
¿Te preocupa which policy will pay if a client sues after a data breach or ransomware event? Many UK SMEs hold professional indemnity (PI) and cyber insurance but still face uncovered losses because the covers were not coordinated. This guide explains the overlap of professional indemnity & cyber gaps in plain British English, with practical checks to identify where cover may fail.
Key takeaways: what to know in one minute
- PI and cyber sometimes overlap, but they cover different risks. PI usually responds to alleged professional negligence; cyber covers digital incidents and associated costs.
- Common gaps occur where PI excludes technology-related losses or where cyber excludes professional liability—this creates 'silent cyber' or uncovered exposures.
- First-party costs (incident response, notification, business interruption) are typically cyber; third-party defence and damages for negligent advice are typically PI, but many scenarios sit between both.
- GDPR regulatory action and fines can fall between covers: fines are often excluded by both policies, but defence costs may be covered—check wording carefully.
- A short checklist and simple endorsement options can reduce the PI–cyber gap; but wording review with a broker or legal counsel is recommended for firm-specific decisions.
How professional indemnity and cyber cover overlap in practice
Professional indemnity insurance is designed to cover legal liability arising from professional services, such as negligent advice, mistakes in deliverables or breaches of professional duty. Cyber insurance is structured to cover losses from cyber incidents, including data breaches, ransomware and system outages.
Overlap arises when a cyber incident leads to a professional liability claim or when a professional error causes a cyber event. Examples:
- A consultant's faulty configuration allows unauthorised access. Clients sue for negligence (PI claim) and the company faces incident response costs (cyber claim).
- A solicitor's email is compromised and confidential client data published. There may be both regulatory breach handling (cyber) and claims alleging professional negligence (PI).
Where both covers could respond, insurers often argue that one policy is primary for particular elements (defence vs. first-party mitigation). This creates coordination issues during claims handling and potential disputes over allocation.
Common gaps where professional indemnity misses cyber exposures
PI policies often contain technology or data-related exclusions. Typical gaps include:
- Exclusion for loss of or damage to electronic data or for liabilities arising from data breaches.
- Narrow definition of professional services that excludes IT configuration, software development or managed services.
- Cyber-related exclusions for criminal acts, unauthorised access or privacy breaches if the PI policy assumes these fall to a standalone cyber policy.
Why gaps persist:
- PI wording was drafted before cyber risks became standard, so many wordings have not kept pace.
- Brokers and insureds may assume PI covers all client data incidents when the policy expressly limits or excludes electronic risks.
- Small firms often buy the cheapest PI without verifying technology-related endorsements.
Practical signals of a gap:
- Policy schedule or definitions mention "electronic data not insured" or similar.
- An endorsement titled technology exclusion or data exclusion.
- Retroactive date limitations that preclude cover for historic acts discovered after a breach.
First-party versus third-party costs after a data breach: who pays what
Understanding which costs are first-party or third-party helps determine which policy may respond.
First-party costs (typically cyber):
- Incident response and forensic investigation
- Notification to affected individuals and regulators
- Credit monitoring and identity protection for customers
- Crisis communications and PR management
- Business interruption losses directly caused by the cyber incident
- Ransom payments (where allowed by policy and law)
Third-party costs (typically PI or liability):
- Defence costs and damages for negligence claims brought by clients
- Claims for breach of contract by clients
- Regulatory enforcement defence (sometimes shared)
Many incidents produce both cost types. For example, following a ransomware attack, a firm may pay for forensic work (cyber) and face a claim from a client alleging failure to secure data (PI). The allocation can be disputed if policies overlap or exclude particular elements.
Table: typical allocation of costs (indicative at time of writing)
| Cost type |
Usually cyber |
Usually PI |
| Forensic investigation |
✓ |
✗ |
| Notification & credit monitoring |
✓ |
✗ |
| Client negligence claims (damages) |
✗ |
✓ |
| Business interruption from systems outage |
✓ (often capped) |
✗ |
| Regulatory fines and penalties |
✗ (commonly excluded) |
✗ (often excluded) |
Notes: this table is indicative and depends on each policy's actual wording. Insurers vary widely.
When GDPR fines fall between your covers
GDPR-related financial consequences are split into two main types:
- Administrative fines and penalties imposed by the Information Commissioner's Office (ICO).
- Compensation claims by data subjects for material or non-material damage.
How covers typically treat them:
- Cyber policies commonly exclude fines and penalties imposed by regulators, or limit them severely. Some cyber products offer extensions for regulatory defence costs but not fines.
- PI policies usually cover legal liability for damages to third parties, which can include compensation claims, but many contain explicit exclusions for fines and regulatory penalties.
Practical implications for UK SMEs:
- Defence costs for ICO investigations may be recoverable under cyber or PI depending on wording; often cyber will cover incident response and legal advice for ICO notification, while PI may cover legal defence for claims of negligent advice that caused the breach.
- Fines themselves are commonly excluded by both policies. A firm facing a significant ICO fine may therefore find fines uninsured unless a very specific endorsement exists.
Relevant UK guidance and links:
Legal interplay and subrogation:
If an insurer pays a regulatory fine under an unusual endorsement, the insurer may seek subrogation against third parties. That can be complex where multiple parties, suppliers or subcontractors are involved.
Policy wording traps: exclusions, retroactive dates and limits
Several recurring wording features can create gaps or surprises.
Exclusions to watch for:
- Technology or data exclusion: excludes liabilities arising from electronic data or technology services.
- Prior acts exclusion / retroactive date: limits cover to events after a specified date. Discovery of historic failures that predate the retroactive date may be uncovered.
- Intentional acts/criminal acts: many policies exclude deliberate wrongdoing; however, whether a ransom attack is criminal can be contested.
- Contractual liability exclusion: some PI policies exclude liabilities assumed under contract, which may leave gaps where contract terms create indemnities.
Limits and sub-limits:
- Cyber policies often apply sub-limits for notification, crisis management, regulatory defence and ransomware. These sub-limits can be low relative to the main limit and create large out-of-pocket costs.
- PI limits may be aggregated for multiple claims or across long-tail liabilities.
Claims-made vs occurrence:
- PI is commonly written on a claims-made basis with a retroactive date; if an act occurred before the retroactive date but the claim arises later, it may be excluded.
- Cyber policies are typically claims-made or loss-occurrence depending on the insurer; verifying basis is important.
Example wording trap (realistic scenario)
A marketing consultancy deploys a cloud marketing tool with weak access controls. An attacker exfiltrates client lists and posts them online. The consultancy's PI policy has a technology exclusion and a retroactive date that does not cover the software work done years earlier. The cyber policy has small sub-limits for notification and excludes regulatory fines. The consultancy faces significant uninsured liabilities—defence costs plus client claims exceed available cover.
Practical checklist to identify and close PI–cyber gaps
This checklist helps an SME or its broker assess likely gaps quickly. Each item is a prompt for a specific policy review.
-
Review definitions
-
Does PI define "professional services" narrowly? If yes, check whether technology work, managed services or cyber security advice are included.
-
Does cyber define "insured event" broadly enough to include breaches caused by vendor misconfiguration or human error?
-
Check exclusions and endorsements
-
Look for technology, data, or electronic data exclusions in PI and privacy/fines exclusions in cyber.
-
Verify any endorsement that modifies cover (e.g. "technology exclusion", "silent cyber" wording).
-
Confirm retroactive dates and continuity
-
Ensure the PI retroactive date covers historic acts that may be discovered later.
-
Check whether lapses in cover or insurer changes create gaps.
-
Identify sub-limits and aggregate limits
-
Add up likely costs (forensic, notification, PR, legal defence) and compare to sub-limits.
-
Consider purchasing higher sub-limits or dedicated endorsements where necessary.
-
Test the claims scenario
-
Walk through three realistic loss scenarios (data breach, ransomware, negligent advice leading to breach) and map which policy would likely pay which costs.
-
Consider a bridging endorsement or policy wording change
-
Many insurers offer endorsements to broaden PI to include cyber-related liabilities, or to extend cyber to cover professional liability for technology services. Evaluate cost vs benefit.
