Insight Archive

Aon  |  Professional Services Practice

Cyber October 2026 – Professional Service Firm Cyber Exposure in an Increasingly Connected World

Release Date: October 2026
pdf download Should Global Professional Service Firms Use Captives for Employee Benefits?

Aon can help firms understand, quantify and manage cyber risk in an increasingly connected world. The PSP Cybersecurity Awareness webpage provides developments, context and updates on this important professional service firm risk.

Key Takeaways

  • As organizations become more connected, cyber exposure is becoming more complex, more interconnected and more consequential.

  • AI adoption, digital supply chains, cloud platforms and third-party dependencies are widening the surface of exposure.

  • Cyber events increasingly drive operational disruption, financial volatility and resilience challenges, not just IT incidents.

Appointment of PSP Head of Cyber


The Professional Service Practice (PSP) at Aon welcomes Brian Gillin as National Product Leader, Head of Cyber, North America.

In his first PSP Featured Insight, below, Brian highlights how the Luna Moth campaign against law firms underscores risks facing organizations across all sectors.


When Trust Becomes the Attack Surface: Why Law Firms Are the Warning Sign for Every Industry


The Luna Moth cyber campaigns point towards a future where cyber extortion increasingly exploits something very difficult to secure: trust.  

Click here to read more


As Underwriting Expectations for Professional Service Firms Evolve, Cyber Risk Visibility Matters More Than Ever


Insurers are taking a closer look at how professional service firms manage cyber risk in practice. Increasingly, underwriting discussions are focused on security controls, governance, incident preparedness, and lessons learned from real-world attacks, creating opportunities for firms to demonstrate cyber resilience and differentiate themselves in the marketplace.

Takeaways


  • Security controls remain a primary underwriting focus.
  • Demonstrable cyber governance can strengthen insurer confidence.
  • Data-driven risk analysis helps organizations prioritize investments and communicate risk more effectively.

Cyber insurers are placing greater emphasis on the effectiveness of security controls, including MFA, EDR, vulnerability management, access controls, and employee awareness training.

Increasingly, underwriters are looking for evidence that cybersecurity programs are actively managed and continuously improved, not simply documented.

Recent attacks such as those by Luna Moth against law firms have heightened attention on operational controls and incident response readiness, reinforcing the need for organizations to regularly review security practices against evolving threats.

Tools such as Aon’s Cyber Risk Analyzer can help organizations quantify cyber exposures, evaluate the impact of security investments, and better communicate risk to leadership and insurers.

Organizations that can demonstrate strong controls, effective governance, and a clear understanding of their cyber risk profile may be better positioned in an increasingly scrutinized underwriting environment.


Recent PSP Cyber Thought Leadership


From Phishing to Deepfakes: Social Engineering Risks are Intensifying for Professional Service Firms


Responsible for significant amounts of client funds and valuable data, professional service firms are perennial targets for social engineering attacks. Generative AI, deepfakes and increasingly sophisticated business email compromise schemes are enabling criminals to convincingly mimic partners, clients and counterparties, often in the context of live matters and large fund movements. Effective risk management is vital in the face of this evolving risk.  

Click here to read more


'Hello, This Is IT': Attacking Professional Service Firms Through Microsoft Teams


Accounting, consulting, and law firms share workpapers, deal files, HR records, and privileged communications with clients, regulators, and counterparties through Microsoft Teams. Firms need to be aware of the potential for a single malicious call or chat opening the door to months of undetected data theft and extortion.  

Click here to read more


Recent and Upcoming Aon Cyber Solutions Thought Leadership



The Professional Services Practice at Aon values your feedback.


Please contact the PSP Cyber Committee to discuss:
 
Brian Gillin National Product Leader, Head of Cyber, North America
[email protected]
Brian Gillin
Marci Alfalla Managing Director and Chief Broking Officer
[email protected]
Marci Alfalla
Erin Kenney Managing Director and Chief Commercial Officer
[email protected]
Erin Kenney
Evan Gidez Senior Vice President
[email protected]
Evan Gidez
Christina Ladouceur Senior Vice President
[email protected]
Christina Ladouceur
Nilton Garcez Filho Vice President
mailto:[email protected]
Nilton Garcez Filho
Stephen Ewart Assistant Vice President
[email protected]
Stephen Ewart
Kieren Jarvis Associate Director
[email protected]
Stephen Ewart
Ronan Kennedy Assistant Vice President
[email protected]
Ronan Kennedy


About Aon

Aon (NYSE: AON) exists to shape decisions for the better — to protect and enrich the lives of people around the world. Through actionable analytic insight, globally integrated Risk Capital and Human Capital expertise, and locally relevant solutions, our colleagues provide clients in over 120 countries with the clarity and confidence to make better risk and people decisions that help protect and grow their businesses.

Follow Aon on LinkedIn, X, Facebook and Instagram. Stay up-to-date by visiting Aon’s newsroom and sign up for news alerts here.

©2026 Aon plc. All rights reserved.

Aon is not a law firm or accounting firm and does not provide legal, financial or tax advice. Any commentary provided is based solely on Aon’s experience as insurance practitioners. We recommend that you consult with your own legal, financial and/or insurance advisors on any commentary provided herein. All descriptions, summaries or highlights of coverage described herein are for general informational purposes only and do not amend, alter or modify the actual terms and conditions of any relevant policy. Coverage is governed only by the terms and conditions of such policy. Insurance coverage in any particular case will depend upon the type of policy in effect, the terms, conditions and exclusions in any such policy, and the facts of each unique situation. No representation is made that any specific insurance coverage would apply in the circumstances outlined herein. Please refer to the individual policy forms for specific coverage details.

The information contained in this document and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity.

This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.

Insurance products and services offered by Aon Risk Insurance Services West, Inc., Aon Risk Services Central, Inc., Aon Risk Services Northeast, Inc., Aon Risk Services Southwest, Inc., and Aon Risk Services, Inc. of Florida and their licensed affiliates.