For accountancy firms, a PI extension can help with some client claims, but it often misses the losses that hurt most in a real incident. It is common to see gaps around ransomware, business interruption, email fraud and the cost of getting systems back online.
A standalone policy vs PI extension for small accountants comes down to what your PI actually covers and where the gaps sit. If you hold client data, rely on cloud software and email, and could suffer data loss, phishing or an attack on your own systems, a standalone policy usually gives broader first-party cover and clearer incident response support.
Quick comparison for small accountants
A PI extension may look cheaper, but it often gives narrower help when a real incident starts. A standalone policy usually costs more, yet it is more likely to cover the things that actually hurt a small firm: recovery work, business interruption and cybercrime response.
| Cover option |
Typical annual premium for a small firm |
What usually starts the cover |
Main gap to watch |
Best fit |
| PI extension |
Often around £50 to £250, but can be bundled into a PI renewal |
Usually negligence, wrongful act or client claim |
First-party costs and cybercrime sub-limits are often tight |
Very small practices with low digital exposure |
| [Standalone](https://dealergen.uk/does-bundled-cyber-match-standalone-for-lost-online-sales/) policy |
Often around £200 to £900 for small UK firms, higher if data volume is larger |
Attack, breach, outage, fraud or extortion event |
Exclusions, waiting periods and excess still matter |
Most accountancy practices with cloud tools and client records |
| Both together |
Usually the highest total premium, but often the widest practical protection |
PI handles claims, cyber handles incident costs |
Avoid overlap and double counting on response costs |
Firms with sensitive client data and low tolerance for downtime |
If a hacker locks your bookkeeping software on a Friday afternoon, a PI extension may not pay to get the work back online. A standalone policy is more likely to fund the recovery path, which is what keeps a small practice trading.
| Type of practice |
Data volume |
Tech exposure |
Best fit |
| Sole practitioner, low cloud use |
Low |
Limited email and no client portal |
PI extension may be enough if the wording clearly includes basic fraud and data handling |
| Small accountancy firm using cloud accounting software |
Medium |
Shared inboxes, remote access, payroll and tax data |
Standalone policy is usually the better base because first-party cover and cybercrime response matter |
| Multi-partner practice with payroll, bookkeeping and portals |
High |
High dependence on cloud platforms and client portals |
Buy both: PI for client claims and cyber for incident response, forensic investigation and systems recovery |
The practical test is not the premium alone, but how much data you hold and how quickly a shutdown would affect billing. A small accountancy firm with one office and a simple desktop setup may tolerate a limited PI extension, but the moment the firm relies on cloud accounting software, 365 email and client portals, the exposure changes. More users mean more phishing attack opportunities, more privilege escalation risk and more chance that a single compromised inbox leads to email fraud or unauthorised payments.
In that situation, standalone insurance for accountants is usually the more resilient starting point.
When a PI extension may be enough
A PI extension may be enough if your firm is tiny, stores little client data, and mainly wants help where an event turns into a negligence claim.
That can work for a sole practitioner or a very small partnership with limited email risk and no high-volume cloud use. The problem is that the cover can look broader than it is, because the key trigger may still be a claim rather than an actual attack.
PI is built for professional mistakes. If an accountant sends the wrong tax filing advice, misses a filing deadline after a systems issue, or causes a client loss through an error, PI is the natural place to look first.
PI often stops when you need money to fix the mess itself. That means forensic investigation, incident response, system restoration, business interruption and ransom handling may sit outside the main comfort zone.
The error most often seen here is assuming that a cyber mention in PI means full cyber cover. It does not. A £1 million PI limit can still hide a £25,000 social engineering sub-limit or a £10,000 cap for data restoration.
A small-firm example
A case common in practice: a two-partner firm suffers mailbox compromise and a fake invoice is sent to a client. The client pays the fraudster, then looks to the accountant for losses. PI may help with the claim, but the firm still needs help with IT clean-up and client notification costs.
When standalone cyber cover is the safer choice
Standalone cover is usually the safer choice for a small accountancy practice that uses cloud accounting, shared inboxes, remote access and client portals.
