Even if your agency protects CVs and identity data, it may still face losses. A payroll-change email or compromised ATS login can divert money.
Does your recruitment agency need cyber cover?
A recruitment agency in England normally needs cyber cover if it stores candidate data digitally. It also needs cover if it relies on an ATS or CRM. Payroll-related details create another reason to consider it.
Does PI pay after a cyber incident?
Professional indemnity insurance may help when a client alleges negligent recruitment advice or service. It does not automatically pay for forensic work after a cyber event.
It may not cover candidate notices, data recovery, or lost income. Such losses can arise while an ATS is unavailable.
Which policy pays for which loss?
| Policy type | Usually aimed at | Usually not the main answer |
|---|
| Cyber insurance | Breach response, restoration, extortion and system downtime | Every payment fraud or poor recruitment advice |
| Professional indemnity | Client claims alleging negligent professional services | Forensics after an ATS account is hacked |
| Public liability | Injury or property damage to third parties | A leaked CV database or ransomware |
Recruitment cyber insurance addresses the financial and operational impact of a security event. Professional indemnity mainly responds to claims that your recruitment service was negligent.
Public liability usually concerns third-party injury or property damage. It does not usually cover failures to protect candidate data.
Vicarious liability is different again. An agency may be legally responsible for an employee's acts during their work.
A recruiter might send a CV to the wrong client without permission. That can create a data protection claim.
The cyber policy may fund breach response. A separate liability section may still be needed for a compensation claim.
Check how each policy handles defence costs. Also ask if one insurer can manage a mixed claim.
Where recruitment cyber losses actually start
Recruitment cyber losses often start in normal workflows. They do not always start with a dramatic hack.
An ATS is a recruitment database. It helps you find candidates, record checks, and manage placements.
One compromised administrator account can expose candidate records and client contacts. It can also expose interview notes and vacancy data.
This can happen without any ransomware appearing on screen.
Check whether your cyber policy includes contingent business interruption. This means lost income after a supplier's system fails.
Standard business interruption cover may need damage to your own property. It may not solve an ATS provider outage.
Match recruitment incidents to the right cover
Each recruitment incident can trigger a different policy section. Map the event, likely cover, costs, and exclusions before buying.
| Likely incident | Likely policy section | Costs that may be covered | Common gap to check |
|---|
| Leaked CVs or ID documents | Privacy breach and third-party liability | Forensics, lawyers, notification and PR | Known incidents, unencrypted devices, prior acts |
| ATS or CRM outage | Business interruption and restoration | Lost income and extra manual-working costs | Waiting period or excluded supplier failure |
| Ransomware | Cyber extortion and incident response | Specialists, restoration and downtime | Security warranties and ransom sub-limits |
| Payroll diversion | Social engineering or crime cover | Misdirected funds, if included | No call-back or dual approval |
| Changed supplier bank details | Funds-transfer fraud or crime cover | Fraud loss subject to sub-limit | Invoice fraud excluded from cyber wording |
Does leaked candidate data trigger cover?
Leaked candidate data may trigger breach-response cover before a legal claim arrives. The insurer may appoint forensic IT experts to find the cause.
It may also appoint lawyers to assess duties. Communications advisers may help where the wording includes them.
The Information Commissioner's Office says firms must assess risks to people's rights and freedoms. The UK GDPR usually requires notification to the ICO within 72 hours.
That deadline starts when you become aware of the breach. See the Information Commissioner's Office for current guidance.
Will payroll-diversion fraud be paid?
Payroll-diversion fraud may be uninsured without social engineering or funds-transfer fraud cover. These clauses often have lower limits than the main cyber limit.
They may require a recorded call-back to a known number. Check this before making a payment.
The usual advice to buy cyber insurance is incomplete here. A criminal may change supplier bank details without causing a data breach.
The core cyber section may never apply.
Set limits for an ATS outage, not just CVs
The right limit reflects the cost of trading through an outage. It is not based only on the number of CVs stored.
Which limits sit inside the headline limit?
Check for smaller limits within the policy. They may apply to extortion, social engineering fraud, public relations, and supplier outage.
They may also apply to regulatory defence costs. A £1 million headline limit can contain a much lower fraud limit.
Compare every line item, not just the front-page figure.
What should be checked before buying?
Check that these controls are in place before the policy starts:
- MFA: Active on email, ATS, CRM, payroll, and administrator accounts.
- Backups: Kept apart from normal systems and tested for recovery.
- Access: Remove leavers quickly and limit exports by role.
- Phishing checks: Finance staff confirm bank changes through an independent call-back.
- CV retention: Keep deletion and retention rules that fit the UK GDPR.
- Suppliers: Contracts state breach notice times, security duties, and outage support.
💡
You might be interested
An encrypted external drive can support a controlled backup of key recruitment records. It should support, not replace, tested backups outside your main network.
- Encryption can protect exported CVs if the drive is lost or stolen
- A separate copy can help recovery when an ATS export or local file is corrupted
- Portable storage can support an incident plan when normal systems are unavailable
View options on Amazon →
If an incident occurs, keep emails and logs. Isolate affected access without deleting evidence.
Call the insurer's incident-response number at once. In the first 24 hours, record decisions and notify relevant suppliers.
Get legal advice before telling candidates or clients what happened. This can prevent an early message creating a further problem.
Before accepting a cyber quotation, give the broker the incident matrix above. Ask which clause, sub-limit, and security condition applies to each row.
This guidance matters less if your business holds no personal data digitally. It also matters less if you do not rely on online systems. It cannot decide if a claim is covered. Policy wording, endorsements, security warranties, and incident facts control the result. Regulated firms and agencies with overseas operations may need specialist legal and insurance advice. Agencies subject to Financial Conduct Authority rules may need that advice too.
Set the cyber limit and interruption period using a realistic loss scenario. Start with fee income at risk each day.
Include days when the ATS, CRM, or payroll process is unavailable. Then add temporary staff and manual candidate-check costs.
Also add forensic work, legal advice, notices, and data recovery. Agencies holding many CVs or bank details may need higher privacy-breach limits.
Basic contact data may create a lower privacy exposure.
International placements can add overseas legal, contract, and notice costs. Test the longest credible recovery period for an ATS security incident.
An agency reliant on one cloud platform may need a longer period. Another agency may work from current offline records.
During the first 24 hours, appoint one incident lead. Keep a timed record of every decision.
Keep suspicious emails, access logs, and affected devices. Isolate accounts or systems as needed.
Do not wipe devices or overwrite evidence before forensic advice. Notify the insurer through its response channel early.
Using unapproved advisers can affect cover.
Reset compromised passwords and review privileged access. Ask ATS, CRM, payroll, job-board, and identity-check suppliers what was affected.
With legal advice, assess risks to individuals' rights and freedoms. Decide whether the ICO needs notice within 72 hours.
Also decide whether candidates or clients need clear, prompt communication.
Frequently asked questions
What insurance does a recruitment agency need?
A recruitment agency commonly needs employers' liability, professional indemnity, public liability, and cyber insurance. The mix depends on client contracts, staff numbers, payroll, candidate data, and ATS reliance.
Does cyber insurance cover a leaked CV?
Cyber insurance may cover a leaked CV where privacy breach response is included. It can fund forensic work, legal advice, and notices.
Prior incidents or missing security controls may be excluded.
Does cyber insurance pay payroll fraud?
Cyber insurance pays payroll fraud only when social engineering or funds-transfer fraud is included. Check the fraud sub-limit before buying.
Also check call-back, dual approval, and payee-check requirements.
How quickly must we tell the ICO about a breach?
You must notify the ICO within 72 hours when a breach risks people's rights and freedoms. Record your assessment even when no notice is needed.
Get legal advice for serious or uncertain incidents.
What is usually excluded from cyber cover?
Common exclusions include known incidents, deliberate acts, unsupported systems, and fraud outside the stated crime section. Ransom payments and supplier failure may have limits.
Regulatory fines may also be limited by law or policy conditions.
How much cyber cover should a small agency buy?
Choose cover for 5 to 20 working days of ATS disruption. Add likely recovery, fraud, legal, supplier, and contract costs.
Do not choose a limit only because the yearly premium feels affordable.
The essentials:- Cyber cover can pay breach, recovery, and outage costs that professional indemnity may not pay.
- Payroll diversion and changed supplier bank details often need social engineering or crime cover.
- Set limits against ATS downtime, payroll reliance, and supplier failure.
- Test MFA, backups, access controls, and fraud checks before relying on policy protection.
Related sources
These articles can help you explore the topic in more depth: