FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Insights

Where your PI cover stops and cyber begins: the gap larger firms fall into

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Published 2026-09-28
Professional indemnity insures the consequences of getting the work wrong; cyber insures the consequences of your systems being attacked or your data being lost. A growing set of losses sits on the line between the two — and where a firm has bought each policy separately, without checking that they meet in the middle, a claim can slip through the join and land on the firm.

For years, professional indemnity was the one insurance question a partnership or a board really engaged with. It was the cover clients demanded, the cover regulators required, the number written into every contract. Cyber came later, was bought separately, and was often treated as an IT problem rather than a boardroom one. The two policies were placed by different people, at different renewals, on different wordings — and nobody stood back to ask whether, between them, they actually covered everything the firm was exposed to.

That worked while professional risk and technology risk were genuinely separate things. They no longer are. The work is done on systems; the systems hold client money and client data; and the losses that follow a failure increasingly have a foot in both camps. For a larger firm, the important question at renewal is no longer just “how much PI do we carry?” It is “where does our PI cover stop, where does our cyber cover start, and is there daylight between them?”

Two policies, two different jobs

Professional indemnity responds to your civil liability to a client or third party for a negligent act, error or omission in the professional service you provide — bad advice, a missed deadline, a defective design, a flawed valuation. The trigger is a claim against you for getting the work wrong, and the loss it pays is usually the client’s financial loss.

Cyber cover does something quite different. It is built around an attack on, or failure of, your own technology: ransomware, a data breach, a system outage, the cost of investigating and notifying, the business interruption while you are down, and the third-party liability that flows from personal data being compromised. Much of it is first-party — it pays for your own losses and response costs, which a PI policy was never designed to touch.

On paper the division is clean. In practice, a single incident often triggers questions for both.

The grey zone where claims get stuck

Consider a few situations that larger professional firms genuinely face. A conveyancer’s email account is compromised, a fraudulent set of bank details reaches a client, and completion money is sent to a criminal. Is that a professional failure — the firm did not protect its client — or a cyber loss arising from a system intrusion? A consultancy delivers negligent advice, but the error traces back to data that was corrupted when its network was breached: is the resulting claim PI or cyber? A firm loses a tranche of confidential client information; if that happened through a filing error it looks like PI, and if it happened through a hack it looks like cyber — but the client’s loss is identical either way.

These are exactly the losses that can fall between two policies. The PI insurer may say the proximate cause was a cyber event; the cyber insurer may say the loss is really professional liability. Where both wordings are well aligned, one of them responds. Where they are not, the firm can find itself arguing with two insurers at once — or discovering that neither policy clearly picks it up.

Why the join matters more than it used to

The reason this has become a live issue is a change the insurance market made deliberately. For a long time, many traditional policies — PI included — neither clearly covered nor clearly excluded cyber-related losses. That ambiguity became known as “silent” or non-affirmative cyber, and it left both sides guessing when a claim arrived. To end the uncertainty, Lloyd’s required its market to state the position clearly in each policy: either affirm cyber cover or exclude it. The wider market followed, and the International Underwriting Association published a model clause to bring some consistency to how it was done.

The effect is that a great many PI wordings now carry an explicit cyber exclusion. That is not, in itself, a bad thing — it removes the doubt. But an exclusion is only as good as its drafting, and a broadly worded cyber carve-out in a PI policy can strip out more than a firm expects, including losses that feel squarely like professional negligence but happen to involve a system somewhere in the chain. The point of the change was clarity, not generosity, and it puts the burden on the buyer to check what has actually been carved out.

One useful distinction here: regulated professions whose cover is written to minimum terms have less room for a sweeping carve-out. Solicitors’ policies written to the SRA’s Minimum Terms and Conditions, for example, are limited in what insurers may exclude, so a solicitor’s PI generally has to respond to civil liability arising from private legal practice even where technology is part of the story. Open-market PI wordings for unregulated firms carry no such floor, and the cyber exclusion in them can be drawn much more widely. If your firm sits outside a minimum-terms regime, the wording is doing more of the work — so it deserves more of your attention.

Where the data-protection exposure lands

There is a further layer that a traditional PI policy was never built to carry. Under the UK GDPR and the Data Protection Act 2018, a firm that mishandles personal data faces the prospect of regulatory attention from the Information Commissioner’s Office and claims from the individuals affected. The investigation costs, the breach-notification obligations and much of the associated liability are the natural territory of a cyber policy, not a PI one. A firm that assumes its long-standing PI cover has this ground covered can be badly wrong — and it is a fast-moving, high-frequency exposure, not a remote tail risk.

The AI question insurers are now asking

The newest wrinkle is artificial intelligence. As professional firms fold AI tools into research, drafting and analysis, insurers have started asking how those tools are governed and how their output is checked. The underlying legal principle has not changed: the duty of care a professional owes a client is the same whether the work was produced by a person or with the help of a tool, and a firm remains responsible for advice it puts its name to. What is changing is the underwriting conversation. Expect questions at renewal about your AI governance and verification, and expect wordings to keep evolving as insurers work out where an AI-driven error belongs. It is another reason to treat PI and cyber as one connected programme rather than two unrelated purchases.

What a managing partner or FD should actually check

The good news is that the market has been competitive through 2026, with real appetite and room to negotiate terms rather than just price — which makes this a sensible moment to close the join rather than a difficult one. A handful of questions covers most of the ground.

Read the cyber exclusion in your PI wording, and read the definition of “cyber” it relies on — a wide definition quietly widens the exclusion. Then check that your standalone cyber policy actually picks up what the PI policy drops, so the two meet rather than leave a gap. Look specifically at social-engineering and fraudulent-payment losses, which often need crime or cyber cover and are not what a PI policy is for. Make sure the excesses and triggers on the two policies do not conflict, so a single incident does not leave you carrying two deductibles or, worse, falling between two definitions. And ask whether the treatment is consistent across every layer of a stacked PI programme, because an exclusion that differs between the primary and an excess layer is its own kind of gap.

None of this requires the firm to become an expert in policy drafting. It requires the two policies to be looked at together, by someone who can see both wordings at once and say plainly where they meet and where they do not. That is a conversation worth having before renewal, while the market is giving you room to fix it — not after a claim has found the gap for you.

Do your PI and cyber policies actually meet in the middle?

If your firm carries a serious PI limit and a separate cyber policy, it is worth knowing whether they align — or whether there is daylight between them — before renewal, not after a claim tests the join.

Get a director’s second opinion →

Frequently asked

If we already have a cyber policy, do we still need to worry about the cyber exclusion in our PI cover?
Yes — that is exactly when it matters. A gap opens up when the cyber exclusion in the PI policy is wider than the cover the cyber policy provides, so a loss falls out of one without falling into the other. The two wordings need to be read side by side to confirm they overlap rather than leave a strip of uninsured ground between them.

A client emailed our firm’s money to a fraudster after a business-email compromise. Which policy responds?
It depends on the wordings, and it is one of the hardest cases precisely because it has a foot in both camps. Fraudulent-payment and social-engineering losses often sit under crime or cyber cover rather than PI, and a PI cyber exclusion can put them out of reach of the professional policy entirely. This is a good example of why the crime, cyber and PI covers should be mapped together rather than bought in isolation.

Does using AI tools affect our PI cover?
Your duty of care to clients does not change because a tool helped produce the work — you remain responsible for the advice you give. What is changing is that insurers are asking more about how AI is governed and checked, and wordings are still evolving. It is sensible to be able to describe your AI governance clearly at renewal, and to raise it with your broker rather than wait to be asked.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy.

Get a quote →