A single phishing email can move money, expose client records and trigger a tense call with the insurer. For a small accountancy firm, the problem is rarely the attack itself; it is assuming the wrong policy will respond when the loss lands on the balance sheet or a client makes a claim.
Professional indemnity and cyber insurance overlap, but they are not the same. PI usually covers claims arising from professional mistakes, while cyber insurance is designed for data breaches, phishing, ransomware and business interruption caused by a cyber incident. Many accountants need both, especially if they store client data, use cloud systems or take payments online.
Do accountants need one or both policies?
Most small accountancy firms need professional indemnity insurance, and many also need cyber insurance. PI usually handles claims that arise from professional mistakes, while cyber cover deals with the costs of a data breach, ransomware, phishing, and business interruption. A firm that handles payroll, tax returns, or cloud bookkeeping can face both kinds of loss from one incident.
The easiest way to think about it is this: PI protects the advice, cyber insurance protects the systems. One is about getting the work wrong. The other is about someone breaking in, tricking staff, or locking the files.
A lot of confusion comes from brochure language. A policy may mention computers, data, or fraud, yet still exclude the exact loss a firm faces in real life. The error most firms make at renewal is assuming the label tells the full story.
The simple rule for firms
If the loss starts with a professional mistake, PI is usually the first policy to check. If the loss starts with hacking, phishing, or ransomware, cyber insurance is usually the first policy to check. If both happen together, both policies may need to be notified quickly.
That matters because claims made policies depend on timing. If a firm waits too long, cover can become messy even when the loss itself looks clear. According to the UK Government, UK GDPR and the Data Protection Act 2018 can force firms to act quickly after a breach, which is one reason response cover has real value UK data protection rules.
A firm that keeps payroll files, client passports, or tax records should not assume PI is enough. The safe choice is usually both policies, checked side by side.
What this means in practice
A small practice in Manchester might lose access to accounts files after ransomware. PI will not usually pay to rebuild the server or hire forensic help. Cyber insurance often will, if the wording fits and the security conditions were met.
A different firm might miss a filing deadline because a partner entered the wrong figures. That is a classic PI claim, not a cyber claim. The system may be involved, but the real issue is the professional error.
If the loss started with a bad piece of advice or a filing mistake, PI is the starting point. If it started with a breach, a scam, or locked systems, cyber insurance is the starting point.
What PI usually covers for accountants
Professional indemnity insurance usually covers claims that a client says were caused by poor advice, a missed deadline, or a wrong filing. It is the standard protection for accountants, bookkeepers, and tax advisers in England. It is not built to pay every bill after a cyber incident, even when the incident hits client data.
The phrase professional indemnity sounds broad, but the cover is still narrow in one key way. It follows the professional service. It does not automatically follow the computer.
The Association of Chartered Certified Accountants, the Institute of Chartered Accountants in England and Wales, and similar bodies treat PI as core cover for regulated work. That is because a bad entry in a tax return can cost a client money long after the work was done.
Negligence, errors and omissions
PI usually responds when a client says the firm made a professional mistake. That can mean a wrong VAT treatment, a missed filing date, a payroll error, or bad advice on a tax position. It can also include the cost of defending the claim.
This is what many insurers call errors and omissions insurance. The words sound technical, but the idea is plain: the firm did the work badly, or the work led to a loss.
The Law Society, ICAEW, ACCA, and CIPFA all sit in a world where professional liability is treated seriously. That is why PI is often written as a claims made policy, where the claim must be reported in the right policy period.
Why cyber losses are often excluded
Many PI wordings exclude cyber events outright, or they add a small sub-limit that is far below the main limit. That means a policy may look generous on paper, yet still leave a firm exposed after ransomware or phishing.
The most common trap is assuming “computer loss” means full cyber cover. It usually does not. A computer is only the tool. The policy still needs the right wording for the event.
A claim can also fall into a grey area if the client says the firm lost confidential information but the insurer treats the event as a breach. That is why accountants need to read the exclusions, not just the limit.
What this section means for a small firm
If the firm gives advice, files returns, or prepares accounts, PI is usually non-negotiable. If the firm also stores personal data, uses cloud software, or sends bank details by email, PI alone is usually too thin.
The practical answer is simple. Keep PI for the professional side. Add cyber cover for the digital side.
What cyber insurance pays for
Cyber insurance is mainly about the cost of dealing with a cyber incident. It often covers the firm’s own losses first, then some claims from third parties. That split matters because the first bill after a breach is usually not a court claim. It is the clean-up.
For a small accountancy practice, that clean-up can be expensive fast. Files need checking. Staff need resetting. Clients may need warning. Systems may need rebuilding. None of that feels like a normal professional mistake.
First-party cover in practice
First-party cover pays the firm’s own bills after an incident. That can include incident response, forensic investigation, data restoration, extortion support, and business interruption. It may also cover the cost of calling in specialists to see what was taken and what still works.
Think of it like home insurance after a burst pipe. The policy is not paying for the neighbour’s complaint first. It is paying to dry the house, fix the floor, and stop more damage.
This is where cyber insurance usually beats PI in a real incident. PI rarely pays for the firm’s own clean-up unless the wording adds that protection in a very specific way.
Third-party liability after a breach
Third-party cover deals with claims from other people. That can mean a client, supplier, or another third party who says the firm exposed confidential information or caused a loss.
That matters under UK GDPR and the Data Protection Act 2018, because a breach can create both direct costs and wider legal risk. The ICO sets out breach reporting rules, and some incidents must be reported within 72 hours if the risk threshold is met ICO breach reporting guidance.
Cyber cover can also help with notification costs, call-centre costs, and legal advice on what must be said and when. That is very different from paying a negligence claim about accountancy work.
What this section means for a small firm
If a breach leads to client notices, forensic work, and time off the network, cyber insurance is the main policy. If the breach also leads to a client claim, PI may join in. The firm should not wait to see which one is nicer to use. It should notify both if both could apply.
It also helps to understand the difference between first-party and third-party cover. First-party cover pays the firm’s own costs, such as forensic investigation, data restoration, business interruption, and incident response after a data breach or ransomware attack. Third-party cover deals with claims from clients or other people who say the firm caused them loss, for example by exposing client records or mishandling confidential information. In practice, an accounting firm using cloud bookkeeping tools may need both: first-party cyber cover to get back online quickly, and third-party protection in case a client brings a claim under UK GDPR or the Data Protection Act 2018.
That split is often what makes cyber insurance so valuable alongside professional indemnity insurance.
Which policy pays for each incident?
The right policy depends on how the loss started. That sounds simple, yet it is where many accountants get caught out. A tax mistake, a phishing attack, and a ransomware event can all involve the same email system, but the insurance response is not the same.
The short version is clear. PI covers professional failure. Cyber insurance covers digital attack, breach response, and system recovery. Some events overlap, so the firm may need both.
Error in a tax return
A wrong figure in a tax return usually points to PI. If the firm filed the wrong data and the client paid a penalty, that is a professional claim. Cyber insurance usually does not pay for the mistake itself.
A common error is to call every software-related issue a cyber event. That does not work. If the accountant entered the wrong VAT code, the loss came from the service, not from a breach.
Unpaid tax penalties can still lead to client complaints, defence costs, and settlement talks under PI. The policy may also pay for the legal defence if the wording allows it.
Phishing or fraudulent transfer
Phishing is when a fraudster sends a fake email to trick staff. A fraudulent transfer happens when money goes to the wrong account because of that trick. Cyber insurance usually sits closer to this risk than PI does.
The edge case is social engineering, which means a scam built around trust and deception. Some cyber policies cover it. Some do not. Some PI policies exclude it unless an endorsement adds it back.
This is one of the places where the first reading of the wording often misleads people. The cover can exist, yet the exact fraud can still fall outside it if the social engineering clause is narrow.
Ransomware and locked systems
Ransomware is malware that locks files or systems until a payment is made. Cyber insurance is usually the relevant policy for this kind of loss. PI is rarely the answer unless the wording has a special extension.
A firm hit by ransomware may lose access to client records, VAT data, and payroll files for days. The cyber policy can be used for recovery, extortion support, and business interruption, if the claim fits the wording.
A PI policy is not built to replace a damaged server. That is the big practical difference, and it is easy to miss when reading a summary sheet.
Lost client data
A lost laptop, a misdirected email, or a hacked inbox can expose client data. Cyber insurance usually handles the breach response side, including notification and forensic checks. PI may still respond if a client claims the firm breached its duty of care.
This is one of the strongest reasons to have both policies. One protects the clean-up. The other protects the complaint.
A case like this often looks small at the start and gets costly later. A single spreadsheet can trigger a week of work and a stack of letters.
A breach can trigger two separate costs: your own recovery bills and a client claim. Cyber usually handles the first; PI often handles the second.
A practical way to separate the two policies is to look at the incident itself. A wrong VAT treatment or a missed filing deadline is usually an error and omission, so professional indemnity insurance is the first policy to check. A hacked inbox, ransomware attack, or lost laptop exposing client records is usually a cyber event, so cyber insurance is more likely to respond first. Phishing and fraudulent transfers sit in the middle: if a fraudster tricks a bookkeeper into changing bank details, the cyber policy may help with the response, but the PI policy may still be relevant if the client says the firm should have spotted the scam.
For accountants, tax advisers and bookkeepers, the question is not just what happened, but how the loss started and which policy wording matches that trigger.
How to read exclusions and endorsements
The policy name is not enough. The wording decides the claim. That is why accountants should read the exclusions, endorsements, limits, and security conditions before assuming PI covers cyber risk.
An endorsement is a change to the standard wording. It can add cover, narrow cover, or create a separate sub-limit. A sub-limit is a smaller cap inside the main policy limit. Those details decide real-world outcomes.
The clauses that matter most
Look for cyber exclusions, social engineering exclusions, data processing exclusions, and any limit on privacy claims. Also check whether the policy only covers third-party claims and leaves first-party clean-up out.
Claims made wording matters too. If the claim arrives late, or the firm fails to report quickly, the insurer may refuse cover even when the loss itself looks plain.
The Association of British Insurers has long pushed buyers to read policy wording carefully, because the title of a policy rarely tells the whole story. That is not a sales problem. It is a wording problem.
Security conditions that can void cover
Many cyber and PI policies expect basic controls such as multi-factor authentication, software updates, backups, and access limits. If a firm ignores those conditions, the insurer may reduce or deny cover.
That sounds harsh, but the logic is simple. Insurance is not a replacement for locking the door.
A firm using cloud accounting software should check whether the policy expects separate logins, backup checks, or email security controls. A missing setting can be enough to create a bad argument after a loss.
What to ask before renewal
Ask whether the policy covers ransomware, phishing, invoice fraud, and data restoration. Ask if there is a separate sub-limit for social engineering. Ask whether notification costs, legal advice, and business interruption sit inside the main limit or outside it.
Ask one more thing too. Ask whether the policy protects you if a contractor, bookkeeper, or outsourced payroll provider causes the loss. That point is often missed until the claim lands.
Before assuming a PI policy will deal with cyber risk, accountants should check the exclusions, endorsements and limits line by line. The key questions are whether the wording excludes phishing, ransomware, social engineering, invoice fraud or data restoration, and whether any cyber extension is capped by a small sub-limit. It is also worth checking if the policy is a claims made policy, because late notification can be fatal even when the facts look straightforward.
A firm that handles client records, payroll data or cloud bookkeeping should confirm whether security conditions such as multi-factor authentication and backups are mandatory. A small practice can think it has cover, only to find that the exact incident falls outside the wording when the claim is reported.
The overlaps brokers see most
The hardest claims are not pure PI or pure cyber. They are mixed cases. One email. One wrong payment. One client complaint. Then the question becomes which policy starts paying first, and whether both need notice.
When one email creates two claims
A spoofed email can fool staff into changing bank details. That can create a cyber claim because the fraud started digitally. It can also create a PI claim if the client says the firm failed to spot the scam.
Unusual cases like this are where delay causes real harm. The firm may need to notify both insurers straight away, even before the size of the loss is known.
A client’s complaint can look like a simple transfer mistake. In practice, it may be a mixed claim with two insurers watching the same facts from different angles.
Why timing matters on claims made policies
A claims made policy only responds if the claim is made and reported in the right period. That means the firm cannot sit on a loss and hope to sort it out later.
Run-off cover matters when a practice closes, a partner retires, or a merger changes the firm’s shape. Old work can still trigger claims years later, especially under PI.
The practical lesson is blunt. If an incident could touch both policies, report it early and let the insurers sort the rest out.
A short audio-ready view
PI is the right starting point for a professional mistake. Cyber insurance is the right starting point for a breach, scam, or system lockout. If the incident has both sides, a small accountancy firm should expect overlap and should not choose one policy blind.
That works well, but only if the wording is checked line by line. The claim outcome usually turns on exclusions, sub-limits, and notification timing. For a small firm in England, the safest move is to treat both policies as partners, not substitutes.
