Cyber insurance for solicitors' firms in the UK
Only 28% of UK law firms hold cyber insurance despite conveyancing money transfers being one of the most-targeted fraud vectors. The SRA has escalated its cyber warning notices year on year. This page sets out how cyber cover works for solicitors' firms in 2026, how it interacts with your SRA MTC PII, and what a specialist broker looks for.
The four cyber threats facing UK solicitors' firms right now
- Conveyancing money-transfer fraud (Friday-afternoon fraud). Fraudster intercepts client-to-firm or firm-to-client bank-detail communication. Client transfers deposit or completion funds to fraud account. The single largest UK legal-sector cyber loss pattern.
- Ransomware. Firm files, matter records, precedent library, calendars all encrypted. Ransom demand typically 6-7 figures. Even without paying, business-interruption cost is material.
- Business email compromise (BEC). Fraudster accesses firm email, impersonates partner, initiates fraudulent payment or extracts client data. Often the entry point for conveyancing fraud.
- Data-breach and confidentiality exposure. Client-sensitive matter data exposed. SRA notification, ICO reporting, professional-liability implications all follow.
How cyber insurance responds — the four cover components
- First-party incident response. Breach coach, forensic investigation, PR, legal counsel, notification costs to affected data subjects. Available typically within hours of first contact.
- Cyber-crime and social-engineering fraud. Direct financial-loss cover for fraudulent transfers and impersonation events. Sub-limits typically apply.
- Business interruption. Lost revenue from systems outage during and after an incident. Standard waiting period 8-24 hours.
- Third-party liability. Client claims arising from firm's data or systems breach. Often the largest single loss element for law firms.
The interaction with SRA MTC PI insurance
The SRA MTC responds to civil liability from the professional work. Cyber responds to the technical breach event and its incident-response costs. Where the two overlap, careful wording matters.
- Fraud loss to firm's client trust account. Cyber covers the fraud loss. SRA MTC covers the firm's liability to reimburse the client. Both engage.
- Client data breach leading to complaint under DISP. Cyber covers incident-response and any direct data-breach claims. SRA MTC covers professional-liability claim from the client for advisory-work implications.
- Business email compromise affecting a client matter. Cyber covers the breach and response. SRA MTC covers the resulting professional liability to the affected client.
- Ransomware affecting file access and deadline missing. Cyber covers ransom decision plus BI. SRA MTC covers any professional liability from missed deadlines.
What SRA warning notices say about your PII risk profile
The SRA has published multiple warning notices on cyber risk. Each affects how PII insurers view solicitors' firm cyber posture at renewal.
- Business Email Compromise Warning Notice (updated 2022). Requires firms to have controls against BEC and to notify SRA of material incidents.
- Cyber Insurance Warning Notice. SRA does not mandate cyber cover but references it as an important protection.
- Money laundering and fraud alerts. Ongoing SRA guidance on evolving fraud patterns.
PII insurers ask specifically at renewal about SRA cyber compliance status. Firms with documented controls, MFA, staff training and incident response protocols secure better PII terms.
Cover-limit sizing for UK solicitors' firms
- Small firm (2-10 fee-earners) — typically £500k-£2m cover. Baseline covers most conveyancing fraud + basic incident response.
- Mid-market firm (10-50 fee-earners) — £2m-£5m cover. Includes third-party liability at scale.
- Large firm (50+ fee-earners) — £5m-£25m cover. Aggregation risk across multiple concurrent matters requires higher limits.
- Legal 500-tier and larger — layered programmes at £25m+. Multiple insurers on the risk.
What Apex looks for when placing solicitors' cyber
- Firm's SRA authorisation number and Practising Certificate holders.
- Turnover breakdown by practice area (conveyancing volume drives cyber rating).
- Existing controls: MFA, endpoint protection, staff training, incident response plan.
- Prior cyber events (attempts and actual incidents).
- Existing SRA MTC PII in place with cover-limit and structure.
- Any recent SRA correspondence about cyber posture.
- Consumer Duty documentation where relevant.
Frequently asked
Do UK solicitors need cyber insurance?
How much does cyber insurance for a small law firm cost?
Does SRA MTC PII cover cyber breaches?
What is Friday-afternoon fraud?
Does cyber cover ransomware?
Does my firm need cyber if we outsource IT?
How is cyber-for-solicitors rating changing in 2026?
What if my firm has already had a cyber incident?
Can I bundle cyber with my SRA MTC PII?
What does Apex recommend for a mid-market solicitors' firm?
Related reading
- Cyber-PI overlap under SRA MTC — deep-dive
- Solicitors sector pillar
- Cyber insurance UK broker guide
- Solicitors 1 October PI renewal shock
Get the right commercial cover, placed by a named broker
Tell us about your business and we’ll place it on the specialist market — or leave your number and a named broker calls you back, usually the same working day.