-
Document supplier and subcontractor responsibilities
-
Ensure contractual flow-down of security obligations and insurance requirements; check whether PI or cyber covers liabilities arising from third-party failures.
-
Ask the insurer(s) for claims examples or wording precis
-
Seek written clarity from insurers or brokers on likely allocation and on who manages the claim in overlapping scenarios.
-
Keep compliance and incident response plans aligned
-
Insurers often expect documented incident response plans and basic cyber hygiene as conditions of cover; aligning these can reduce disputes.
-
Log and store policy wordings centrally
-
Maintain a single folder with copies of current policy wordings, endorsements and correspondence for fast reference during a claim.
Who notifies whom and which policy acts first
Breach response flow for PI–cyber overlap
🔍 **Step 1** → Detect incident and secure systems
📞 **Step 2** → Notify cyber insurer's incident response team (if available)
📣 **Step 3** → Assess whether clients were affected; inform PI insurer if there is likely negligence claim
⚖️ **Step 4** → Coordinate legal defence and regulator notification; allocate costs (cyber vs PI)
✅ **Success** → Incident contained, costs allocated, lessons logged
Strategic analysis: advantages, risks and common errors to avoid
✅ Benefits / when alignment makes sense
- Coordinated PI and cyber cover can minimise uninsured gaps and speed claims resolution.
- Clear endorsements can reduce dispute risk and clarify which insurer leads defence.
- For technology-focused SMEs, adding cyber extensions to PI (or vice versa) can reduce uncertainty for clients and regulators.
⚠️ Errors to avoid / risks
- Assuming PI covers any data incident without checking for a technology exclusion.
- Relying on headline limits without checking sub-limits and retention levels.
- Accepting contractual indemnities for cyber events without ensuring the necessary cover or obtaining supplier assurances.
FAQ: common questions on overlap of professional indemnity & cyber gaps
Who pays first when both PI and cyber are triggered?
Allocation depends on policy wording and cause; often insurers negotiate allocation, but policy wording determines legal responsibility for each cost.
Can PI cover data breach notification costs?
PI may cover defence costs for negligence claims but will rarely cover standard first-party notification and credit monitoring unless amended by endorsement.
Do cyber policies ever cover regulatory fines under GDPR?
Some cyber products may include limited cover for regulatory fines in certain jurisdictions, but most standard UK cyber policies exclude fines; check wording carefully.
What is a retroactive date and why does it matter?
A retroactive date is the earliest date an act can have occurred and still be covered on a claims-made policy; claims for acts before that date are typically excluded.
Is subrogation a concern in overlapping claims?
Yes. If one insurer pays and subrogates, it may seek recovery from third parties or the other insurer, complicating settlement and relationships.
Should an SME buy broader PI or a separate cyber policy?
It depends on the business model. Firms providing technology services may need broader PI plus a comprehensive cyber policy. This is a general consideration, not personalised advice.
How can brokers help resolve PI–cyber disputes?
Brokers can obtain insurer positions in writing, negotiate endorsements, and help structure limits and sub-limits to reduce uncertainty in claims allocation.
What documentation helps when making a claim involving both policies?
Keep incident logs, system snapshots, client communications, contract copies and the full policy wordings and endorsements. Insurers commonly request these promptly.
Example practical scenarios and how covers usually interact
Scenario A: a bookkeeper accidentally emails client payroll data to the wrong recipient. Notification costs and credit monitoring are first-party cyber costs; if a client sues for negligence, PI may cover defence and damages. If PI has a technology exclusion, the PI insurer may decline and the insured may be left to defend without coverage.
Scenario B: a software developer's update contains a bug that exposes customer data. Clients sue for loss of business; cyber insurer covers incident response and some BI, while PI may cover claims alleging negligent code.
These scenarios illustrate why scenario testing in the checklist is a practical way to predict likely outcomes.
Your next step:
- Obtain current PI and cyber policy wordings and search for technology, data, privacy, retroactive date, sub-limits and fines.
- Run three realistic breach scenarios against both wordings and note likely primary payer for each cost element.
- Discuss identified gaps with a broker or legal adviser and consider specific endorsements or limit changes as general options.