FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
PI insurance explained

Do I need cyber insurance as well as professional indemnity?

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05

In short: Often yes. Professional indemnity (PI) covers claims that you gave negligent professional advice or work. Cyber insurance covers the cost of a data breach or attack — ransomware, IT restoration, breach investigation and notifying affected people. The two rarely overlap, so most firms handling personal data or relying on IT need both.

Two different policies for two different problems

People assume one business policy covers "everything that goes wrong online". It doesn't. PI and cyber are built for separate risks, and each has exclusions that assume the other exists.

Professional indemnity responds when a client alleges your professional service caused them a financial loss — a negligent design, wrong advice, a missed deadline, a defamatory report. It is about the quality of your work and the duty of care you owe.

Cyber insurance responds when your systems or data are compromised — a hacked network, a ransomware demand, an employee emailing a spreadsheet of client details to the wrong address. It covers both your own costs (first-party) and claims made against you by others (third-party liability).

Where PI stops and cyber starts

The clearest way to see the gap is by the type of cost involved.

Scenario Typically PI Typically cyber
Client sues over negligent advice or work
Ransomware locks your systems
Personal data exposed in a breach
Cost of notifying affected individuals
Business interruption after an attack
Fraudulent invoice diversion (social engineering)Often (check wording)

Crucially, many modern PI wordings now carve out cyber losses explicitly. Following work led by Lloyd's and the wider market to remove so-called "silent cyber" — unintended, unpriced cover sitting quietly inside non-cyber policies — insurers increasingly state clearly where a policy does and does not respond to a cyber event. That is good for clarity, but it means you can no longer assume a PI policy will quietly pick up a breach. If you want that cover, you generally need a dedicated cyber policy.

Why data-heavy firms usually need both

If your business holds personal data — client records, employee files, health or financial information — you are a data controller (or processor) under the UK GDPR and the Data Protection Act 2018. That brings legal duties that a breach triggers directly.

Where a personal data breach is likely to result in a risk to people's rights and freedoms, you must report it to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, you may also have to tell the affected individuals. Meeting those obligations takes forensic investigation, legal advice, and communications — the exact costs cyber insurance is designed to fund.

The firms most exposed tend to be:

For these businesses the practical answer is usually both: PI for the advice you give, cyber for the data and systems you depend on. Tell us what your firm does and we'll flag the realistic gaps.

What a cyber policy actually pays for

Cover varies by insurer, but a typical cyber policy is built around two halves.

First-party (your own costs): incident response and IT forensics, data restoration, business interruption while you're offline, cyber extortion and ransomware costs, and breach-notification expenses. Many policies include a 24/7 incident-response team — often the most valuable feature, because the first hours of an attack decide how bad it gets.

Third-party (liability to others): defence costs and damages if affected individuals or clients bring claims, plus cover for regulatory investigation costs and, where legally insurable, certain penalties. Whether a specific regulatory fine can be insured is a legal question and depends on the nature of the fine and public policy — a good broker will explain what a given wording does and does not do.

Can one loss trigger both policies?

Yes — and this is exactly why holding both matters. Imagine a consultancy is breached, client data is stolen, and a client then sues alleging you failed in your professional duty to protect their information. The breach-response and notification costs fall to your cyber policy; the negligence claim from the client may engage your PI policy. Held separately with sensible limits, the two respond to their own part of the event. Held as PI alone, you could find the first-party breach costs simply aren't covered.

How much cover, and how they fit together

Limits are chosen to match your exposure, not picked off a shelf. PI limits are often driven by client contracts and professional-body requirements — common illustrative options run at £1m, £2m or £5m. Cyber limits are driven by how much data you hold and how badly downtime would hurt. There is no single "correct" figure; the right level is the one that reflects your worst realistic scenario.

One point that applies to both: under the Insurance Act 2015 you owe a duty of fair presentation when you buy and renew — a duty to disclose the risk clearly and accurately. For cyber, that includes answering questions about your security controls (things like multi-factor authentication and backups) honestly. Getting those answers right protects your claim later.

Need cover, or just want it explained by a person? Apex places PI for UK professionals — and can line up cyber alongside it.

Get a PI quote →

Common questions

If I only have PI, am I covered for a data breach?

Usually not for the breach itself. PI responds to claims about your professional work, and many wordings now specifically exclude cyber losses. First-party costs like forensics, ransomware and notifying individuals typically need a dedicated cyber policy.

Is cyber insurance a legal requirement in the UK?

No. There is no law requiring cyber insurance. But the underlying duties — notifying the ICO within 72 hours of a qualifying breach under the UK GDPR — are legal obligations, and cyber cover exists to fund the response. Some client contracts also now require it.

We use cloud providers like Microsoft or Google — aren't we covered by them?

No. Cloud providers secure their platform, but responsibility for your data, users and access sits with you. A phishing email or a misconfigured setting on your side is your risk to manage — and to insure.

Not sure which risks actually apply to your firm? Start a quote and we'll talk it through.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for reading your policy wording.

Ready to look at cyber cover?
Our online proposal takes about ten minutes — you can save and come back any time, and a broker reviews every submission personally. Prefer to talk it through first? Call 0117 325 0027.
Start your cyber proposal →
Get a quote →