Will Cyber Insurance Cover a Law Firm Wire Fraud Loss?

Law firms are prime targets for wire fraud. 

Attorneys regularly handle sensitive financial transactions involving trust accounts, retainers, settlements, real estate closings, vendor payments, and client funds. That makes law firms attractive to cyber criminals who know that one convincing email can lead to a very expensive mistake.

A typical wire fraud scenario:

It starts with an email that looks legitimate. It may appear to come from a client, a title company, opposing counsel, a vendor, or even someone inside the firm. The email may include a real matter name, familiar language, and wiring instructions that seem reasonable. In some cases, the fraudster has gained access to an actual email account. In other cases, the email address is simply spoofed or altered slightly.

The firm wires the money. Then, after the transfer is complete, someone realizes the instructions were fraudulent.

At that point, the firm has two immediate concerns. 

First, can the money be recovered? 

Second, will insurance cover the loss?

Many attorneys assume that if their firm has cyber liability insurance, a wire fraud loss will automatically be covered. Others assume the loss will fall under crime coverage or lawyers professional liability insurance. Unfortunately, the coverage answer is not always that simple.

Wire fraud can fall into a complicated area between different types of policies. A cyber policy may include coverage for social engineering fraud or funds transfer fraud, but that coverage may be limited by a sublimit. The policy may also include conditions that must be satisfied before coverage applies. For example, the firm may be required to follow specific verification procedures before transferring funds.

A crime policy may also provide coverage in certain situations, but not every fraud scenario fits neatly into the policy language. Lawyers professional liability insurance, meanwhile, is generally designed to respond to professional negligence claims. It should not be treated as a catch-all policy for every financial loss connected to a cyber event.

That is why law firms should not assume they are covered just because they have “cyber insurance” listed on a policy. The details matter.

Firms should review whether their policies address social engineering fraud, fraudulent instruction schemes, and funds transfer fraud. They should also pay close attention to sublimits, exclusions, deductibles, and any required internal controls. A policy may provide a $1 million cyber limit, but the amount available for social engineering fraud could be much lower.

Just as important, the firm’s internal procedures should match the risk.

Email alone should never be enough to change wiring instructions or authorize a transfer. 

If new or revised instructions are received, the firm should verify them using a trusted phone number already on file – not the phone number included in the suspicious email. Any last-minute change, unusual urgency, or request to bypass normal procedures should be treated as a red flag.

Wire fraud prevention is not just an IT issue. It is a law firm management issue, a risk management issue, and an insurance issue.

Before a loss occurs, attorneys should speak with their insurance advisor and review their coverage carefully. The goal is to understand what coverage may apply, what limits are available, and what procedures the firm must follow.

The worst time to discover a gap in coverage is after the money is gone. If your law firm handles wire transfers or client funds, make sure you know how your insurance would respond before a fraud attempt turns into a claim.

What Happens to Prior Acts Coverage When an Attorney Leaves a Law Firm?

Are You Leaving Your Law Firm? 

What are you doing about your Prior Acts Coverage?

When an attorney leaves one firm to join another, merges a solo practice into a larger firm, or shuts down an existing office, there are usually many practical issues to address. Client files have to be transferred. Engagement letters may need to be updated. Conflicts need to be checked. Staff, leases, technology, and client communications all have to be handled carefully.

But one issue that can easily be overlooked is lawyers professional liability coverage — specifically, what happens to your prior acts.

Prior acts are the legal services performed before the attorney joins the new firm or before the old policy ends. Even if the attorney has no known claims, no pending disputes, and no reason to believe anything went wrong, that does not mean the exposure disappears. 

Unfortunately, a malpractice claim can arise months or even years after the legal work was completed…That is why attorneys need to know exactly which policy will respond if a claim is made later.

A common mistake is assuming that the new firm’s malpractice policy will automatically cover the attorney’s past work. 

In many cases, it will not. 

The new firm may be willing to cover the attorney for work performed after joining the firm, but that does not necessarily mean it wants to accept responsibility for past files.

From the new firm’s perspective, that is understandable. The firm did not supervise the attorney’s prior matters. It did not collect the fees. It did not manage the client relationships. It had no control over how those services were performed. As a result, the firm may not want its insurance limits exposed to a claim involving work done before the attorney ever joined the firm.

