Do I need cyber insurance as well as professional indemnity?
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05
Two different policies for two different problems
People assume one business policy covers "everything that goes wrong online". It doesn't. PI and cyber are built for separate risks, and each has exclusions that assume the other exists.
Professional indemnity responds when a client alleges your professional service caused them a financial loss — a negligent design, wrong advice, a missed deadline, a defamatory report. It is about the quality of your work and the duty of care you owe.
Cyber insurance responds when your systems or data are compromised — a hacked network, a ransomware demand, an employee emailing a spreadsheet of client details to the wrong address. It covers both your own costs (first-party) and claims made against you by others (third-party liability).
Where PI stops and cyber starts
The clearest way to see the gap is by the type of cost involved.
| Scenario | Typically PI | Typically cyber |
|---|---|---|
| Client sues over negligent advice or work | ✓ | — |
| Ransomware locks your systems | — | ✓ |
| Personal data exposed in a breach | — | ✓ |
| Cost of notifying affected individuals | — | ✓ |
| Business interruption after an attack | — | ✓ |
| Fraudulent invoice diversion (social engineering) | — | Often (check wording) |
Crucially, many modern PI wordings now carve out cyber losses explicitly. Following work led by Lloyd's and the wider market to remove so-called "silent cyber" — unintended, unpriced cover sitting quietly inside non-cyber policies — insurers increasingly state clearly where a policy does and does not respond to a cyber event. That is good for clarity, but it means you can no longer assume a PI policy will quietly pick up a breach. If you want that cover, you generally need a dedicated cyber policy.
Why data-heavy firms usually need both
If your business holds personal data — client records, employee files, health or financial information — you are a data controller (or processor) under the UK GDPR and the Data Protection Act 2018. That brings legal duties that a breach triggers directly.
Where a personal data breach is likely to result in a risk to people's rights and freedoms, you must report it to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, you may also have to tell the affected individuals. Meeting those obligations takes forensic investigation, legal advice, and communications — the exact costs cyber insurance is designed to fund.
The firms most exposed tend to be:
- IT, software and tech consultancies — you hold client systems and data, and an incident can cascade to their operations.
- Professional services — accountants, solicitors, surveyors, recruiters and consultants sit on concentrated personal and financial data.
- Healthcare and wellbeing practitioners — special category data carries a higher regulatory bar.
- Any firm reliant on email, cloud tools or online payments — which is now almost every firm.
For these businesses the practical answer is usually both: PI for the advice you give, cyber for the data and systems you depend on. Tell us what your firm does and we'll flag the realistic gaps.
What a cyber policy actually pays for
Cover varies by insurer, but a typical cyber policy is built around two halves.
First-party (your own costs): incident response and IT forensics, data restoration, business interruption while you're offline, cyber extortion and ransomware costs, and breach-notification expenses. Many policies include a 24/7 incident-response team — often the most valuable feature, because the first hours of an attack decide how bad it gets.
Third-party (liability to others): defence costs and damages if affected individuals or clients bring claims, plus cover for regulatory investigation costs and, where legally insurable, certain penalties. Whether a specific regulatory fine can be insured is a legal question and depends on the nature of the fine and public policy — a good broker will explain what a given wording does and does not do.
Can one loss trigger both policies?
Yes — and this is exactly why holding both matters. Imagine a consultancy is breached, client data is stolen, and a client then sues alleging you failed in your professional duty to protect their information. The breach-response and notification costs fall to your cyber policy; the negligence claim from the client may engage your PI policy. Held separately with sensible limits, the two respond to their own part of the event. Held as PI alone, you could find the first-party breach costs simply aren't covered.
How much cover, and how they fit together
Limits are chosen to match your exposure, not picked off a shelf. PI limits are often driven by client contracts and professional-body requirements — common illustrative options run at £1m, £2m or £5m. Cyber limits are driven by how much data you hold and how badly downtime would hurt. There is no single "correct" figure; the right level is the one that reflects your worst realistic scenario.
One point that applies to both: under the Insurance Act 2015 you owe a duty of fair presentation when you buy and renew — a duty to disclose the risk clearly and accurately. For cyber, that includes answering questions about your security controls (things like multi-factor authentication and backups) honestly. Getting those answers right protects your claim later.
Need cover, or just want it explained by a person? Apex places PI for UK professionals — and can line up cyber alongside it.
Get a PI quote →Common questions
If I only have PI, am I covered for a data breach?
Usually not for the breach itself. PI responds to claims about your professional work, and many wordings now specifically exclude cyber losses. First-party costs like forensics, ransomware and notifying individuals typically need a dedicated cyber policy.
Is cyber insurance a legal requirement in the UK?
No. There is no law requiring cyber insurance. But the underlying duties — notifying the ICO within 72 hours of a qualifying breach under the UK GDPR — are legal obligations, and cyber cover exists to fund the response. Some client contracts also now require it.
We use cloud providers like Microsoft or Google — aren't we covered by them?
No. Cloud providers secure their platform, but responsibility for your data, users and access sits with you. A phishing email or a misconfigured setting on your side is your risk to manage — and to insure.
Not sure which risks actually apply to your firm? Start a quote and we'll talk it through.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for reading your policy wording.