That matters because accountants face a mix of email fraud, phishing, ransomware and accidental data loss. Those are first-party problems first, and liability issues second.
A standalone policy is more likely to pay for forensic work, breach response, legal advice, data restoration and business interruption. Those are the costs that arrive before anyone starts arguing about negligence.
If your firm could not easily absorb one to two weeks of downtime, separate cyber insurance is usually worth serious attention. A few lost days of fee-earning work can cost more than the premium.
The trigger is the event that makes the policy start. In cyber cover, that can be a breach, an attack, a system outage or extortion demand.
In PI, the trigger is more likely to be a wrongful act, a service failure or a claim from a client. That difference sounds small, but in a real incident it decides whether money arrives early enough to matter.
Phishing often leads to mailbox takeover, then invoice redirection. Ransomware can lock file shares and cloud-synced documents. Accidental deletion can wipe out a month of working papers if backups are weak.
For a firm turning over under £1 million, a cyber incident that stops billing for five working days can hurt more than a modest cyber premium. That is why the right cover is the one that pays when work stops, not only when a claim starts.
A typical ransomware case for accountants starts with a phishing email, followed by stolen credentials and then encrypted files across a shared drive or cloud accounting software. In that moment, the firm needs incident response, forensic investigation and systems recovery before it can think about client claims. A standalone policy is more likely to pay for the emergency work needed to contain the attack, recover backups and restore access to billing systems, while a PI extension may only become relevant if clients later allege delay, missed deadlines or poor supervision.
The same logic applies to data breach events: if a mailbox or document store is exposed, the immediate costs are notification, legal advice and recovery, not just compensation. For a small accountancy firm, the real value of insurance for accountants is that it funds the clean-up while the practice is still trying to trade.
Costs, excesses and hidden trade-offs
Price is only part of the decision. A cheaper PI extension can look tidy on paper, but the excess, sub-limits and waiting periods can leave a small firm paying the real bill anyway.
For a UK accountancy practice, standalone premiums are often higher, but they can still be better value if one incident would cost more than the premium gap.
Small-firm premiums in the UK commonly sit in a band of about £200 to £900 a year, while a PI extension may be tens or low hundreds of pounds if offered as an add-on. The lower number is not always the better deal.
Sub-limits are smaller caps inside the main policy limit. They matter because social engineering, computer fraud, ransomware and restoration often carry their own lower ceiling.
One policy may advertise £1 million cover but only £25,000 for cybercrime. Another may have a £100,000 main limit for incident response and a separate restoration bucket.
Excesses can be one practical issue. Waiting periods for business interruption can be another. Some policies only start paying after a delay of 8, 12 or 24 hours, which can matter if your work stops on a Monday morning.
There is also the cost of overlap. If PI and cyber both respond, one insurer may try to pass the claim to the other.
One of the most useful checks is to map the trigger and the sub-limit before you buy. A PI extension is often triggered by a client claim or a negligence allegation, so it may not respond until the loss has already become a dispute. A standalone policy, by contrast, is usually triggered by a data breach, ransomware event, system outage or cybercrime response incident, which means it can fund incident response earlier. That matters because a £1 million PI limit can still be unhelpful if the social engineering sub-limit is only £25,000, or if restoration costs sit under a separate small cap.
In practice, overlap is common: PI may cover client claims arising from an email fraud loss, while cyber pays for forensic investigation, data breach notification and systems recovery. If both policies respond, the policy wording decides which insurer leads and whether defence costs erode the limit.
Which cover fits each type of firm
The right choice depends on how digital your practice is, how much client data you hold and how painful a short shutdown would be.
If you mostly do annual accounts for a few local clients and keep limited data, a PI extension may be enough. If you manage payroll, VAT, cloud bookkeeping and remote access, standalone is usually the better base.
Small, low-tech practices
A small firm with minimal online systems, little remote access and low client data volumes may find a PI bolt-on acceptable.
Even then, check whether the extension covers data restoration, fraud and incident response. If it does not, the policy may be too thin to matter when something goes wrong.
