Consultants regularly handle sensitive client data, give advice that affects clients’ finances or compliance, and rely on digital systems. Which insurance matters first: cyber insurance or professional indemnity? Practical decisions depend on contract terms, the nature of advice, and where financial losses arise.
Quick clarity helps reduce exposure without technical complexity. The following explains differences, overlaps, likely gaps, sample clauses and a short decision route tailored to UK consultants.
Key takeaways
- PI protects negligent advice and professional errors; cyber protects data incidents, extortion and IT failure.
- Many PI policies exclude or limit cyber-related liabilities; cyber policies frequently exclude negligent professional advice.
- If advice errors cause direct financial loss to a client, PI is usually primary; if a data breach, ransomware or business interruption due to digital failure occurs, cyber is usually primary.
- For most consultants, holding both covers the majority of practical risks, consider limits, retroactive dates and aggregates.
- Contracts and client requirements often dictate priority; review wording and consider endorsed cover or combined packages where available.
How PI and cyber insurance differ for consultants
What professional indemnity (PI) typically covers
Professional indemnity (PI) is designed to respond when a client alleges a negligent act, error or omission in the provision of professional services that causes a financial loss. Typical examples for consultants include: flawed financial modelling, incorrect compliance advice, late or incorrect project specifications, and mistake-driven contract breaches. PI generally covers defence costs, settlements and damages for covered claims, and can include costs of rectification where expressly written into the policy wording.
What cyber insurance typically covers
Cyber insurance focuses on incidents related to information security, IT systems and data privacy. Common cover elements include: incident response and forensic costs, data breach notification and credit monitoring, regulatory response costs and fines (subject to policy wording and insurer stance), business interruption from system outage, and cyber extortion/ransom payments. Many policies also include access to incident response vendors and legal/PR support.
Key differences at a glance (HTML comparative table)
| Event / Loss |
PI likely to cover? |
Cyber likely to cover? |
Typical policy limit examples (indicative) |
| Negligent advice causing client loss |
Yes, primary cover (if claim arises from professional services) |
Usually no, typically excluded unless explicit wording |
£100k–£5m+ (PI) |
| Client data breach (personal data exposed) |
Possibly, narrow cover for defence if allegation links to advice, often excluded for pure data breach |
Yes, primary cover for breach notification, forensics, PR, and regulatory response |
£50k–£10m (Cyber) |
| Ransomware / extortion |
No |
Yes, often includes ransom, negotiation, recovery (subject to policy wording and sanctions rules) |
£100k–£5m (Cyber) |
| Business interruption from systems failing |
Sometimes, only if linked to negligent consulting deliverables |
Yes, typically a core part of cyber cover |
Dependent on sum insured; indemnity periods 30–180 days |
(NB: Examples are indicative and current at time of writing.)
Should consultants choose Cyber or Professional Indemnity first?
Decision order depends on the nature of the consultancy, client exposure and contractual obligations. For clarity:
Prioritise PI where advice or design causes direct financial loss
For consultancies whose principal risk is giving expert advice or producing deliverables that, if wrong, will cause client financial loss (for instance, financial, tax, HR or regulatory consultants), PI usually sits at the core of risk management. PI responds to negligent advice claims; without it, a single claim could quickly erode capital.
Prioritise cyber where data handling, online services or IT availability are central
Where the business stores or processes personal data, operates online platforms, or provides cloud-hosted services, cyber exposure is material. Losses from a breach, regulatory costs, notification, forensic response and customer remediation, can be substantial even without a negligence allegation.
Practical decision route (short)
- Review primary revenue sources: are losses from advice or incidents more likely?
- Check client contracts for insurance clauses and minimum limits.
- If both advice-related and cyber risks exist, consider obtaining both, prioritising immediate exposure and cashflow capacity.

Cyber or PI for GDPR fines after a breach?
GDPR and UK data protection law can create regulatory scrutiny and, in some cases, monetary penalties. The Information Commissioner's Office (ICO) ICO handles data protection enforcement in the UK. Important points:
- Regulatory fines and insurance: Many insurers exclude fines and penalties. Some cyber policies provide cover for regulatory fines arising from data breaches, but this varies and often carries conditions or sub-limits. Where cover exists, it is usually subject to exclusions (for wilful breach or where cover is prohibited by law). Always check policy wording for references to fines, penalties or regulatory sanctions.
