News & Events

Cyber Insurance Won’t Save You: Why Law Firms, Medical Practices, and Accounting Firms Must Prove Their Security in 2026

MFA incomplete.
Backups untested.
Endpoint protection inconsistent.
Incident response plan missing.
Insurance application based on assumptions.

That combination is becoming financially dangerous for law firms, medical practices, accounting firms, financial advisors, and other organizations handling sensitive information.

In 2026, cyber insurance is no longer a substitute for cybersecurity. It is a contract built around your cybersecurity.

If you cannot prove that the controls listed on your application were actually implemented, monitored, and tested, your policy may not protect you when you need it most.

Cyber Insurance Pays for Damage. It Does Not Make You Secure.

Cyber insurance can be valuable. Depending on the policy, it may help cover:

  • Forensic investigation
  • Legal counsel and breach notification
  • Data restoration
  • Business interruption
  • Public relations support
  • Ransomware response
  • Third-party claims from clients, patients, or consumers

That financial protection matters. A serious breach can disrupt operations for weeks and create costs far beyond the ransom demand.

But insurance is a backstop, not a security program.

It does not prevent an employee’s compromised mailbox from redirecting a wire. It does not restore client trust after confidential legal files are exposed. It does not eliminate HIPAA obligations, GLBA compliance responsibilities, professional ethics requirements, or FTC enforcement risk.

The FTC Safeguards Rule requires covered financial institutions under FTC jurisdiction to maintain safeguards for customer information. The Rule also makes organizations responsible for taking reasonable steps to ensure that affiliates and service providers protect information in their care.

Insurance cannot make an incomplete risk assessment complete. It cannot turn an undocumented backup into a tested disaster recovery plan.

And it cannot make an inaccurate insurance application true.

The Cost of Unproven Security Is Rising

The FTC’s maximum civil penalty for a violation is $53,088 in 2026.

That number is concerning on its own. The larger concern is how violations may be calculated. Each day of continuing non-compliance, and potentially each affected consumer record, may be counted as a separate violation.

The resulting exposure can become substantial very quickly.

The FTC is increasingly focused on foundational failures, including:

  1. No written risk assessment
  2. No designated qualified individual responsible for the security program
  3. No multi-factor authentication
  4. No incident response plan
  5. No written vendor security requirements
  6. No evidence that required safeguards are operating
  7. No documentation showing that controls are reviewed and updated

This is not about whether your firm owns a firewall or subscribes to an antivirus product.

It is about whether your organization can demonstrate that security is being managed as an ongoing business process.

Since May 13, 2024, covered financial institutions must report certain security events involving 500 or more consumers to the FTC within 30 days of discovery. That reporting obligation adds another layer of urgency for accounting firms, financial service organizations, tax professionals, and other businesses covered by the Rule.

The question after an incident is no longer simply, “Were you hacked?”

It is also:

  • What did you know about your risks?
  • Who was responsible for managing them?
  • Which safeguards were in place?
  • Were they monitored?
  • Were they tested?
  • Can you produce the records?

Underwriters Now Want Evidence, Not Promises

Cyber insurers have changed how they evaluate small and mid-sized businesses.

“Do you have MFA?” is no longer enough.

The more useful question is: “Can you prove MFA is enforced across every applicable system, including administrative accounts, email, remote access, cloud platforms, and backup consoles?”

In 2026, insurers commonly expect evidence of:

  • MFA across business-critical and privileged accounts
  • Endpoint detection and response (EDR) or managed detection and response (MDR) on servers and workstations
  • Immutable, offline, and encrypted backups
  • Documented restore testing
  • A written and tested incident response plan
  • Business continuity and disaster recovery procedures
  • Security awareness training and phishing simulations
  • A written information security program
  • Patch management and vulnerability remediation
  • Vendor security contracts and oversight

These controls are not arbitrary. They address the most common ways a business is compromised and the most important factors in recovering from ransomware or a destructive attack.

Industry guidance from Coalition’s cyber insurance requirements overview similarly identifies MFA, security training, tested backups, identity access management, EDR, incident response planning, and security risk assessments as important components of insurability and risk reduction.

The practical result is straightforward:

If your security cannot be documented, an insurer may treat it as incomplete.

IT security consultant and office manager reviewing cyber insurance requirements and a written security program

The “Hey Margaret” Problem

Picture a partner calling the office manager.

“Hey Margaret, do we have MFA everywhere?”

Margaret checks with the office administrator.

The administrator asks the person who manages the accounting software.

That person says, “I think so.”

Then someone remembers that the firm’s old remote desktop system may still be accessible with a password alone.

This is how many organizations discover that their security posture is based on assumptions.

The same problem appears with backups.

“Do we have backups?”

“Yes.”

“Have we restored from them?”

Silence.

A backup that has never been restored is not a demonstrated recovery strategy. It is a hope-filled subscription.

The insurance carrier may ask for screenshots, policy documents, audit reports, training records, endpoint inventories, restore-test results, and incident response documentation. If your firm cannot produce them, you may face:

  • Higher premiums
  • Larger deductibles or retentions
  • Ransomware exclusions
  • Reduced coverage limits
  • A declined renewal
  • A denied or limited claim if controls were misstated

This is why misrepresenting controls is so risky. A checkmark on an application is not a security control. It is a representation that the control exists and is operating as described.

