FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
Cyber for law firms · UK 2026

Cyber insurance for solicitors' firms in the UK

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Published 14 July 2026

Only 28% of UK law firms hold cyber insurance despite conveyancing money transfers being one of the most-targeted fraud vectors. The SRA has escalated its cyber warning notices year on year. This page sets out how cyber cover works for solicitors' firms in 2026, how it interacts with your SRA MTC PII, and what a specialist broker looks for.

The four cyber threats facing UK solicitors' firms right now

  1. Conveyancing money-transfer fraud (Friday-afternoon fraud). Fraudster intercepts client-to-firm or firm-to-client bank-detail communication. Client transfers deposit or completion funds to fraud account. The single largest UK legal-sector cyber loss pattern.
  2. Ransomware. Firm files, matter records, precedent library, calendars all encrypted. Ransom demand typically 6-7 figures. Even without paying, business-interruption cost is material.
  3. Business email compromise (BEC). Fraudster accesses firm email, impersonates partner, initiates fraudulent payment or extracts client data. Often the entry point for conveyancing fraud.
  4. Data-breach and confidentiality exposure. Client-sensitive matter data exposed. SRA notification, ICO reporting, professional-liability implications all follow.

How cyber insurance responds — the four cover components

  1. First-party incident response. Breach coach, forensic investigation, PR, legal counsel, notification costs to affected data subjects. Available typically within hours of first contact.
  2. Cyber-crime and social-engineering fraud. Direct financial-loss cover for fraudulent transfers and impersonation events. Sub-limits typically apply.
  3. Business interruption. Lost revenue from systems outage during and after an incident. Standard waiting period 8-24 hours.
  4. Third-party liability. Client claims arising from firm's data or systems breach. Often the largest single loss element for law firms.

The interaction with SRA MTC PI insurance

The SRA MTC responds to civil liability from the professional work. Cyber responds to the technical breach event and its incident-response costs. Where the two overlap, careful wording matters.

  1. Fraud loss to firm's client trust account. Cyber covers the fraud loss. SRA MTC covers the firm's liability to reimburse the client. Both engage.
  2. Client data breach leading to complaint under DISP. Cyber covers incident-response and any direct data-breach claims. SRA MTC covers professional-liability claim from the client for advisory-work implications.
  3. Business email compromise affecting a client matter. Cyber covers the breach and response. SRA MTC covers the resulting professional liability to the affected client.
  4. Ransomware affecting file access and deadline missing. Cyber covers ransom decision plus BI. SRA MTC covers any professional liability from missed deadlines.

What SRA warning notices say about your PII risk profile

The SRA has published multiple warning notices on cyber risk. Each affects how PII insurers view solicitors' firm cyber posture at renewal.

  1. Business Email Compromise Warning Notice (updated 2022). Requires firms to have controls against BEC and to notify SRA of material incidents.
  2. Cyber Insurance Warning Notice. SRA does not mandate cyber cover but references it as an important protection.
  3. Money laundering and fraud alerts. Ongoing SRA guidance on evolving fraud patterns.

PII insurers ask specifically at renewal about SRA cyber compliance status. Firms with documented controls, MFA, staff training and incident response protocols secure better PII terms.

Cover-limit sizing for UK solicitors' firms

  1. Small firm (2-10 fee-earners) — typically £500k-£2m cover. Baseline covers most conveyancing fraud + basic incident response.
  2. Mid-market firm (10-50 fee-earners) — £2m-£5m cover. Includes third-party liability at scale.
  3. Large firm (50+ fee-earners) — £5m-£25m cover. Aggregation risk across multiple concurrent matters requires higher limits.
  4. Legal 500-tier and larger — layered programmes at £25m+. Multiple insurers on the risk.
Cover-limit sizing rule of thumb for solicitors. The plausible worst-case is: single-transaction conveyancing fraud loss (£250k-£1m for residential, higher for commercial) + incident response (£100k-£500k) + third-party claims (up to firm's aggregate exposure). Size cover to cover the combined worst case with headroom.

What Apex looks for when placing solicitors' cyber

  1. Firm's SRA authorisation number and Practising Certificate holders.
  2. Turnover breakdown by practice area (conveyancing volume drives cyber rating).
  3. Existing controls: MFA, endpoint protection, staff training, incident response plan.
  4. Prior cyber events (attempts and actual incidents).
  5. Existing SRA MTC PII in place with cover-limit and structure.
  6. Any recent SRA correspondence about cyber posture.
  7. Consumer Duty documentation where relevant.

Frequently asked

Do UK solicitors need cyber insurance?
Not statutorily required by the SRA. Practically essential given conveyancing fraud exposure, SRA warning notices, and business-critical data holdings. Only 28% of UK law firms currently hold cover per Law Society research.
How much does cyber insurance for a small law firm cost?
For a 2-10 fee-earner firm with £500k-£2m cover: typically low-to-mid four figures annually. Higher for material conveyancing volume or prior incidents.
Does SRA MTC PII cover cyber breaches?
No. SRA MTC covers professional-liability civil claims. Cyber breaches, incident-response costs and cyber-crime fraud are separate cover. Both may engage on the same incident but they address different aspects.
What is Friday-afternoon fraud?
Fraudster intercepts communication about property completion funds, changes bank details, and diverts the transfer. Named for the typical timing of conveyancing completions.
Does cyber cover ransomware?
Standard cyber wording covers ransomware including ransom-payment decision support, incident response, and business interruption. Some jurisdictions restrict ransom payments — discuss with broker.
Does my firm need cyber if we outsource IT?
Yes. Outsourcing IT doesn't transfer legal responsibility for client-data protection or SRA compliance. Cyber cover remains essential.
How is cyber-for-solicitors rating changing in 2026?
The UK cyber market has stabilised after the 2021-2022 hardening. Rates for firms with good controls have softened; firms with prior incidents or weak controls remain hardened. Documented control maturity is the main factor in renewal pricing.
What if my firm has already had a cyber incident?
Get specialist broker involvement. Prior-incident placements require careful presentation, evidence of remediation, and often placement into specialist Lloyd's markets.
Can I bundle cyber with my SRA MTC PII?
Some markets offer combined SRA MTC + cyber packages. Trade-off: administrative simplicity vs cover flexibility. Standalone cyber often gives broader cover than bundled options.
What does Apex recommend for a mid-market solicitors' firm?
Baseline: £2m-£5m cyber standalone with strong incident-response provisions. Combined with SRA MTC PII at whatever the firm's exposure warrants. Documented controls, MFA and staff training as the price of entry to competitive terms.

Related reading

Speak to a broker

Get the right commercial cover, placed by a named broker

Tell us about your business and we’ll place it on the specialist market — or leave your number and a named broker calls you back, usually the same working day.

Get a commercial quote → or call 0117 325 0027

Get a quote →