Cyber and 'silent cyber' exclusions in professional indemnity policies
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-05
What "silent cyber" means
"Silent cyber" (also called non-affirmative cyber) describes a policy that neither clearly grants nor clearly excludes cover for a cyber-related loss. The wording was written before cyber risk was a mainstream concern, so it simply said nothing about it. When a hacking, ransomware or data-breach claim landed, both the policyholder and the insurer were left arguing over whether a general professional indemnity or property wording responded.
That ambiguity was uncomfortable for everyone. Insurers could not price a risk they had not explicitly agreed to carry, and policyholders could not rely on cover they were not sure they had. Following guidance from Lloyd's of London and the Prudential Regulation Authority, the market moved to make cyber cover affirmative: every policy should now state, in clear terms, whether cyber exposure is included or excluded. In practice, on standard PI wordings, it is usually excluded.
Why cyber exclusions appear in PI policies
Professional indemnity insurance is designed to respond to claims that you were professionally negligent — that your advice, design or service fell below a reasonable standard and caused a client financial loss. It was never intended to act as a cyber policy.
As cyber losses grew, insurers did not want a PI wording being stretched to pay for events it was never priced for: a ransomware attack, a systems outage, a phishing fraud, or the cost of notifying customers after a breach. So they added an explicit cyber exclusion. The exclusion removes cyber-triggered losses from the PI policy entirely, or narrows cover to a small write-back for a claim of professional negligence that happens to involve technology.
The gap this creates
The exclusion is sensible from an underwriting point of view, but it leaves a hole for any firm that touches client data or relies on IT to deliver its service. A cyber incident can generate two very different types of cost, and the PI exclusion can strip out both:
- Third-party liability — claims from clients or individuals whose data you lost, compensation for distress, and legal costs defending them.
- First-party costs — your own losses: IT forensics, restoring systems and data, business interruption, ransom handling, breach notification, and PR to protect your reputation.
A traditional PI policy would never have covered the first-party costs in any event. But with a firm cyber exclusion in place, even the liability side of a cyber-driven claim can fall outside your PI cover. If you assume "I've got PI, so a data breach is covered," you may be badly wrong.
Check whether your current PI policy carries a cyber exclusion →
PI cover versus cyber cover: what sits where
The two policies answer different questions. PI asks "did your professional work cause a client a loss?" Cyber asks "did an attack on, or failure of, your data and systems cause a loss?" The table below shows the typical split.
| Scenario | Typically PI | Typically Cyber |
|---|---|---|
| Negligent professional advice causes client loss | Yes | No |
| Ransomware locks your systems | No (excluded) | Yes |
| Hacker steals client personal data | No (excluded) | Yes |
| Breach notification and forensic costs | No | Yes |
| Business interruption from a systems outage | No | Yes |
| Invoice / payment diversion fraud | No | Often (crime/cyber) |
This is a general guide only. What your PI policy excludes and what a cyber policy grants depend entirely on the specific wordings, so always read the exclusion clause and the cyber schedule together.
Why data-handling firms in particular need cyber
Almost every professional firm now holds personal data — client records, contact details, financial information, sometimes special category data. Under UK GDPR and the Data Protection Act 2018, you are responsible for keeping it secure, and the Information Commissioner's Office (ICO) can take enforcement action following a breach.
If you are a firm whose service is data — an IT provider, software developer, marketing or analytics business, accountant, recruiter, healthcare administrator or anyone processing large volumes of personal information — a cyber event is not a remote possibility, it is a core operational risk. A single breach can trigger client compensation claims, regulatory scrutiny, notification obligations, downtime and reputational damage all at once. With cyber excluded from PI, standalone cyber insurance is what actually responds.
Cyber cover also brings something PI does not: incident response. Good cyber policies give you access to a breach response team — forensic IT specialists, legal advisers and PR support — on day one, when speed matters most.
Not sure whether your PI leaves you exposed to cyber loss? We'll review your wording and quote both covers together.
Get a PI quote →How to close the gap
- Read the exclusions section of your PI policy and find the cyber wording — confirm whether it is a full exclusion or a limited write-back.
- Map your real exposures: what data you hold, how you'd cope with downtime, and what a client claim after a breach would look like.
- Arrange a standalone cyber policy sized to those exposures — first-party and third-party cover, plus incident response. Illustrative limits of £1m, £2m or £5m are common starting points; the right figure depends on your data volumes and turnover.
- Keep the two policies with a broker who can line up the PI exclusion and the cyber grant so there is no gap and no accidental double-counting.
Common questions
Does my PI policy still cover anything cyber-related?
Sometimes, but narrowly. Some PI wordings keep a limited write-back for a claim of professional negligence that happens to involve technology — for example, advice you gave that turned out to be wrong. But the pure cyber events — hacking, ransomware, data theft, systems failure — are typically excluded. You need to read your specific exclusion to know where the line sits.
Is "silent cyber" still a risk in 2026?
Much less than it was. The market has moved to affirmative wording, so most policies now state clearly whether cyber is in or out. The practical risk today is not ambiguity — it's an explicit exclusion you didn't realise was there, leaving cyber losses uninsured unless you buy separate cover.
Do small firms really need standalone cyber cover?
If you hold client data or depend on IT to trade, yes. Attackers often target smaller firms precisely because defences are lighter, and the cost of a breach — notification, forensics, downtime, compensation — is not proportional to your size. Ask us for a cyber quote alongside your PI renewal.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.
