Marketing & digital agencies need cyber insurance because one compromised shared login can expose client data. It can halt campaigns and trigger contractual claims.
Why PI may not cover a hacked ad account
Cyber insurance pays the costs of a cyber incident. Professional indemnity insurance usually covers claims that your work caused a client financial loss.
Incident costs are not advice claims
The most frequent error is treating a client complaint and a system breach as the same claim.
A client may allege that missed Google Ads activity cost £12,000 in sales. The agency may also face £5,000 to £20,000 in emergency support and recovery costs.
The first issue may involve PI. The second needs cyber wording that clearly responds.
| Policy | Typical trigger | Forensics and recovery? | Agency example |
|---|
| Cyber insurance | Unauthorised access, ransomware or data breach | Often, subject to limits and terms | Restoring a compromised CRM |
| Professional indemnity | Alleged negligent professional service | Usually not the primary purpose | Campaign strategy allegedly caused loss |
| Public liability | Injury or property damage | Normally no | Visitor injured at your office |
| Media liability | Content, defamation or IP claim | Rarely | Copyright claim over campaign copy |
Buyer cover differs from cyber marketing
An agency buying cover for its own systems should focus on client data, access details and platform dependence.
An agency marketing cyber insurance products may need closer checks on PI and media liability. It must also consider financial promotion rules under the Financial Services and Markets Act 2000.
A practical cost model should add losses that can happen at the same time. Think of it as adding several bills after one broken key.
A five-person agency may lose two working days of campaign work. At 40 hours per person and £85 per hour, that value alone is £6,800.
That figure excludes overtime and recovery work. An attacker may also redirect £15,000 of advertising spend.
The agency may then need digital forensics, account recovery, client messages and legal advice. It must also check whether social engineering or business interruption cover applies.
The figures are illustrative, but the point is clear. Set limits for multi-client exposure, not just password resets.
Set cover by agency assets, not turnover
A suitable limit reflects the cost of losing your key agency systems. It should not depend only on annual turnover.
Risk matrix for agency assets
| Agency asset | Likely impact | Relevant cover | Control to show |
|---|
| Meta and Google Ads accounts | Campaigns stop or spend is misdirected | Forensics, interruption, social engineering | MFA and named access |
| CMS and hosting | Website downtime or malicious content | Recovery, network security liability | Backups and patching |
| CRM, email and analytics | Personal data breach and client delay | Legal, notification, third-party liability | Role-based access |
| Cloud storage and shared logins | Several client environments exposed | Response, recovery, extortion | MFA and leaver process |
A £250,000 aggregate limit is shared across all insured costs during a policy period. One incident may trigger IT recovery, legal advice, notification and claims from several clients. Check whether each cost comes from that same pot.
Shared logins can weaken a claim
Shared credentials are common in agencies. This is especially true for Meta, Google Ads, WordPress and email platforms.
They are hard to investigate after an account takeover. Nobody can prove who approved access or which former freelancer still knew the password.
Shared access can turn one stolen password into several client problems.
📦
Available on Amazon
A FIDO2 security key adds separate proof of identity for key administrator accounts. It helps where staff manage high-value ad spend or client records.
- Reduces reliance on passwords stolen through phishing.
- Gives named administrators stronger logins on supported platforms.
- Supports an MFA control that insurers may ask the agency to prove.
Search on Amazon →
Compare policy wording before price
Compare the aggregate limit, excess and cyber-extortion sub-limit before comparing price. Also check interruption waiting periods, retroactive dates and supplier cover.
A retroactive date is the earliest date on which an event can arise and still be covered. This matters in a claims-made policy.
- Ask if a cloud-service outage is covered, not only an attack on your own network.
- Check if payment fraud, invoice changes or voluntary transfers need separate crime cover.
- Confirm whether missing MFA, known flaws or earlier incidents can exclude a claim.
- Ask if you must use the insurer's forensic firm, solicitor and PR panel.
- Record contracts needing £1 million, £2 million or higher cyber limits before seeking quotes.
This approach is not the main priority for agencies doing only offline work, provided they never access client systems, data or accounts. It also cannot replace broker, insurer or legal advice when contracts require a named limit, clause or certificate.
For digital agencies, phishing often enters through email marketing platforms, cloud mailboxes or ad administrator accounts. It is rarely a direct attack on the agency website.
A fake Meta or Google Ads alert can steal a password and session details. This can then lead to a hacked ad account or changed bank details.
It may also cause unauthorised campaign spend. Use named accounts and multi-factor authentication for every administrator.
These controls improve Google Ads and Meta account security. They also show who approved access and whether data duties were affected.
Frequently asked questions
Do marketing agencies need cyber insurance?
Marketing agencies need cyber insurance if they hold client data, manage accounts or rely on online systems. One compromised shared login can stop campaigns and create costs that PI may not cover.
Does professional indemnity cover a hacked CRM?
Professional indemnity may cover a negligence claim, but it often does not fund CRM forensics or data recovery. Check that cyber response and network security liability are clearly included.
How much cyber cover does a small agency need?
Many small agencies compare limits between £250,000 and £1 million. The right figure depends on client numbers and platform access.
Add likely recovery, downtime, legal and multi-client claim costs before choosing. Your turnover alone is not a safe guide.
Does cyber insurance cover GDPR fines in England?
Cyber insurance may cover legal defence and some regulatory costs, subject to policy terms and insurability rules. It cannot promise payment of every fine or remove UK GDPR duties.
Choose wording that can pay after an attack
The best policy matches your agency's access model, client contracts and recovery costs. It is not always the policy with the lowest premium.
The practical order is simple: remove shared access, enable MFA, test backups and list key suppliers. Then compare wording and limits.
Although this works well in theory, agencies often miss a freelance account that remained active before a breach.
A policy only helps if it defines the incident, sets usable limits and matches controls the agency can prove.
The essentials:- Cyber cover can fund breach response and downtime where PI may not respond.
- Set limits against account, data and supplier exposure, not turnover alone.
- Shared credentials and missing MFA can affect security and cover.
- Compare sub-limits, exclusions and response firms before accepting the cheapest quote.
When comparing UK providers, separate the insurer, broker and incident-response firms. They have different jobs after a breach.
Two quotes can show the same headline limit but offer very different response terms. One may give a 24-hour breach line and approved forensic firms.
Another may need consent before forensics and recovery work can start. That delay can matter when campaigns are live.
Ask if the provider knows agency cyber risk. Ask if its legal and forensic partners can support UK GDPR notification choices.
Also ask if the wording covers third-party platforms, outsourced IT suppliers and client account access.
Will cyber insurance pay if staff do not use MFA?
It may not pay if the policy makes MFA a condition or excludes weak security controls. Read proposal answers and security warranties before relying on cover for shared access.
Related sources
These articles can help you explore the topic in more depth: