issued the policy. For law firms, the ethical overlay compounds the problem. ABA Formal Opinion 483 and Model Rule 1.1 require competence in technology risk management. A firm that cannot produce documentation of its security posture faces both an insurance problem and an ethics problem. If this sounds familiar, it should. This series has documented how cybersecurity failures create compounding legal exposure: fromfree email providers scanning privileged communicationstothe encryption gap between secure firms and insecure clientstopassword failures that open the front door to attackers. Cyber insurance is the final layer of protection, the safety net for when every other control fails. If the safety net has holes, the entire risk architecture collapses. This article examines how cyber insurance policies actually work, where law firms most commonly fail to meet their obligations, and what documentation practices separate firms that collect on claims from those that discover their policy is worthless after the breach has already occurred. ## How Cyber Insurance Policies Actually Work Cyber insurance applications are not intake forms. They are underwriting instruments that create binding representations about your firm’s security posture. When you sign the application, you attest, under penalty of policy rescission, that the information you provided is accurate. The Travelers v. International Control Services case in 2022 established this principle with painful clarity. ICS, an electronics manufacturer, represented on its application that it used multi-factor authentication across its systems. After a ransomware attack, Travelers discovered that ICS had deployed MFA only on its firewall, not on its servers or other systems. Travelers filed suit to rescind the policy entirely, and the court voided the policy from inception. Not a reduced payout. Not a coverage dispute. The policy ceased to exist, retroactively, as if Travelers had never issued it. The implications for law firms are direct. Your application likely asked whether you use MFA for remote access, email, and administrative accounts. Whether you maintain encrypted backups. Whether you have an incident response plan. Whether you conduct employee security awareness training. Whether you perform vulnerability assessments. Every affirmative answer is a representation that your insurer will verify at claim time. And if the answer reflected aspiration rather than fact, the insurer’s response will mirror Travelers’: rescission. As this series explored inYour Password Is the Weakest Link in Your Security Chain, 95% of data breaches involve human error, and passwords remain the primary point of failure. The MFA question on your insurance application is not hypothetical. It connects directly to the credential vulnerabilities that this blog has documented across multiple posts. Cyber insurance policies typically contain several categories of conditions that law firms need to understand before a breach forces the education. Prerequisite controls.These are security measures the insurer requires as a condition of coverage. MFA is the most common, but policies increasingly mandate endpoint detection and response software, regular patching schedules, and offline or immutable backups. If these controls are not in place when the breach occurs, the insurer denies the claim regardless of how the breach happened. Notification timelines.Most policies require notification to the insurer within 48 to 72 hours of discovering an incident. Waiting to “assess the situation” before calling your carrier can void your coverage before the investigation begins. The insurer needs to approve forensic vendors, legal counsel, and remediation steps. Engaging your own team first without carrier approval often results in costs the insurer refuses to reimburse. Cooperation clauses.Policies require the insured to cooperate fully with the insurer’s investigation, preserve evidence, and follow the insurer’s approved remediation process. Firms that wipe systems, restore from backups without forensic imaging, or attempt to handle the breach internally before involving the carrier risk losing coverage for the entire event. Exclusions.Common exclusions include losses resulting from unpatched known vulnerabilities, insider threats, acts of war (which remains contested after Merck’s litigation), prior known incidents not disclosed on the application, and social engineering attacks unless the firm purchased a specific endorsement. The exclusion list in a typical cyber policy runs several pages. Most policyholders have not read it. ## The Documentation Trap The pattern that emerges from denied claims is consistent: organizations believed they had security controls in place but could not prove it when the insurer asked for evidence. This is the documentation trap. Implementing MFA is not enough. You need a record showing when you deployed MFA, which systems it covers, and when you last verified it. Conducting security awareness training is not enough. You need attendance logs, training content records, and evidence of phishing simulation results. Running vulnerability scans is not enough. You need dated reports showing findings and, critically, evidence of remediation actions taken in response. The insurer’s claim investigation will request documentation across several categories. What you cannot produce, you effectively did not do. Security governance documentation.Written security policies, acceptable use policies, data classification standards, and the dates they last received review and approval. An undated Word document on a shared drive does not constitute a governance framework. Control implementation evidence.Configuration screenshots, system logs, or vendor reports confirming that required controls (MFA, EDR, encryption, patching) remained active at the time of the breach. If your MFA provider’s admin console shows that three partners carried exemptions, that is a compliance gap the insurer will find. Risk assessment records.Dated vulnerability assessments, penetration test reports, and documented remediation timelines. A risk assessment that identified critical vulnerabilities six months before the breach, with no evidence of remediation, is evidence against your claim, not for it. Incident response plan and testing records.A written plan is the minimum. Insurers increasingly expect evidence of tabletop exercises or simulated incident drills. The ABA’s 2023 survey found that only 34% of firms have an incident response plan. The percentage that have tested that plan is almost certainly lower. Training records.Employee security awareness training completion records, phishing simulation results, and evidence that training occurred within the policy period. Annual training completed 14 months before the breach may not satisfy a policy condition requiring training “within the preceding 12 months.” Vendor management documentation.Third-party risk assessments, vendor security questionnaires, and evidence of due diligence on cloud providers, IT managed service providers, and any vendor with access to client data. The New York City Bar Association’s Formal Opinion 2024-3 