
Blog Post
Cyber Loss When the Asset Is Privilege
September 13, 2026
A loss model for a professional services firm counts records and applies a per-record cost. The firm holds client documents, so the arithmetic looks straightforward.
It misses the thing that makes this sector different. A single compromised matter can trigger obligations to several clients at once, each with its own notification standard, and the material at risk carries a legal status that a record count does not capture.
Why Isn't Privilege a Data Category?
Because it is a protection attaching to communications rather than a classification attaching to files, and it can be weakened by how a firm responds rather than by the breach itself.
A theft does not waive privilege, since the disclosure was not voluntary. What can weaken it is inaction afterward. A firm that does not take affirmative steps to prevent use of exfiltrated material, such as seeking protective orders or demanding removal of leaked files, may find the protection harder to assert later.
Which Puts a Cost on Response Quality
Most loss models treat response cost as a fixed expense. Here the response affects whether a legal protection survives, so the quality and speed of it changes the magnitude of the loss rather than just its handling cost. The relationship differs from the one a breach model assumes.
How Does the Forensic Report Create Exposure?
Through disclosure, which is the trap most specific to this sector and the one most likely to be walked into during an incident.

Sharing a cybersecurity forensic report with auditors, regulators or clients can weaken privilege over the underlying investigation. Courts have distinguished between technical material, which frequently has to be produced, and internal legal analysis of the same incident, which may remain protected. A firm that hands the full report to a client demanding transparency has made a decision whose consequences outlast the disclosure.
Two Documents Rather Than One
Structuring the investigation so technical findings and legal analysis sit in separate documents preserves the option. It is a decision made at the start of an incident, when nobody is thinking about it, and it cannot be reconstructed afterward. Producing evidence on somebody else's timeline is harder when the document structure itself is part of the exposure.
Why Does One Matter Multiply Into Many Obligations?
Because notification duties in this sector run to clients individually rather than to a regulator collectively, and each client relationship has its own standard.
Professional conduct rules require notifying a current client where an incident compromises material confidential information or impairs the firm's ability to act. The test applies per client rather than once, so a single compromised system holding twenty matters produces twenty assessments, each turning on what that client's material was and how sensitive it is.
Former Clients Are a Separate Question
Confidentiality obligations survive the end of a matter while the communication duty largely does not, which creates a genuinely unsettled position. A firm holding closed-matter files for retention reasons carries the confidentiality exposure without a defined notification path, and the volume of closed matters usually exceeds the open ones considerably.
What Is the Real Severity Driver?
Client concentration rather than record count, which is the input a data-oriented model omits entirely.

A firm where a handful of clients account for most billings has an exposure defined by whether those relationships survive. The loss is not the cost of notifying, it is the mandate that goes elsewhere next year and the panel place that is not renewed. The loss lands in future revenue rather than in incident cost, which is why a per-record model produces a figure with the wrong order of magnitude.
How Do You Estimate That?
From concentration and switching cost rather than from breach benchmarks. What proportion of revenue sits with the largest clients, how long a typical mandate runs, and how readily that work moves. Those are known internally and none appears in a cyber questionnaire, and concentration that cannot be diversified away applies to a client book as much as to infrastructure.
What Does the Interruption Side Look Like?
Better than in most sectors, and worth stating because it corrects an instinct.
Professional services work can frequently continue through an outage. People draft on local files, take calls and meet clients, so the loss is measured in billable hours displaced and deadlines at risk rather than in stopped production. A firm without access to its document management system for three days is impaired rather than halted.
Where Does That Break?
On court and filing deadlines, which do not accommodate an outage. A missed limitation date or a filing window closed while systems were unavailable produces a loss with a different character entirely, since the consequence is to the client's position rather than to the firm's throughput. It is the interruption scenario worth modeling, and it is defined by the calendar rather than by duration alone.
Which Exposures Sit Outside Cyber Cover?
The two largest, which is the pattern in every sector where the loss is not informational.
A claim that the firm's failure to protect material caused a client loss is a professional indemnity question rather than a cyber one. Loss of future mandates is uninsured almost everywhere. A cyber policy responds to the response costs, the notification exercise and the data-related consequences, which here may be the smaller part of the event.
Which Argues for Modeling Before Asking About Coverage
Producing one figure and asking whether cyber insurance covers it gives a misleading answer, since the figure spans two towers and an uninsured category. Modeling by damage type and mapping each to the policy that would respond shows what is genuinely unfunded, and the exclusions that surface at claim is where that gets discovered otherwise.
What Do Clients Ask For Afterward?
Evidence, and the request arrives from the people best equipped to evaluate it, which is a condition no other sector faces in quite this form.
A corporate client whose material was exposed will ask what happened, when it was detected, what was accessed and what controls failed. Those questions come from in-house counsel who reads security assessments professionally and will notice an answer that does not hold together. A firm producing a narrative assembled after the request is producing testimony to an audience trained to test it.
Which Raises the Standard for the Record
Records that existed before the incident carry weight that reconstruction does not. Dated access logs showing which matters a compromised account could reach, a control assessment predating the event, and a documented response decision each survive scrutiny in a way a summary written afterward does not, and a trail holding only the current state cannot supply them.
Does the Panel Review Change This?
Substantially, and it is the mechanism by which the exposure becomes financial. Large clients run periodic reviews of their legal panels with security questionnaires attached, so a firm that handled an incident poorly meets that process at the next cycle. The loss arrives as a review outcome rather than as a claim, which is why it appears in no insurance category and in future revenue instead.
What Should a Firm Establish?
Four things, and none requires a security assessment.
What proportion of revenue sits with the largest clients, since that is the severity driver. How many closed matters are retained and for how long, since confidentiality survives the matter, and what a modeled figure cannot establish applies to the categories that resist pricing. Whether the incident response plan separates technical findings from legal analysis, since that decision cannot be made retrospectively. Then which deadlines in the next quarter would be jeopardized by a multi-day outage. Cyber risk quantification built from those inputs produces a figure a managing partner can act on rather than one derived from a per-record average.
Count Relationships, Not Records
A per-record model applied to a professional services firm reaches the wrong order of magnitude, because the material carries a legal protection rather than a classification and the largest consequence is the work that goes elsewhere. Privilege is not waived by a theft and can be weakened by the response, which puts the quality of the response inside the magnitude rather than beside it. Notification runs client by client, each with its own test, so one compromised system produces many assessments. The severity driver is also client concentration, which no cyber questionnaire asks about. Kovrr's cyber risk quantification models loss by damage type, which is what allows a sector with unusual categories to be priced.
To see exposure modeled from client concentration and interruption rather than from a per-record average, book a demo with our risk experts.
Professional Services Cyber Loss FAQs
Speak to an ExpertWhy isn't privilege a data category?
Because it is a protection attaching to communications rather than a classification attaching to files, and it can be weakened by how a firm responds rather than by the breach itself. A theft does not waive privilege, since the disclosure was not voluntary. What can weaken it is inaction afterward, since a firm that does not take affirmative steps to prevent use of exfiltrated material may find the protection harder to assert later, which puts response quality inside the loss magnitude.
How does a forensic report create exposure?
By being disclosed. Sharing a cybersecurity forensic report with auditors, regulators or clients can weaken privilege over the underlying investigation, and courts have distinguished between technical material that frequently has to be produced and internal legal analysis of the same incident that may remain protected. Structuring the investigation so those sit in separate documents preserves the option, and it is a decision made at the start of an incident that cannot be reconstructed afterward.
Why does one compromised matter produce many obligations?
Because notification duties run to clients individually rather than to a regulator collectively. Professional conduct rules require notifying a current client where an incident compromises material confidential information or impairs the firm's ability to act, and that test applies per client, so a single compromised system holding twenty matters produces twenty assessments. Former clients are a separate question, since confidentiality survives the matter while the communication duty largely does not.
What is the real severity driver?
Client concentration rather than record count. A firm where a handful of clients account for most billings has an exposure defined by whether those relationships survive, so the loss is the mandate that goes elsewhere next year and the panel place not renewed rather than the cost of notifying. That lands in future revenue rather than incident cost, and it is estimated from concentration and switching cost rather than from breach benchmarks.
How bad is the interruption exposure?
Better than in most sectors, since professional services work can frequently continue through an outage. People draft on local files, take calls and meet clients, so the loss is billable hours displaced rather than stopped production, and a firm without its document management system for three days is impaired rather than halted. Where that breaks is court and filing deadlines, which do not accommodate an outage and produce a loss to the client's position.
Which exposures fall outside cyber cover?
The two largest. A claim that the firm's failure to protect material caused a client loss is a professional indemnity question rather than a cyber one, and loss of future mandates is uninsured almost everywhere. A cyber policy responds to response costs, the notification exercise and data-related consequences, which here may be the smaller part of the event, so modeling by damage type and mapping each to the responding policy shows what is genuinely unfunded.




