FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
Ransomware · Professional firms

Ransomware and UK professional firms

Ransomware attacks on UK professional firms have become routine. The interaction between PI, cyber, and business interruption cover matters — and most firms miss part of it.

Is it legal to pay a ransom in the UK? Paying is not generally illegal for a private business today, but it is a serious criminal offence if the money reaches anyone under UK financial sanctions (OFSI guidance), or if you know or have reasonable cause to suspect it may fund terrorism (Terrorism Act 2000 s.17). Government proposals would ban payments by public sector bodies, including councils, schools and the NHS, and by regulated critical national infrastructure, and make other victims notify the government before paying; at 28 September 2026 they are not yet law. A cyber policy may meet extortion costs only where payment is lawful and agreed in advance, subject to the policy terms.

Speak to a specialist broker
Get a considered PI quote from Apex
Get a quote Speak to a broker
  • FCA directly authorised, FRN 724952
  • 17 years in business
  • a named broker reads every submission.

Apex places business across 30+ markets and reports 95% client retention; both of those are firm-wide figures covering Apex’s business as a whole.

Reviewed by Apex Insurance Brokers · Published 15 July 2026

What ransomware costs a professional firm

  • Any ransom demand, and the legal risk of paying it (see below).
  • Forensic investigation and remediation.
  • Business interruption — lost fees, staff time, deferred billings.
  • Client notification and remediation obligations.
  • ICO reporting and potential fines.
  • Legal and PR support.

PI vs cyber — where the boundaries lie

PI generally covers professional error resulting in third-party financial loss — a ransomware event may not qualify unless client data was compromised and negligence caused it.

Cyber cover can pick up, subject to the policy terms: forensics, business interruption, breach notification, regulatory defence costs, PR crisis management and, only where payment is lawful and agreed in advance, the ransom itself.

Overlap where client data compromised through professional negligence — both policies may respond.

Standalone cyber cover is materially cheaper than the combined potential loss.

ICO reporting obligations

  1. Personal data breach: 72-hour notification requirement to ICO.
  2. High-risk breach: also notify data subjects.
  3. Failure to notify: penalties up to £8.7m or 2% global turnover.
  4. Preserve evidence — forensics matters for both cyber claim and ICO defence.

Practical steps

  1. Do not pay a ransom without legal advice, sanctions checks and your insurer’s prior consent.
  2. Preserve forensic evidence — do not restore from backup until preserved.
  3. Notify cyber insurer within 24 hours; PI insurer within notification-clause deadline.
  4. Instruct panel breach counsel where cyber policy provides.
  5. Comply with ICO 72-hour clock — do not delay to complete investigation.

Frequently asked

Should we buy cyber if we already have PI?
Yes. PI rarely covers ransom, forensics, business interruption, or ICO defence adequately.
Is it legal to pay a ransom?
Generally yes for a private business today, but not if the payment reaches anyone under UK financial sanctions: that is a serious criminal offence, and OFSI can also impose a civil penalty of up to £1 million or 50% of the value of the breach, whichever is greater. Paying where you know or have reasonable cause to suspect the money may be used for terrorism is also an offence. The government has proposed a ban for public sector bodies and regulated critical national infrastructure, and a duty for other victims to notify it before paying; these are not yet law. Other countries’ sanctions, such as the US’s, may also apply. Take legal advice before any payment.
How much cyber cover is standard?
£250k-£2m for professional firms. Higher for firms handling regulated client data or client money.
What if we self-insure the ransom?
Consider: forensics, business interruption, ICO defence and client remediation costs are often larger than the ransom itself.
Does the insurer decide whether we pay?
Insurers usually reserve the right to decline ransom-payment cover if the payment doesn't meet policy conditions. Broker involvement essential.
What about attorney-client privilege?
Communications with breach counsel typically privileged. Log-file forensics may not be. Legal advice matters early.

Related

Sources

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Firm reference number 724952. Registered in England and Wales, company number 07014570.
Get a quote →