A director opens an urgent email from a key client. Project files may have been accessed through a compromised Microsoft 365 account.
Cyber insurance can pay for practical incident costs. These can include forensic work, client notice, ransomware response and lost income. It differs from professional indemnity (PI), though both may matter.
Why consultancies often need cyber cover beside PI
PI does not always pay for ransomware or stolen email access. It may not pay to rebuild cloud files either.
PI usually responds when professional work allegedly harmed a client. Cyber cover responds when criminals, system failures, or accidental disclosure harm the consultancy's digital work.
PI may pay defence costs and damages after alleged professional negligence. It may not fund forensics, data recovery, or lost income after criminals encrypt systems.
If poor security advice leads to an attack, PI or tech E&O may address the client's claim. Cyber cover may fund the consultancy's own response.
The policy trigger matters more than its label. The trigger is the event that makes an insurer consider a claim.
Compare cyber, PI, liability and tech E&O
| Cover type | Usual trigger | Costs it may pay | Key gap or overlap |
|---|
| Cyber cover | Breach, attack, outage, or cyber extortion | Forensics, legal advice, recovery, notice, downtime | May overlap with PI after a client loss claim |
| Professional indemnity | Claimed error, omission, or poor advice | Defence costs, settlements, or damages | Often excludes the firm's own ransomware recovery |
| Public liability | Injury or property damage to others | Legal defence and compensation | Usually does not cover a data breach |
| Tech E&O | A technology service fails or causes client loss | Claims linked to software or IT work | Often matters for IT and cyber consultancies |
The right balance depends on the consultancy's work, not just its size. Management or finance firms often need cover for financial data, email compromise, and cloud disruption.
HR, recruitment, and legal-support firms may hold CVs and payroll data. They may also hold right-to-work documents or special-category data.
That data can make a breach cost more.
Marketing agencies may face account takeover or campaign-platform outages. They may also expose client data.
IT and cyber consultancies should assess cyber cover and Tech E&O insurance. They should also review professional indemnity insurance.
A client may claim that a poor setup caused its loss. The same can happen after weak security advice.
What a cyber policy can pay after a breach
A suitable policy can fund urgent work after a breach. Payment depends on its wording, limit, and sublimits.
A sublimit is a smaller cap inside the main cover limit. Ransomware, outsourced providers, and downtime may each have their own cap.
Costs that can arrive in the first week
A breach can create bills for forensic work and legal advice. It can also create costs for client messages, notice, restoration, and emergency IT help.
If work stops, business interruption cover may pay eligible lost income. It may also pay extra costs needed to keep trading.
Cyber extortion payments should never be assumed covered. Insurers may need to agree first and check sanctions rules.
The first week often decides the total cost.
GDPR duties remain with the consultancy
The UK GDPR and Data Protection Act 2018 require every firm to assess personal-data breaches. The Information Commissioner's Office is the UK data protection regulator.
When people face a risk to their rights, the ICO expects prompt notice. Where feasible, this should happen within 72 hours.
Insurance may pay for legal advice or notification work. It does not remove these legal duties or promise payment of regulatory fines.
Check exclusions as closely as you check limits. Policies often exclude deliberate acts, dishonest acts, and known incidents before the policy starts.
Some policies also limit losses linked to war or state-backed cyber events. The wording and proof rules can differ between insurers.
Cover may rely on declared controls, such as MFA, backups, or patching. Wrong proposal answers can lead to a dispute about cover.
MFA means multi-factor authentication. It asks for a second proof of identity, like a code on your phone.
The most frequent mistake is assuming a cloud provider's security solves every risk. Your firm still controls user access, client data, and many settings.
Ask how the policy treats cloud providers and managed service providers. Also ask about subcontractors and dependent business interruption.
Dependent business interruption means loss caused by a supplier's outage. Think of it like a shop losing sales because its payment terminal provider fails.
Check whether extortion, data restoration, and social-engineering fraud have separate caps. Check waiting periods and insurer approval rules too.
Consider a Microsoft 365 account compromise. An attacker changes mailbox rules, downloads client contacts, and sends false messages.
Staff may lose access to project files. A response may start with forensic work and legal advice.
It may then include breach-notification decisions and password resets. It can also include cloud file recovery or wider system recovery.
Lost income cover may help with eligible billable time. Extra IT costs may also be covered after any waiting period.
