PI insurance vs cyber insurance: what's the difference, and do you need both?
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05
PI and cyber insurance are often confused because both can respond when a client's data or money is affected. But they are built for different problems. One is about the quality of your professional work; the other is about the security and availability of your IT and data. Understanding where they meet — and where neither reaches — is the key to not being caught out.
What professional indemnity insurance covers
Professional indemnity insurance responds to claims arising from your professional services: a mistake, an act of negligence, a missed deadline, bad advice, or a breach of professional duty that leaves a client out of pocket. It typically covers your legal defence costs and any damages or settlement you become liable to pay.
Common triggers include a design error, a flawed report, an accounting slip, a negligent misstatement, or professional advice a client relied on to their detriment. For many regulated professions — solicitors, accountants, architects, surveyors, financial advisers — PI is a mandatory condition of practising or of membership of a professional body.
PI is almost always written on a claims-made basis. That means the policy that responds is the one in force when the claim is made against you, not the one in force when you did the work. Continuity of cover, and retroactive dates, therefore matter enormously — a gap in cover can leave old work unprotected.
What cyber insurance covers
Cyber insurance responds to cyber incidents and their fallout. A typical policy is split into first-party cover (your own losses and costs) and third-party cover (your liability to others).
First-party cover usually includes:
- Incident response — specialist IT forensics, legal and PR support to contain and investigate a breach
- Ransomware and cyber extortion costs, including negotiation and, where lawful, ransom payments
- Data restoration and system repair after an attack
- Business interruption — lost income while systems are down
- Notification costs — telling affected individuals and the regulator when a personal data breach occurs
Third-party cover typically includes your liability to clients or individuals whose data was compromised, defence of regulatory investigations, and any fines or penalties that are legally insurable.
The notification point is worth stressing. Under the UK GDPR and the Data Protection Act 2018, a personal data breach must in many cases be reported to the Information Commissioner's Office (ICO) without undue delay — and, where required, generally within 72 hours of becoming aware of it. Meeting that obligation costs real money in advice and administration, and cyber cover is designed to fund it.
PI vs cyber: a side-by-side comparison
| Professional indemnity | Cyber | |
|---|---|---|
| Core risk | Errors in your professional work or advice | Breaches, hacking, ransomware, data loss, outage |
| Typical trigger | A client alleges negligence and financial loss | A cyber attack or data incident affecting you |
| Who it protects | Mainly your liability to clients | Your own costs and your liability to others |
| Notification costs | Not usually covered | Core feature |
| Business interruption | No | Commonly included |
| Basis | Claims-made | Usually claims-made, with incident response often on a discovery basis |
Where they overlap — and where the gaps hide
The grey area is a professional mistake involving data or technology. Suppose a consultant misconfigures a client's system and, as a result, the client's data is exposed. Is that a professional error (PI) or a cyber event (cyber)? The honest answer is: it depends entirely on the wording of each policy and how the loss is characterised.
This is where firms get caught. A PI policy may exclude losses arising from a cyber breach, on the basis that cyber is a separate class of risk. A cyber policy may exclude claims that are really about the standard of your professional work. Between two narrowly drafted wordings, a genuine loss can fall down the gap in the middle — each insurer pointing at the other.
Two practical points follow. First, read the cyber exclusion in your PI policy carefully; some are broad enough to strip out cover you assumed you had. Second, where you carry both, it is worth having them reviewed together so the boundary between them is deliberate rather than accidental. A broker who places both can line the wordings up. Ask Apex to review your cover for gaps.
Who needs both?
As a rule of thumb, if your work involves professional advice or services and you hold client data or depend on IT to operate, you are exposed to both risks and should consider both covers. That describes a large share of modern professional firms.
- IT, software and data firms — the clearest case. A coding or configuration error is a PI matter; a breach of the systems or data you hold is a cyber matter. Both are live risks, often at once.
- Accountants, financial advisers and bookkeepers — PI for advice; cyber for the sensitive client financial data they hold and the phishing and fraud risk that comes with it.
- Solicitors and law firms — PI is mandatory; cyber addresses client confidentiality, and the well-known risk of funds being diverted by attackers during transactions.
- Consultants, marketers, designers and architects — PI for the work product; cyber for client data and business continuity.
The smaller and less data-heavy your firm, the more you might reasonably prioritise one over the other — but very few professional businesses today have zero cyber exposure. Email alone is enough to be a target.
How to decide what you need
Start with your obligations. If a professional body or a client contract requires PI at a set limit, that is your floor. Then map your data and IT dependency: what personal or confidential data you hold, and what happens to your income if your systems go down for a week. That tells you whether cyber is a genuine need or a nice-to-have.
Under the Insurance Act 2015, businesses have a duty to make a fair presentation of the risk when buying or renewing commercial insurance — disclosing what you know, or ought to know, in a clear and accessible way. Getting your disclosures right on both PI and cyber proposals is not box-ticking; it is what keeps the cover reliable when you need to claim.
Common questions
Does professional indemnity insurance cover a data breach?
Usually not in the way a cyber policy does. PI may respond if a breach stems from a negligent professional error and a client sues over it, but PI does not typically fund breach response, notification, ransomware or business interruption. Many PI policies also contain a specific cyber exclusion. For breach costs, cyber cover is the right tool.
Is cyber insurance a legal requirement in the UK?
No. There is no general legal requirement to hold cyber insurance. However, the UK GDPR imposes real obligations to protect personal data and to report certain breaches to the ICO, and client contracts increasingly require cyber cover. It is voluntary, but for data-handling firms it is fast becoming a practical necessity.
Can I get PI and cyber under one policy?
Sometimes. Some insurers offer combined or packaged covers, and some PI policies include a limited cyber extension. These can be convenient, but the cyber element is often narrower than a standalone cyber policy. The right structure depends on your exposure — which is worth talking through with a broker rather than assuming a bundle is enough.
Need cover, or just want it explained by a person? Apex places PI for UK professionals — and can review your PI and cyber together so nothing falls through the gap.
Get a PI quote →PI and cyber are not competing choices so much as two halves of a professional firm's protection: one for the work you do, one for the data and systems you rely on to do it. If you are unsure where your current cover ends, talk it through with Apex before you renew.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for reading your policy wording.
