There is a moment that happens in a lot of law firms around renewal time. The cyber insurance application comes in, it is longer than last year, and somebody forwards it to the IT provider with a note that says something like "can you fill this out."
The provider fills it out. Everything gets a yes. The policy binds. Nobody thinks about it again until there is a claim, which is exactly the wrong time to find out that one of those answers was optimistic.
This is worth paying attention to, because the renewal application has quietly become the most honest security assessment most firms will ever receive. It is not a sales document. Nobody is trying to upsell you. It is a list of the controls that an industry with actual loss data has determined are the ones that matter.
So it is a useful place to start.
Not hackers. Three parties with paperwork.
Your cyber carrier. The application is a controls checklist, and every question maps to a specific technical configuration. Answering yes without documentation creates a problem you discover at claim time rather than application time.
Your malpractice carrier. Increasingly asking the same questions, for the same reasons. Your professional liability exposure and your data security posture stopped being separate topics a few years ago.
Your clients. Corporate clients now attach security requirements to outside counsel guidelines. Those are contractual obligations, not suggestions. Some include audit rights, which means a client can ask to see your controls, and you agreed to that when you signed the engagement.
None of these parties are trying to frighten you. They are trying to price risk. That makes them a much better guide to what actually matters than any vendor pitch, including ours.
Pull your last application and you will find these, in some form.
The first four are fundamentals. Any firm should be able to answer yes and prove it. The next three are the layer that insurance created, and they are where most firms get uncomfortable. The last one is where almost everybody is honest by accident, because most firms simply do not have an incident response plan and know it.
Here is the part that matters more than any individual question: the difference between a yes and a defensible yes is documentation. MFA enforced with a dated policy export is a yes. MFA that is mostly on because most people set it up is not, even though it feels like one.
Number seven. How quickly is access revoked when someone leaves.
Almost every firm answers this confidently, and almost every firm is wrong, because they are thinking about email.
Email dies within the hour. That part is handled.
Document management often does not. Practice management and billing frequently does not, especially if billing is administered by a different person than IT. Court filing portals and third-party vendor logins almost never get reviewed, because nobody owns that list and half of those accounts were set up individually by the attorney who left.
And then there is the quiet one: files that were synced to a personal laptop or a personal cloud account months ago. That is not an access problem you can revoke. It is a configuration decision that was made, or not made, long before anyone resigned.
This is not a product problem. There is no software you can buy that fixes it. It is a process problem, and it is the single most common finding in the security reviews we run for firms.
The fix is unglamorous: a documented offboarding checklist that covers every system, not just the ones IT administers, executed same-day and signed off. It costs nothing. It is also the thing you will wish you had if a departure ever turns adversarial.
Two patterns.
Buying a security platform to solve a permissions problem. A lot of firms have document management systems where, functionally, everyone can see everything. That feels like a security gap, so somebody proposes a monitoring layer on top of it. The actual fix is role-based access inside the system you already own. It is cheaper, more effective, and it is the answer a carrier or a client would prefer to hear.
Paying for empty seats. Security is licensed per user. Firms have turnover. Nobody reconciles the count. We find this in most of the reviews we run, and it is pure waste.
Email authentication and business email compromise protection.
The realistic threat to a law firm holding client funds is not a sophisticated intrusion. It is a well-written email about wire instructions that arrives at exactly the right moment in a real estate closing or a settlement disbursement, from an address that is one character off from a real one.
That threat is defeated by unglamorous things: proper email authentication so your domain cannot be convincingly spoofed, filtering that catches lookalike domains, and a verbal callback procedure for any change to payment instructions. None of it is expensive. All of it gets skipped in favor of products that demo better.
Nobody is telling you to buy everything on the list.
Our position is that security should be sized to the size and scope of the firm and grow as the firm grows. A four-attorney practice does not need what a sixty-attorney firm needs. The difference is not how seriously each takes confidentiality. It is the obligations they carry: how many carriers, how many client contracts with security terms, how much data, how many people with access.
What sets your floor is not your own judgment about risk. It is what you have already told a carrier or a client is true. Everything above that floor is a business decision you should get to make with real numbers in front of you.
Which brings up the awkward part.
Most firms get one bundled line item on the invoice. Something like "security services." The number moves occasionally and nobody can explain why, because nobody can see inside it.
That means you cannot tell whether you are paying for the tier you are actually in, whether two products are doing the same job, or whether the user count still matches your headcount.
We itemize every component with a monthly report behind it, because a client who can see what they are buying makes better decisions. That is the entire reason.
If your provider cannot produce a line-item breakdown of your security stack within a day, that is the finding. You do not need to understand endpoint detection to know that is a problem.
If you do nothing else after reading this: pull your most recent cyber insurance application, go through it question by question, and for each yes, ask what document proves it.
Wherever you cannot name the document, you have found the gap. It is a better security assessment than most firms have ever paid for, and it costs you an hour.
Carriers consistently ask about multi-factor authentication on remote access and email, endpoint detection and response on all devices, offsite backups with recent restore testing, email filtering and authentication, annual security awareness training with completion records, managed detection or monitoring, prompt access revocation when staff leave, and a written incident response plan. Requirements vary by carrier and policy size, but that set appears on nearly every application.
Yes. Coverage is underwritten based on the controls you stated were in place on the application. If a claim investigation determines a stated control was not actually enforced, the carrier may dispute or deny coverage. This is why the difference between a control existing and a control being documented matters more than most firms realize.
Same day, across every system, not just email and network login. That includes the document management system, practice management and billing, court filing portals, and third-party vendor accounts. Most firms handle email within the hour and leave several other systems active for weeks, usually because no single checklist covers everything.
No. Security should be proportionate to the size and scope of the firm. A four-attorney practice and a sixty-attorney firm both owe clients confidentiality, but they carry different obligations in terms of client contracts, carrier requirements, data volume, and number of people with access. The floor is set by what you have already represented to carriers and clients as true.
Offboarding. Access revocation is treated as an HR errand rather than a security control, so it typically covers email and network login and misses document management, billing, filing portals, and vendor accounts. It requires no software to fix, only a documented checklist executed the same day, and it appears on nearly every insurance application.
Ninety-second version: take the three-question self-check. No email required to see your result.
Longer version: send us your cyber policy or your most recent renewal application, whichever you have handy. A client security questionnaire works too. We will tell you which of those controls your firm can actually prove today, which ones you cannot, and which tier you are genuinely operating at. Send your IT invoice along with it if you want us to check whether your spend matches your tier, though that part is optional.
No charge. No meeting required. Five business days. If your renewal is in the next sixty days, this is the useful window.
Request a Security Stack Review
Four Winds IT is a technology company serving 300+ businesses across Southwest Florida, headquartered right here in Sarasota. Call us at (941) 315-2380 and an engineer picks up.