Security consultants
A security consultant is paid to reduce a danger that can never be eliminated — so when a client is burgled, breached or attacked despite your advice, you are the first person they look to. Professional indemnity insurance answers the allegation that your assessment, plan or survey was negligent, and funds your defence whether or not it was.
Part of: Professional indemnity at Apex
In short
Professional indemnity insurance protects an independent security consultant against claims that your advice, your risk or threat assessment, or your security plan was negligent and caused a client a financial loss. It is the cover that responds when a client argues ‘you assessed us as secure’ or ‘you told us this was enough’ after an intrusion, theft, assault or other security failure. Crucially, it pays your legal defence costs even where the allegation is unfounded — and for advisory work being defended is often the real value, because an incident is not, by itself, proof that your advice fell short. Professional indemnity covers the advice; it sits apart from the public liability and contracting exposures you would take on by installing equipment or supplying guards. There is no statutory minimum limit for security consultants: the figure you carry is driven by your contracts and the scale of the sites you advise on.
You are engaged for your judgement: to assess a site, model the threats against it, and recommend measures proportionate to them. That judgement is the product — and it is exactly what a client questions when something goes wrong. Professional indemnity insurance responds to a civil claim that a failure in your professional work caused a client to lose money.
For a security consultant the exposures are distinctive, because the subject matter is loss itself. Typical allegations include:
The table below sets out how these tend to present and what responds.
| Typical security-consultant claim | What tends to respond |
|---|---|
| A client suffers an intrusion or theft and alleges your threat assessment was negligent | Professional indemnity — defence costs, plus damages for loss attributable to negligent advice |
| A security plan you designed is said to have been inadequate for the risk | Professional indemnity — civil liability for negligent professional services |
| A survey missed a vulnerability that was later exploited | Professional indemnity — negligent error or omission in your work |
| Confidential site-security information is disclosed | Professional indemnity (breach of confidentiality); cyber cover where a data system is involved |
| A visitor is injured, or property damaged, by your physical act during a site visit | Public liability — not professional indemnity |
| An allegation that you acted in breach of a professional or regulatory duty | Professional indemnity defence costs, subject to the wording; the firm’s own dishonesty is usually excluded |
It is the defence, not only the damages, that matters. Advisory claims frequently turn on causation — whether your advice, rather than the offender or the client’s own failings, caused the loss. Disproving that takes expert evidence and lawyers, and professional indemnity funds that work from the outset, win or lose.
Security consultancy shares its defining problem with advice on cyber risk: you are paid to reduce a danger that is never zero. No assessment makes a site impregnable, and no plan can ensure that a determined offender will fail. Yet when an incident happens the client has a real, visible loss and is looking for someone to hold responsible — and the consultant who said the arrangements were sound is an obvious target.
An incident is not proof of negligence. The law does not ask whether your advice was correct with hindsight; it asks whether it was delivered with the reasonable skill and care expected of a competent security consultant at the time, on the information then available. A burglary, a breach or an assault does not, by itself, show that you fell short. It does, however, invite close scrutiny — your report, your assumptions and your recommendations will be read closely and measured against what a reasonable peer would have done.
That is why two things decide most claims:
Your advisory duty is not the same as the client’s own responsibility. You advise; the client owns the risk, controls the budget and decides what to implement. A well-drafted report makes that division explicit and does not overstate what any measure can achieve. Language matters — describing a site as ‘secure’ rather than ‘secured to a standard appropriate for the assessed threat’ is exactly the phrase a claimant will quote back to you.
Professional indemnity covers advice. It is not the right cover — and often not cover at all — for the physical and contracting risks that arise the moment you stop advising and start doing. Knowing where your work sits matters, because the insurance that responds changes at that boundary.
Advisory work sits under professional indemnity. Assessing, surveying, planning, specifying and advising — including advising on a manned-guarding strategy, deployment or escalation procedures — are professional services. If the allegation is that your thinking was negligent, professional indemnity is the relevant cover.
Installing equipment is a different exposure. Fitting locks, barriers, cameras or alarm systems brings product and workmanship risks: faulty installation, damage to a client’s property, injury from equipment you supplied. These fall to public and product liability, not to an advisory professional indemnity policy — and many consultants deliberately stay out of installation to keep their risk profile advisory.
