Cyber liability insurance for New Hampshire law firms pays for breach notification, forensic investigation, ransomware response, and third-party lawsuits after a hack or data leak — costs a legal malpractice policy or general liability plan won't touch. Firms holding client Social Security numbers, trust account records, or medical files in personal injury cases carry more exposure than most small businesses, and standard business policies were never built to cover it.
- Cyber liability insurance for New Hampshire law firms covers breach notification, ransomware extortion, and third-party data lawsuits, not legal negligence.
- Legal malpractice coverage and cyber coverage are separate policies — one does not substitute for the other in 2026.
- Firms using cloud case management software, e-discovery vendors, or remote staff carry higher breach exposure than paper-file practices.
- A standalone cyber policy or a cyber endorsement on a BOP are the two most common paths for New Hampshire firms.
Why cyber liability insurance matters for law firms
A law firm's file cabinet, physical or digital, is a concentrated target: Social Security numbers in probate and family law files, bank account numbers in trust accounting, medical records in personal injury cases, and passport numbers in immigration matters. Ransomware groups target professional services firms precisely because that data sits in one place and the firm often has thinner IT defenses than a hospital or a bank.
New Hampshire's data breach notification law, RSA 359-C, requires any business — including a law firm — to notify affected residents after a security breach exposing personal information. Model Rule 1.6 of the Rules of Professional Conduct also puts an ethical duty on attorneys to make reasonable efforts to protect client information, and several state bars now list cyber liability coverage in their risk management guidance for exactly that reason.
A broader look at cyber liability insurance for New Hampshire small businesses covers the baseline mechanics — this guide narrows it to what changes when the business is a law practice.
Verdict: a law firm that treats cyber coverage as optional because it's "just a small practice" is the exact profile ransomware operators prefer to target in 2026.
Inventory the client data your firm actually holds
Before pricing a policy, list what's actually sitting in your files and systems. This step costs nothing and it's what determines the limits you'll need.
- Social Security numbers in probate, family law, and estate files
- Trust account and IOLTA banking details
- Medical records tied to personal injury or workers' comp cases
- M&A due diligence and financial documents from business clients
- Passport and immigration status documents
- Employee HR files including W-2 and direct deposit data
Separate cyber coverage from your malpractice policy
Legal malpractice insurance covers negligent advice, missed deadlines, and conflicts of interest — it does not cover a hacker encrypting your case management system or a phishing email that drains a trust account. Firms that assume one policy covers both find that out during a claim, which is the worst possible time.
- Confirm your malpractice carrier explicitly excludes cyber events (most do)
- Check whether your professional liability insurance for New Hampshire consultants-style policy has any silent cyber sublimit
- Ask if ransomware extortion payments are excluded under your current E&O language
- Review whether regulatory fines from a bar complaint are handled separately from a data breach fine
Check what your general liability and BOP already exclude
A standard commercial general liability policy or business owner's policy was written for slip-and-fall claims and property damage, not digital intrusion.
- Data breach notification costs are excluded from most CGL forms
- Cyber extortion and ransomware payments are excluded
- Costs to restore or rebuild your own compromised systems are excluded
- Third-party lawsuits from clients whose data leaked are typically excluded
Match coverage limits to your firm's actual risk profile
A two-attorney solo practice running paper files has a different exposure than a ten-attorney firm doing e-discovery for corporate clients through cloud platforms like Clio or NetDocuments.
- Number of client records with personally identifiable information on file
- Whether case management runs through cloud software versus local servers
- Whether remote or hybrid staff access firm systems from personal devices
- Size and activity of trust/IOLTA accounts
- Volume of e-discovery or document review work handled digitally
Add employment practices coverage for HR-driven breaches
A large share of law firm breaches start with a phishing email aimed at payroll or HR staff, not a technical exploit against the network. That's a people problem, and it usually needs a separate policy layer.
