State Line Data Security

For law firms · Michiana

Get to yes before the renewal asks.

Cyber insurers have gotten strict. Renewals now hinge on multi-factor authentication everywhere, endpoint protection, tested backups, and a written incident response plan — and premiums jump when the answers are shaky. Corporate clients are starting to ask outside counsel the same questions.

We help solo and small firms get those answers to an honest yes before the application shows up, and keep them there.

What happens next

  1. A 20-minute callWhen does the policy renew, who are your largest clients, and what have they asked for? That tells us what actually matters.
  2. A readiness reviewWe work through the insurer's application with you, check the firm's systems and settings against it, and document what's true today.
  3. A closed-gap list and the paperworkWhat to fix before renewal, in order, plus the written incident response plan and policies the application asks whether you have.

Timed to your renewal. Two to three weeks, fixed fee.

What renewals and clients are asking for

The questions are the same from every carrier. The firms that answer them well pay less and get covered.

MFA on everything, not just email

Email, the practice management system, remote access, the document system. Carriers now decline or surcharge firms without it across the board.

Endpoint protection and tested backups

“Do you have backups” has become “when did you last restore from them, and are they offline from ransomware.”

A written incident response plan

The application asks whether one exists. After a breach, your carrier, your bar, and your clients all ask to see it.

Client security questionnaires

Insurance defense, business, and corporate clients are sending outside counsel the same questionnaires they send vendors. A firm without answers loses the work quietly.

Confidentiality obligations that assume competence with technology

The duty of confidentiality now includes a duty to understand the technology holding client information. “We didn't know” isn't the defense it used to be.

Where to start

Fixed fee, quoted before we begin. No hardware to buy, no software to license.

from$2,500

Cyber Insurance Readiness Review

  • Line-by-line work through your carrier's application, with honest answers documented
  • Review of MFA, endpoint protection, backups, remote access, and email security against what carriers require
  • Written incident response plan sized for a small firm
  • Core security policy set the application asks about
  • Prioritized fix list, timed to your renewal date
  • Answers you can reuse for client security questionnaires
  • Optional: AI use policy for client data and confidentiality

For firms that handle disability, personal injury, or elder law: you likely hold medical records and may be a HIPAA Business Associate. We'll tell you if that applies.

Then, if you want it handled

Ongoing plans from $1,500 a month: the annual reassessment, policy upkeep, staff training, vendor agreements, and someone to call when something looks wrong. For offices that would rather not think about this again until we bring it up.

No long contract. Month to month after the first term, and we'll tell you if you've outgrown needing us.

Questions we hear

Our IT company handles all this.

They handle the tools, and that matters. The insurance application, the written plan, the policies, and client questionnaires are a different kind of work — and the partners sign the application, not the IT company. We work alongside them.

We're a two-attorney firm. Is this overkill?

Small firms are the ones carriers are declining. The review is sized for a firm your size, and the fee is smaller than a single premium increase.

Do you need access to client files?

No. Systems, settings, and paperwork. We never open a matter, and our agreement says so.

A client sent us a security questionnaire. Can you help?

Yes — that's often the trigger. The readiness review produces most of the answers, and we'll help with the rest.

What about AI tools and confidentiality?

If anyone at the firm is using a chatbot with client information, you need a policy that says what's allowed. We can include one, and the conversation with staff is usually short and welcome.

Start with a conversation

Twenty minutes, no charge. Tell us when the policy renews and we'll tell you what to expect from the application and what to do first.

Or send a note

Please don't include patient or client details here. We'll ask for what we need on a call.