Blog Post

Cyber Loss When the Asset Is Privilege

September 13, 2026

Table of Contents

A loss model for a professional services firm counts records and applies a per-record cost. The firm holds client documents, so the arithmetic looks straightforward.

It misses the thing that makes this sector different. A single compromised matter can trigger obligations to several clients at once, each with its own notification standard, and the material at risk carries a legal status that a record count does not capture.

Why Isn't Privilege a Data Category?

Because it is a protection attaching to communications rather than a classification attaching to files, and it can be weakened by how a firm responds rather than by the breach itself.

A theft does not waive privilege, since the disclosure was not voluntary. What can weaken it is inaction afterward. A firm that does not take affirmative steps to prevent use of exfiltrated material, such as seeking protective orders or demanding removal of leaked files, may find the protection harder to assert later.

Which Puts a Cost on Response Quality

Most loss models treat response cost as a fixed expense. Here the response affects whether a legal protection survives, so the quality and speed of it changes the magnitude of the loss rather than just its handling cost. The relationship differs from the one a breach model assumes.

How Does the Forensic Report Create Exposure?

Through disclosure, which is the trap most specific to this sector and the one most likely to be walked into during an incident.

Annual loss broken down by event type, impact scenario and damage type showing which categories contribute most
Where a sector carries a loss category outside the usual set, the breakdown by damage type is what shows it.

Sharing a cybersecurity forensic report with auditors, regulators or clients can weaken privilege over the underlying investigation. Courts have distinguished between technical material, which frequently has to be produced, and internal legal analysis of the same incident, which may remain protected. A firm that hands the full report to a client demanding transparency has made a decision whose consequences outlast the disclosure.

Two Documents Rather Than One

Structuring the investigation so technical findings and legal analysis sit in separate documents preserves the option. It is a decision made at the start of an incident, when nobody is thinking about it, and it cannot be reconstructed afterward. Producing evidence on somebody else's timeline is harder when the document structure itself is part of the exposure.

Why Does One Matter Multiply Into Many Obligations?

Because notification duties in this sector run to clients individually rather than to a regulator collectively, and each client relationship has its own standard.

Professional conduct rules require notifying a current client where an incident compromises material confidential information or impairs the firm's ability to act. The test applies per client rather than once, so a single compromised system holding twenty matters produces twenty assessments, each turning on what that client's material was and how sensitive it is.

Former Clients Are a Separate Question

Confidentiality obligations survive the end of a matter while the communication duty largely does not, which creates a genuinely unsettled position. A firm holding closed-matter files for retention reasons carries the confidentiality exposure without a defined notification path, and the volume of closed matters usually exceeds the open ones considerably.

What Is the Real Severity Driver?

Client concentration rather than record count, which is the input a data-oriented model omits entirely.

Exceedance curve showing the likelihood of annual loss exceeding successive percentages of revenue with the average marked
Expressing loss against revenue is the useful frame where the largest consequence is the loss of future work rather than a per-record cost.

A firm where a handful of clients account for most billings has an exposure defined by whether those relationships survive. The loss is not the cost of notifying, it is the mandate that goes elsewhere next year and the panel place that is not renewed. The loss lands in future revenue rather than in incident cost, which is why a per-record model produces a figure with the wrong order of magnitude.

How Do You Estimate That?

From concentration and switching cost rather than from breach benchmarks. What proportion of revenue sits with the largest clients, how long a typical mandate runs, and how readily that work moves. Those are known internally and none appears in a cyber questionnaire, and concentration that cannot be diversified away applies to a client book as much as to infrastructure.

What Does the Interruption Side Look Like?

Better than in most sectors, and worth stating because it corrects an instinct.

Professional services work can frequently continue through an outage. People draft on local files, take calls and meet clients, so the loss is measured in billable hours displaced and deadlines at risk rather than in stopped production. A firm without access to its document management system for three days is impaired rather than halted.

Where Does That Break?

On court and filing deadlines, which do not accommodate an outage. A missed limitation date or a filing window closed while systems were unavailable produces a loss with a different character entirely, since the consequence is to the client's position rather than to the firm's throughput. It is the interruption scenario worth modeling, and it is defined by the calendar rather than by duration alone.

Which Exposures Sit Outside Cyber Cover?

The two largest, which is the pattern in every sector where the loss is not informational.

A claim that the firm's failure to protect material caused a client loss is a professional indemnity question rather than a cyber one. Loss of future mandates is uninsured almost everywhere. A cyber policy responds to the response costs, the notification exercise and the data-related consequences, which here may be the smaller part of the event.

Which Argues for Modeling Before Asking About Coverage

Producing one figure and asking whether cyber insurance covers it gives a misleading answer, since the figure spans two towers and an uninsured category. Modeling by damage type and mapping each to the policy that would respond shows what is genuinely unfunded, and the exclusions that surface at claim is where that gets discovered otherwise.

What Do Clients Ask For Afterward?

Evidence, and the request arrives from the people best equipped to evaluate it, which is a condition no other sector faces in quite this form.

A corporate client whose material was exposed will ask what happened, when it was detected, what was accessed and what controls failed. Those questions come from in-house counsel who reads security assessments professionally and will notice an answer that does not hold together. A firm producing a narrative assembled after the request is producing testimony to an audience trained to test it.

Which Raises the Standard for the Record

Records that existed before the incident carry weight that reconstruction does not. Dated access logs showing which matters a compromised account could reach, a control assessment predating the event, and a documented response decision each survive scrutiny in a way a summary written afterward does not, and a trail holding only the current state cannot supply them.

Does the Panel Review Change This?

Substantially, and it is the mechanism by which the exposure becomes financial. Large clients run periodic reviews of their legal panels with security questionnaires attached, so a firm that handled an incident poorly meets that process at the next cycle. The loss arrives as a review outcome rather than as a claim, which is why it appears in no insurance category and in future revenue instead.

What Should a Firm Establish?

Four things, and none requires a security assessment.

What proportion of revenue sits with the largest clients, since that is the severity driver. How many closed matters are retained and for how long, since confidentiality survives the matter, and what a modeled figure cannot establish applies to the categories that resist pricing. Whether the incident response plan separates technical findings from legal analysis, since that decision cannot be made retrospectively. Then which deadlines in the next quarter would be jeopardized by a multi-day outage. Cyber risk quantification built from those inputs produces a figure a managing partner can act on rather than one derived from a per-record average.

Count Relationships, Not Records

A per-record model applied to a professional services firm reaches the wrong order of magnitude, because the material carries a legal protection rather than a classification and the largest consequence is the work that goes elsewhere. Privilege is not waived by a theft and can be weakened by the response, which puts the quality of the response inside the magnitude rather than beside it. Notification runs client by client, each with its own test, so one compromised system produces many assessments. The severity driver is also client concentration, which no cyber questionnaire asks about. Kovrr's cyber risk quantification models loss by damage type, which is what allows a sector with unusual categories to be priced.

To see exposure modeled from client concentration and interruption rather than from a per-record average, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Professional Services Cyber Loss FAQs

Speak to an Expert

Why isn't privilege a data category?

How does a forensic report create exposure?

Why does one compromised matter produce many obligations?

What is the real severity driver?

How bad is the interruption exposure?

Which exposures fall outside cyber cover?