MFA Gaps: Is Your Law Firm’s Cyber Claim at Risk?


Key Takeaways

  • Failure to maintain Multi-Factor Authentication is repeatedly cited by insurers as one of the leading causes of denied cyber insurance claims across small and medium-sized organisations
  • Cyber insurance claim volume rose nearly 40% in 2024, and a large share of closed claims — nearly three in four, per NAIC data — closed without payment, most commonly linked to missing security controls or policy misrepresentations.
  • Small law firms with five to twenty fee earners are prime targets for business email compromise, ransomware, and funds transfer fraud
  • A denied cyber claim can trigger bar discipline, malpractice litigation, and even loss of attorney-client privilege – consequences explored in detail below
  • Closing MFA gaps is less about complexity and more about covering every login pathway consistently

A law firm cyber claim can be denied over something as simple as one missing MFA setting. Small firms often assume a single MFA toggle on their email system is enough to satisfy an insurer, but cyber insurance underwriters now disagree. The gap between what firms believe they have covered and what is actually protected has become one of the most costly blind spots in legal practice management. Getting this wrong can mean far more than a slower payout after a breach – it can mean no payout at all.

MFA Gaps Are a Leading Cause of Denied Claims

Failure to maintain Multi-Factor Authentication is one of the most frequently cited reasons cyber insurance claims get denied for small and medium-sized organisations. That pattern reframes MFA from a helpful login step into a make-or-break condition of coverage. Firms that believe they have “done MFA” because staff tap an approval notification each morning may still be missing entire categories of protected access.

Cyber insurance claim volume rose nearly 40% in 2024, and NAIC data shows nearly three in four closed claims that year ended without payment — a figure that includes claims below the deductible and withdrawals as well as outright denials, most commonly linked to missing security controls or policy misrepresentations. In plain terms, a business tells its insurer that certain protections exist, a breach happens, and the forensic review afterwards proves that protection was only partly true. As we’ve said before, business security is rarely about complexity – it comes down to covering the basics properly and consistently, everywhere they apply.

Nearly 75% of law firm cyber claim filings close without payment, often due to misrepresentation
Nearly 75% of cyber insurance claims close without payment, often due to security control misrepresentation.

This is exactly why a law firm cyber claim can fall apart so quickly. It matters enormously for firms that handle sensitive client records, financial transactions, and confidential case files as part of daily operations. A denied claim can leave a firm absorbing the entire cost of a ransomware attack, a fraudulent wire transfer, or a data breach out of its own pocket.

Why Insurers Rescind Policies Over MFA Gaps

Cyber insurance did not always work this way. In the earlier days of the market, policies were largely issued based on self-attested questionnaires with little technical verification behind them. Rising claim costs, driven heavily by ransomware payouts and business email compromise losses, pushed insurers to tighten how they assess risk and how strictly they enforce the promises made on an application.

Insurers now build security control warranties directly into policy wording. These clauses state that coverage depends on continuously maintaining every safeguard the applicant declared, not just having it in place on the day the form was signed. Even properly configured MFA can be bypassed through a separate technical route entirely — see 9 cyber risks law firms miss even when fully compliant for how session hijacking gets around it. When a firm files a claim, the insurer’s forensic team does not start with recovery. It starts by checking whether the breach happened through a pathway that was supposed to be protected by MFA but was not.

If that gap is found, the consequences for a law firm cyber claim go beyond a simple denial. Under the insurance laws of most jurisdictions, a material misrepresentation on an application allows the insurer to void the entire policy from its inception, a legal outcome known as rescission ab initio. This does not require proof of deliberate dishonesty. An honest mistake, a misunderstanding about which systems were covered, or an outdated assumption about a legacy application can be enough.

