Professional services
When a cyber incident may involve both Cyber Insurance and Professional Indemnity
A cyber incident can create both first-party costs and a professional indemnity claim at the same time — why the two may overlap.
One incident can create more than one type of loss
A cyber incident is not always only an IT problem.
For a professional or technology business, the same event may cause:
- costs within the business itself;
- interruption to operations;
- loss or compromise of data;
- a demand from an affected client;
- an allegation that professional services were performed negligently; or
- legal and regulatory consequences.
This is where Cyber Insurance and Professional Indemnity can sometimes intersect.
They are different types of insurance, but the facts of one incident may potentially engage both.
Cyber Insurance commonly focuses on the cyber event itself
Cyber policies vary considerably, but depending on the wording and cover selected they may include matters such as:
- incident response;
- forensic investigation;
- data breach response;
- privacy and legal assistance;
- system restoration;
- cyber business interruption;
- cyber extortion;
- network security liability;
- privacy liability;
- cyber crime; and
- social engineering or funds transfer fraud.
Some of these are first-party losses — costs suffered directly by the insured business.
Others may involve third-party liability — claims or allegations made by customers, individuals or other parties.
Not every Cyber policy contains all of these covers, and sub-limits, conditions and exclusions can materially change the outcome.
Professional Indemnity focuses on professional services
Professional Indemnity (PI) generally addresses claims arising from the professional services described in the policy.
Depending on the wording, a claim may involve allegations such as:
- negligent advice;
- an error or omission;
- failure to perform contracted professional services;
- defective design or implementation;
- failure to meet a professional standard; or
- financial loss said to result from the insured’s professional work.
The important point is that PI is usually concerned with the professional service and the allegation arising from it, rather than simply the fact that a cyber event occurred.
Where can the two overlap?
Consider a technology provider that configures a client’s cloud environment.
A configuration error is alleged to have exposed client data.
The technology provider may face its own incident-response costs, while the client may also allege that the provider failed to perform its professional services properly.
The same event can therefore involve two questions:
- What cyber-related loss has the insured business suffered or become liable for?
- Has a client made a claim arising from an alleged failure in professional services?
The answer may involve Cyber Insurance, Professional Indemnity, Technology Liability, or a combined technology policy.
Which policy responds is not determined by the label placed on the incident. It depends on the facts and the wording of the policies.
Other examples
Similar questions can arise where:
- an IT provider’s system outage interrupts a client’s operations;
- a software implementation is alleged to contain a security weakness;
- a digital agency’s compromised account leads to a client’s data or advertising account being affected;
- a consultant mishandles confidential client information;
- a managed service provider is accused of failing to maintain agreed security controls; or
- a professional firm’s email account is compromised and a client alleges that its loss arose from failures in the firm’s professional processes.
These examples do not mean a claim would automatically be covered under either policy. They illustrate why the underlying allegation matters.
Why separate policies can create difficult questions
If PI and Cyber are placed with different insurers, an incident may need to be considered under both policies.
Questions can arise about:
- which policy is triggered;
- whether one policy excludes matters intended to be covered by the other;
- how professional services are defined;
- whether technology activities are fully described;
- notification requirements;
- defence costs; and
- how the insurers respond where allegations overlap.
This does not mean separate policies are necessarily unsuitable. For many businesses, separate policies can work well.
It does mean that the scope of each policy should be understood rather than assuming “PI covers professional mistakes” and “Cyber covers anything involving a computer”.
Combined technology policies
For some technology and digital businesses, insurers offer combined products that may bring together:
- Technology / Professional Indemnity;
- Cyber Insurance; and
- Public & Products Liability.
A combined structure can reduce some of the ambiguity that may arise when related exposures sit with different insurers.
However, a combined policy is not automatically broader or more suitable. The definitions, limits, sub-limits, exclusions and business activities described in the policy still need to be reviewed.
What should a business disclose?
For businesses with both professional and cyber exposures, insurers may want to understand:
- exactly what services are provided;
- revenue split by activity;
- types of clients;
- largest contracts;
- technology or software responsibilities;
- data held or processed;
- use of subcontractors or offshore teams;
- security controls;
- contractual responsibilities; and
- previous incidents, complaints or claims.
A broad description such as “IT consulting” or “digital services” may not be enough.
How Wesure can assist
We can help clients:
- describe their professional and technology activities accurately;
- identify where PI, Cyber and Technology Liability exposures may intersect;
- compare relevant policy structures and material differences;
- review insurance requirements contained in client contracts; and
- coordinate notifications where an incident may involve more than one policy.
The insurer remains responsible for determining whether a particular claim is covered.
Contractual legal obligations should be reviewed by an appropriately qualified legal adviser.
Key point
A cyber incident can involve both what happened to the business’s systems and what a client says the business did wrong professionally.
Those are different questions — and they may not be answered by the same policy.
General information / important information
General information only: This article does not take into account your objectives, financial situation or needs. Cover depends on the facts, the cover selected and the terms, conditions, limits and exclusions of the relevant policy.
Information on this website is general in nature and does not take into account your objectives, financial situation or needs. Cover is subject to insurer acceptance, policy terms, conditions, limits and exclusions. You should review the relevant policy documents and seek advice appropriate to your circumstances before making a decision.