Even if the new firm is open to the idea, its insurance carrier may not be. The carrier may agree to add the attorney going forward, but refuse to include prior acts coverage. That leaves the attorney with a critical question: 

How will claims arising from past work be covered?

In many situations, the answer is tail coverage, also known as an extended reporting period. 

Tail coverage allows an attorney to report future claims based on work performed before the policy ended. It does not provide coverage for new legal work. Instead, it protects against claims tied to past services.

The cost of tail coverage can surprise attorneys. It is typically based on the last premium paid. 

For example, if the attorney’s annual premium was $3,000, an unlimited tail might cost somewhere around $9,000. In many cases, tail coverage can be approximately 255% to 300% of the current premium.

[show this as an image]

That cost should be discussed before the move happens, not after. If a solo attorney is closing a practice to join another firm, or if an attorney is leaving a multi-person firm, the parties should address prior acts coverage directly.

Key questions to discuss include:

  • Who is responsible for the prior acts exposure?
  • Will the new firm’s policy pick it up?
  • Will the new firm’s carrier allow it?
  • Does the attorney need to purchase tail coverage?
  • Who will pay for that tail?

In some cases, the attorney may be able to negotiate the issue. The new firm might agree to pay for the tail instead of adding the prior acts to its own policy. The parties might split the cost. Or the cost might become part of the overall merger, acquisition, or compensation discussion.

The important point is that this should never be assumed.

Before leaving a firm, closing a solo office, or joining a new practice, attorneys should speak with their lawyers professional liability insurance advisor. A careful review can help prevent a dangerous gap in coverage.

Your prior work does not disappear just because you move to a new firm. Make sure your prior acts are protected before the transition is complete.

Vacation Mistakes That Can Lead to Malpractice Claims

Key Takeaway

Did you know that the summer vacation season can create unexpected malpractice risks for law firms when deadlines, file coverage responsibilities, and client communication are not handled properly before attorneys and staff take time away from the office? 

Many malpractice claims begin with small administrative breakdowns—not major legal mistakes—which is why planning ahead during vacation season is so important.

Why Summer Can Increase Risk for Law Firms

Most attorneys look forward to summer vacations and holiday weekends. After all, everyone needs time away from work occasionally.

But for law firms, vacation season can also create conditions where preventable mistakes become more likely.

Reduced staffing, attorneys being out of the office, delayed communication, and shifting responsibilities can all increase the risk of something important slipping through the cracks.

In many malpractice situations, the issue is not that someone misunderstood the law. Instead, the problem often involves:

  • Missed deadlines
  • Calendar oversights
  • Unreturned client communications
  • Poor internal handoffs
  • Lack of file coverage
  • Miscommunication between attorneys and staff

These types of administrative issues can become more common during busy summer months when schedules are less structured and firms may be operating with fewer people in the office.

Out-of-Office Messages Do Not Stop Deadlines

One of the biggest risks during vacation season is assuming that an out-of-office email or reduced summer schedule somehow slows down legal obligations.

Unfortunately, deadlines continue regardless of whether someone is on vacation.

Court filing deadlines, statutes of limitation, discovery responses, transactional deadlines, and client obligations do not pause simply because key staff members are unavailable.

If a file is not being actively monitored while someone is away, the risk of missing something important increases significantly.

Many malpractice claims begin with something relatively small:

  • a missed filing deadline,
  • a document that was never reviewed,
  • or an email that nobody realized required immediate attention.

Often, the issue could have been prevented with better planning before the attorney or staff member left the office.

Communication Breakdowns Can Create Problems Quickly

Vacation season can also create communication challenges inside the firm and with clients.

For example, clients may become frustrated if:

  • they are unsure who is handling their matter,
  • emails are not returned promptly,
  • or urgent concerns are not addressed while their primary attorney is away.

Even when no actual legal error has occurred, poor communication can damage trust and increase the likelihood of complaints.

Internally, communication problems can arise when responsibilities are not clearly assigned before someone leaves for vacation.

It is not uncommon for multiple people within a firm to assume that “someone else” is monitoring a file or handling a deadline. Unfortunately, that assumption can create significant exposure if no one is actually responsible for the matter.

