A client indemnity can expose your business to far more than the cost of fixing a breach. If you promise to cover data losses, regulatory claims or third-party costs, contractual wording may define what you owe.
Professional services: Cyber vs client contractual indemnities: cyber insurance and a client indemnity do different jobs. Insurance may fund covered incident costs. An indemnity sets what your business owes under the contract.
Cyber cover does not set your client liability cap
A liability cap is the highest sum your contract says you must pay. An insurance limit is the highest sum an insurer may pay under its policy terms.
A £1m policy cannot make exposure unlimited
An unlimited indemnity can require payment beyond £1m. It can also apply beyond one policy year. It may include losses the policy never covers.
The most frequent mistake is treating an insurance certificate as approval for the client's wording. A certificate proves that cover exists. It does not confirm that your exact contract term is insured.
Read the three figures separately: a £100,000 contract cap controls your promise to the client. A £500,000 separate data cap controls a defined exception. A £1m aggregate is the most the insurer may pay across covered claims during that policy period.
A policy limit and a contract cap are different ceilings.
Map each incident to its cap and policy
Each cyber event needs separate analysis. Professional errors, ransomware attacks and payment scams can create different losses. They may also trigger different cover.
| Event | Client indemnity risk | Cap to check | Potential policy |
|---|
| Professional error | Client's direct loss from bad advice | General cap or PI cap | Professional indemnity insurance |
| Data breach | Privacy claims and notification costs | Data clause and cap exception | Cyber insurance, sometimes PI |
| Ransomware | Client disruption claim | General or cyber-specific cap | Cyber first-party and liability cover |
| Business email compromise | Mis-sent or diverted payment | Fraud wording and cap | Cyber crime cover, if included |
| Subcontractor failure | Your liability for its security lapse | Flow-down and main cap | Cyber, PI and subcontractor cover |
| Regulatory investigation | Defence and response costs | Fine wording and cap | Cyber, subject to terms |
One incident, four separate questions
1. Cause
Advice error, breach, ransom or fraud?
2. Promise
Does the indemnity apply?
3. Contract
Which cap applies?
4. Policy
Is it insured after retention?
A breach can trigger two policies
A single event can create first-party and third-party cyber claims. This distinction matters when comparing a client indemnity with cyber insurance.
First-party cover may pay your own incident costs. These can include forensic work, system restoration and lawful, approved ransomware payments. It may also cover business interruption, notification and regulatory investigation costs.
Third-party cover concerns liability to other people. It may address a client's breach claim, affected individuals' data claims, or claims that your security failure caused loss.
One breach can create several separate bills.
Ransomware and BEC are not the same
Business email compromise is often called BEC. It happens when criminals divert a payment through a false or hacked email.
BEC may need cyber crime cover. A client's demand for repayment may still sit outside the policy. This can happen where the demand rests only on your contractual promise.
A ransomware event may also fall outside cover. This can happen if you miss a policy condition. It can also happen if a sublimit applies.
Negotiate data indemnities that match cover
A workable client indemnity should cover defined third-party claims caused by your breach. It should have a stated cap. Check it against the cover you can buy.
Keep data claims inside a stated cap
Putting data protection or confidentiality claims outside the general cap can create unlimited exposure. A fairer option is a higher separate cap.
For a smaller professional services contract, this cap is often between £250,000 and £1m. The right sum depends on the service, data volume and available insurance.
A separate data cap can protect both sides. It gives the client more protection than the basic cap. It also gives the supplier a clear maximum exposure.
A clause structure to adapt and review
Supplier-friendly wording: “The Supplier shall indemnify the Client against reasonable, documented third-party claims. Those claims must arise directly from the Supplier's breach of data protection, confidentiality or security duties. This indemnity is subject to the liability cap in clause [X].”
Client-friendly alternative: “This clause has a separate aggregate cap of £[amount] in any 12-month period. The Supplier is not liable for indirect loss, lost profit, or fines that are not legally recoverable or insurable.”
Fines need a separate answer
Set the contractual liability cap by modelling the service. Do not simply match the supplier's headline insurance limit.
Consider the records or systems you can access. Consider whether you can start payments. Also consider notification costs, restoration time and realistic third-party exposure.
A consultancy with access to a 20,000-record CRM may face costs above its annual fees. A supplier receiving anonymised analytics may support a lower cap.
Then check the proposed cap against the cyber policy aggregate. Deduct the retention, defence costs and any relevant sublimits first.
