Cyber Insurance Requirements Tighten: Why 61% of Law Firms May Now Be Uninsurable
Date Published

Canadian cyber insurers have shifted from pricing risk to prescribing mandatory security controls, leaving an estimated 61% of SMBs — including many law firms — unable to obtain meaningful coverage regardless of budget. This article breaks down the eight-control baseline, current pricing, and claims requirements law firms need to understand.
Key Insights
Cyber insurers have moved from pricing risk to prescribing mandatory controls — below a certain threshold, coverage isn't available at any price.
Roughly 61% of SMBs fall below the minimum security standard carriers now require to qualify for a quote.
Eight controls dominate underwriting: MFA, EDR/XDR, immutable backups, identity/access management, incident response planning, DMARC/phishing filtering, patch management, and security training.
Missing MFA is the single most common reason applications are declined outright.
Premiums for a typical 50-person Canadian firm run $4,000–$12,000 CAD annually, but pricing now reflects control maturity, not practice area.
Claims are increasingly denied over inadequate log preservation and forensic evidence, meaning coverage alone doesn't guarantee a paid-out claim.
For years, cyber insurance was a line item you could shop for. In 2026, it's become a compliance test — and most Canadian small and mid-sized businesses are failing it. Industry estimates suggest roughly 61% of SMBs fall below the minimum security threshold carriers now require just to receive a quote. For law firms holding client records, trust account data, and privileged communications, that gap isn't a pricing problem. It's an eligibility problem.
The Question Has Changed
Carriers used to ask what a policy would cost. Now they ask whether you qualify at all. Below a certain control threshold, meaningful cyber coverage isn't available at any price. Insurers have moved from actuarial risk pricing to prescriptive underwriting — they specify what your security stack must look like before they'll consider you insurable, and most carriers have converged on a similar list.
The Controls That Now Determine Eligibility
Eight controls dominate underwriting decisions across Canadian carriers: multi-factor authentication on every account, endpoint detection and response (EDR/XDR) across all devices, immutable or offline backups with a tested restore process, identity and privileged access management, a tested incident response plan, DMARC and phishing filtering, patch management, and staff security awareness training. Missing MFA is by far the most common reason applications are declined outright — many insurers won't even quote a business that lacks it on email and remote access.
Why This Hits Law Firms Particularly Hard
Law firms sit at the intersection of everything ransomware operators want: sensitive client data, financial transaction records, and a professional obligation to protect confidentiality that makes breach disclosure especially damaging. Canada's Cyber Centre has named ransomware the top cybercrime threat to the country's critical infrastructure in its 2025-2026 threat assessment, and initial ransom demands jumped 47% year over year to more than US$1 million in 2025. Notably, 86% of policyholders hit by ransomware refused to pay — which only works if the firm's backup and recovery infrastructure is actually capable of restoring operations without the ransom key.
Pricing Now Reflects Posture, Not Practice Area
Two firms in the same practice area with different control maturity will see very different premiums — sector classification matters far less than demonstrated security posture. For a typical 50-person Canadian professional services firm with $5M–$10M in coverage, current premiums sit in the $4,000–$12,000 CAD per year range, with retentions starting around $10,000 CAD. That's down from 2022 peaks, but still meaningfully above pre-2021 levels, and firms without the baseline controls aren't seeing higher quotes — they're seeing no quotes.
Coverage Isn't the Finish Line
Even firms that qualify face a tightening claims process. Ransomware claims increasingly require forensic evidence from centralized, off-domain logs, notification within 72 hours of discovery, and immutable log retention. Most SMBs fail on log preservation during an actual incident, which can jeopardize a claim even when a policy is technically in force. Policies also now explicitly carve out ransom payments to sanctioned entities, adding a compliance layer most firms haven't built into their incident response planning.
What This Means for Your Digital Presence
For a law firm, insurability now depends on infrastructure decisions that go well beyond the practice management software you use day to day. That means auditing whether your website's client intake forms, document portals, and email systems enforce MFA and encrypted transmission; whether your hosting and backup provider can produce immutable, tested recovery points; and whether your firm's digital vendor relationships — including your web and IT partners — can document the controls carriers are asking for in an application.
Practically, this often starts with a gap assessment against the eight-control baseline, followed by remediation of the highest-impact items first: MFA everywhere, tested backups, and a written incident response plan. Firms rebuilding or auditing their digital infrastructure should treat insurability as a design requirement, not an afterthought — the same client-facing systems that need to look professional also need to meet the technical bar insurers are enforcing before coverage, or claims payouts, become possible.
Get Started
Ready to grow your business online?
Free consultation, no pressure. Tell us about your business and where you want to take it.
Frequently Asked Questions
Can a law firm still get cyber insurance without multi-factor authentication?
Unlikely. Missing MFA on email and remote access is the most common reason insurers decline applications outright, and many carriers won't generate a quote at all without it in place across every account.
Why does having cyber insurance not guarantee a paid claim?
Increasingly, ransomware claims require forensic evidence from centralized, off-domain logs, notification within 72 hours of discovery, and proof of immutable log retention. Most SMBs fail on log preservation during an actual incident, which can jeopardize an otherwise valid claim.
How much does cyber insurance cost for a mid-sized law firm in Canada?
A typical 50-person professional services firm with $5M–$10M in coverage currently pays $4,000–$12,000 CAD per year with retentions starting around $10,000 CAD — down from 2022 peaks but still above pre-2021 pricing.
What's the first step for a firm that doesn't meet the minimum control set?
Start with a gap assessment against the eight-control baseline, then prioritize the highest-impact fixes first: MFA across all accounts, tested and immutable backups, and a documented incident response plan, since these are the most heavily scrutinized items in underwriting.
Does this affect firms without cyber insurance today?
Yes. With ransomware named the top cybercrime threat to Canadian critical infrastructure and ransom demands rising 47% year over year, firms without insurance still face the same operational risk — they simply absorb it without a financial backstop, making the underlying security controls even more important.