The best insurance for consultants working from home is a policy that covers data breaches, ransomware, business interruption and incident response, while fitting how you actually work: client data, home Wi‑Fi, personal devices and cloud tools. For UK consultants, the right cover depends on your services, turnover and whether you handle sensitive information or payments.
Can your home-working consultancy be covered?
A home-working consultancy can often be covered, but only if the policy matches how you really work.
Working from home does not make cyber risk smaller. A laptop on a kitchen table can be safer than a shared office, but a weak Wi‑Fi password, an old phone or a family member using the same device can still open the door to phishing, malware or a data breach.
Which consultants need cyber cover most?
Consultants who hold client personal data, bank details, contracts or login access need the strongest cover. That includes accountants, HR consultants, IT consultants, recruiters, legal advisers and contractors who manage client systems.
Does working from home lower the premium?
Not always. Some insurers price by turnover, sector and controls, not by office rent or commute time. If you use good security, such as multi-factor authentication, encryption and current software, the quote can be better.
What matters more is whether the insurer sees your home setup as controlled. A policy may cost less if you use only company devices, keep backups and separate business from family use.
A home-working consultant with £150,000 turnover and client data on one encrypted laptop will often need a different policy from a contractor with five staff, shared logins and access to payroll records. The setup changes the risk, and the price should change with it.
How cyber cover works alongside professional indemnity
Professional indemnity insurance and cyber insurance solve different problems. PI is about advice, mistakes and negligence, while cyber cover is about digital events such as data breaches, ransomware, phishing, service interruption and other malicious or accidental online incidents.
A client claim in England can touch both. If you give bad advice and then a cyber event exposes files, or if a cyber incident causes financial loss and a service mistake worsens the damage, the question is not which policy sounds better, but which one responds to the actual loss. That is why consultants should not buy one and ignore the other: the policies can sit side by side, like a lock on the door and a burglar alarm on the wall.
PI helps when the claim is about a professional mistake, such as wrong advice or a missed deadline. It may not help when the loss comes from malware, stolen credentials or a hacked mailbox. If you send a client the wrong spreadsheet because your email was compromised, both policies may matter. The exact response depends on the wording and on what caused the loss first.
Good cyber insurance usually pays for incident response, forensic investigation, data restoration, ransom support, legal help and business interruption. In practice, the first hours after an attack are expensive. You may need a specialist to find out what happened, a lawyer to check notice duties, and someone to restore files or stop a fraud in progress. Under UK GDPR and the Data Protection Act 2018, that can quickly become a compliance job as well as a recovery job.
Forensic support means a specialist checks how the attack got in, what was touched and what still needs fixing. Think of it as the digital version of calling an engineer after a burst pipe, before you can sort the floor. Many policies include this only up to a limit, sometimes with a panel provider you must use. If you call your own IT person first, the insurer may not reimburse the cost unless the wording allows it.
Business interruption cover pays when a cyber event stops you working and you lose income. For a home-based consultant, that could be a locked mailbox, a disabled laptop or a cloud account frozen after phishing. Some policies only pay if the outage is caused by a named event and lasts beyond a waiting period. I have seen claims where the cover looked strong on the quote sheet, but the client learned the interruption part only started after 8 or 12 hours.
Minimum cover for a remote consultant
A remote consultant should look for incident response, data restoration, business interruption, third-party liability and clear wording on remote working and personal devices.
For UK GDPR and Data Protection Act 2018 exposure, add legal advice, regulatory response and notification costs. If a client’s personal data leaks, the first bill is often not the fine, but the work needed to tell people, investigate the issue and put it right.
What must be on the policy wording?
Look for wording that names remote working, home office security, personal devices and cloud accounts. If those words are missing, ask the insurer to show how they are covered anyway.
You should also check whether the policy covers stolen data, corrupted files and service interruption caused by a cyber event, not just a full network outage. A home consultant may never have a network in the old sense, so the wording has to fit the way you work.
Which exclusions matter most?
The big exclusions are old software, weak passwords, failure to use multi-factor authentication and unapproved devices. These are the parts that can turn a valid claim into a dispute.
I have seen small firms lose cover because a policy assumed business-grade controls that were never in place at home. That is the trap: the insurer prices for one way of working, then the buyer works another.
How much cover is enough?
For many solo consultants, cyber limits between £100,000 and £250,000 can be a practical starting point. If you hold lots of personal data, take card payments, or rely on your laptop for all income, higher limits can make sense.
There is no magic number. The right limit should reflect the cost of recovery, the income you might lose for a few days, and the worst likely third-party claim.
Should personal devices be included?
Yes, if you ever use them for work. A personal laptop or phone can be fine, but only if the insurer allows bring-your-own-device, often shortened to BYOD.
The device should be encrypted, locked with a strong passcode and updated regularly. If your policy excludes household devices, a claim can fail even when the incident itself looks straightforward.
Best cyber insurance for consultants working from home is usually the policy that matches your actual setup, not the one with the lowest annual premium. A cheaper policy with a long waiting period, weak social engineering cover or no BYOD allowance can cost more after one small incident.

A practical minimum checklist for a home-working consultant should start with cyber liability insurance that includes data breach cover, ransomware cover, incident response and forensic investigation, then add business interruption insurance, third-party liability and social engineering cover. For a solo consultant, the details matter as much as the headline limit: check whether the policy covers one encrypted laptop, a work phone used for client emails, and cloud storage such as Microsoft 365 or Google Workspace. A good baseline also includes UK GDPR and Data Protection Act 2018 notification costs, because a small breach can still trigger legal and client communication work.
If you keep backups off-site and use multi-factor authentication, encryption and backup management properly, the insurer is more likely to view your home office risk as controlled rather than ad hoc.
Compare policies by your consultancy type
The best policy for an IT consultant is not the same as the best policy for a management adviser or freelance marketer. Different consultants handle different data, connect to different systems and face different claims.
A useful way to compare is by turnover, data sensitivity and device use. That gives you a better match than broad labels like “small business cyber cover”, which can hide gaps.
IT consultants often need stronger third-party liability and system access wording. If you manage client servers, remote admin tools or code repositories, a mistake can spread far beyond your own laptop.
They also need careful subcontractor wording. If a contractor patches the wrong system or exposes credentials, the policy should still respond.
What about data-heavy professional services?
Accountants, HR advisers, legal consultants and recruiters usually need stronger cover for personal data handling. That is because the harm from a breach is not just downtime, but privacy harm and notice costs.
For these firms, the UK Cyber Security Council and the National Cyber Security Centre both stress basic controls like multi-factor authentication, updates and backups. Insurers often expect the same habits before they pay.
Which home-working risks are sector-specific?
A marketing consultant may worry more about account takeover and fraud, while a financial consultant may worry more about confidential files and payment diversion. The risk changes with the work, not the postcode.
When comparing policies by consultancy type, it helps to look at turnover, data sensitivity and how much of the job depends on personal devices. A £75,000-turnover marketing consultant who mainly uses cloud tools and stores limited client data may need a different limit and excess from a £400,000 IT contractor with admin access to client systems and higher third-party liability exposure. Consultants who rely on BYOD should check that mobile phones, tablets and home laptops are expressly included, while firms processing payroll, HR or financial records should prioritise stronger data breach cover and regulatory response.
This kind of comparison also makes it easier to spot weak social engineering cover, narrow cloud security wording or exclusions around household devices that could otherwise be missed.
What changes if you use personal devices
If you use a personal laptop, phone or tablet for work, the policy must explicitly allow it. Homeworking cover should not assume office-owned hardware, managed servers or an IT department on hand.
This is where many claims go wrong. The insurer thinks you used controlled equipment, but the actual job runs on a family laptop, a shared home Wi-Fi line and a password saved in a browser.
Is BYOD accepted by insurers?
BYOD is accepted by some insurers, but not all. The wording should say whether personal devices are allowed and whether they must meet minimum security rules.
If BYOD is allowed, check for encryption, screen locks and approved backup methods. If it is not allowed, the policy may still look cheap while quietly leaving you exposed.
Does shared Wi-Fi create exclusions?