The clause that decides the claim
The deciding issue is often not the headline cover. It is the exact wording. One policy may look better on the brochure, yet fail once the insurer reads the facts.
The wording most articles skip
Read the insuring clause first. That clause says what the policy promises to pay for. Then read the exclusions, because that is where cyber gaps often hide.
A PI policy may cover negligent advice but still exclude cyber extortion, invoice fraud, or data restoration. A cyber policy may cover breach response but leave a social engineering loss to a tiny sub-limit.
This is where firms get surprised. The title says one thing. The claim file says another.
Regulatory angles firms overlook
UK GDPR can create notification duties after a breach, and the ICO can expect reports in many cases. Depending on the work the firm does, there may also be other obligations tied to data handling and secure processing.
A small accountancy firm should also think about payment card exposure if it takes card payments. PCI DSS is not an insurance rule, but it shapes the control standards insurers expect.
Regulatory fines are a separate issue. Some policies exclude them entirely. Some only pay where the law allows insurance of that fine. That point needs checking before renewal.
How to choose limits for a small firm
The right limit depends on the firm’s real exposure, not its size alone. A two-partner practice that handles payroll, tax, and cloud files can face bigger breach costs than a larger but simpler firm.
Matching limit to exposure
A firm with hundreds of client records should expect higher notification and forensic costs after a breach. A firm that only prepares a few self-assessment returns may need less cyber exposure, but PI still matters if advice errors can hit clients hard.
The cost of an incident often scales with the number of people affected. One breached spreadsheet can mean dozens of notices, legal checks, and a trail of client calls.
Many firms review both policies together at renewal, because a cheap limit on one policy can leave the other carrying too much weight.
Run-off and merger issues
Run-off cover keeps PI protection alive after a firm closes or a partner retires. That matters because claims can arrive long after the work was done.
Cyber exposure can also linger if old client data remains in archives or cloud systems. A closed firm is not always a clean break.
A buyer or merging practice should ask who carries historic liabilities. That question can save a very awkward argument later.
Quick decision table for accountants
Use this table to decide where the first check should be. It does not replace the wording, but it gives a fast answer for common incidents.
| Incident |
PI likely to respond |
Cyber likely to respond |
Own costs covered? |
Third-party claim covered? |
| Tax return error |
Yes |
No |
Usually no |
Yes |
| Phishing email leading to transfer loss |
Maybe |
Yes |
Often yes, if social engineering is included |
Sometimes |
| Ransomware lockout |
Usually no |
Yes |
Yes |
Sometimes |
| Client data breach |
Sometimes |
Yes |
Yes |
Yes |
| Missed filing deadline due to software failure |
Yes, if negligence is proven |
Rarely |
No |
Yes |
How to use the table
If the loss is a professional mistake, PI is usually the first stop. If the loss is a breach, a scam, or locked systems, cyber insurance is usually the first stop. If both are in play, notify both insurers.
A firm should not wait for a neat label. Claims are messy. Facts come first.
Which accountants need PI and cyber cover?
Most accountants in practice need PI cover because clients can claim for losses caused by advice, filing errors, or missed deadlines. It is the classic cover for professional work. Any firm advising on tax, accounts, payroll, compliance, or filings should expect PI to sit at the centre of its protection. A mistake in that work can cost a client money quickly. That includes sole practitioners and small partnerships. Size does not remove the risk.
Cyber cover is most useful where a firm stores personal data, sends sensitive files, or depends on cloud systems for daily work. That includes many small accountancy practices, not just large firms in London. A practice that handles payroll, VAT, company accounts, or self-assessment for many clients has a bigger breach exposure. The same is true if the firm uses remote access, shared inboxes, or outsourced bookkeeping tools. The more client data moves by email, the more phishing matters. A single fake bank detail change can turn into a serious financial loss.
PI does not replace cyber cover, and cyber insurance does not replace PI. A firm can be fully covered for a ransomware attack and still have no protection for a bad tax return. This is the most common misunderstanding in the market. One policy covers digital attack. The other covers professional failure. They solve different problems.
A very small practice with little digital storage, few client records, and no online payment flow may still want PI only, or PI plus a slim cyber extension. That is rare, but it does happen. The catch is that even small firms now rely on cloud email, online banking, and shared files. That means “low digital use” is less common than it used to be. If the firm still stores client data on connected systems, cyber cover deserves a serious look.
