Ransomware attacks on UK professional firms have become routine. The interaction between PI, cyber, and business interruption cover matters — and most firms miss part of it.
Is it legal to pay a ransom in the UK? Paying is not generally illegal for a private business today, but it is a serious criminal offence if the money reaches anyone under UK financial sanctions (OFSI guidance), or if you know or have reasonable cause to suspect it may fund terrorism (Terrorism Act 2000 s.17). Government proposals would ban payments by public sector bodies, including councils, schools and the NHS, and by regulated critical national infrastructure, and make other victims notify the government before paying; at 28 September 2026 they are not yet law. A cyber policy may meet extortion costs only where payment is lawful and agreed in advance, subject to the policy terms.
Apex places business across 30+ markets and reports 95% client retention; both of those are firm-wide figures covering Apex’s business as a whole.
PI generally covers professional error resulting in third-party financial loss — a ransomware event may not qualify unless client data was compromised and negligence caused it.
Cyber cover can pick up, subject to the policy terms: forensics, business interruption, breach notification, regulatory defence costs, PR crisis management and, only where payment is lawful and agreed in advance, the ransom itself.
Overlap where client data compromised through professional negligence — both policies may respond.
Standalone cyber cover is materially cheaper than the combined potential loss.