Clear internal communication and documented coverage plans can go a long way toward reducing these risks.

Summer Staffing Changes Can Increase Exposure

Many firms also bring in interns, law clerks, or temporary staff during the summer months.

While additional support can be helpful, newer employees may not fully understand:

  • office procedures,
  • confidentiality expectations,
  • calendaring systems,
  • or the importance of certain deadlines and communications.

This creates another layer of risk that firms should consider during vacation season.

Even experienced employees may be covering unfamiliar responsibilities while coworkers are away, increasing the possibility of administrative mistakes.

Training, supervision, and clearly defined procedures become especially important during periods when staffing structures change.

Why Small Administrative Problems Matter

One of the biggest misconceptions about malpractice claims is that they usually involve major legal errors or courtroom mistakes.

In reality, many claims begin with smaller administrative breakdowns that gradually escalate into larger issues.

Examples may include:

  • failing to properly calendar a deadline,
  • missing a client communication,
  • failing to document advice or instructions,
  • or not clearly assigning responsibility for a file during an absence.

These situations often become more likely during holidays, vacations, or periods where firms are operating with reduced staffing levels.

The good news is that many of these risks are preventable.

Risk Management Tips Before Taking Vacation As An Attorney

Vacation itself is not the problem. 

The issue is usually the lack of preparation before someone leaves the office. Before attorneys or staff take time away, firms should consider reviewing several important areas.

Review All Upcoming Deadlines

Take time to carefully review calendars, court dates, filing deadlines, and active matters before leaving.

This helps ensure that important dates are not overlooked while someone is unavailable.

Clearly Assign File Responsibility

Every active matter should have a clearly designated point of contact while the primary attorney or staff member is away.

Avoid situations where responsibility is assumed rather than specifically assigned.

Communicate Internally

Make sure attorneys, paralegals, assistants, and administrative staff understand:

  • who is covering which matters,
  • who should receive urgent communications,
  • and how emergencies should be handled.

Set Clear Client Expectations

Clients should know:

  • when their attorney will be unavailable,
  • who they should contact if an urgent issue arises,
  • and what type of response time they can expect.

Good communication helps reduce frustration and confusion.

Review Cybersecurity Risks

Vacation periods can also increase cybersecurity exposure because employees may be working remotely, using mobile devices, or moving quickly through emails before leaving town.

Law firms should remind employees to remain cautious about:

  • phishing emails,
  • wire transfer requests,
  • password security,
  • and suspicious links or attachments.

Strong Internal Systems Help Prevent Avoidable Claims

No law firm can eliminate every possible risk.

However, firms with strong procedures, communication systems, and file management practices are generally in a much better position to avoid preventable malpractice problems.

Summer vacation season is a good reminder that many malpractice claims do not begin with dramatic legal mistakes. They often begin with small administrative issues that were never addressed early.

Good planning, clear communication, and proper file coverage can significantly reduce the likelihood of problems developing while attorneys and staff are away from the office.

Start Planning Now And Enjoy Your Vacation

Taking vacation and spending time away from work is important for attorneys and staff alike. But before leaving the office, it is worth taking a few extra steps to make sure files, deadlines, and client communication are properly managed.

In many cases, preventing a malpractice claim starts long before a problem develops.

It starts with preparation.

Claim vs. Potential Claim: When Should Attorneys Report to Their Malpractice Carrier?

One of the most common questions I get from attorneys is this:

“What’s the difference between a claim and a potential claim—and when do I actually need to report it?”

It’s a great question, and the answer can have a major impact on whether your malpractice coverage protects you when you need it most.

What Is a “Claim”?

A claim is typically straightforward. It involves a clear allegation of wrongdoing or a demand for money. This could be a lawsuit, a formal demand letter, or any situation where a client (or former client) is asserting that an error caused them harm.

At that point, most attorneys know they need to notify their insurance carrier.

What Is a “Potential Claim”?

A potential claim is less obvious—but just as important.

This is when you become aware of a situation that could lead to a claim, even if no one has formally complained yet. Common examples include:

  • Missing a filing deadline
  • Discovering a mistake in a document or case strategy
  • Receiving communication from a client that suggests dissatisfaction (including online reviews)
  • Realizing something may not have been handled correctly

In these situations, nothing has escalated yet—but there’s a reasonable chance it could.

