
How cybercrime, company silos and coverage gaps put client money at risk
Piers Winton, executive director and head of solicitors at Gallagher, highlights why cyber incidents, including email-based or AI-enabled social engineering, may require multiple layers of insurance cover rather than one insurance policy alone
It is 3.45 pm on a Friday. A law firm’s accounts team receives an email confirming revised bank details for a client transaction. The message appears to come from a known contact, follows an existing email chain and uses the right tone and terminology. The payment is authorised. Hours later, the firm discovers that £175,000 of client money has been sent to a criminal-controlled account.
The scenario is hypothetical, but the threat is not. The important question is no longer whether we could suffer a cyberattack. It is also: if cybercrime causes a financial loss, do we know which parts of our insurance programme may respond?
Why payment fraud deserves attention
Ransomware still attracts headlines, but recent claims data shows how prominent email-enabled fraud has become. The insurance provider CFC reported that theft of funds accounted for 25% of the global cyber claims it resolved in 2025, making it its most common cyber event. Based on notifications so far in 2026, CFC says theft-of-funds incidents are approaching half of cyber claims notifications.
Coalition’s 2026 Cyber Claims Report tells a similar story. Throughout its global policyholder base, business email compromise (BEC) and funds transfer fraud accounted for 58% of claims, while 71% of funds transfer fraud claims were directly linked to social engineering.
These attacks do not always rely on sophisticated malware. A criminal may compromise an inbox, monitor a transaction and wait for the right moment to substitute payment instructions. Technology is also making impersonation more convincing: Beazley has highlighted the increasing use of AI-generated voice and video alongside emails in social engineering fraud.
Law firms are also increasingly reliant on cloud-hosted practice management systems (PMS’s), outsourced IT providers and digital communications platforms. As a result, they create new access points for hackers to enter a law firm’s network and opportunities for impersonation to gain entry through social engineering.
For firms, who routinely manage confidential information and client money, these combinations deserve particular attention.
Where does insurance respond?
This is where cyber risk becomes a cross-class insurance issue. Solicitors’ compulsory professional indemnity insurance (PII) should not be treated as a substitute for standalone cyber cover. The SRA’s Minimum Terms and Conditions (MTC) allow insurers to apply certain cyber exclusions, but those exclusions cannot remove the civil liability protection required by the MTC, including the obligation to remedy a breach of the SRA Accounts Rules.
That distinction matters. PII is fundamentally concerned with civil liability arising from private legal practice. If a client suffers a loss because of a firm’s actions, PII may therefore be relevant. But a cyber incident can create much wider costs for the firm itself.
In the example of email compromise and an external actor using digital deception to create a fraudulent fund transfer, a cyber policy may be triggered. Depending on the cover purchased, a standalone cyber policy may provide access to incident-response specialists, forensic investigation, legal advice, data recovery, notification support and business interruption cover. Some policies can also address fraudulent transfers or social-engineering losses.
Crime or fidelity insurance may create another potential layer where money has been stolen through fraud or deception. However, triggers, limits and exclusions differ between policies, particularly where an employee has voluntarily transferred funds after being deceived. The answer could therefore involve cyber, PII and crime cover, rather than one policy viewed in isolation.
Client money is under greater scrutiny
The regulatory backdrop is changing too. In June 2026, the SRA announced reforms intended to strengthen safeguards around client money, including annual accountants’ reports for firms holding client money and greater separation between senior decision-making and compliance roles in higher-risk firms. Subject to Legal Services Board approval, the SRA expects the rules to take effect in early 2027.
Separately, the government has decided that the Financial Conduct Authority (FCA) will take over anti-money laundering (AML) and counter-terrorist-financing supervision of legal and accountancy firms. The transfer has not yet occurred and remains subject to legislation and transition planning, but it represents a considerable change in the supervision of financial-crime controls within the legal sector.
Cyber security, client-money controls, AML and insurance should therefore not sit in separate silos.
Five questions for law firm leaders
Cyber Security Awareness Month (October) provides a useful opportunity to test both controls and cover:
- If client money disappeared following a cyber incident tomorrow, which policies would we notify?
- Have our cyber, PII and crime policies been reviewed together for potential gaps or overlaps?
- Does our cyber or crime programme address funds-transfer and social-engineering fraud?
- Are changes to payment instructions independently verified using trusted contact details?
- Have the cyber security controls and practices of your third-party suppliers been assessed and approved as part of your vendor due diligence process?
As cybercrime increasingly crosses the boundaries between technology, fraud, professional liability and regulatory risk, understanding how both controls and insurance work together is becoming an important part of law firm resilience. If a firm falls victim to a fraudulent transfer, steps to mitigate risk to itself and its clients should have started well before the event.