Extortion costs may need insurer consent and sanctions checks. A separate client claim for missed work may involve PI or Tech E&O.
The consultancy must decide if it is a controller or processor. A controller decides why and how personal data is used.
A processor handles data for another organisation. A controller may need to notify the ICO within 72 hours when the risk test is met.
Set limits using data, downtime and contracts
Choose a limit for the largest plausible event. Do not base it on turnover alone.
Model between three and 10 working days of disruption. This matters when your firm relies on email, cloud storage, client portals, or accounting software.
A sensible limit covers the response bill, lost fees, and client demands. It should also match any minimum limit in a client contract.
A small consultancy with low turnover can still face high costs. This can happen when it holds payroll, health, identity, or financial data.
Use this limit-setting check
Start with the largest likely response bill. Add downtime and allow for possible client claims.
Check data volume and how sensitive that data is. Check contract limits, incident deadlines, and any overseas work too.
Ask whether clients require cyber liability or tech E&O. Those terms can mean different things in different contracts.
Excesses and sublimits can change value
An excess is the amount your firm pays first. The insurer pays only above that amount.
A sublimit is a smaller cap within the main policy limit. It often applies to social-engineering fraud, supplier outages, or data restoration.
Compare cloud-provider definitions and outsourced IT cover. Compare subcontractor cover and waiting periods before treating quotes as equal.
For most consultancies, start with the worst realistic week, not annual turnover. Add response costs, between three and 10 days of lost fees, contract limits, and sensitive data exposure. A firm with few records and no client portals may need less. A recruitment or HR consultancy may need more because one breach can expose many identities. Use this model before asking brokers for quotes.
Security controls insurers usually ask to see
Insurers often ask for MFA, tested backups, and safe remote access. Your proposal answers must match every relevant system.
MFA on email alone may not be enough. Administrator accounts, finance tools, and remote access also need protection.
The controls must work when an incident starts.
Check these controls before seeking quotes
Apply MFA to email, cloud admin, remote access, and finance systems. Keep a separate backup and test that files can be restored.
Use endpoint detection and response software where suitable. This software watches devices for signs of harmful activity.
Train staff to report phishing emails. Phishing is a false email or message that tries to steal access or money.
Write down who calls the insurer, IT provider, legal adviser, and clients. Make this list for the first 24 hours after an incident.
Give insurers clear evidence
Provide evidence that your controls work. This can include MFA settings, backup test dates, and staff training records.
A common case involves a firm that says it has MFA. Its finance mailbox still uses only a password.
A criminal then sends false bank details to a client. The firm may face a fraud loss and a hard coverage question.
This guide does not replace a review of policy wording, client contracts, or your legal position. It may matter less if your consultancy holds no third-party data and barely uses digital systems. Even a microbusiness still faces risk through email, bank accounts, and devices. Regulated firms and consultancies with complex contracts should check sector rules and contract terms.
Before seeking terms, give your broker a completed control checklist. Include your largest client insurance requirement and five days of lost billable work.
Ask the broker to show limits, sublimits, and excesses side by side. This makes it easier to spot a cheap quote with a costly gap.
Common questions
Does a consultancy need both cyber insurance and PI?
Usually, yes, if it holds client data or relies on cloud systems. PI addresses claimed professional mistakes, while cyber cover may fund breach response or ransomware costs.
How much cyber cover should a small consultancy have?
Choose a limit based on breach costs and between three and 10 days of downtime. Also check contract demands and the type of data you hold.
Does cyber insurance cover GDPR fines?
It may pay legal defence and some fines where insurance is lawful. Terms differ, and it cannot remove UK GDPR duties or promise payment of an ICO penalty.
Is phishing covered by a cyber policy?
Phishing response is often covered, but stolen invoice money may have a separate fraud sublimit. Check approval rules before paying suppliers or engaging incident firms.
What is the difference between cyber insurance and Tech E&O?
Cyber cover responds to digital incidents and their costs. Tech E&O addresses claims that technology services, software, or security advice failed.
Make the cover test before renewal
Review PI, cyber cover, public liability, and tech E&O together. Then check that declared controls work across every relevant account.
The best renewal is not always the cheapest policy. It is cover with enough limits, workable sublimits, and conditions your firm can meet during an incident.
Read the policy wording before relying on a client requirement. A policy schedule alone rarely explains every exclusion, condition, or sublimit.
Further reading
If you want to learn more about this topic, these sources may interest you: