For law firms · Michiana
Get to yes before the renewal asks.
Cyber insurers have gotten strict. Renewals now hinge on multi-factor authentication everywhere, endpoint protection, tested backups, and a written incident response plan — and premiums jump when the answers are shaky. Corporate clients are starting to ask outside counsel the same questions.
We help solo and small firms get those answers to an honest yes before the application shows up, and keep them there.
What happens next
- A 20-minute callWhen does the policy renew, who are your largest clients, and what have they asked for? That tells us what actually matters.
- A readiness reviewWe work through the insurer's application with you, check the firm's systems and settings against it, and document what's true today.
- A closed-gap list and the paperworkWhat to fix before renewal, in order, plus the written incident response plan and policies the application asks whether you have.
Timed to your renewal. Two to three weeks, fixed fee.
What renewals and clients are asking for
The questions are the same from every carrier. The firms that answer them well pay less and get covered.
MFA on everything, not just email
Email, the practice management system, remote access, the document system. Carriers now decline or surcharge firms without it across the board.
Endpoint protection and tested backups
“Do you have backups” has become “when did you last restore from them, and are they offline from ransomware.”
A written incident response plan
The application asks whether one exists. After a breach, your carrier, your bar, and your clients all ask to see it.
Client security questionnaires
Insurance defense, business, and corporate clients are sending outside counsel the same questionnaires they send vendors. A firm without answers loses the work quietly.
Confidentiality obligations that assume competence with technology
The duty of confidentiality now includes a duty to understand the technology holding client information. “We didn't know” isn't the defense it used to be.
Where to start
Fixed fee, quoted before we begin. No hardware to buy, no software to license.
Cyber Insurance Readiness Review
- Line-by-line work through your carrier's application, with honest answers documented
- Review of MFA, endpoint protection, backups, remote access, and email security against what carriers require
- Written incident response plan sized for a small firm
- Core security policy set the application asks about
- Prioritized fix list, timed to your renewal date
- Answers you can reuse for client security questionnaires
- Optional: AI use policy for client data and confidentiality
For firms that handle disability, personal injury, or elder law: you likely hold medical records and may be a HIPAA Business Associate. We'll tell you if that applies.
Then, if you want it handled
Ongoing plans from $1,500 a month: the annual reassessment, policy upkeep, staff training, vendor agreements, and someone to call when something looks wrong. For offices that would rather not think about this again until we bring it up.
No long contract. Month to month after the first term, and we'll tell you if you've outgrown needing us.
Questions we hear
Our IT company handles all this.
They handle the tools, and that matters. The insurance application, the written plan, the policies, and client questionnaires are a different kind of work — and the partners sign the application, not the IT company. We work alongside them.
We're a two-attorney firm. Is this overkill?
Small firms are the ones carriers are declining. The review is sized for a firm your size, and the fee is smaller than a single premium increase.
Do you need access to client files?
No. Systems, settings, and paperwork. We never open a matter, and our agreement says so.
A client sent us a security questionnaire. Can you help?
Yes — that's often the trigger. The readiness review produces most of the answers, and we'll help with the rest.
What about AI tools and confidentiality?
If anyone at the firm is using a chatbot with client information, you need a policy that says what's allowed. We can include one, and the conversation with staff is usually short and welcome.
Start with a conversation
Twenty minutes, no charge. Tell us when the policy renews and we'll tell you what to expect from the application and what to do first.
- Pick a time for a 20-minute callChoose any open slot — no phone tag
- (574) 250-4475Call or text during business hours
- info@statelinedata.comWe answer within one business day
- South Bend, Mishawaka, Elkhart, Niles, and the surrounding areaOn site when it helps, remote when it doesn't