Why Timing Matters When It Comes To Legal Malpractice Claims

Most legal malpractice policies are claims-made policies, which means coverage is triggered based on when a claim is reported—not just when the incident occurred.

That’s why the distinction between a claim and a potential claim is so important.

Reporting early isn’t just a requirement of the policy—it can also work in your favor. 

Getting your carrier involved sooner can help reduce defense costs, improve the chances of resolving the issue efficiently, and give you more options if the situation develops into a formal claim.

In fact, many malpractice claims don’t begin with a lawsuit—they start as smaller issues that weren’t addressed early.

The Risk of Waiting To Report A Claim

It’s not uncommon for attorneys to hesitate before reporting a potential issue. There’s often concern about how it might impact premiums or whether it’s “too early” to involve the carrier.

But waiting can create serious problems.

If you’re aware of a potential issue and choose not to report it—and that issue later turns into a claim—there’s a risk your carrier may deny coverage altogether.

A Simple Rule to Follow

If there’s any doubt, it’s usually better to have the conversation early.

You don’t need to have all the answers, and reporting something doesn’t mean it will automatically turn into a claim. It simply puts you in a better position if it does.

If you’re unsure about your current policy or what should be reported, it’s worth taking a few minutes to review your coverage and get clarity before an issue arises.

If you have questions about your current coverage or want a second opinion, feel free to reach out 412.563.2106

Choosing the Right Clients: A Risk Law Firms Often Overlook

One of the most important risk decisions a law firm makes doesn’t happen in the middle of a case. 

It happens at the very beginning — when deciding whether to take on a client.

Over the years, I’ve seen situations where problems didn’t come from how the work was done, but from taking on work that wasn’t the right fit to begin with.

Every Firm Has a Sweet Spot

Every law firm has a “sweet spot” — the types of cases it handles well, the types of clients it works best with, and the structure it has in place to support that work.

When a case falls outside of that sweet spot, risk tends to increase, which can lead to malpractice claims.

Sometimes it’s a matter of complexity. 

A sole practitioner may take on a matter that realistically requires a larger team — multiple paralegals, more time, and additional support.

The opportunity may look attractive from a revenue standpoint. But if the firm doesn’t have the capacity to fully support the work, the situation can become difficult to manage.

When Revenue and Risk Don’t Align

I’ve seen cases where a matter generates significant revenue, but also creates exposure that far exceeds it.

What looks like a strong opportunity on the surface can carry risks that aren’t immediately obvious.

That’s why it’s important to evaluate not just the potential upside of a case, but whether the firm has the capability and resources to handle it properly.

The Client Fit Matters Too

In other situations, the issue isn’t the case — it’s the client.

Some clients require more communication, more oversight, or a different working style than others. Every firm operates a little differently, and not every client will be a good fit.

If your firm has a certain pace, structure, or approach to communication, it’s important that the client aligns with that.

Sometimes your instincts will tell you that something isn’t quite right. That doesn’t necessarily mean the client is difficult — it may simply mean they’re not the right fit for your firm.

Listen To Your Gut.

It’s Okay to Say No

Referring a case out or declining to take on a client is often a good decision — for both the firm and the client.

Making sure a client is in the right place, with the right resources and expertise, ultimately leads to better outcomes.

Start with the Right Decision For Your Firm

At the end of the day, the goal is to ensure that the work you take on matches your firm’s capabilities — the right experience, the right resources, and the right structure. 

When those things are aligned, you’re in a much better position to serve your clients effectively while managing risk.

And sometimes, the best decision you can make is the one you make before the work ever begins.

Vacation as a Risk Management Tool

No, this isn’t a quick break from my desk—I’m actually taking a few days away from the office on a proper vacation. As I sit here on the porch, soaking in the peaceful view of the water and feeling more relaxed than I have in a long time, a thought struck me:

This might be one of the best risk management tools I can recommend—take a break.

That’s right. Step away from the desk. Let your brain unplug. Play a round of golf, cast a line into the water, take a boat ride, dive into a good book, or simply sit outside and do nothing. You don’t need a plane ticket to a faraway beach or a mountain retreat—just find a way to get out of the office and into a state of calm.