“I Got a Guy” Is Not a Security Strategy

Every professional firm has a version of this conversation.

“I got a guy.”

He fixes the printer.
He resets passwords.
He knows the server.
He once recovered a laptop.

That may be useful for break/fix support. It is not the same as a managed cybersecurity program.

A security program requires consistency across people, processes, and technology. Someone must maintain an accurate asset inventory, verify MFA coverage, monitor endpoint alerts, manage patches, review backup jobs, test restores, document incidents, and prepare evidence when an insurer or regulator asks questions.

That work does not happen reliably through occasional favors.

Your firm needs ownership.

Internal IT vs. a Managed Services Provider

Hiring or expanding internal IT may be the right choice for some organizations. A balanced decision requires understanding both sides.

Internal IT: Pros

  • Direct control over priorities
  • Immediate familiarity with internal workflows
  • A dedicated employee focused on your organization
  • Potentially faster in-person support for day-to-day issues

Internal IT: Cons

  • Recruiting and retaining experienced security professionals is expensive
  • One employee may not provide 24/7 monitoring or coverage during absences
  • Training costs rise as threats and compliance expectations change
  • Security tools, backup platforms, and reporting systems add licensing expenses
  • Documentation often becomes secondary to urgent support tickets
  • Employee turnover can create a dangerous knowledge gap

For a 10- to 150-person firm, building a complete internal cybersecurity function may require multiple specialists: helpdesk, systems administration, cloud security, compliance, backup and recovery, and incident response.

That is a significant investment.

Managed Services Provider: Pros

A qualified managed services provider gives you access to a broader team and established processes without the full cost of hiring every role internally.

Benefits may include:

  • Predictable monthly costs
  • Economies of scale on security tools
  • Proactive monitoring and maintenance
  • Documented policies and procedures
  • Centralized endpoint security
  • Experienced Microsoft 365 and cloud management
  • Helpdesk support and strategic planning
  • Regular reporting for leadership and insurance renewals
  • Faster coordination during an incident

Managed Services Provider: Cons

  • You must select a provider with genuine cybersecurity and compliance experience
  • Poorly defined responsibilities can create gaps between your firm and the provider
  • You still retain executive accountability for business decisions
  • The provider needs appropriate access, contracts, and oversight
  • Changing providers can require time, planning, and documentation transfer

The answer is not to outsource responsibility blindly.

The answer is to choose a partner that clearly defines who owns each control, how it is monitored, and what evidence is retained.

Cybersecurity technician monitoring endpoint security and ransomware protection in a professional office

What a Real IT Assessment Should Reveal

Before renewal, an IT assessment or IT audit should give you a defensible view of your current position.

At minimum, it should examine:

  1. Identity and MFA
    Are MFA protections enforced on email, remote access, administrative accounts, cloud systems, and backup platforms?

  2. Endpoint security
    Is EDR or MDR installed and actively monitored on every workstation and server?

  3. Backup and recovery
    Are backups encrypted, isolated, immutable or offline, and recently tested through an actual restore?

  4. Incident response
    Does your written plan identify decision-makers, technical contacts, legal counsel, insurance contacts, notification obligations, and recovery steps?

  5. Business continuity
    Can your firm continue serving clients, patients, or customers if systems are unavailable?

  6. Vendor management
    Do contracts require vendors and service providers to protect the information they handle?

  7. Documentation
    Can you produce policies, reports, test results, training records, and remediation plans?

A proper IT audit should not simply hand you a list of weaknesses. It should prioritize findings by business impact, regulatory exposure, likelihood, and cost to remediate.

That gives ownership a roadmap instead of another technical report that sits unread.

Security Evidence Supports Better Business Decisions

Strong documentation does more than satisfy an insurer.

It helps you make informed decisions about technology spending. It identifies aging devices before they create downtime. It clarifies which vendors have access to sensitive information. It gives managing partners a realistic view of risk.

It also creates a competitive edge.

Law firms can demonstrate a stronger commitment to client confidentiality. Medical practices can support their HIPAA compliance efforts. Accounting firms can show clients that GLBA-related safeguards and financial data protection are being managed seriously.

Security becomes part of your reputation: not just an expense buried in the IT budget.

Managed IT professional and accounting firm owner reviewing a disaster recovery restore test report

Final Word

Cyber insurance still matters.

Buy it. Review it. Understand its exclusions, conditions, sublimits, and reporting requirements.

But do not mistake a policy for protection.

In 2026, your law firm cybersecurity, medical practice IT, or accounting firm IT environment must be defensible before an incident occurs. You need controls that work, people who own them, and documentation that proves the work was done.

That is where a capable outsourced IT partner can provide measurable value: implementing MFA, managing endpoint security, monitoring threats, protecting backups, testing disaster recovery, supporting HIPAA or GLBA compliance efforts, and maintaining the records your insurer or regulator may request.

Do not wait until renewal: or ransomware: to discover what your organization cannot prove.

Schedule an IT assessment with A PC of Mind and turn cybersecurity from an assumption into documented, ongoing protection.