Cybersecurity firms
A cybersecurity firm is paid to reduce a risk that never reaches zero, which makes it unusually exposed: when a client is breached, tested or audited and something still goes wrong, the firm hired to protect or assess them is the obvious target for blame. Professional indemnity — written for technology businesses as technology errors & omissions (tech E&O) — answers the allegation that your service, advice or testing failed the client. This page explains how it works and where it differs from your own cyber cover.
Part of: Technology professional indemnity
In short
Professional indemnity, or technology errors & omissions (tech E&O), protects a cybersecurity firm against claims that its professional services caused a client financial loss — that it missed a vulnerability, scoped an engagement too narrowly, advised badly, or simply failed to stop the breach it was retained to prevent. The defining exposure is failure to detect or prevent: because you are hired precisely to reduce cyber risk, a client breach is easily reframed as your negligence — ‘you were supposed to catch this’. The policy funds your legal defence and any damages or settlement when a client alleges negligent work, and defence costs alone can dwarf the disputed fee. Cover is almost always written on a claims-made basis, so the policy that responds is the one in force when the claim is made, not when the work was done. It is distinct from the cyber policy that protects your own systems, and a security firm typically needs both.
Most professions are sued when they do something wrong. A cybersecurity firm faces a harder problem: it is retained specifically to reduce a risk that can never be eliminated, so when a client is compromised anyway, the firm that was paid to protect, test or advise them is the first place the loss is pointed. The allegation is rarely that you did nothing — it is that you missed something, scoped the work too narrowly, gave assurance you could not stand behind, or failed to warn of a risk you should have spotted.
Professional indemnity, written for technology businesses as technology errors & omissions, responds to that allegation. It meets the cost of defending the claim and any damages or settlement where you are found to have fallen short of the reasonable skill and care expected of a competent security professional. The table below maps the claims a security firm actually sees to the cover that answers them.
| What the client alleges | Typical trigger | What responds |
|---|---|---|
| You failed to detect or prevent a breach | Client compromised despite your monitoring, testing or advice | Professional indemnity / tech E&O |
| You missed a vulnerability | A flaw your assessment should have found is later exploited | Professional indemnity / tech E&O |
| You scoped or advised the work wrongly | Gaps the client says you should have flagged or covered | Professional indemnity / tech E&O |
| Your testing caused an outage or data loss | A test disrupts or corrupts a live system | Professional indemnity, for the financial loss |
| A breach of your own systems exposed client data | Your network, not the client’s, is the one attacked | Your own cyber policy — not tech E&O |
| A report defamed a third party or infringed IP | Wording or reused material in a deliverable draws a complaint | PI often extends to this — check the wording |
Read together, the pattern is clear: tech E&O answers the quality of your service to a client, while a breach of your own network is a different policy. The distinction matters because the same incident — a breach — can sit on either side of the line depending on whose systems failed.
Penetration testing carries exposures that ordinary consultancy does not, because the work itself involves attacking a live environment. A test can knock over a production system, corrupt data, trip fraud controls or cause an outage that costs the client far more than the engagement fee — and if the testing strayed beyond what was agreed, the firm can struggle to argue it was acting reasonably.
Three failures drive most testing claims:
This is why written scope and authorisation are not paperwork — they are the heart of your defence. A signed statement of work that defines exactly which assets, networks and techniques are in scope, a written authorisation to test from someone with authority to give it, and clear rules of engagement (timing, escalation and stop conditions) let you show you acted within your instructions. Insurers expect to see them, and a claim is far easier to defend when the engagement was documented before a single packet was sent. Where you subcontract testing, pin down responsibility for scope and authorisation in writing too.
A managed security service provider, SOC or incident-response firm carries a structural risk that a one-off consultancy does not: it performs the same service for many clients from the same people, tooling and processes. If a single failing — a missed alert pattern, a flawed playbook, an unpatched piece of your own tooling — lets several clients be compromised at once, you can face multiple claims arising from one root cause. Whether those claims are treated as one event or many, and how that interacts with your limit and excess, is governed by the aggregation wording in your policy. It is worth understanding before you need it, because it decides how far a single limit actually stretches.
Contracts make this sharper. Clients increasingly ask security suppliers to accept uncapped liability, to indemnify them against any breach, or to warrant that systems are ‘secure’. These are dangerous to sign. A professional indemnity policy responds to your liability in negligence — your duty to exercise reasonable skill and care — not to obligations you have voluntarily assumed that go beyond it. If you contract to a standard higher than the law would impose, the extra liability may sit outside your cover.
The safest position is also the honest one: you cannot promise perfect security, and you should not contract as if you can. Commit to reasonable skill and care and a defined scope, resist warranties of outcome, and keep any liability cap proportionate to the fee and to the cover you actually hold. A specialist broker can check that what you are about to sign is consistent with what your policy will pay.
This is the distinction a security firm most often gets wrong, sometimes because its own expertise breeds the assumption that it will never be the one that is breached. The two policies answer two different questions.
The boundary is clearest in a single scenario. If you miss a flaw in a client’s network and they are later attacked through it, that is a tech E&O matter — your service is alleged to have failed. If an attacker instead gets into your SOC platform and steals the client logs and credentials you were holding, that is your cyber policy — your systems were breached. The same client, the same data, two completely different policies.
A cybersecurity firm realistically needs both, and should not assume that being good at security removes the need for either. Expertise lowers the chance of your own breach; it does nothing to stop a client alleging your work was negligent, and it is no defence against the cost of proving you were right. Check how the two policies interlock, mind the claims-made trigger and retroactive date on the PI side, and disclose fully at renewal: under the Insurance Act 2015, a fair presentation of the risk is what keeps both policies reliable when you need them.
It is worth asking us to re-market your cover when:
We would rather say so than waste your time. We are probably not for you if:
Yes. Technology errors & omissions (tech E&O) is the name professional indemnity tends to take when it is written for technology and cybersecurity businesses. It covers claims that your professional service — testing, monitoring, consultancy, configuration or advice — was negligent and caused a client financial loss. The label differs; the job is the same.
Not automatically. You are liable only if you fell short of the reasonable skill and care expected of a competent security professional — for example, by missing a flaw your test should have found. But you are very likely to be blamed, and defending that allegation is expensive even when you did nothing wrong. That defence cost is a main reason security firms carry professional indemnity.
Generally no. A cyber policy is built to respond when your own systems are breached. A claim that your testing, monitoring or advice let a client down is third-party professional liability and belongs under technology errors & omissions. Relying on a cyber policy to answer a negligence claim about your service usually leaves a gap, which is why most security firms need both covers.
Because they define what you were instructed to do and prove you had permission to do it. Clear written scope, a signed authorisation from someone able to give it, and agreed rules of engagement let you show you acted within your instructions if a test causes damage or a dispute arises. Without them a claim is far harder to defend, and testing outside scope can raise issues beyond a civil claim.
Be very cautious. Professional indemnity responds to your liability in negligence, not to obligations you take on that go beyond reasonable skill and care. Warranting an outcome you cannot control, or accepting uncapped liability, can create exposure your policy will not pay. Keep commitments to reasonable care and a defined scope, keep any liability cap proportionate, and have the wording checked before you sign.
It means the policy that responds is the one in force when a claim is made against you, not the one in force when you did the work. If you let cover lapse, claims about past engagements may have nothing to respond to, so continuous cover and the right retroactive date matter. When you stop trading or exit a contract, run-off cover keeps you protected for work already done.
Yes. Because you serve many clients with the same people, tooling and processes, a single failing can affect several at once and produce multiple claims from one root cause. How your policy aggregates those claims decides how far your limit stretches, so it is worth reviewing your aggregation wording, limit and excess with a specialist broker with this scenario specifically in mind.
Tell a specialist broker what your firm actually does — penetration testing, managed detection, SOC, incident response or consultancy — and the contracts you are being asked to sign. The right programme usually pairs technology errors & omissions with your own cyber cover, with limits and wording matched to your work. Get a quote and compare terms before your next engagement or renewal. Or call 0117 325 0027.
Get a quote Request a callbackApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.