CFC Underwriting, Hiscox, AXA, and Aviva all sell versions of cyber cover in the UK market, but the wording varies a lot. The market is competitive. The wording is not.
Which policy is better on price?
Cyber insurance can cost less than many people expect, but price alone is a bad guide. A cheap policy with weak exclusions can be worse than a dearer policy with stronger response cover.
What shapes the premium
Premiums usually depend on revenue, client numbers, data volume, security controls, and the type of work done. Firms handling payroll, card data, or large numbers of personal records often pay more.
PI pricing depends more on the work type, fee income, claims history, and the size of the limit. A tax-heavy practice can pay more than a simple bookkeeping firm.
The excess matters too. A low premium with a high excess may save money up front and hurt later.
Where the hidden cost sits
The hidden cost is often the sub-limit. A policy can advertise a large headline limit yet cap cyber response, social engineering, or data restoration at a small amount.
That is why the cheapest option is not always the best value. A firm buying on price alone often finds the small print later.
What to do before renewal
A renewal is the right time to compare wording, not just price. The firm should look at the exclusions, the cyber sub-limit, the claims made wording, and the security conditions side by side.
A short checklist for partners
Check whether the PI wording excludes cyber events.
Check whether cyber cover includes invoice fraud and social engineering.
Check the limits for data breach response, business interruption, and forensic help.
Check the notification deadline and the claims made period.
Check whether run-off cover is needed for retiring partners or a closing firm.
A practical rule
If the firm would struggle to pay for breach response, client notices, and system recovery from its own cash, cyber insurance deserves real attention. If the firm gives advice that can trigger client loss, PI still matters even when cyber is strong.
Which policy should a small firm pick?
The best choice for most small accountancy firms in England is both policies, bought with matching limits and checked wording. PI alone leaves a gap after phishing, ransomware, and breach response. Cyber alone leaves a gap after a tax error or negligent advice.
That recommendation works well, but only if the firm actually stores client data or gives professional advice. If a business has almost no digital exposure and very simple work, a slim cyber add-on may be enough for now. The decision should follow the risk, not the sales pitch.
Frequently asked questions
Is professional indemnity insurance enough for
No, not for most firms. PI covers professional mistakes, but it usually does not pay for ransomware recovery, forensic work, or breach response. A firm that handles client data, cloud files, or online payments usually needs cyber insurance as well.
Does cyber insurance replace PI for accountants?
No. Cyber cover deals with breaches, scams, and system recovery, while PI deals with claims about advice, filing errors, and negligence. A practice can have excellent cyber protection and still be exposed to a client claim over a tax error.
What does first-party and third-party cover mean?
First-party cover pays the firm’s own costs after an incident, such as recovery, forensics, and interruption loss. Third-party cover pays claims from other people, such as clients or suppliers. For accountants, both can matter after a data breach.
Does cyber insurance cover GDPR fines in the UK?
Not always. Some policies exclude fines, and some only pay where the law allows insurance of that fine. The firm should check the wording and the legal position under UK GDPR and the Data Protection Act 2018.
What should a small accountancy firm check first
The firm should check cyber exclusions, social engineering wording, notification deadlines, and the PI claims made period. It should also confirm any sub-limit for breach response or fraud. Those four points often decide the claim.
When do accountants need both PI and cyber
Most accountants need both when they store client data, use email heavily, or handle payroll and tax work. That mix creates both professional liability and cyber exposure. A small practice in England often fits that profile even if it feels “too small” for cyber cover.
This advice is not a substitute for a broker review or legal advice. It is also not the right first step if the firm does not handle client data, uses almost no digital systems, or already has a tailored commercial policy checked by a broker.
The plan to use now
The safest move is to treat PI and cyber as different tools. PI protects the quality of the accounting work. Cyber protects the firm when the system, inbox, or data gets hit.
A firm should review both wordings before renewal, not after a loss. The claim rarely waits for a convenient moment, and the gap usually shows up when the invoice arrives.
If the choice is still unclear, the question to ask is simple: would the firm lose more money from a bad professional decision, or from a breach and the clean-up that follows? For most accountants, the answer is both.
For a small accountancy firm, the honest answer is usually both policies. PI handles the mistake. Cyber handles the attack.
Will PI cover phishing fraud?
Sometimes, but not reliably. Some PI policies exclude social engineering or invoice fraud, or they cap it at a low sub-limit. Cyber insurance is usually a better fit, but the wording still needs checking.