This exact scenario shows how a law firm cyber claim can unravel: it played out in Travelers Property Casualty Co. of America v. International Control Services Inc. The insured company had told Travelers it used MFA for administrative and privileged access, and Travelers issued a cyber policy on that basis. When ransomware struck weeks later, the forensic investigation found that MFA had only been applied to the perimeter firewall — the internal server attackers actually used to gain access had no MFA at all. Rather than litigate the issue, the insured agreed to a stipulated judgment voiding the policy from inception, leaving it fully liable for the fallout — an outcome insurers have since pointed to as a warning about how strictly MFA misrepresentations can be enforced.

A similar pattern unfolded in the City of Hamilton, Ontario, following a February 2024 ransomware attack that ultimately cost the city roughly $18.3 million to recover from. The city’s $5 million cyber insurance claim was denied because MFA had not been fully rolled out across every department, a reminder that passwords alone are not treated as adequate protection by any serious underwriter.

Small Law Firms in the Crosshairs

Small legal practices are exactly the kind of firm most likely to see a law firm cyber claim denied. Those with between five and twenty fee earners sit squarely in the path of these risks. They hold exactly the kind of information criminals want: client financial details, trust account transactions, confidential case strategy, and personal records. That combination makes small firms prime targets for business email compromise, ransomware, and funds transfer fraud.

This is exactly the pattern that puts a law firm cyber claim at risk: attacks typically start small, a stolen password used to open a door rather than a complex technical exploit, followed by a ransomware demand that most small practices could not absorb without insurance support.

Small firms rarely have a dedicated IT department scrutinising every login pathway. Our 7 ways law firms can prevent client data breaches covers the broader Zero Trust and access-control framework this fits into. Attorneys and support staff are focused on casework, deadlines, and client service, rather than auditing whether a legacy VPN appliance still accepts a password alone. That operational reality is precisely what makes MFA gaps so easy to overlook and so damaging when they surface during a claim investigation.

Where MFA Coverage Quietly Fails

This is where most gaps behind a denied law firm cyber claim actually hide: firms often believe MFA is fully in place because it appears on the surface, in the one system everyone logs into every day. Technical audits tell a different story, revealing unprotected pathways in systems that rarely get a second look.

Diagram showing five unauthenticated entry paths that bypass law firm MFA
MFA gaps often hide in email protocols, remote access, client portals, and privileged accounts.

Email and Cloud Accounts

Most small firms report enabling MFA on their primary email or cloud productivity platform, whether that is Microsoft 365 or Google Workspace. The trouble is that cloud environments often leave legacy authentication protocols, such as IMAP, POP3, and older Exchange ActiveSync connections, switched on by default. These older protocols do not support multi-factor challenges at all, so attackers can bypass MFA entirely using automated credential-stuffing tools.

Selective enforcement compounds the problem. Full-time attorneys might have MFA enabled while part-time staff, contract paralegals, temporary hires, or shared mailboxes are quietly left without it. Insurers assess this on an absolute basis: if even one active account can reach company email without MFA, an affirmative answer on the insurance application is technically false, regardless of how well everyone else is protected.

Remote Access Points

Remote access is consistently the most common entry point for ransomware targeting professional service firms. Small practices that still run on-premises servers for legacy billing or case management software sometimes expose Remote Desktop Protocol directly to the internet, protected by nothing more than a single password. That kind of connection can be cracked using widely available brute-force tools.

Older VPN appliances create a similar weakness. Many rely purely on network passwords with no secondary verification step, which underwriters now expect to see closed across every remote entry point without exception. See our 7-step guide to setting up SSO and MFA for small business for the rollout plan that retires exactly these gaps.

Admin and Client Portals

Administrative accounts and client-facing portals carry some of the highest stakes yet often receive the least attention. Emergency “break-glass” administrator accounts are sometimes deliberately left without MFA to avoid the risk of anyone being locked out, which makes them an obvious target for attackers seeking to encrypt an entire network. Automated service accounts tied to backups or case management integrations can carry administrative privileges while relying on nothing more than a static password.