- Defence and investigation costs: Both cyber and PI may cover costs of defending investigations or regulatory responses, but allocation depends on the cause, cyber tends to pay for forensic and notification work; PI tends to meet defence costs where alleged professional negligence is the issue.
- ICO guidance and precedent: Recent ICO enforcement actions and guidance shape insurer behaviour; insurers consider the detail of whether a fine is insurable and whether the insured acted reasonably, in line with FCA commentary on fair treatment and governance. For up-to-date positions, refer to the ICO and the National Cyber Security Centre (NCSC) NCSC.
When is cyber cover sufficient for consultants?
Cyber-only may be sufficient in defined situations, for example:
- The consultant provides purely technical IT services (e.g. managed hosting) where the primary exposures are system availability and data breaches, and contractual terms require cyber cover specifically.
- The consultancy trades as a small microbusiness with minimal advisory liability exposure (for instance, non-regulated generalist advice where contracts limit liability and clients are low-risk).
However, if the consultant provides formal advice, opinions, financial or regulatory guidance, or if contracts create potential for claims of professional negligence, PI should be considered even where cyber cover exists.
Do PI policies exclude cyber incidents for consultants?
Many PI policies contain express cyber or electronic data exclusions. Typical exclusion features:
- Exclusion of liabilities arising from unauthorised access, data loss or corruption unless the claim arises directly from professional services rendered.
- Narrow definitions of defence costs relating to privacy incidents, or sub-limits for data protection response.
- Retroactive date and claims-made triggers that affect whether past acts or current allegations are covered.
In practice, PI insurers may respond to claims where the central allegation is negligent advice that caused economic loss, even if an IT element exists, while cyber insurers respond where the incident is an information security event or system failure. Over-reliance on assumed cross-cover is a common error: policy wordings should be compared side-by-side.
Hidden costs of relying on PI instead of Cyber
Relying solely on PI can leave gaps that translate to real, often unexpected costs:
- Immediate response costs: forensic investigation, legal notification letters and PR support are usually outside PI cover. These costs can mount quickly after a breach.
- Ransom and extortion: PI rarely covers payments or negotiation costs.
- Customer remediation and monitoring: credit monitoring, identity protection and notification letters are typically cyber-covered items.
- Business interruption from IT outages: PI may not pick up losses caused by a systems outage unrelated to professional advice.
- Contractual compliance costs: costs imposed by clients for failing to meet cybersecurity clauses can be uninsured under PI.
These hidden costs can exhaust reserves even where PI responds to a subsequent negligence claim.
Should small consultancies bundle Cyber with PI to save?
Bundling options can appear attractive, but trade-offs exist:
- Pros: single broker relationship, potential premium discount, simplified admin and aligned renewal dates. Some insurers offer combined programmes or endorsements that avoid double administration.
- Cons: combined policies can have shared aggregates (one incident depleting both covers), restrictive cross-liability language, or limited sub-limits that are insufficient for major cyber incidents. Bundles may also reduce competition between insurers for specialised cyber expertise.
A balanced approach often involves maintaining separate PI and cyber policies while ensuring coordination clauses, cross-liability language and aggregate limits are understood. Where bundled products are considered, review whether cyber cover includes modern features such as incident response services, ransomware negotiation and regulatory expense cover.
Contract clauses and wording consultants should watch
Below are indicative wording examples and clauses often seen in client contracts. These are examples for reference and not legal advice.
Example: client insurers and minimum limits clause (indicative)
"The consultant shall maintain in force professional indemnity insurance of at least £[amount] per claim and cyber insurance of at least £[amount] per event, each with an insurer authorised in the UK, and shall provide certificates of insurance on request."
Example: limitation of liability draft clause (indicative)
"Subject to liability for death or personal injury, each party’s aggregate liability for direct loss arising out of or in connection with this agreement shall be limited to the greater of £[amount] or [multiple] times fees paid in the preceding 12 months. This limit shall not apply to liabilities arising from fraud or wilful misconduct."
Example: data processing and security clause (indicative)
"The consultant will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Data Protection Legislation and contractual obligations. The consultant will notify the client without undue delay upon becoming aware of a personal data breach."
Carefully negotiate obligations that impose strict, uninsured duties (for example, unlimited liability for data breaches). Contracts that require unlimited or very high liability can make insurance unaffordable; where possible, agree buckets of liability and insured limits.
