Cyber Insurance for Law Firms and CPA Firms in Washington

Law and accounting firms hold client financial, tax, and legal records and move client money, which makes them prime targets for breaches and wire fraud. Washington lawyers must make reasonable efforts to protect client information under RPC 1.6(c); tax preparers fall under the FTC Safeguards Rule, which requires a written security plan and FTC notice of breaches affecting 500 or more people. Cyber coverage should be coordinated with professional liability.

By Trella Commercial · Updated October 4, 2026

The short version

  • The data is valuable and the money moves. Tax returns, Social Security numbers, bank details, and settlement or trust funds make these firms targets for both breaches and payment fraud.
  • Professional rules raise the bar. Washington's RPC 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized access to client information. The FTC Safeguards Rule treats tax preparers as financial institutions, with required security controls.
  • There are extra notice duties. Tax preparers must notify the FTC within 30 days of a breach involving 500 or more consumers. ABA Formal Opinion 483 says lawyers have a duty to notify clients of breaches involving material client information.
  • The Washington data shows it. Legal practices filed 35 and professional services firms 57 breach notices with the Attorney General.
  • Coordinate cyber with professional liability, so a client's wire fraud loss or a breach of client files is not caught between the two.

The rules that shape a firm's cyber exposure

Law firms

RuleWhat it saysCyber relevance
Washington RPC 1.6(c)A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a clientSecurity controls are an ethics issue, not just an IT issue
Washington RPC 1.15ALawyers must hold client and third-party property, including funds, separate from their ownTrust accounts are a target for fraudulent disbursement requests
ABA Formal Opinion 483 (2018)Lawyers have a duty to monitor for breaches, act to stop them, and notify current clients when material client information is involvedBreach response includes client communication, alongside state notice laws
ABA Formal Opinion 477R (2017)Lawyers may communicate over the internet if they make reasonable efforts to prevent unauthorized access, with more care for sensitive mattersEncryption and secure portals for sensitive documents
WSBA Advisory Opinion 2215Lawyers may use online storage if they take reasonable care that client information remains confidential and secureVendor and cloud choices need due diligence
Washington APR 26Lawyers certify annually whether they carry professional liability insurance, and the information is publicWashington does not require malpractice insurance, but disclosure is public

CPA firms and tax preparers

RuleWhat it saysCyber relevance
FTC Safeguards Rule (16 CFR 314)A business completing income tax returns is a financial institution under the ruleApplies regardless of firm size
Required controlsA written information security program, a qualified individual in charge, multifactor authentication for anyone accessing information systems, and encryption of customer information in transit and at restThe same controls cyber insurers ask about
Breach notice to the FTCFor a notification event involving at least 500 consumers, notify the FTC as soon as possible and no later than 30 days after discovery (effective May 13, 2024)An additional deadline beside state breach laws
IRS Publications 4557 and 5708Tax preparers must create security plans; Publication 5708 provides a written information security plan (WISP) templateA WISP is evidence of reasonable security for regulators and insurers
IRS data theft reportingReport client data theft to your local IRS Stakeholder LiaisonHelps stop fraudulent returns filed with stolen data
WAC 4-30-050A Washington licensee in public practice shall not disclose confidential client information without the client's specific consentConfidentiality duties sit alongside breach laws

The losses firms actually face

ScenarioWho losesCoverage that usually responds
Ransomware locks files during tax season or before a filing deadlineThe firm, through downtime and missed deadlinesCyber extortion, data restoration, business interruption
A hacker accesses client tax returns or case filesClients whose data was exposed; the firm through response costsCyber breach response and privacy liability
An employee wires trust or escrow funds after a fake instructionThe firm, and potentially clientsSocial engineering coverage under cyber or crime
A client wires money to a criminal after instructions from the firm's hacked emailThe client, who may claim the firm was negligentPossibly professional liability or cyber liability, depending on wording
Fraudulent tax returns are filed using stolen client dataClients, with IRS and state remediationCyber breach response; IRS reporting
A regulator or the FTC investigates the firm's securityThe firmCyber regulatory defense

Where cyber and professional liability meet

Professional liability (lawyers' or accountants' malpractice coverage) covers mistakes in your professional services. Cyber covers breaches, ransomware, and privacy claims. The gray areas:

  • A client loses money because of your hacked email. The client may sue for negligence. Some professional liability policies respond; others exclude claims arising from security failures, pushing it to cyber liability, which may or may not cover the client's financial loss.
  • A breach exposes client files. Usually a cyber claim, but the client's complaint may also allege a professional breach of confidentiality.
  • Missed deadlines caused by ransomware. A malpractice claim for the missed deadline, triggered by a cyber event.

Ask your broker to read both policies together and confirm which responds to each scenario. See cyber vs tech E&O vs crime and the CPA firm story.

Coverage features to insist on

FeatureWhy it matters for law and CPA firms
Social engineering with a meaningful sublimitTrust, escrow, and client payments are large; small sublimits do not match the exposure
Coverage for client funds you holdSome fraud coverage applies only to the firm's own money
Regulatory defense, including FTC and bar inquiriesSafeguards Rule and ethics investigations follow breaches
Business interruption with a short waiting periodTax season and court deadlines make every day offline expensive
Breach response sized for your client recordsFirms hold complete identity profiles; notification and monitoring scale with clients
Coordination with professional liabilityPrevents both policies from pointing at the other

Controls that satisfy both regulators and insurers

  1. Multifactor authentication on email, practice management, tax software, document portals, and banking. The Safeguards Rule requires it for tax preparers.
  2. A written information security plan. Required for tax preparers; strong evidence of reasonable efforts for lawyers.
  3. Encryption of client data in transit and at rest, including laptops and email of sensitive documents.
  4. Secure client portals instead of email attachments for returns and case files.
  5. Call-back verification for every change in wiring instructions, for both outgoing payments and instructions you give clients.
  6. Tested backups, separated from the network, especially before tax season.
  7. Vendor due diligence for cloud practice management and storage.

Common questions

Do law firms need cyber insurance?

Most do. Law firms hold confidential client information, often handle trust or settlement funds, and have ethical duties to protect client data under Washington RPC 1.6(c). A breach can require notice to clients and under state law, and malpractice policies typically do not cover breach response or ransomware.

Are CPA firms required to have cyber insurance?

No law requires cyber insurance. But the FTC Safeguards Rule requires tax preparers to maintain a written security program with controls such as multifactor authentication and encryption, and to notify the FTC within 30 days of a breach involving 500 or more consumers. Cyber insurance pays for responding to those obligations.

What is a WISP for tax preparers?

A written information security plan describing how a tax practice protects client data. The FTC Safeguards Rule requires one, and IRS Publication 5708 provides a template for tax and accounting firms.

Does malpractice insurance cover a data breach?

Usually not fully. Lawyers' and accountants' professional liability covers mistakes in professional services. Breach response, ransomware, and regulatory investigations are generally cyber coverages. Some malpractice policies include a small cyber endorsement, but it is typically limited.

What should a firm do if client tax data is stolen?

Call your cyber insurer's breach hotline, report the theft to your local IRS Stakeholder Liaison, and follow state breach notice laws. If the information of 500 or more consumers is involved, notify the FTC within 30 days. See the first 24 hours after a breach.

Sources

This page is general information, not legal or ethics advice. Confirm your obligations with your bar, the Board of Accountancy, or counsel. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.