For UK accountants, cyber insurance and professional indemnity usually depend on who suffered the loss. PI commonly responds when clients allege that negligent work caused financial loss. Cyber insurance is for your firm’s own costs after a cyber incident.
PI pays client claims, cyber pays breach response
Professional indemnity usually responds when a client alleges professional negligence. Cyber insurance usually responds to first-party losses faced by your own firm after a cyber incident.
PI can pay legal defence costs and damages where covered professional services allegedly caused a client loss. A wrong VAT calculation, negligent tax advice, or missed Companies House filing is familiar PI territory.
Cyber cover can fund incident response after phishing, malware, or unauthorised access. It can include IT forensics, legal advice, client notices, data recovery, and business interruption. Limits and conditions still apply.
The two policies solve different problems.
Choose both policies if your firm holds client records digitally and gives advice. This includes firms preparing accounts, running payroll, or accessing cloud-accounting platforms. Choose PI alone only after checking that cyber exposure is truly very low. That is unusual for an active accountancy practice.
Accountancy incidents: which policy may respond?
The same incident can create different losses, so both PI and cyber insurance may need to be notified.
| Accountancy incident | Likely first response | Cost or condition to check |
|---|
| Phishing exposes client records | Cyber, possibly PI later | Forensics, notification costs, and a client negligence claim |
| Ransomware stops bookkeeping work | Cyber, possibly PI later | Data recovery, extortion, 24 to 72-hour waiting period, lost income |
| Tax return sent to wrong recipient | Cyber and/or PI | Data breach definition, professional-service error, and excess |
| Cloud accounting login stolen | Cyber | Investigation, restoration, and any PI cyber exclusion |
| Payment sent after spoofed email | Possibly neither, or crime cover | Social engineering sublimit and transfer checks |
Ransomware response is usually a cyber question first, although a later PI claim is possible. Locked systems may cause a client to miss a filing deadline. The client may allege that your firm failed to protect its work.
Payment fraud often falls into a gap. Cyber liability and crime insurance are not the same thing. Many policies have a lower social-engineering sublimit, often between £25,000 and £100,000. They may require a call-back or dual approval process.
Fraud cover can be much narrower than expected.
How one breach can trigger two policies
1. Phishing or ransomware
2. Cyber funds IT, legal, and recovery
3. Client alleges loss
4. PI may defend that claim
Choose cyber cover with fraud protection or separate crime cover if staff can alter bank details. Do the same if they release payments or hold client banking credentials.
Policy wording can defeat a good-looking limit
A £250,000 or £1 million limit helps only when the relevant cost falls within the wording.
Terms worth checking before renewal
A cyber exclusion removes some or all cyber-related losses from PI. Affirmative cyber cover clearly states which cyber events it covers. Silent cyber means the wording may be unclear because it was not designed to address cyber losses directly.
Sublimits and notification rules
Compare sublimits for IT forensics, data recovery, extortion, business interruption, breach notices, and social engineering. Report a breach, suspected fraud, or client threat promptly. Notify both insurers, or notify through your broker. Do not admit liability.
A client claim and an IT emergency can arise from the same event. They are not the same insured loss.
Choose wording that names costs you would face during the first incident week.
Price is not a reliable reason to choose one policy over the other. PI and cyber insurance are rated on different exposures. PI premiums often reflect annual fee income, services, client concentration, claims history, limit, and excess.
Higher-risk work can raise PI costs. Examples include tax planning, audit-related services, and corporate finance. Cyber pricing often reflects turnover, client records, cloud accounting, payroll, remote access, payment authority, and prior incidents.
Insurers also review security controls, including multi-factor authentication, backups, and staff phishing training. A low premium may mean a lower sublimit for ransomware, social engineering, or business interruption.
Compare the cover, not just the price.
Choose limits by data, systems and payment access
The right cover depends less on staff numbers than on what your firm holds, accesses, and cannot operate without.
A practical fit by firm type
A sole practitioner should usually keep PI. They should also consider cyber cover with breach response and business interruption. A practice running payroll or bookkeeping should usually hold both.
Sensitive staff data and fixed deadlines make recovery costs more likely. Holding both policies is like keeping both a fire extinguisher and a legal adviser. One tackles the immediate damage. The other deals with a later claim.
Fines, regulators and real limits
The ICO can investigate a breach under UK GDPR. Regulatory fines are not automatically insurable. Check whether the policy covers regulatory defence costs. Check whether it covers penalties only where legally insurable.
Do not rely on broad wording such as “fines and penalties”.
Choose PI plus cyber as the default for an accountancy practice handling digital client data. Add crime cover where staff can influence or release payments. Ask your broker to confirm overlaps in writing before buying.
This comparison matters less if you do not provide accountancy services. It also matters less if you do not process client data or depend on digital systems. It cannot replace a review of a specific policy. After a breach, fraud, threat of claim, or regulatory contact, follow your insurer's notification procedure. Obtain suitable professional advice.
Before renewal, send your broker the five table scenarios. Ask which policy responds, which sublimit applies, and whether notice is needed.
For UK accountants, PI and cyber cover serve different needs. No single law requires every accountant to buy cyber insurance. Professional-body rules, practising certificates, engagement terms, and client contracts can make PI compulsory. They can also make PI commercially essential.
Members in public practice under ICAEW or ACCA may need PI. Their cover may need to meet applicable rules. Those rules can include minimum limits and approved wording requirements.
Cyber insurance is more often a risk-management or contract choice, particularly where a firm processes personal data or uses cloud systems. Larger clients may ask for evidence of cyber resilience. Check membership rules and client agreements. Do not assume one policy meets both needs.
Your daily work should guide the cover.
Match insurance to how the practice actually works. A sole practitioner using email and a cloud ledger still needs PI for client allegations. They should consider cyber cover for account takeover, breach response, and lost system access.
A small bookkeeping or payroll firm has added exposure. It holds employee data and works to fixed payment and filing dates. Business interruption can matter greatly in that setting.
A firm with cloud accounting administrator rights should check restoration cover. It should also check client records cover and third-party claims after compromised credentials. Where staff can view, amend, or release bank details, add crime protection. Support it with dual approval and independent call-back controls.
FAQs
Do accountants need cyber insurance?
Usually, yes, if they hold client data or depend on email and cloud systems. Cyber insurance is not a general legal duty. PI alone may not pay breach response, ransomware recovery, or lost income.
Does PI insurance cover a data breach?
Sometimes, but usually only when a third party alleges professional negligence caused loss. It may not pay forensic IT, data recovery, or client notification costs. Specific cover may be needed.
Does cyber insurance cover ICO fines?
It may cover regulatory defence costs and fines only where legally insurable. Check the regulatory section. UK GDPR penalties and ICO outcomes depend on facts and law.
What is a claims-made PI policy?
It is a PI policy that usually responds when you report a claim or known circumstance during the policy period. Keep continuous cover. Check the retroactive date when changing insurer.
Can one incident be reported to two insurers?
Yes, and this is often sensible when a cyber event could create a client claim. Notify each insurer promptly. Do not decide liability or admit fault.
How much excess should an accountant accept?
Choose an excess your firm can pay without delaying urgent IT or legal help. Cyber excesses can range from nil to several thousand pounds. Fraud sections may have separate conditions.
Is crime insurance needed with cyber cover?
It may be needed where staff release payments or manage client bank details. Standard cyber policies can exclude direct fund loss. They may limit social engineering claims to between £25,000 and £100,000.
Buy both where the risks overlap
Most accountancy firms in England should treat PI and cyber insurance as complementary products. They are not competing products.
The edge case is a very small practice that holds no client data digitally and does not rely on email, cloud systems, or online payments. That profile is now rare.
That practice still needs PI where professional rules, contracts, or services require it. Choose PI for professional claims. Add cyber insurance where breach response and recovery are relevant. Add crime cover where payment fraud is a real risk.
The best choice is usually both policies.
Will cyber insurance pay a ransomware demand?
It can, but only when extortion is included and policy conditions are met. Check the extortion sublimit and insurer consent requirement. Check sanctions restrictions before relying on it.