Many recruitment agencies assume their professional indemnity (PI) policy will pay when ransomware locks their ATS or exposes CVs. That assumption can leave a costly gap. Incident investigators, candidate notices, legal support and lost fees may sit outside PI cover. A reportable personal data breach may need notice to the ICO within 72 hours.
Cyber cover pays when recruitment systems fail
Cyber insurance is built for digital incidents that affect an agency's data, systems or income.
A cyber policy may pay the practical costs of a covered breach. The result depends on wording, aggregate limit, sublimits, excess and exclusions. Never treat regulatory fines as automatically insured. Legal insurability and policy wording both matter.
A comparison of specialist sources shows a clear split. PI may respond when a client alleges financial loss from your service. Cyber cover is designed for incident response and system recovery.
There can be overlap between the policies. Each claim still needs checking against its own wording.
The Information Commissioner’s Office explains UK data protection rules under UK GDPR and the Data Protection Act 2018. The 72-hour notice period can be very short. A breach-response lawyer and forensic team can therefore matter.
Consider how a claim can unfold. A recruiter gets a convincing email that seems to come from a contractor. The recruiter then changes the payroll bank details.
If payment is sent, business email compromise and social engineering cover may matter more than a standard breach section. Recovery can depend on telling the bank quickly.
In another case, ransomware blocks ATS access during a busy hiring week. This can create recovery costs and lost placement income. Check whether ransomware and ATS downtime fall within cyber business interruption wording.
A misconfigured CRM can expose CVs and candidate data. The agency may need forensic work, legal advice and an ICO notification assessment. It may also need candidate messages and credit-monitoring support.
These costs should be checked against data breach response sublimits before purchase.
Map each system before choosing a policy
The best starting point is your real workflow, not an insurer's label.
| Operational flow | Likely incident | Likely cost | Cover that may respond |
|---|
| ATS | Ransomware or account takeover | Forensics, restoration, lost fees | Cyber insurance |
| CRM and CVs | Unauthorised export | Legal advice, notification, defence | Cyber, possible PI overlap |
| Shared email | Business email compromise | Fraud inquiry, communications | Cyber if social engineering is included |
| Payroll | Bank-detail manipulation | Misdirected wages, recovery work | Crime or fraud cover, subject to wording |
| Cloud supplier | Supplier outage | Lost billings and recovery costs | Cyber BI if supplier cover applies |
ATS downtime can stop placements
An ATS is not just a filing cabinet. Recruiters may lose candidate notes, compliance records and client needs. Vacancies can stay unfilled, and contractor starts can stop.
Supplier failure needs named cover
The most common error is treating every digital loss as a PI claim. A payroll transfer after a fraudulent email may fall outside cyber cover. Social engineering, funds-transfer fraud or crime cover must be clearly included.
A practical incident path for an agency
Suspicious email or locked ATS
→
Call insurer response line
→
Contain, investigate, restore
→
Assess ICO, clients and loss
Keep the insurer's emergency number outside the affected email system. Delayed notice can affect the insurer's control of response costs.
Once you map the workflow, compare policy terms rather than premiums alone.
A recruitment agency should see each policy as a response to a different loss. Cyber insurance mainly covers a security incident. This can include ransomware, breach response, recovery costs and cyber business interruption.
Professional indemnity insurance may address claims about negligent recruitment advice, screening or service. Such claims must have caused a client's financial loss. The policy terms still apply.
Employers' liability covers employee injury or illness claims. It may be compulsory when you employ staff. Public liability covers third-party injury or property damage.
Legal expenses or regulatory cover may give separate help for disputes or investigations. It does not replace cyber cover. Ask the broker to show the trigger, limit and exclusions for each policy.
Compare limits, fraud terms and recovery time
Two quotes with a £1 million headline limit may cover very different risks.
Check the limits behind the headline
Ask if incident response, forensic work and data recovery have separate lower caps. Also check cyber extortion and business interruption limits. Ask if defence costs reduce the main limit.
Think of it like one household budget. A large legal bill can leave less money for the rest.
Test bank changes outside email
A comparison of specialist sources shows common insurer checks. These include multi-factor authentication, tested backups and limited ATS access. Insurers also check phishing training and supplier checks.
The National Cyber Security Centre and Cyber Essentials offer useful starting points. Certification does not guarantee acceptance or a lower premium.
✅
Our recommendation
A FIDO2 USB security key adds a physical check to key accounts. These include email, payroll and ATS administration. It helps most where staff already use multi-factor authentication. It gives stronger protection against stolen passwords.
- It helps protect ATS administrator accounts from password-based phishing.
- It gives payroll staff a separate physical sign-in check for high-risk changes.
- It gives a backup sign-in method when a phone is lost or replaced.
Check availability →
Before renewal, prepare one security questionnaire. Give the same answers to each insurer or broker. This makes quotes easier to compare.
It also shows whether a low price comes from a narrow fraud or supplier exclusion.
Cyber cover matters less for a sole trader with no digital systems, provided they also hold no third-party personal data and do not rely on technology suppliers. This is unusual for an agency handling CVs, client contacts or online placements. This guide gives general information. It is not personal insurance, legal or regulatory advice.
Cyber insurance pricing for recruitment agencies depends on more than turnover and headcount. Insurers may consider the number of candidate records held. They may also consider payroll and dependence on an applicant tracking system.
They can check annual gross profit, past incidents and client contract limits. They may also assess MFA and offline-tested backups.
For comparable quotes, give each insurer the same renewal declaration. List systems, ATS and CRM suppliers, revenue figures and data volumes. Include security controls, claims history and requested limits.
State the limits needed for ransomware, funds-transfer fraud and cyber business interruption.
Then compare the excess, waiting period and sublimits with the annual premium. A cheaper policy may exclude the supplier outage that stops placements.
Frequently asked questions
What insurance do recruitment agencies need?
Recruitment agencies commonly consider PI, employers' liability, public liability and cyber insurance. Employers' liability is generally compulsory if you employ staff. The right mix also depends on contracts, premises, payroll and candidate data.
Does cyber insurance cover a GDPR breach?
Cyber insurance may cover breach response, legal advice and third-party claims after a UK GDPR incident. Regulatory fines are not automatically covered. Wording, law and legal insurability determine the result.
Does PI insurance cover ransomware?
PI insurance does not usually pay to remove ransomware or restore an ATS. It may respond to a later claim about your professional service. The service must have caused a client's financial loss, subject to policy terms.
How much cyber cover should a small agency buy?
A small agency should choose cover based on data volume, gross profit reliance and client contracts. Staff numbers alone are not enough. Check whether £1 million to £5 million contract demands have suitable response and interruption sublimits.
Does cyber essentials reduce insurance costs?
Cyber Essentials can support underwriting but does not guarantee a lower premium. Insurers commonly assess MFA, backups, access control and phishing training. They also assess past incidents alongside certification.
The essentials:- PI cover and cyber cover address different problems. Do not assume that one replaces the other.
- Map ATS, CRM, email, payroll and suppliers against the costs of a real incident.
- Compare sublimits, fraud wording, supplier cover, excesses and interruption periods before comparing premiums.
- Use MFA, tested backups and independent bank-detail checks. These steps can reduce risk and insurer concerns.
Learn more
Here are some additional resources on this subject: