FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
PI insurance explained

Cyber and 'silent cyber' exclusions in professional indemnity policies

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-05

In short: Most professional indemnity (PI) policies now carry a cyber exclusion, and insurers have removed the old "silent cyber" grey area by stating plainly whether cyber risk is in or out. The result is a real gap: a data breach or hacking loss that PI once might have paid is now excluded. Firms that hold or process client data need standalone cyber cover to close it.

What "silent cyber" means

"Silent cyber" (also called non-affirmative cyber) describes a policy that neither clearly grants nor clearly excludes cover for a cyber-related loss. The wording was written before cyber risk was a mainstream concern, so it simply said nothing about it. When a hacking, ransomware or data-breach claim landed, both the policyholder and the insurer were left arguing over whether a general professional indemnity or property wording responded.

That ambiguity was uncomfortable for everyone. Insurers could not price a risk they had not explicitly agreed to carry, and policyholders could not rely on cover they were not sure they had. Following guidance from Lloyd's of London and the Prudential Regulation Authority, the market moved to make cyber cover affirmative: every policy should now state, in clear terms, whether cyber exposure is included or excluded. In practice, on standard PI wordings, it is usually excluded.

Why cyber exclusions appear in PI policies

Professional indemnity insurance is designed to respond to claims that you were professionally negligent — that your advice, design or service fell below a reasonable standard and caused a client financial loss. It was never intended to act as a cyber policy.

As cyber losses grew, insurers did not want a PI wording being stretched to pay for events it was never priced for: a ransomware attack, a systems outage, a phishing fraud, or the cost of notifying customers after a breach. So they added an explicit cyber exclusion. The exclusion removes cyber-triggered losses from the PI policy entirely, or narrows cover to a small write-back for a claim of professional negligence that happens to involve technology.

The gap this creates

The exclusion is sensible from an underwriting point of view, but it leaves a hole for any firm that touches client data or relies on IT to deliver its service. A cyber incident can generate two very different types of cost, and the PI exclusion can strip out both:

A traditional PI policy would never have covered the first-party costs in any event. But with a firm cyber exclusion in place, even the liability side of a cyber-driven claim can fall outside your PI cover. If you assume "I've got PI, so a data breach is covered," you may be badly wrong.

Check whether your current PI policy carries a cyber exclusion →

PI cover versus cyber cover: what sits where

The two policies answer different questions. PI asks "did your professional work cause a client a loss?" Cyber asks "did an attack on, or failure of, your data and systems cause a loss?" The table below shows the typical split.

Scenario Typically PI Typically Cyber
Negligent professional advice causes client loss Yes No
Ransomware locks your systems No (excluded) Yes
Hacker steals client personal data No (excluded) Yes
Breach notification and forensic costs No Yes
Business interruption from a systems outage No Yes
Invoice / payment diversion fraud No Often (crime/cyber)

This is a general guide only. What your PI policy excludes and what a cyber policy grants depend entirely on the specific wordings, so always read the exclusion clause and the cyber schedule together.

Why data-handling firms in particular need cyber

Almost every professional firm now holds personal data — client records, contact details, financial information, sometimes special category data. Under UK GDPR and the Data Protection Act 2018, you are responsible for keeping it secure, and the Information Commissioner's Office (ICO) can take enforcement action following a breach.

If you are a firm whose service is data — an IT provider, software developer, marketing or analytics business, accountant, recruiter, healthcare administrator or anyone processing large volumes of personal information — a cyber event is not a remote possibility, it is a core operational risk. A single breach can trigger client compensation claims, regulatory scrutiny, notification obligations, downtime and reputational damage all at once. With cyber excluded from PI, standalone cyber insurance is what actually responds.

Cyber cover also brings something PI does not: incident response. Good cyber policies give you access to a breach response team — forensic IT specialists, legal advisers and PR support — on day one, when speed matters most.

Not sure whether your PI leaves you exposed to cyber loss? We'll review your wording and quote both covers together.

Get a PI quote →

How to close the gap

Common questions

Does my PI policy still cover anything cyber-related?

Sometimes, but narrowly. Some PI wordings keep a limited write-back for a claim of professional negligence that happens to involve technology — for example, advice you gave that turned out to be wrong. But the pure cyber events — hacking, ransomware, data theft, systems failure — are typically excluded. You need to read your specific exclusion to know where the line sits.

Is "silent cyber" still a risk in 2026?

Much less than it was. The market has moved to affirmative wording, so most policies now state clearly whether cyber is in or out. The practical risk today is not ambiguity — it's an explicit exclusion you didn't realise was there, leaving cyber losses uninsured unless you buy separate cover.

Do small firms really need standalone cyber cover?

If you hold client data or depend on IT to trade, yes. Attackers often target smaller firms precisely because defences are lighter, and the cost of a breach — notification, forensics, downtime, compensation — is not proportional to your size. Ask us for a cyber quote alongside your PI renewal.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.

Ready to look at cyber cover?
Our online proposal takes about ten minutes — you can save and come back any time, and a broker reviews every submission personally. Prefer to talk it through first? Call 0117 325 0027.
Start your cyber proposal →
Get a quote →