What IT Controls Professional Indemnity Insurers Now Expect from Law Firms

Monday April 6, 2026

Professional indemnity insurance is not simply a compliance requirement for legal practices.

It is a commercial safeguard.

When a claim arises — particularly following a data breach, email compromise or internal error — insurers will look beyond the incident itself. They will assess whether reasonable steps were in place to reduce foreseeable risk.

Over the past several years, expectations around technology controls have increased significantly.

The question is no longer whether a firm has “some security.”

It is whether safeguards are structured, consistent and defensible.

Why Insurers Are Asking More Questions

Legal practices routinely handle:

  • sensitive client information
  • financial transaction data
  • trust account access
  • confidential matter documentation

From an insurer’s perspective, the exposure is clear.

As ransomware, email compromise and credential theft incidents have increased, insurers have adjusted underwriting expectations accordingly.

Today, many policies — and renewal questionnaires — ask specifically about:

  • multi-factor authentication
  • endpoint monitoring
  • backup arrangements
  • email security
  • staff awareness training
  • incident response processes

These are no longer optional discussion points.

They are underwriting considerations.

The Shift From “Do You Have It?” to “Can You Demonstrate It?”

A common misunderstanding is that insurers only care whether controls exist.

Increasingly, the issue is evidentiary.

If a claim arises, insurers may ask questions such as:

  • was multi-factor authentication implemented consistently?
  • were security updates applied in a timely manner?
  • were backups tested regularly?
  • was access revoked promptly after staff departure?
  • were known risks reviewed and documented?

The presence of controls matters.

However, the ability to demonstrate that they were implemented, maintained and reviewed often matters more.

Core IT Controls Commonly Expected by Insurers

While policies vary, mid-sized legal practices are increasingly expected to maintain structured safeguards across several areas.

1. Identity & Access Controls

These typically include:

  • multi-factor authentication across email, cloud platforms and remote access
  • role-based access permissions for sensitive matters
  • formal onboarding and offboarding procedures
  • centralised identity management

Uncontrolled credential access remains one of the most common sources of claim exposure.

2. Endpoint Protection & Monitoring

Appropriate safeguards often include:

  • managed endpoint detection and response monitoring
  • automated patch management
  • secure device configuration standards
  • ongoing monitoring for suspicious behaviour

Basic antivirus alone is generally no longer considered sufficient within professional services environments.

3. Email & Payment Fraud Protection

Email compromise remains a significant source of financial and reputational exposure.

Controls often include:

  • advanced email filtering
  • impersonation detection
  • defined verification procedures for payment instruction changes
  • staff awareness training around payment redirection risk

Payment redirection incidents remain a major claim driver across professional services firms.

4. Backup & Recovery Validation

Backup arrangements should include:

  • structured, offsite or cloud-based backup
  • regular recovery testing
  • clearly defined restoration procedures
  • separation of backup access from general user accounts

Backup systems that cannot be restored quickly offer limited protection during an incident.

5. Documented Review & Oversight

Increasingly, insurers assess governance as well as individual technical controls.

This often involves demonstrating that:

  • security controls are reviewed periodically
  • responsibilities for oversight are clearly defined
  • improvements are prioritised based on risk
  • technology changes and reviews are documented

Ad hoc controls create uncertainty.

Structured oversight creates defensibility.

Where Many Firms Fall Short

Across many mid-sized legal firms, common gaps include:

  • multi-factor authentication enabled only for some users
  • backup systems implemented but never tested
  • security reviews conducted only after incidents
  • informal staff offboarding processes
  • no documented oversight cadence

These issues are rarely visible until an incident or insurance review highlights them.

What Leadership Should Be Able to Answer

From a commercial standpoint, leadership should have clarity on several questions:

  • which security controls are currently implemented
  • whether they align with insurer expectations
  • how those controls are maintained and reviewed
  • whether evidence of implementation exists
  • who is responsible for oversight

If those answers are uncertain, the issue is typically structural rather than technical.

Closing Perspective

Professional indemnity insurance does not eliminate risk.

It assumes reasonable safeguards are already in place.

For legal practices, IT controls are no longer purely operational decisions.

They are part of broader commercial risk management.

Layered security safeguards, structured oversight and documented review processes strengthen not only protection — but defensibility.

Your focus should remain on clients and matters.

Technology governance should quietly support that responsibility.

If you’re unsure how this applies to your environment, we’re happy to walk you through it.

If useful, you can see how we approach IT support and cybersecurity specifically for law firms here: → IT Services for Law Firms

Related Legal Technology Guidance

You may also find these related guides helpful:

About MSP Blueshift

MSP Blueshift provides structured IT services and cybersecurity for professional services organisations across Australia.

We work closely with law firms where confidentiality, document management, operational continuity and client trust require a deliberate approach to technology management.

Our focus is on ensuring technology environments remain secure, reliable and aligned with the operational needs of the firms we support.

Get in touch
MSP Blueshift office meeting