A £1m policy may not leave £1m for one client's claim. Earlier incidents may have reduced the aggregate.
Under English law, governing law and drafting affect which losses a client can recover. An indemnity should name its trigger, protected party and covered losses.
It should also state whether it covers third-party claims. A broad reference to all losses from confidentiality breaches gives less certainty.
Recovery still depends on the contract wording, causation and remoteness rules. It also depends on any valid exclusion or cap.
Regulatory fines need special care. Their recovery between parties depends on the regime, conduct and public policy.
Defence, investigation and remediation costs may still be recoverable or insured. That can apply even where the fine itself is not.
A broad data indemnity should never be accepted just because cyber cover exists. Match the trigger, cap and loss types to the policy wording. A higher cap can be fair where you run client systems or handle sensitive data. It is rarely sensible to accept unlimited liability without legal advice and written insurer confirmation.
Check wording, sublimits and notification rules
The policy wording, not the schedule alone, decides claims. Ask your broker to compare the exact client clause with cyber and PI wording.
- Contractual liability exclusion: Check whether the policy excludes duties accepted only under the client agreement.
- Prior acts and retroactive date: Check whether cover includes work done before renewal, and from what date.
- Sublimits: Check whether ransomware, notification, regulatory work, BEC and public relations have limits below the aggregate.
- Retention: Check whether your firm can pay the excess and uninsured response costs.
- Panel counsel: Check whether you must use the insurer's approved lawyers and incident firms.
- Notification: Check whether the client contract requires notice within 24 to 72 hours. Also check the policy's prompt reporting rule.
Notify early and preserve your options
Many policies require notice when you first know of circumstances that may lead to a claim. Waiting for a formal client demand can be too late.
Tell your broker or insurer as soon as required by the policy. Ask before appointing lawyers, forensic firms or ransom negotiators.
Early notice can protect your right to claim.
Subcontractors need matching promises
Your client can still claim against you if your contract makes you responsible for subcontractors. Check your flow-down terms and the subcontractor's insurance.
Also check whether your cyber policy covers outsourced service providers. Do not assume that it does.
A common case involves a small agency using a cloud contractor. The contractor exposes client data. The agency faces the client's claim first, even when the contractor caused the breach.
Sign only terms your policy can meet
Accept a client cyber indemnity only after matching its trigger, losses, cap, duration and notice duties. Compare these terms with the full policy wording.
For a normal SME services deal, a defined indemnity is usually a sensible position. It should cover direct third-party claims and have a stated aggregate cap.
It should exclude indirect losses and uninsurable fines. It should also require both sides to cooperate after an incident.
This approach may not suit every supplier. A higher cap may be fair where you handle sensitive data, run client systems or work in a regulated sector.
This guidance is not legal or insurance advice. It is less relevant where you do not serve clients or handle their data or systems. It cannot resolve an incident that has already happened. For an active dispute, regulatory claim, complex drafting or a potentially unlimited indemnity, seek legal advice. Obtain written confirmation from your insurer or broker before signing.
Before signing, send your broker the exact clause and proposed cap. Ask for a written response on cover, exclusions, sublimits and notification duties.
Common questions
Does cyber insurance cover contractual liability?
It may cover some contractual liability where policy wording allows it and all conditions are met. A client indemnity does not create insurance cover. This is especially true where assumed liability or a contractual liability exclusion applies.
Should a UK SME accept an unlimited cyber indemnity?
Usually, no, unless legal advice and written insurer confirmation show that the defined risk is acceptable. An unlimited promise can exceed a £1m policy limit. It may also include uninsured fines, indirect loss or losses after the policy period.
Does professional indemnity insurance cover a cyber breach?
It can cover a breach linked to negligent professional advice or services. It may not pay ransomware response, restoration or notification costs. Cyber insurance often addresses those first-party costs, subject to sublimits and retention.
Can GDPR fines be claimed from my supplier?
Possibly, but the answer depends on the contract, causation, governing law and fine type. UK GDPR fines are not automatically recoverable or insurable. Regulatory defence costs may be treated differently under the policy.
What happens if a subcontractor causes the breach?
Your client can still claim against you if your contract makes you responsible for subcontractors. Check flow-down terms and the subcontractor's insurance. Also check whether your cyber policy covers outsourced service providers.
What should I ask my broker before I sign?
Ask whether the exact indemnity is covered and whether defence costs reduce the limit. Ask which sublimits apply to data, ransomware, BEC and regulatory work. Also request written details of the retroactive date, retention, panel counsel and notice rules.