Extract from Michael C. Maschke, Sharon D. Nelson, and John W. Simek‘s article, “Cyber Insurance Is Not A Cybersecurity Strategy.”
Ed. note: This is the latest in the article series, Cybersecurity: Tips From the Trenches, by our friends at Sensei Enterprises, a boutique provider of IT, cybersecurity, and digital forensics services.
Cyber insurance has officially gone mainstream.
According to the 2026 Travelers Risk Index, 70% of surveyed businesses now report purchasing cyber insurance, up seven percentage points from last year and the highest level since the survey began focusing on cyber risk in 2018. Among large businesses, adoption has reached 82%, while even half of small businesses now report having coverage.
That’s encouraging news. Law firms should carry cyber insurance. The potential costs of ransomware, data breaches, business interruption, forensic investigations, regulatory actions, and litigation can quickly become enormous. But there’s a danger in mistaking cyber insurance for preparedness for a cyberattack.
Insurance Isn’t a Security Control
No law firm would buy fire insurance and then conclude it no longer needs smoke or fire-detection devices. Cyber insurance should be viewed the same way.