FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
PI insurance explained

PI insurance vs cyber insurance: what's the difference, and do you need both?

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05

In short: Professional indemnity (PI) insurance covers claims that you gave negligent professional advice or service that caused a client financial loss. Cyber insurance covers the costs of a cyber incident — a data breach, ransomware, hacking or system outage — including breach response, notification, business interruption and third-party liability. They protect against different risks, and many firms need both.

PI and cyber insurance are often confused because both can respond when a client's data or money is affected. But they are built for different problems. One is about the quality of your professional work; the other is about the security and availability of your IT and data. Understanding where they meet — and where neither reaches — is the key to not being caught out.

What professional indemnity insurance covers

Professional indemnity insurance responds to claims arising from your professional services: a mistake, an act of negligence, a missed deadline, bad advice, or a breach of professional duty that leaves a client out of pocket. It typically covers your legal defence costs and any damages or settlement you become liable to pay.

Common triggers include a design error, a flawed report, an accounting slip, a negligent misstatement, or professional advice a client relied on to their detriment. For many regulated professions — solicitors, accountants, architects, surveyors, financial advisers — PI is a mandatory condition of practising or of membership of a professional body.

PI is almost always written on a claims-made basis. That means the policy that responds is the one in force when the claim is made against you, not the one in force when you did the work. Continuity of cover, and retroactive dates, therefore matter enormously — a gap in cover can leave old work unprotected.

What cyber insurance covers

Cyber insurance responds to cyber incidents and their fallout. A typical policy is split into first-party cover (your own losses and costs) and third-party cover (your liability to others).

First-party cover usually includes:

Third-party cover typically includes your liability to clients or individuals whose data was compromised, defence of regulatory investigations, and any fines or penalties that are legally insurable.

The notification point is worth stressing. Under the UK GDPR and the Data Protection Act 2018, a personal data breach must in many cases be reported to the Information Commissioner's Office (ICO) without undue delay — and, where required, generally within 72 hours of becoming aware of it. Meeting that obligation costs real money in advice and administration, and cyber cover is designed to fund it.

PI vs cyber: a side-by-side comparison

  Professional indemnity Cyber
Core risk Errors in your professional work or advice Breaches, hacking, ransomware, data loss, outage
Typical trigger A client alleges negligence and financial loss A cyber attack or data incident affecting you
Who it protects Mainly your liability to clients Your own costs and your liability to others
Notification costs Not usually covered Core feature
Business interruption No Commonly included
Basis Claims-made Usually claims-made, with incident response often on a discovery basis

Where they overlap — and where the gaps hide

The grey area is a professional mistake involving data or technology. Suppose a consultant misconfigures a client's system and, as a result, the client's data is exposed. Is that a professional error (PI) or a cyber event (cyber)? The honest answer is: it depends entirely on the wording of each policy and how the loss is characterised.

This is where firms get caught. A PI policy may exclude losses arising from a cyber breach, on the basis that cyber is a separate class of risk. A cyber policy may exclude claims that are really about the standard of your professional work. Between two narrowly drafted wordings, a genuine loss can fall down the gap in the middle — each insurer pointing at the other.

Two practical points follow. First, read the cyber exclusion in your PI policy carefully; some are broad enough to strip out cover you assumed you had. Second, where you carry both, it is worth having them reviewed together so the boundary between them is deliberate rather than accidental. A broker who places both can line the wordings up. Ask Apex to review your cover for gaps.

Who needs both?

As a rule of thumb, if your work involves professional advice or services and you hold client data or depend on IT to operate, you are exposed to both risks and should consider both covers. That describes a large share of modern professional firms.

The smaller and less data-heavy your firm, the more you might reasonably prioritise one over the other — but very few professional businesses today have zero cyber exposure. Email alone is enough to be a target.

How to decide what you need

Start with your obligations. If a professional body or a client contract requires PI at a set limit, that is your floor. Then map your data and IT dependency: what personal or confidential data you hold, and what happens to your income if your systems go down for a week. That tells you whether cyber is a genuine need or a nice-to-have.

Under the Insurance Act 2015, businesses have a duty to make a fair presentation of the risk when buying or renewing commercial insurance — disclosing what you know, or ought to know, in a clear and accessible way. Getting your disclosures right on both PI and cyber proposals is not box-ticking; it is what keeps the cover reliable when you need to claim.

Common questions

Does professional indemnity insurance cover a data breach?

Usually not in the way a cyber policy does. PI may respond if a breach stems from a negligent professional error and a client sues over it, but PI does not typically fund breach response, notification, ransomware or business interruption. Many PI policies also contain a specific cyber exclusion. For breach costs, cyber cover is the right tool.

Is cyber insurance a legal requirement in the UK?

No. There is no general legal requirement to hold cyber insurance. However, the UK GDPR imposes real obligations to protect personal data and to report certain breaches to the ICO, and client contracts increasingly require cyber cover. It is voluntary, but for data-handling firms it is fast becoming a practical necessity.

Can I get PI and cyber under one policy?

Sometimes. Some insurers offer combined or packaged covers, and some PI policies include a limited cyber extension. These can be convenient, but the cyber element is often narrower than a standalone cyber policy. The right structure depends on your exposure — which is worth talking through with a broker rather than assuming a bundle is enough.

Need cover, or just want it explained by a person? Apex places PI for UK professionals — and can review your PI and cyber together so nothing falls through the gap.

Get a PI quote →

PI and cyber are not competing choices so much as two halves of a professional firm's protection: one for the work you do, one for the data and systems you rely on to do it. If you are unsure where your current cover ends, talk it through with Apex before you renew.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for reading your policy wording.

Ready to look at cyber cover?
Our online proposal takes about ten minutes — you can save and come back any time, and a broker reviews every submission personally. Prefer to talk it through first? Call 0117 325 0027.
Start your cyber proposal →
Get a quote →