Is a Cyber Endorsement Enough for a Law Firm?
Is a cyber endorsement enough for your firm? Read the sublimits before you rely on them.
- By Dallas Downey, CLCS
Published 2026-09-11 - Commercial Insurance
The cyber line on your general liability or LPL policy looks like protection. The schedule page tells a shorter story. Here is how to read that page like the person who will file the claim.

The answer
For most Houston firms, no. A cyber endorsement is a small rider stapled to a policy that was built for something else, and the sublimits inside it are usually exhausted before the first forensic invoice is paid. A standalone cyber policy is priced, sized, and staffed for the whole event. The only way to know which one your firm holds is to read the schedule page, and most firms never have.
What a cyber endorsement actually buys
General liability was written for slip and falls and property damage. Lawyers professional liability was written for claims about your legal work. A cyber endorsement is a rider on one of those contracts, and the carrier prices it like a rider.
Open the endorsement schedule and the structure repeats across carriers. One modest aggregate limit for the whole cyber event. Inside it, smaller carve outs for the pieces that matter most, forensic investigation, breach counsel, client notification, regulatory defense. Each carve out has its own cap, and each cap was set by an underwriter who never saw your trust account.
I read these schedules for a living, and the pattern that matters is simple. The limits are drawn for a minor incident at a business with a minor digital footprint. A litigation practice holding settlement funds and privileged files is a different animal, and the schedule was never drawn for it.
The endorsement is honest about what it is. It says so on the schedule page, in numbers. The problem is that almost nobody reads the schedule page until the week they need it.
Dallas Downey, CLCS
Where the gap hits a litigation practice hardest
Social engineering fraud is the scheme where a criminal poses as opposing counsel, a client, or a title contact and reroutes a settlement wire. On a basic endorsement it is often excluded outright. Where it appears, the sublimit is frequently a fraction of a single settlement disbursement. The FBI's Internet Crime Complaint Center puts business email compromise near the top of its reported loss categories year after year, and litigation practices move exactly the kind of large, scheduled payments that scheme was built to intercept.
Business interruption is the second blind spot. When ransomware locks a case management system, billable hours stop while payroll keeps running. Endorsements rarely carry a real business interruption grant. Standalone policies build it in as first party coverage.
The third gap is the response team. A standalone carrier hands you a breach coach, panel forensics, and panel counsel within hours of the call. An endorsement usually leaves the firm sourcing its own vendors in the middle of the worst week it has had.
Endorsement and standalone, side by side
The math the schedule page has to survive
Hold your endorsement schedule next to those figures. The mismatch is the whole article.
The trust account problem no LPL policy solves
Legal professional liability responds when your legal work is alleged to have harmed a client. A criminal spoofing an email and rerouting a settlement disbursement is a crime against the firm, so the LPL policy stands aside. The coverage written for that exact moment is a social engineering fraud endorsement on a standalone cyber or crime policy, with a sublimit sized to the largest wire your firm actually sends and a verified callback procedure your staff actually follows.
Houston firms moving personal injury settlements, litigation tied closings, and class distributions move sums most small businesses never touch, and trust accounting makes every one of those dollars someone else's. That is why the sublimit conversation deserves twenty focused minutes before renewal, and my desk exists to give it exactly that.
How I size a cyber program for a firm
Firms ask me for the right number. The right number comes from four places, in this order.
- Your largest wire. Pull twelve months of trust account disbursements and find the biggest one. The social engineering sublimit starts at that figure or above it. A sublimit below your normal wire size is decoration.
- Your settlement calendar. A docket with seven figure matters pending needs limits that survive the week one of them closes.
- Your data shelf. Count the matters, and count the people inside them. Medical records, financial disclosures, and discovery files each carry notification duties under Chapter 521 of the Texas Business and Commerce Code, and notification is priced per person you owe it to.
- Your revenue and headcount. Bigger firm, bigger interruption exposure, bigger target. Scale the aggregate limit with the practice instead of renewing last year's number by habit.
Bring those four numbers to any broker and you will get a real quote instead of a rate sheet default. Bring them to mine and I will also read the endorsement you already have, line by line, before recommending anything new.
The Sublimit Check
Your schedule page, read line by line against your real wires.
Get My Sublimits ReadKeep reading before renewal
Sources worth opening before you decide.
This article uses public source material from the FBI Internet Crime Complaint Center 2025 Internet Crime Report, the IBM Cost of a Data Breach Report, and Chapter 521 of the Texas Business and Commerce Code.
The purpose is to help you ask better questions before claim time.
Frequently asked questions
Does a general liability policy cover a data breach?
No. General liability responds to bodily injury and property damage claims. Any cyber protection riding on that policy comes from a separate endorsement with its own narrow scope and its own low sublimits, and those sublimits govern what actually gets paid.
Is a cyber endorsement enough for a small law firm?
For a firm that emails invoices, holds client funds, or stores case files digitally, the sublimits are usually too thin to matter once a real incident starts. The honest way to answer the question for your firm is to read the endorsement schedule next to your actual trust account activity.
What does a standalone cyber policy add that an endorsement does not?
Higher limits sized for the full event, dedicated social engineering and business interruption coverage, and a carrier provided breach team that puts forensics and counsel to work within hours instead of leaving the firm to find its own vendors mid-crisis.
How much cyber coverage should a litigation firm carry?
Enough that the social engineering sublimit covers the largest wire you send and the aggregate limit reflects your settlement sizes, trust account activity, and headcount. Those are your firm's numbers, so the right limit comes from your documents instead of a generic rate sheet.
The button below books a commercial review, and the calendar behind it is mine. Bring the endorsement schedule you have never read all the way through. By the end of that meeting it will have margins full of notes, and you will know exactly what you own.
We place standalone cyber coverage for Texas law firms from 50+ top Texas carriers we know well. We translate the insurance contract before claim time.
The worst time to learn your sublimits is the week you need them.
Size My Cyber CoverageThe review is free. The decision is yours.
By