You may be paying for professional indemnity and still be uncovered when a client’s data is lost, leaked or stolen. That is a costly gap for consultants, because a single breach can trigger client claims, regulatory notifications, recovery costs and days of lost work, often before you have time to work out which policy should respond.
Professional indemnity and cyber insurance do not do the same job. PI covers claims of professional mistakes, negligence or bad advice, while cyber insurance is designed for data breaches, attacks, incident response and business interruption. For many consultants, especially those handling client data, the key is knowing where each starts and ends, and which one your contracts, data exposure and notification duties make essential.
Which policy covers what when a client problem turns cyber
Professional indemnity insurance, or PI, is the policy that usually responds when a client says your advice, report, design, or work caused them loss. Cyber insurance is the policy that usually responds when the problem is a hacked inbox, stolen laptop, locked files, or a data breach that needs fast action. That split matters because a breach can create both a claim and a clean-up bill.
| Question |
Professional indemnity |
Cyber insurance |
| Client says your advice was wrong |
Usually yes, if the claim is for negligence, error, or omission |
Usually no, unless the policy wording adds specific liability cover |
| Email account is hacked |
Often no, unless a cyber extension is built in |
Usually yes for response costs, subject to terms |
| Client data is leaked |
May defend the claim, but often not the clean-up costs |
Usually covers incident response, forensic work, and notification support |
| You cannot work for three days |
Usually no, unless the loss comes from a covered advice claim |
Often yes, but business interruption may have a waiting period or sublimit |
Professional indemnity insurance covers the claim, while cyber insurance covers the mess. That simple split helps when you are deciding under pressure, because the clean-up often starts before the legal argument does.
Association of British Insurers guidance and market wording trends both point to the same issue: the label on the policy matters less than the exclusions, limits, and notification rules inside it.
Does PI pay for advice mistakes only?
PI is mainly there for professional negligence, which means a client says your advice, work, or omission caused them loss. For a consultant, that could be a wrong recommendation, a missed deadline, a faulty report, or a contract breach linked to the work you were paid to do.
Cyber insurance is designed for the real-world clean-up after a hack, a malware event, or a data leak. That usually means incident response, IT forensic work, legal help, regulatory notification support, ransom negotiation, and business interruption cover if you cannot trade for a time.
A client data breach can create two separate problems. One is the clean-up after the breach. The other is the claim that your handling of the work, data, or access was negligent.
If your work can create both a complaint and a breach, the right answer is often to hold both PI and cyber cover, then check how they interact before renewal.
Marketing, finance and legal consultants need different
The right policy mix depends on the type of consultant you are, because not all risk sits in the same place. If you store lead lists, payroll files, client identities, or draft contracts, cyber risk rises. If your value is mainly advice, analysis, or judgment, PI usually matters more.
Marketing consultants: data and access risk
Marketing consultants often hold email lists, campaign data, ad account access, and analytics dashboards. That makes them vulnerable to account takeover, stolen credentials, and accidental sharing, even if they are not a tech business.
Financial and legal consultants: advice claim risk
Financial and legal consultants usually face a different risk pattern. Their biggest exposure is often a claim that advice was wrong, incomplete, or late, and that is classic PI territory.
Freelancers often think they are too small to need cyber insurance, but size is not the real test. If you use Google Workspace, Microsoft 365, Dropbox, payroll software, or a CRM, you already depend on systems that can fail, be hacked, or be locked out.
Choose PI first if the main risk is bad advice. Choose cyber first if the main risk is hacked systems, lost files, or data handling. If you do both kinds of work, the safer answer is usually both policies, with the wording checked line by line.
For non-technical consultants, the right answer often depends on the kind of work you do. A marketing consultant may mainly face email compromise, stolen ad account access and accidental data leak from mailing lists, while a management consultant is more likely to worry about client claims over a flawed recommendation or missed deadline. Financial consultants tend to need strong liability cover because a negligence claim can be costly, and legal consultants may need even tighter limits if their advice feeds into regulated decisions.
A freelance generalist who uses cloud tools, stores client contacts and shares drafts by email may not look like a cyber target, but a simple ransomware attack or compromised inbox can still trigger data breach response costs and disrupt billing for days.
How to choose between PI, cyber, or both
The simplest way to decide is to look at three things: the type of data you hold, the promises in your client contracts, and whether your work would stop if your systems were down for three days. If the biggest loss is a claim about your work, PI comes first. If the biggest loss is the incident itself, cyber comes first.
| Your exposure |
What to prioritise |
Why |
| Mostly advice, little client data |
PI first |
The main claim risk is negligence, not response costs |
| Regular client data storage in cloud apps |
Cyber plus PI |
You need help with both breach costs and complaint defence |
| Client contract asks for data breach notice within 24 hours |
Cyber first, then PI check |
Speed and response support matter more than a broad advice policy |
| High-value advice with a small team |
PI with cyber extension, or both |
A single policy may be enough only if the cyber sublimit is meaningful |
A practical rule for England: if you hold personal data, use cloud software, or work under a client contract, treat cyber cover as a separate need, not a bonus add-on.
PI premiums for small UK consultants often sit somewhere between £200 and £1,000 a year for lower-risk work, but can rise above that for regulated or high-value advice. Cyber cover for a sole trader or small firm often starts around £100 to £600 a year, then climbs with higher limits, breach response support, and business interruption cover.
A small breach can cost less than the policy limit and still hurt cash flow. UK response costs often include IT forensics, legal advice, notification letters, call centre help, and credit monitoring, and even a modest event can run from a few thousand pounds to well over £20,000 once external help is involved.
If a consultant can be offline for a day and still bill normally, the pressure is lower. If three hours of downtime stops delivery, business interruption becomes much more valuable.
A practical way to choose between consultant insurance options is to look at three questions: what data you hold, what your client contract says, and how badly your work would stop if systems failed. If you hold personal data, payment details or confidential client files, cyber insurance becomes more important because the main exposure is incident response, forensic investigation and regulatory notification. If your work is mainly advice, planning or drafting, professional indemnity insurance should come first because the biggest risk is a negligence claim.
If your contracts include indemnities, strict incident reporting duties or minimum insurance levels, you usually need both policies because one protects the claim while the other supports the breach itself.
Contracts can force the answer before your insurer does
Your client contract can make the insurance decision for you. Many contracts ask for minimum limits, broad indemnities, proof of PI, proof of cyber cover, or quick notice of any incident that might affect the client’s data or work.
Minimum limits and why they matter
Minimum limits are the least amount of insurance your client accepts. A larger customer may ask for £1 million, £2 million, or more for PI, and may also ask for separate cyber cover if you handle personal data or access their systems.
Indemnities that outgrow your policy
An indemnity is a promise to pay for certain losses, even if they are wider than normal negligence. That can sound harmless in a contract, but it can quietly push your risk beyond what your policy was written to cover.
Data processing and breach notice duties
Under UK GDPR and the Data Protection Act 2018, data handling rules are not just a legal box to tick. If you process personal data for clients, the contract may set duties on storage, access, subcontractors, and how fast you report an incident.
Use this simple checklist before renewal or before you accept a new client contract:
- Check the minimum insurance limit. Make sure your PI and cyber limits meet the contract requirement, not just your budget.
- Read indemnity wording line by line. If the promise is wider than negligence, ask how your policy answers it.
- Check breach notice timing. Your insurer may want notice much earlier than the client does.
- Look for sublimits. A cyber section inside PI may be too small for a real incident.
- Confirm who handles notification. Some policies want you to call a breach line before hiring your own IT firm.
The error most consultants make is signing the contract first and checking cover later. By then, the insurance is already being asked to do a job it may never have been written to do.
Frequently asked questions about cyber insurance for UK SMEs
Does professional indemnity insurance cover cyber?
Sometimes, but only in a limited way. Some PI policies include cyber extensions, yet these often have sublimits, exclusions, or narrow wording that does not pay full breach response costs.
Do i need cyber insurance as a consultant?
If you hold client data, use cloud tools, or can lose income when systems go down, yes, you should seriously consider it. Even a small breach can create costs from £2,000 to well over £20,000 once legal and IT help are added.
Is cyber insurance the same as professional
No, they are different forms of cover. Professional liability, often called PI, deals with claims about your work, while cyber insurance deals with incidents involving systems, data, and downtime.
Do consultants need professional indemnity
Most consultants do if they give advice, prepare reports, manage projects, or sign client contracts with liability clauses. If a client can say your work caused loss, PI is usually the base policy to have.
What is silent cyber in simple terms?
Silent cyber means the policy does not clearly say whether a cyber event is covered or excluded. That gap can lead to argument after a loss, which is why wording review matters before renewal.
Can i rely on one policy if my budget is tight?
Yes, sometimes, but only if the wording fits the real risk. If you mainly give advice and handle little data, PI may come first, but if you store personal data or use cloud software, cyber cover becomes hard to ignore.
What should i tell my broker before renewal?
Tell them what data you hold, which client contracts require insurance, what systems you use, and how quickly you could stop working if your laptop or cloud account failed. That gives them the facts needed to match cover to your risk.
If you do not hold client data, do not use digital systems to run the work, and have no meaningful contract or reputation exposure, cyber cover may add little value on its own. In that narrow case, a broker or lawyer review of your PI wording may be enough for now.
Your next step for the right cover
The best choice for most consultants is not a single policy. It is PI for advice risk, cyber insurance for breach and downtime risk, and a contract check so the two policies actually match what you promised a client.
If you want the safest practical rule, use this: choose PI first if the main risk is a bad professional call, choose cyber insurance if the main risk is data and downtime, and choose both if you do both work and store client data. Then check the exclusions, sublimits, and notification rules before you renew.
The details inside the policy matter as much as the headline cover. A cyber policy may have exclusions for old systems, poor security practices or certain social engineering losses, while a PI policy can include sublimits for cyber extensions that are too small to fund a serious breach. Silent cyber is another issue: if the wording does not clearly say whether a cyber event is covered, you can end up in a dispute when the email compromise or data breach has already happened.
In practice, the safest approach is to check who handles incident response, whether the policy pays for forensic investigation and regulatory notification, and how quickly you must notify the insurer after discovering a loss.