specifically addressed the obligation to conduct due diligence on third-party vendors who store or transmit client data. ## The Numbers That Should Concern You Industry data from 2024 and 2025 quantifies the gap between coverage and collection. Fitch Ratings data indicates that nearly one in four cyber insurance claims filed in 2024 failed to meet coverage requirements, resulting in rejection. Multiple industry analyses tracking broader denial categories, including misrepresentation, delayed notification, and documentation gaps, place overall denial rates above 40%. The most frequently cited denial grounds: misrepresentation on applications, failure to maintain required security controls, delayed notification to the carrier, and the inability to prove compliance at the time of the breach. IBM’s 2024 Cost of a Data Breach Report found the average breach cost reached $4.88 million globally. For law firms specifically, the financial exposure extends beyond remediation costs to include malpractice liability, regulatory penalties, client notification expenses, and the business interruption losses that accumulate while systems sit offline and attorneys cannot bill. As this series documented inWhy Hackers Target Law Firms, law firms concentrate the most sensitive information from multiple clients in one place, making them high-value targets. That concentration of sensitive data is precisely what drives insurers to classify the legal services sector among the highest-premium industries for cyber coverage. The ABA’s 2023 Legal Technology Survey provides the law-firm-specific data points that insurers are also reading. Only 40% of firms carry cyber insurance. Only 34% have an incident response plan. Only 54% use MFA. Only 29% have had a full third-party security assessment. These numbers represent the baseline against which insurers calibrate their underwriting requirements. A firm that falls below these benchmarks is not just underinsured. It is underwriting its own claim denial. ## The Ethics Overlay You Cannot Separate Cyber insurance compliance and ethical compliance are not separate obligations. They converge on the same set of practices, and failure in one domain creates exposure in the other. Model Rule 1.1 requires competent representation, which Comment 8 extends to understanding “the benefits and risks associated with relevant technology.” A firm that signs a cyber insurance application attesting to security controls it does not actually maintain has both a contract problem and a competence problem. The attestation reveals that the firm knows what controls the industry expects. The absence of those controls reveals that the firm has not implemented what it knows is required. This is the same competence gap this series has examined acrossemail security,phone call encryption, andpassword management: attorneys who understand the risk in the abstract but fail to act on it in practice. ABA Formal Opinion 483 requires reasonable efforts to monitor for breaches, stop intrusions, investigate scope, and notify affected clients. These are the same obligations that cyber insurance policies condition coverage on. An insurer that denies a claim because the firm lacked monitoring tools identifies the same gap that a bar disciplinary panel would identify under Rule 1.6(c). Model Rule 5.1 extends supervisory responsibility to ensuring that lawyers within the firm conform to the Rules of Professional Conduct. Model Rule 5.3 extends similar obligations to nonlawyer assistants. When an insurer denies a claim because a staff member’s credentials fell to compromise due to the absence of MFA, the firm faces a parallel question under Rules 5.1 and 5.3: who held responsibility for ensuring that basic security measures covered everyone with access to client data? The convergence creates a compounding problem. A firm that suffers a breach and cannot collect on its insurance policy faces the full financial exposure of remediation, notification, and potential litigation. That same firm then faces bar complaints questioning whether it maintained the security practices it was ethically obligated to maintain. The insurance claim denial becomes evidence in the ethics proceeding. The documentation gap that voided the policy is the same documentation gap that suggests a failure of competence. ## What the Application Is Really Asking Cyber insurance applications have grown substantially more detailed in recent years. Insurers no longer ask whether you “have” security measures. They ask for specifics that create verifiable, ongoing obligations. A typical 2025 cyber insurance application asks questions across several domains. Each affirmative answer creates a representation that the insurer will test if you file a claim. Identity and access management.Do you require MFA for all remote access, email access, and privileged/administrative accounts? Do you restrict and monitor service accounts? Do you enforce password policies with minimum complexity requirements? The answer must hold true across every system, not just the ones your IT staff remembers. Endpoint protection.Do you deploy endpoint detection and response software on all endpoints, including servers? Does a security operations center or managed detection and response provider monitor endpoint agents? Do you patch operating systems and applications within a defined timeline (typically 30 days for critical patches)? Backup and recovery.Do you maintain backups that you test regularly? Do you store backups offline, air-gapped, or in immutable storage that ransomware cannot encrypt? Can you restore critical systems within a defined recovery time objective? Security awareness.Do you conduct security awareness training for all employees at least annually? Do you perform phishing simulations? Do you document completion rates and remediate for employees who fail? Governance and planning.Do you have a written information security policy? Do you have an incident response plan? Have you conducted a risk assessment within the past 12 months? Have you designated an individual responsible for information security? Each of these questions creates a thread the insurer can pull during claims investigation. If you answered yes to MFA but three partners carried exemptions, that is a compliance gap the insurer will find. If you attested to offline backups but your incident response plan only includes restoring from online snapshots, that is a documentation gap. If you said you conduct annual security awareness training but cannot produce attendance logs, that is a verifiable failure to meet a policy condition. ## The Takeaway Cyber insurance is not a substitute for cybersecurity. It is a financial control that transfers risk, but only if the insured meets its contractual obligations. For law firms, this means understanding that the application is an attestation, the policy is a contract, and the claim is an audit. The gap between what you say you do and what you can prove you do is the documentation trap. And falling into it can turn your cyber insurance policy into a policy you paid for but cannot use.
Originally published on LinkedIn Newsletter: The Technology Blind Spot