Why? Because time away helps you rejuvenate.

And when you’re back in the office, something magical happens:
You think more clearly.
You work more creatively.
You produce a better work product for your clients.

And that’s where risk management comes in.

Better Work = Lower Risk

A refreshed mind leads to fewer mistakes. That means fewer legal malpractice claims, better relationships with your clients, and even a more positive atmosphere in your workplace. It also means you’re more likely to be offered favorable malpractice insurance rates and terms—because insurers notice when your practice runs smoothly and claims stay low.

So, yes—a short vacation isn’t just good for your soul, it’s good for your business.

It may be the simplest risk management strategy, but it just might be the most powerful.

Coach Said It Best

There’s a quote from one of my favorite TV shows, Friday Night Lights, that always sticks with me:
“Clear eyes, full heart, can’t lose.”

So don’t lose.

Take some time off this year. Step away from the grind. Let yourself breathe, reset, and come back sharper than ever.

Reporting A Claim Is Important

https://youtu.be/888biQm756k

In law, as in life, things can change quickly—and not always for the better. When it comes to legal malpractice insurance, a sudden shift usually means one thing: a claim has been filed against you.

If that ever happens, there are several important steps you’ll need to take. But one step matters more than all the others:

Report the claim or potential claim immediately.

This cannot be overstated. As soon as you become aware of an issue, you should contact your carrier—whether by phone, email, mail, or fax. However you choose to report it, just make sure you do.

At INF, we encourage clients to include us on all claim-related correspondence. This allows us to follow up directly and ensure proper documentation is in place from the beginning.

You might think reporting a claim is a no-brainer—but too many insureds hesitate or delay. Why?

  • Denial: Hoping the issue will disappear
  • Discomfort: Avoiding the stress of reliving the situation
  • Delay: Believing there’s more time than there actually is

Unfortunately, these delays can lead to devastating consequences. When a claim is finally reported late, coverage can be denied—simply because of the timing. This is not a situation you want to be in.

So here’s the bottom line: 

If you suspect a malpractice claim is coming, report it immediately.

Think of it as giving yourself a free shot from a buried lie. It’s the first—and most critical—step in protecting yourself, your firm, and your future.

An Often Overlooked Risk Management Tip – Read Your Policy

male reading an insurance policy

I have an easy and surprisingly somewhat overlooked risk management tip for you. Read your policy. When was the last time you read yours?

I’m always a little bit surprised that when I speak to prospects and clients alike, how many of them tell me they never or very rarely ever read their policy. Look, I know that we are all busy because our reading stack is very high. And after going through the application and quoting, no one is thinking about finishing the process by reading the policy.

Reading your policy is essential to the process and should supplement any risk management technique you utilize in your offices. The policy tells you who’s insured, what’s insured, what you’re supposed to do when and if you do get sued, your coverage limits, your deductible, and how much it actually costs. These are just to name a few.

The policy is also going to tell you what’s not covered, referred to as exclusions in the policy. And perhaps this is even more important than knowing what is covered.

So, don’t ignore my comments and do nothing. Take a moment and read it. You don’t need to become an expert in legal malpractice insurance. Just an informed consumer. A little knowledge in this matter will go a long way in your risk management efforts to avoid legal malpractice.

Why Do You Need a Dual Calendaring System?

The importance of dual calendaring.

According to the most recent ABA studies, malpractice claims stemming from calendaring errors continue to be a common mistake made by law firms. One of the ways to reduce calendaring errors is to make sure that your firm or office has a dual calendaring system in place.

Dual calendars can include calendars on your computer, laptop, desktop, other electronic devices, paper calendars, wall calendars, desk calendars, diaries, phones, there’s a slew of them. My point being is that there are actually several ways to implement a dual calendar system, and you should choose one that works best for you and your firm.

The risk management benefit of having a dual program in place is the backup benefit. If a calendar entry is missed on one system, it should be picked up by the other system. Hence the chance of a missed deadline by the office is reduced with a dual calendar system. consistency with the entering of the information, weekly cross checking of the system and having two people maintaining the system are key elements to a successful program.

So if you want to reduce your risk of a legal malpractice claim, and lower your malpractice insurance premiums, make sure you have a dual calendaring system in place. 