Cloud-heavy accountancy firms
Firms using cloud accounting, 365 email, shared drives and client portals should lean towards standalone cover.
If you also handle payroll, pension data or tax IDs at scale, the stakes rise again. An event can become a notification job, a legal job and an IT job at the same time.
How to choose without the jargon
Choose the policy that pays for the loss you are most likely to face first. For most small accountants, that is not a courtroom fight; it is an inbox breach, locked files or a client payment scam.
If your PI extension only responds to negligence or a third-party claim, treat it as partial cover. If you want help with recovery, interruption and cybercrime, standalone is usually the better starting point.
Ask these four questions
Does the wording cover ransomware, business interruption and data restoration, or only claims? Does it cover social engineering and fraudulent transfer requests? Are the sub-limits large enough to matter? Can the insurer step in before a client claim is even made?
If the answer to any of those is no, the policy may not be enough for a small firm that works mainly online.
Use this rule of thumb
If losing email for two days would be painful, buy standalone cyber. If the main concern is a client suing over advice or a filing mistake, keep the PI focus but do not assume the cyber bolt-on is enough.
That rule is simple because it mirrors the loss. Recovery costs belong to cyber. Negligence claims belong to PI.
What most guides leave out
The biggest blind spot is the overlap between policies. If one cover pays for legal defence and the other pays for IT recovery, you need to know who pays first and who decides the response.
The second blind spot is claim notification. Cyber policies can require fast notice, sometimes within days.
A £250,000 cyber section with broad response cover can be better than a £1 million PI extension with a small cyber note. That sounds counterintuitive, but it reflects how accountants are actually hit.
The FCA, ICO and NCSC are all useful reference points here, but the real test is your own wording. If it does not cover the event you fear, the brand on the front of the policy will not save you.
Check for sub-limits on social engineering, computer crime, ransomware and restoration. Check whether your cloud accounts are included. Check whether business interruption needs a minimum outage period before payment starts.
Also check if defence costs reduce the limit or sit outside it. That detail can change the size of the claim payout more than the premium difference.
What people ask
Does PI insurance cover cyber attacks?
Sometimes, but only in a narrow way. PI usually helps when the cyber event turns into a negligence claim or third-party dispute, not when you need to restore systems or recover from ransomware.
Is a standalone cyber policy worth it for a small firm?
Yes, if you use cloud software, email and client portals. Even a few days of downtime can cost more than a modest annual premium of about £200 to £900.
What is the biggest gap in a PI cyber extension?
The biggest gap is first-party recovery. Many extensions do not fully pay for forensic work, business interruption, data restoration or ransom-related costs.
Do cyber policies cover phishing and invoice fraud?
Often, yes, but only if the policy includes social engineering or fraud cover. The sub-limit may be much lower than the main limit, so check the cap before you buy.
Can I rely on PI if my clients are the main risk?
Only if the main risk is a claim, not a recovery job. If the likely loss is an inbox takeover or system lockout, PI is usually the wrong main tool.
Should I buy both PI and cyber cover?
Many small practices do, because the policies solve different problems. PI is for claims and cyber is for recovery, so the combined setup can be the safest option when you hold sensitive client data.
What should I ask a broker first?
Ask whether ransomware, business interruption, fraud and data restoration are covered, and at what sub-limit. Also ask whether the policy responds to an actual attack without a negligence claim.
Which cover to choose in your case
For most small UK accountants, a standalone cyber policy is the better choice. It gives broader first-party cover, clearer help after phishing or ransomware, and less dependence on a client claim arriving first.
A PI extension is only enough when your cyber exposure is low, your digital setup is simple and the wording clearly covers the losses you care about. Even then, check the sub-limits carefully, because the real weakness is often hidden there.
If you want a simple answer, use this one: choose standalone cyber if your firm would struggle to pay for outage, recovery and fraud losses from cash flow. Keep the PI extension as support for liability, not as a substitute for cyber cover.
For a small accountancy practice, the right cover is the one that pays when email goes wrong, files disappear or a machine is locked. A PI extension can help with claims, but a standalone cyber policy is usually the better answer when the incident itself is what stops the firm trading.