Client portals and cloud practice management systems, including platforms firms use to exchange sensitive files and manage matters, frequently rely on user-set passwords with no centrally enforced MFA policy. Given that these systems hold client communications, work product, and financial details, an unprotected portal represents exactly the kind of gap forensic investigators look for after a breach.

Reading through the login pathways above is one thing — knowing whether your own firm has actually closed all of them is another. Most firms don’t discover a gap until a claim is denied. Use the quick self-audit below to check your own MFA coverage against the exact pathways insurers scrutinize during a breach investigation.

MFA Coverage Self-Audit
Check every login pathway your firm actually has. Be honest — insurers will be.
Email & Cloud Accounts
Remote Access Points
Admin & Client Portals
Check off each pathway your firm has covered.

If you left any boxes unchecked, you’ve just found a gap an insurer’s forensic team would find too — the difference is you get to close it before a breach, not after a denial. None of these fixes require a specialist on retainer; they require a methodical pass through every login pathway your firm actually uses, not just the ones you use every day.

The Fallout Beyond a Denied Claim

A denied law firm cyber claim rarely stays contained to a financial loss. It tends to trigger a chain of professional and legal consequences that reach well beyond the cost of the breach itself.

Bar Discipline and Ethics Violations

Legal ethics rules were written with technology firmly in mind. Model professional conduct standards require lawyers to stay informed about the risks and benefits of the technology they use, and separate confidentiality obligations require reasonable efforts to prevent unauthorised access to client information. Because MFA and encryption are now treated as baseline expectations, operating without full MFA coverage can fall short of that reasonable-efforts standard. Supervisory obligations extend this responsibility to outside IT vendors and managed service providers, meaning a firm cannot simply outsource the risk away.

The ABA’s Formal Opinions 483 and 477R, along with guidance from several state bars, call on lawyers to safeguard client data with reasonable technical measures — including enforcing MFA across all platforms, using encrypted email for sensitive matters, and maintaining a tested incident response plan. Falling short of these expectations after a breach can expose a firm to formal disciplinary scrutiny, separate entirely from any insurance dispute.

Loss of Attorney-Client Privilege

Courts weigh whether a firm took reasonable precautions to keep communications confidential when deciding if privilege still applies. If sensitive work product was transmitted over unencrypted channels or left accessible on a server without basic MFA, a court may conclude the firm did not take reasonable steps to protect that confidentiality. The result can be a formal waiver of attorney-client privilege during discovery, exposing case strategy and client communications that were meant to remain protected.

A denied law firm cyber claim doesn’t happen in isolation – layered on top of it is the malpractice exposure that follows a serious breach. Standard legal malpractice policies typically exclude network security incidents — a distinction confirmed by most legal malpractice carriers and bar-association guidance — which means a firm facing a client lawsuit over compromised data cannot necessarily lean on that coverage either. A denied cyber claim can leave a firm facing costs from several directions at once, with no policy stepping in to soften any of them.

Full MFA Coverage Is Non-Negotiable

The clearest lesson for anyone trying to protect a law firm cyber claim is that partial protection now carries the same practical risk as no protection at all, at least from an insurer’s point of view. Underwriters are no longer accommodating gradual rollouts, forgotten accounts, or promises to “get to that server eventually.” Coverage depends on MFA being enforced everywhere it was declared, consistently, rather than only in the systems that happen to be easiest to secure.

Protecting a law firm cyber claim does not require an in-house IT department or a specialist consultant on retainer. It requires a clear, methodical review of every login pathway, including the ones that rarely come up in daily conversation, such as shared mailboxes, legacy protocols, remote access tools, and administrative accounts. Firms that treat their cyber insurance application as a precise and binding statement, rather than a box-ticking exercise, put themselves in a far stronger position if a breach ever occurs.

Getting every access point covered, verified, and properly documented is the single most reliable way to keep a law firm cyber claim valid when it matters most. For a practical starting point, small firms can review multi-factor authentication basics to identify where their own coverage gaps might be hiding.

TechEdShield Writer
TechEdShield Writer