- W-2 phishing scams targeting payroll and HR
- Fake wire transfer requests impersonating a partner
- Compromised employee email accounts used to reroute client payments
- Review whether employment practices liability insurance is bundled or needs to sit alongside your cyber policy
Get limits reviewed against your firm's real tech stack
Once the manual inventory and exclusion review are done, the fastest way to close gaps is a coverage review built around what your firm actually runs — cloud case management, remote staff, trust accounting software — instead of a generic small business template.
Get your firm’s cyber coverage reviewed
A quick review shows what your current policies actually cover.
Comparison: coverage options for New Hampshire law firms
| Coverage type | Best for | Key limitation | Verdict |
|---|---|---|---|
| Standalone cyber liability policy | Firms with e-discovery, cloud case management, high client PII volume | Doesn't cover legal negligence or malpractice claims | Buy |
| Cyber endorsement on a BOP | Solo or small firms wanting one bundled policy | Usually carries lower sublimits than a standalone policy | Consider |
| Legal malpractice (professional liability) alone | Covering negligence, missed deadlines, conflicts of interest | Excludes third-party data breach and ransomware costs entirely | Skip as sole protection |
| Umbrella layered over cyber limits | Firms with large trust accounts or M&A practices needing extra limits | Extends existing limits only, doesn't add new perils | Consider |
A firm carrying malpractice coverage alone and calling it "cyber protection" is the single most common gap seen in New Hampshire law firm reviews — the two policies solve entirely different problems.
Common mistakes New Hampshire law firms make
- Assuming malpractice coverage extends to hacking. It doesn't, and the exclusion is usually explicit in the policy language.
- Storing case files and trust records on personal devices without any endorsement covering those devices under the firm's cyber policy.
- Delaying carrier notification after a suspected breach. Cyber policies are typically claims-made — a late report can jeopardize the claim itself.
- Ignoring vendor risk. A breach at your cloud case management provider or e-discovery vendor can still expose your firm even though the hack didn't happen on your network.
- Believing small firms aren't targets. Solo and small practices are targeted specifically because their IT defenses tend to be thinner than large firms with dedicated security staff.
FAQ
What does cyber liability insurance cover for a law firm?
Cyber liability insurance for a law firm covers breach notification costs, forensic investigation, ransomware extortion, and lawsuits from clients whose data was exposed. It does not cover legal malpractice claims arising from bad legal advice.
Is cyber liability insurance required for New Hampshire attorneys?
New Hampshire does not mandate cyber liability insurance for attorneys by statute, but Model Rule 1.6 creates an ethical duty to safeguard client information, and several bar associations recommend it as standard risk management.
Does legal malpractice insurance cover a data breach?
No. Legal malpractice insurance covers negligent legal advice and missed deadlines, not hacking, ransomware, or data breach notification costs. Those require a separate cyber liability policy.
How much cyber liability coverage does a small law firm need?
Coverage needs depend on the volume of client PII on file, whether case management runs through cloud software, and the size of trust account activity. A firm handling e-discovery or high client volume needs higher limits than a solo paper-file practice.
What’s the difference between cyber liability and employment practices liability insurance?
Cyber liability covers data breaches and hacking incidents, while employment practices liability covers claims tied to employment decisions like wrongful termination or harassment. Firms with HR-driven breach risks, like W-2 phishing, often need both.
Do solo attorneys need cyber liability insurance?
Yes, solo attorneys handling Social Security numbers, medical records, or trust account data face the same breach exposure as larger firms, often with fewer IT defenses in place.
What happens if a law firm doesn’t have cyber liability insurance and gets hacked?
The firm pays out of pocket for breach notification, forensic investigation, credit monitoring for affected clients, and any resulting lawsuits. Malpractice and general liability policies typically deny these claims outright.
Does cyber insurance cover ransomware payments?
Most standalone cyber liability policies include cyber extortion coverage for ransomware payments and negotiation costs, though terms vary by carrier and policy in 2026.
One last thing
The gap that catches New Hampshire firms off guard isn't the ransomware attack itself — it's discovering during the claim that the malpractice policy they've carried for years never covered digital breaches in the first place. Check that distinction before 2026 renewal, not after an incident.
Related guides
- General liability insurance for New Hampshire small businesses
- Umbrella insurance for New Hampshire business owners