Supplying guards is different again. Providing manned guarding, as opposed to advising on how a client should structure it, makes you a contractor with your own workforce on someone else’s site. That brings employers’ liability, public liability for the acts of your guards, and a contractual exposure that dwarfs the advisory one. It also brings regulation: activities such as manned guarding, door supervision and public-space CCTV monitoring are licensable under the Security Industry Authority regime, and those obligations attach to the people carrying out the work. Advising on a client’s guarding arrangements generally sits outside that regime; deploying guards yourself does not.
If your work ever extends beyond advice into delivery, each activity needs its own cover — a specialist broker can map what you actually do against the covers that respond, so that nothing you are paid for falls into a gap.
The duty insured is reasonable skill and care. The policy does not promise that your advice will prevent every loss — no insurer offers that, and no consultant should claim it. It responds where you are alleged to have fallen below the standard of a reasonably competent security consultant: it protects you against negligence, not against the ordinary possibility that a determined offender defeats sound advice.
Professional indemnity is written on a claims-made basis. This is the mechanism that catches people out. The policy responds to claims first made against you during the policy year, regardless of when you did the work — so the policy in force when the complaint arrives answers it, not the one in force when you wrote the report. Two consequences follow:
There is no statutory minimum — your contracts set the figure. Unlike some regulated professions, security consultants face no legally mandated level of professional indemnity. The right limit is driven instead by what your client contracts require, the value and sensitivity of the sites you advise on, and the scale of loss a disputed assessment could be said to have caused. Check each engagement’s terms before you sign.
Present the risk fully when you arrange cover. Under the Insurance Act 2015 you owe a duty of fair presentation: you must disclose everything a prudent underwriter would want to know — the nature of your work, the sites you advise, and any circumstance that might give rise to a claim. A fair presentation protects the policy; an incomplete one can give the insurer grounds to reduce or decline a claim when you most need it.
It is worth asking us to re-market your cover when:
We would rather say so than waste your time. We are probably not for you if:
No — and it must never be presented that way. Professional indemnity insures the reasonable skill and care of your advice, not an outcome. It responds if you are alleged to have been negligent; it does not promise that a site you assessed will never suffer a loss. Neither your cover nor your advice can guarantee security, and telling a client otherwise would itself create a risk.
No. An incident is not proof of negligence. The question is whether your assessment and advice met the standard of a reasonably competent security consultant on the information available at the time. Professional indemnity funds the expert and legal work needed to answer that allegation, whether or not it ultimately succeeds.
There is no statutory minimum limit for security consultancy. In practice the requirement comes from your contracts: many clients will not engage a consultant without a stated level of professional indemnity in place, and the figure you carry should reflect the contracts you sign and the sites you advise on.
Professional indemnity covers claims arising from your advice and professional work — a negligent assessment, plan or survey. Public liability covers injury to third parties, or damage to their property, arising from your physical activities, such as during a site visit. An advisory practice typically needs both, because they answer entirely different allegations.
Advising on a guarding strategy is professional work and sits under professional indemnity. Actually supplying guards would make you a contractor, bringing employers’ and public liability exposures and the Security Industry Authority licensing that attaches to regulated security activities. Keeping your role advisory keeps your risk profile, and your insurance, straightforward — but tell your broker if that ever changes.
Because professional indemnity is claims-made. The policy responds to complaints made during its year, but usually only for work carried out after the retroactive date. If that date resets when you switch insurer, advice you gave in earlier years can fall outside cover. Preserving it keeps your past assessments protected.
Not safely. Security advice is long-lived, and a claim can arrive years after you give it — potentially after you have stopped trading. A claims-made policy only responds while it is live, so run-off cover is what keeps your past work insured once you no longer need a trading policy.
Whether you assess threats, design security strategy or advise on crisis and resilience, your professional indemnity should match the work you actually do and the contracts you sign. A specialist broker can review your scope, the limit your clients require and your retroactive date, and arrange cover with insurers that understand advisory security risk. Tell us what your consultancy does and we will help you put the right programme in place. Or call 0117 325 0027.
Get a quote Request a callbackApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.