Cyber security consultant insurance
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
You spend your working life finding the holes in other people's defences. Penetration tests, red-team engagements, security assessments, remediation advice, board-level reporting on risk. It is precise, high-trust work, and your clients act on what you tell them. That is exactly why your own insurance deserves the same rigour you apply to their environments. This page walks through the covers that genuinely matter for a cyber security consultancy or independent consultant in the UK, why each one exists, and what your clients will almost certainly demand before they sign.
What insurance does a cyber security consultant actually need?
There is no single "cyber consultant policy" that ticks every box by name, but the shape of the right programme is fairly consistent across the sector. Most firms doing penetration testing and security advisory need four things working together: technology professional indemnity for the work and advice itself, cyber insurance for the data and systems you touch, public liability for the physical side of visiting client premises, and employers' liability the moment you take on staff. Depending on your output — reports, training material, published research — a media or intellectual property extension can matter too.
The reason it stacks up this way is that a single engagement can expose you on several fronts at once. Miss a critical vulnerability and the client suffers a loss: that is a professional indemnity question. Get breached yourself while holding a client's scoping data or credentials: that is a cyber question. Trip over a server-room cable on site: public liability. One incident, several policies, which is why these covers are usually arranged as one coordinated programme rather than bought piecemeal.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure whether your current cover would respond to a missed vulnerability or a breach of your own systems? Let an Apex technology specialist pressure-test it with you.
Get a tailored quote →Why do I need technology professional indemnity as a pen tester?
Technology professional indemnity — sometimes called technology errors and omissions, or tech E&O, which is simply the American term for the same cover — responds when a client alleges that a mistake, oversight or negligent piece of advice in your work caused them financial loss. For a security consultant, the exposure is unusually direct. Your entire value is your judgement about where the risk sits. If you run a penetration test and miss an exploitable vulnerability, or scope an assessment too narrowly, or sign off a remediation that turns out to be incomplete, and the client is later compromised through that gap, they may look to you for the consequences.
That is not a remote or theoretical exposure; it is the core professional risk of the discipline. Tech PI is what funds your legal defence and any damages if such a claim is made, whether or not you were actually at fault. A well-structured technology PI policy for a consultancy of this kind should be written to cover advisory work, testing services, and any software or tooling you develop and deploy in the course of an engagement. If you build and licence your own tooling, make sure the wording reflects that rather than assuming a pure advisory scope.
One important point on framing: professional indemnity is not a statutory legal requirement for IT and technology firms in the UK. What makes it effectively unavoidable is your clients. It is almost always a contractual requirement, written into master services agreements and statements of work, often at a specified limit. You can read more in our guide to technology professional indemnity insurance.
If I secure other people, why would I need my own cyber insurance?
This is the question we hear most often from security professionals, and it deserves a straight answer: being good at defence does not make you un-breachable, and it certainly does not remove the data you are holding. During an engagement you routinely handle some of the most sensitive material a client has — network diagrams, credentials, scoping documents, vulnerability findings, sometimes live access to production systems. That data sitting in your environment is a target in its own right, and a compromise of your consultancy could be far more damaging than a compromise of an average small business.
Tech PI and cyber insurance answer different questions. Tech PI is about harm to your client caused by your work. Cyber insurance is about an incident affecting your own systems and the data you hold — a ransomware attack, a business email compromise, a breach of client information you were entrusted with. A good cyber policy is really an incident-response service wrapped in cover: it funds forensic investigation, legal and regulatory support, notification of affected parties, and the cost of getting your operations back on their feet, alongside your business interruption losses and any third-party liability that flows from the breach.
A word on regulatory fines, because it is widely misunderstood. Under UK GDPR and the Data Protection Act 2018, the Information Commissioner's Office (ICO) can impose penalties for serious data-protection failures. The insurability of such fines in the UK is legally uncertain and is frequently excluded or restricted by policies — you should never assume cyber insurance will simply pay a regulatory penalty on your behalf. What cyber cover reliably does is fund the breach response, the business interruption, and the third-party claims that follow an incident, which are usually the larger and more immediate costs. Our explainer on cyber insurance goes into the detail.
Should tech PI and cyber be one combined technology policy?
For most cyber security consultancies, yes — a combined technology policy that bundles tech PI and cyber into a single contract is usually the cleaner route. The practical advantage is that it closes the grey area between the two. When a real incident happens, it is often genuinely arguable whether the trigger was your professional work or a cyber event: a breach that flows from a missed vulnerability, for example, has elements of both. When the two covers sit with one insurer under one policy, you avoid the risk of two insurers each pointing at the other while your claim stalls.
A combined policy also tends to be more straightforward to administer and to present to clients, who increasingly want to see both PI and cyber evidenced on a single certificate. It is not the only valid structure — larger firms sometimes have good reasons to place covers separately, or to carry higher, standalone limits — but for a typical consultancy it removes friction where it matters most. If you want to weigh the two approaches, see our comparison of professional indemnity vs cyber insurance for tech companies, or the dedicated page on a combined technology policy.
Do I need public liability if I work on client sites?
Plenty of security work is remote, but a good deal of it is not. On-site testing, physical security assessments, social-engineering exercises, workshops and board briefings all put you in someone else's building. Public liability responds if you cause injury to a third party or damage their property in the course of your work — the classic example being accidental damage on a client's premises, but it extends to any bodily-injury or property-damage claim brought by a third party arising from your activities.
Even where the physical risk feels low, public liability is often written into client and landlord contracts as a baseline requirement, so it earns its place in the programme for commercial reasons as much as protective ones. If you rent office or lab space, or attend client sites regularly, treat it as standard rather than optional.
When does employers' liability become a legal requirement?
The moment you employ anyone — an analyst, an apprentice, an office manager, even most part-time or temporary staff — employers' liability insurance becomes a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969. There are narrow exceptions, for example some businesses employing only close family members or certain owner-only companies, but for a growing consultancy the general rule is simple: staff means you must carry it. It covers claims from employees who are injured or made ill as a result of their work for you.
This is the one genuinely non-negotiable, statutory cover on the list, and it is worth arranging correctly from day one of your first hire rather than as an afterthought. If you are a sole trader today but expect to bring people on, flag it with your broker early so the transition is seamless.
What about my reports, research and IP?
Security consultants produce a lot of written and published output — detailed findings, methodologies, training content, and sometimes public research or disclosures. Where you publish, present or distribute material, a media and intellectual property liability element can respond to allegations such as defamation or infringement of a third party's IP arising from that content. Whether this belongs in your programme depends on how much you publish and how public-facing your work is; for a research-active firm it can be worth building in, while a purely private-engagement consultancy may not need it. It is a conversation to have based on what you actually produce, not a box everyone ticks.
Does insurance affect my IR35 status?
No — and it is important to be clear on this because the two topics get tangled together for contractors. IR35, the off-payroll working rules, is a tax matter about whether HMRC treats you as employed or self-employed for tax purposes on a given engagement. Holding professional indemnity, cyber or any other insurance does not change, improve or determine your IR35 status. The covers on this page exist to protect you against professional and cyber risk; they are not an IR35 tool. For your actual status and how to structure engagements, speak to a qualified accountant or tax adviser who deals with contractor tax. If you operate as an independent, our IT contractor insurance guide covers the insurance side.
What drives the cost of the cover?
We do not quote figures blind, because the price reflects your specific profile rather than a sticker rate. The main factors an insurer weighs for a cyber security consultancy are your annual fee income, the nature of the work (advisory-only versus live testing and exploitation), the sensitivity and volume of client data you hold, your own security posture and controls, your claims history, and the limits of indemnity you need to carry — commonly driven by what your client contracts demand.
On limits, clients frequently specify a required level in the contract, and typical illustrative options you will see discussed are £1m, £5m or £10m of indemnity, chosen to match the scale of the clients and engagements you take on. The right number is the one that satisfies your contractual obligations and reflects your realistic worst-case exposure, not the cheapest tier available. A broker who understands technology risk will help you land on limits that hold up rather than ones that merely look compliant on paper.
- Fee income and headcount — the size and scale of what you do.
- Type of work — hands-on penetration testing and exploitation carry a different risk profile from advisory-only engagements.
- Data you hold — the volume and sensitivity of client information in your environment.
- Your own controls — the security measures protecting your consultancy.
- Required limits — often set by your client contracts.
How Apex helps cyber security firms get this right
We work with technology and IT businesses every day, and we understand that a security consultancy is not a generic professional-services firm with a laptop. The overlap between your professional work and your cyber exposure is where cover falls down if the wording is loose, and it is exactly where we spend our time making sure your tech PI and cyber respond as one. We will map your engagements, read the insurance clauses in your key client contracts, and build a programme that both protects you and lets you say yes to the work you want to win. For a wider view of the sector, our overview of what insurance an IT company needs is a useful companion to this page.
Whether you are a solo pen tester or a growing security practice, we will build cover around the way you actually work — and check it against what your clients demand.
Get a tailored quote →If you would rather talk it through than fill in a form, speak to an Apex technology specialist and we will start from your engagements and contracts, not a generic template.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