‘Tis the Season for Cyber Security

02J68283

As the holiday season draws near, so do cyber criminals.  With more and more people shopping online, the number of potential cyber breach victims increases every day.  In fact, Adobe is predicting that Black Friday 2017 will see the highest sales ever on record.

So, without completely withdrawing from the online world, how can you protect yourself and your business online?  Try applying the following tips:

Make sure that you are on the website that you think that you are on

One of the most common ways to scam your username and password or credit card information from you is to send you to a fake website that looks very similar to the website that you are expecting.  An example of this is paypal.com versus paypa1.com.  Note that the only difference is the “L” at the end of the first one and there is a “1” at the end of the second one.

To get you to these fake sites, scammers will send you an email that directs you with a bogus link.  One way to see where the link is taking you is to hover over it with your mouse.  The website address will popup.  If the link is bad, block the email sender and move the email to your “SPAM” folder to prevent receiving emails from that person in the future.

One way to confirm that you are visiting the website that you want is for you to type the website into the address bar.  This way, you know that you are not following any false links and you arrive at the correct website.

Don’t fall for holiday phishing schemes

On Black Friday 2017, retailers sent over 3 BILLION emails to consumers, advertising their best deals and sales.  This day was also filled with scammers sending out tons of emails, pretending to be a retailer.  They were taking advantage of the fact that consumers were expecting to receive these emails and may not have questioned them as much.  This is known as phishing and its main purpose is to collect as much personal information about you as possible.

Commonly, phishing emails will try to direct you to a login page or a payment page.  They want to get your information as quickly as possible without you questioning the validity of the site.

A few ways to identify phishing schemes:

  • The “From” field display name is a store or bank.  However, when you click into it to reveal the full email address, it’s an address not related to that entity.
  • The email has graphics that look “off” or “fuzzy”.  Sometimes, to make the fake email look more legitimate, a scammer will copy the graphics from a store or bank from their website, which are not a high resolution.  As a result, when they are placed into an email, they look wrong.
  • When you hover over the link that the email wants you to visit, it is not pointing to the website that it claims to be sending you to.
  • Check for spelling mistakes and bad grammar.  Legitimate companies are sticklers when it comes to spelling and grammar.  If the email sounds poorly written, there is a good chance that the email is not legitimate

Check for an SSL certificate upon checkout

When you check out online, you want to make sure that there is an SSL certificate in the address bar.  You should see that the web address starts with “https://”.  Normally, there will be a lock image next to the address or the whole bar will turn green.

An SSL is important any time that you are entering financial information or passwords.  This encrypts that information and keeps it private from anyone that may be watching your transaction.

Create a strong password (and don’t use the same one) for your customer (and business) accounts

Your customer accounts for stores and banks should be protected by a strong password.  The company can have the best security measures and encryption in place, but if your account has an easily guessed password, none of that matters.

A strong password is 12 characters or more and contains at least one of each of the following:

  • Uppercase letter
  • Lowercase letter
  • Number
  • Symbol

You also do not want to use the same password for all of your accounts.  This is because if one of the accounts is hacked, the hacker now has the login information for all of your other accounts and they WILL check this immediately.

The average American has over 60 online accounts that they have to remember, so look into a good password manager to help you maintain the information.  Not only will the password manager help you remember all of your login information, but it will help you create secure passwords.

Some highly rated password managers include KeePass, Dashlane and LastPass.  Check out this article from PC mag for more information on the top password managers of 2017: https://www.pcmag.com/article2/0,2817,2407168,00.asp

BONUS: Turn on two factor authentication where possible

Two factor authentication (TFA) is becoming more prevalent as hackers become more savvy and have access to greater computing power.  TFA uses not only your username/password, but one other means of verification before you have access to your account.

This is now commonly available with banking and credit card websites.  When you turn this on, after you sign in with your username and password, they will ask if you want to receive a text or email for secondary verification of the account.  Once you make your selection, they will send a one-time only code to the phone number or email associated with that account, which you then have to enter to gain access.

This is helpful because even if someone had your password, they would still need access to your email or phone to be able to access your account.  If TFA is available to you, INF recommends turning it on to better protect yourself.

Have a safe and secure holiday season from INF!