Your PII proposal form is now a cyber questionnaire
Most firms have just been through renewal. The cyber section has grown every year, the answers are warranties rather than opinions, and a good number of firms are answering yes to things that are not quite true.
If your firm renews its professional indemnity cover on 1 October, as the large majority of firms in England and Wales still do, you have just filled in a proposal form that looked rather different from the one you filled in five years ago. The cyber section has grown from a line to a page, the questions have become specific, and they are no longer asking whether you take security seriously. They are asking whether a named control is switched on.
This matters more than it looks, for a reason that has nothing to do with security. An answer on a proposal form is a statement to an insurer that they rely on in deciding whether to write the risk and at what price. If the answer is wrong, you have a coverage problem on top of whatever has just happened to you, and the moment you find out is the worst possible moment.
What they are asking now
The cyber questions that recur across proposal forms are narrow and factual:
- Is multi-factor authentication enforced on all remote access and all email accounts, with no exceptions?
- Are backups held offline or immutable, and have they been tested by restoring?
- Do you operate a verified callback procedure before changing any bank details, and is it documented?
- Are you running any unsupported operating systems or applications?
- Do you hold Cyber Essentials or Cyber Essentials Plus?
- Has the firm trained staff on phishing in the last twelve months, and do you test it?
- Have you had an incident, claim or notifiable breach in the last five years?
Three of those are where firms come unstuck.
The exception you forgot you made
"Multi-factor authentication on all accounts, no exceptions" is the question. The honest answer in a good number of firms is "yes, except two partners and the shared reception mailbox", because someone found it irritating and an exemption was granted quietly eighteen months ago and never reviewed.
That is not a technicality. The exempted accounts are almost always the ones with the most access and the most authority, which is precisely why they were exempted and precisely why an attacker wants them. Ticking yes on the form while that exception exists is the single most common inaccurate answer we see in this sector.
It takes ten minutes to check properly. Pull the list of accounts without MFA enforced from your tenancy rather than asking whether anybody has been excluded, because the answer to the second question is usually "I do not think so".
"Tested" backups
The question asks whether backups have been tested. Most firms read this as whether backups are running. Those are different claims, and the distance between them is where ransomware recoveries fail.
A backup that has never been restored is a hypothesis. Restore something, ideally a matter file and a database, confirm it opens, and write down the date you did it. That record is also what your insurer will ask for after an incident.
Unsupported software
Firms answer no to this question and mean it, then discover a practice management server on an operating system that went out of support, or a document bundling tool nobody has updated since the person who bought it left. It is worth checking before you answer rather than after, because this is a question insurers will go back to if a claim arises.
Why Cyber Essentials turns up on the form
Insurers did not add that question because they admire certification. They added it because it is a single document that answers five of their other questions at once, and because an independently assessed answer is worth more to an underwriter than a self-declaration on a form.
The practical effect for a firm is that it shortens the proposal, it gives you something to attach rather than assert, and in a hardening market it is one of the few things within your control that changes how the risk reads. It also happens to be the same document your corporate clients and panel managers are increasingly asking for, so it is not work done solely for the insurer.
We are an appointed IASME Certification Body, which means we assess and issue directly. More on what that involves on the Cyber Essentials for law firms page.
What to do before the next renewal
- Pull the real MFA exception list from your system today, and close it. Partners included.
- Restore something from backup and record the date. That record is the answer to the question.
- Inventory what is unsupported, particularly servers and anything attached to practice management.
- Document the callback procedure for bank detail changes, and check it survives a Friday completion.
- Certify, so next year's form is an attachment rather than an essay.
- Test what is exposed, under penetration testing, if your clients or panels are asking for independent assurance.
Eleven months is a long time to leave this, and the work above is a week at most. The firms that find renewal painless are the ones that answered honestly last year and then fixed what the honest answer revealed.
We have written separately on the regulator's side of this in 2,300 breach reports to the SRA, which covers the enforcement pattern and the reporting obligations that sit alongside the insurance one.
Common questions
Does an inaccurate answer on a PII proposal form affect cover?
Do we need Cyber Essentials for PII renewal?
We renewed on 1 October. Is it too late to do anything?
Is Cyber Essentials Plus worth it over Cyber Essentials?
Our IT provider completes the technical sections for us.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.