An accountancy practice holds records that can include payroll, financial information and tax documents. A cyber quotation should address the systems holding those records and the practice’s ability to keep working after an incident.
Incident response and cyber cover
Cyber policies can address different combinations of response services, the insured business’s own losses and third-party allegations. Check each section rather than relying on the product name. Security obligations and consent before spending can be important parts of the comparison.
The decision that deserves the closest review
Describe cloud accounting access, document sharing, staff permissions and backup arrangements. Compare first-response assistance with restoration, interruption and third-party allegations. Ask how cyber and professional indemnity policies treat a client loss arising from both system compromise and service failure.
Premiums, excesses and usable cover
Request quotations using the same business description, required limits and relevant dates. Put the annual premium, any instalment charges, excesses and important sublimits in one comparison. A cheaper premium can represent a different transfer of risk rather than the same cover at a better price.
| Comparison item | Question to resolve |
|---|---|
| Volume and sensitivity of client records | Are cloud accounts and outsourced IT included? |
| Identity controls and mailbox security | Which fraud-verification conditions apply? |
| Connections between cyber and professional cover | Can the incident team advise on notification obligations? |
Request the proposed wording and schedule, not just a price or certificate. Mark any difference that affects a real activity before deciding whether the premium saving is worthwhile.
A hypothetical example
A compromised staff mailbox sends altered bank details to a client. The practice needs to know whether the policy treats this as a data incident, a funds-transfer loss or an allegation about professional work.
Prepare an accurate insurance enquiry
Give each adviser a consistent description of the activities being insured. Include important contracts, changes since the previous enquiry and matters the insurer asks you to disclose. Do not guess answers merely to obtain a faster or cheaper quote; ask for clarification when the proposal wording is unclear.
Map client information and the recovery sequence
Record where client documents, payroll files and account working papers are held. Identify staff and outside suppliers with administrative access. A small practice can use this map to explain its dependencies and to prioritise which records must be available first after an incident.
Compare response arrangements using that recovery sequence. Ask how the practice would obtain approved technical, legal and communications assistance and who coordinates those services. Confirm the proposed conditions against the security measures actually in use, especially where an adviser is relying on outsourced IT.
Include overseas work or sales in the UK business’s enquiry and confirm the accepted territories and jurisdictions.
A mistake to avoid
Comparing only restoration limits while overlooking fraud and liability wording.
Check what happens after the policy starts
Ask who to contact when activities change or a potential claim arises. Understand the notification and consent process before arranging repairs, appointing specialists or settling a complaint. At renewal, compare the new documents with the accepted business description; continuity of a familiar brand does not prove continuity of every term.
Questions before choosing
Should the practice accept every incident-response supplier automatically?
Review availability, consent requirements and coordination with existing IT support before binding cover.
Is an IT support contract the same as cyber insurance?
The support contract defines the supplier’s service. Compare it alongside the insurance wording to identify which incident services, expenses and liabilities each arrangement addresses.
Sources and further reading
- NCSC: cyber insurance guidance
- ICAEW: professional indemnity insurance regulations
- ICO: contracts with processors
Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.