Shared Wi-Fi can create problems if the policy expects secure home controls and you do not have them. A weak router password is like leaving the front door half open.
The danger is not only hacking. A household device infected by malware can also spread risk to work files, and that can become a claims issue if the policy excludes poor device hygiene.
Can family use void a claim?
Yes, if family use breaks the policy terms. If children, partners or housemates use the same laptop for personal browsing, the insurer may want proof of separation, such as separate profiles and business-only access.
A good policy will say whether this is acceptable. A bad one assumes the point away and leaves the buyer to discover the gap after a loss.
What to check before you buy
The safest choice is a policy that names remote working, personal devices, incident response, business interruption and social engineering in clear words. If any of those are missing, ask why before you sign.
Compare policies by turnover band, data type, device ownership and subcontractor use, not by headline price. A lower premium can hide a higher excess, a longer waiting period or a narrower claims process.
For consultants in London, Manchester or anywhere in England, the best policy is the one that matches your real working day. That means your laptop, your cloud tools, your clients and your cash flow.
Use this shortlist before renewal
- Check remote working wording, so the policy clearly covers home office use and off-site access.
- Confirm personal devices are allowed, especially if you use your own laptop or phone for work.
- Ask about incident response, because fast specialist help often matters more than the annual premium.
- Review business interruption terms, including the waiting period and the loss formula.
- Look for social engineering cover, because invoice fraud and fake payment requests are common.
- Pair cyber with PI if needed, especially if your advice, data handling or client access creates dual exposure.
This does not fit every buyer. If you never store client data, never take payments online and only use a locked corporate device with central IT control, your cyber needs may be narrower. In that case, check whether the policy is still worth the premium or whether a lighter package fits better.
What people ask
What does cyber insurance cover?
It usually covers breach response, data restoration, legal help, ransomware support and lost income from downtime. Some policies also cover social engineering and regulatory response, but not all do.
Do i need cyber insurance if i work from home?
Yes, if you use email, cloud tools, client data or personal devices for business. Working from home changes the risk, but it does not remove it.
Is cyber insurance worth it for a small consultancy?
It is often worth it when one incident could stop work for days or trigger a client claim. For a solo consultant, even a short outage can be expensive.
Does a laptop hack count as a cyber claim?
Usually yes, if the hack leads to data loss, access theft, malware or business interruption. The exact result depends on the wording and on how the incident happened.
Can i claim if a client email is spoofed?
Sometimes, but only if the policy includes social engineering or invoice fraud cover. Many basic cyber policies leave this out or cap it tightly.
Do i need cyber insurance if i already have PI?
Yes, often you do, because PI and cyber cover different risks. PI may help with advice errors, while cyber handles digital attacks and recovery costs.
What if i use my own phone for work?
Check that the policy allows BYOD and that the phone is protected with a passcode, updates and, ideally, encryption. If it is not allowed, the claim may be harder to pay.
How much cover should a consultant buy?
Many solo consultants start around £100,000 to £250,000, then adjust for client data, turnover and downtime risk. If you hold sensitive data or depend on one laptop for all income, higher limits may be safer.
Which policy is right for your consultancy?
The right policy is the one that fits your turnover, your data and your devices.
A policy with strong wording, clear BYOD acceptance and sensible social engineering cover usually beats a cheaper plan with gaps. If you also advise clients, touch confidential records or handle payments, pair cyber insurance with professional indemnity and check the overlap before you buy.
For most consultants in England, the best decision is the one that matches the risk you can actually describe. If you can explain your working setup in one short paragraph, your policy should be able to match it in one clear schedule.
Imagine a freelance HR consultant working from home who receives a convincing email that appears to come from a regular client. The message asks for updated bank details and a new document upload link. If the consultant clicks the link, malware can compromise cloud access, expose employee records and trigger incident response costs, forensic investigation and notification duties under UK GDPR. In another common scenario, a management consultant loses a personal laptop on a train after a client meeting; if the device is encrypted and backed up, the claim may focus on restoration and response rather than full data loss.
These examples show why remote working risk is not theoretical: the best policy is the one that responds to the way freelancers actually handle email, files, payments and devices at home.