Scenario A, Independent financial consultant: negligence claim
A spreadsheet error leads to a client overpaying tax by £120,000. Client sues for loss and recovery costs. PI pays defence costs and settlement. Cyber insurance not triggered. Result: PI exhausted legal defence budget; dispute resolved without related cyber costs.
Scenario B, Small digital marketing consultancy: ransomware
Ransomware encrypts client files and internal systems; negotiation and forensic response cost £40,000; client data exposed requires notification and monitoring costing £25,000; business interruption loss estimated at £60,000. Cyber policy responds; PI is not triggered. Result: cyber insurance prevents cashflow shock.
Scenario C, Hybrid: advice + breach
A compliance consultant shares spreadsheets with clients via a misconfigured cloud folder; client data is exposed and a client claims the consultant’s failure to secure data caused regulatory fines and business loss. Outcome: allocation dispute between PI and cyber insurers; both may contribute to defence costs depending on wording; regulatory penalties may be uninsured or limited. Result: Both policies needed and clear contractual wording, plus robust IT controls, would reduce insurer disputes.
These scenarios illustrate why a single-policy approach can fail in mixed-risk events.
Quick decision flow → Which policy first?
- Is the primary service advice or data/IT?, If advice, PI first; if IT/data, cyber first.
- Do client contracts require specific cover?, Match contract minimums.
- Do operations rely on cloud or payment processing?, Strongly consider cyber.
- Does the consultant give regulated advice?, PI is critical.
Typical recommended cover for small consultancies
PI: £250k–£1m
Cyber: £100k–£1m (with incident response)
(Indicative, depends on contract risk and sector)
Strategic analysis: pros and cons of combined vs separate policies
- Pros of separate specialist policies: dedicated underwriting expertise per peril, clearer limits, less chance of shared aggregate depletion.
- Cons of separate policies: potential coverage disputes, more administration, misaligned renewal dates.
- Pros of combined or packaged products: administrative simplicity and possible cost savings.
- Cons of packages: narrower wording, lower sub-limits for cyber features and potential gaps in professional-liability aspects.
FAQ
What is the main difference between PI and cyber insurance for consultants?
PI covers negligent professional advice causing financial loss; cyber covers information-security incidents, data breaches and IT outages. Overlap exists but depends on wording.
Can a cyber policy cover regulatory fines for GDPR breaches?
Some cyber policies include regulatory fines cover but many exclude fines or limit them. Check policy wording and insurer position; consult the ICO guidance ICO for regulatory context.
Are defence costs always covered under PI and cyber?
Both types often cover defence costs, but allocation depends on the nature of the claim. PI typically covers defence against negligence claims; cyber covers incident response and regulatory defence where the event is an information-security incident.
Should a consultant list both PI and cyber on a client’s contract schedule?
Where clients request proof of cover, listing both can demonstrate thorough risk management. Ensure certificates match contractual minimums and that insurers are notified if contracts materially increase exposure.
Do small consultancies always need both policies?
Not always. A small consultancy with minimal advisory exposure and low data handling may accept cyber-only or PI-only depending on their primary risk. Most consultancies with mixed exposures find both necessary.
What is a retroactive date and why does it matter?
A retroactive date limits PI/cyber cover for events occurring before that date. For claims-made policies, acts before the retroactive date may be excluded, check for continuity when switching insurers.
Can insurers refuse a claim if cybersecurity measures were poor?
Insurers may decline or reduce cover if policy conditions (such as minimum security standards or failure to patch known vulnerabilities) are breached. Maintaining reasonable controls improves claims prospects.
Conclusion, 3-step action plan (under 10 minutes each)
Quick action plan
- Check client contracts (5–10 minutes): note required minimum limits and insured perils; flag any unlimited liability clauses.
- Review current policies (10 minutes): find retroactive dates, sub-limits and cyber exclusions; identify immediate gaps (notification costs, ransomware, BI).
- Seek expert review (10 minutes): contact an FCA-authorised broker or regulated adviser to compare PI and cyber wordings and to discuss combined vs separate placements.
These steps provide rapid clarity on priority gaps and practical next steps.
Further reading and sources: National Cyber Security Centre NCSC, Information Commissioner's Office ICO, Prudential commentary from UK financial regulators. For decisions with legal or financial impact, consult regulated advisers.