The carrier that renews your malpractice and cyber coverage is now underwriting your hardware refresh cycle, your backup logs, and the specific software your attorneys use to open a document. A signed application and a clean claims history used to close the deal five years ago; today that paperwork is the start of a much longer conversation.
Underwriters have watched too many six-figure ransomware payouts land on firms that answered yes on a questionnaire nobody verified. The review has moved off the paperwork and into the environment itself. Premiums, retentions, and sublimits move with what the carrier finds.
Follow a modern firm through the application-to-renewal cycle, and you can see where technology decisions become insurance decisions.
The Application Is No Longer the Whole Conversation
A firm used to fill in a two-page form and get a quote back in a week. The form is still there. Underwriters have stopped taking the answers at face value, and they now ask for evidence: a screenshot of the MFA enforcement policy, an EDR console showing coverage across every endpoint, a backup report from the last 30 days, an incident response plan with a date on it.
That shift is why a cyber insurance guide from Huntress is worth reading before the application, not after: carriers want verifiable proof of the controls, not a checkbox. A firm that overstates its posture and then files a claim can watch coverage disappear once the insurer compares the application to what was running.
The Underwriter Walks the Environment
Once the questionnaire is in, the technical review begins. External scans probe the perimeter. Internal questions get pointed. Three things move the premium more than anything else, and each one traces back to a decision a managing partner signed off on years ago without thinking of it as an insurance decision.
- Hardware age. Machines still running an operating system past end-of-support get flagged immediately. So do unpatched network appliances and servers old enough to have shipped without modern secure-boot features. The firm bought cheap; the underwriter prices the risk of a device that can no longer receive security updates. 60 Second Marketer listed the tech mistakes that cost firms money, and buying hardware on price alone sits at the top for a reason: the discount at purchase becomes a premium loading three renewals later.
- Backup testing. Having backups is table stakes. What carriers want to see is a tested restore from an immutable, off-network copy inside the last quarter. Firms that can produce a dated restore log get one number; firms that can only say backups are running get another.
- Software choices. The document management system, the practice management platform, the email tenant, and the remote access tool all show up in the review. Consumer file-sharing tools in an attorney workflow are a red flag. So is a remote access setup with no conditional access or session logging.
Renewal Is Where the Repricing Actually Happens
The first quote may look reasonable. The second one, twelve months later, is where firms feel the change. Carriers keep raising the floor on what they expect a firm to have deployed before they will hold the price.
An analysis from Todyl on cyber insurance requirements tracks the escalation year over year: backups first, then MFA, then EDR, then managed detection and response, with Zero Trust principles now working their way into how the largest brokers assess risk.
For a law firm, the practical effect is that last year's control set becomes next year's baseline. A firm that added MFA in 2023 and stopped there is quoted in 2026 as a firm with no EDR. The premium moves accordingly, and coverage terms tighten: higher retentions on ransomware, sublimits on social engineering, coinsurance on business interruption.
Change These Things Before the Next Renewal
The same moves that lower the premium also lower the odds of a claim, and none of them require a rebuild.
- Inventory the hardware. List every device, its age, and its support status. Retire anything the vendor no longer patches, and put the rest on a refresh schedule the underwriter can see.
- Test a restore. Choose an actual matter file, pull it back from backup into an isolated environment, and write down how long it took. Do it quarterly. Keep the logs.
- Name the software that touches client data. Reconsider tools that were not built for privileged work, and turn on the audit logs in the ones that are.
- Answer the application with evidence attached. Every yes should have a document behind it. Underwriters reward firms that make verification easy, and penalize the ones that make them guess.
The carrier is going to read the tech stack either way. The choice is whether it reads like a firm that priced technology as a cost, or one that treated it as the thing keeping the practice open.



