Cyber Insurance by Industry
Architects' Professional Indemnity Insurance and Cyber Cover
Architects professional indemnity insurance is not optional in the UK. Under the Architects Registration Board (ARB) rules, holding adequate cover is a condition of staying on the register, and engineering firms face the same demand from clients and contracts even where no regulator forces it. The problem most practices miss is that a professional indemnity (PI) policy was never designed to answer a ransomware attack or a stolen laptop full of client data. That is a separate risk, and it needs separate cover.
This guide sets out exactly what ARB, RIBA and CIAT require of a design practice, then shows where PI stops and cyber insurance has to start. If you run an architecture studio, an engineering consultancy or a mixed design firm, both policies belong in your renewal file.
What the regulators require: PI as the baseline
For architects, PI cover sits under ARB Standard 8, which expects insurance held on a civil liability basis rather than narrow negligence-only wording. That wider basis captures negligence, breach of contract and other civil claims arising from the practice of architecture. The headline numbers to know:
- Minimum limit of indemnity: the ARB floor is £250,000 for any one claim, rising to a higher minimum for sole principals and partnerships whose turnover passes a published threshold. Treat this as a floor, not a target; most practices working on commercial or higher-risk projects carry far more.
- Run-off cover: when a practice closes, ARB expects run-off cover to continue for a period that matches the statutory limitation for negligence and breach of contract, typically at least six years. Claims can surface long after a project completes, so run-off protects a retired principal.
- RIBA Chartered Practices: RIBA sets minimums on a sliding scale linked to annual turnover, pitched above the ARB floor and increasing with practice size.
- CIAT Chartered Practices: CIAT uses a similar sliding scale calibrated to a firm’s fee income for architectural technology work.
Engineers are not registered by ARB, so the legal driver is different, but the effect is the same. Client appointments, framework agreements and public-sector tenders almost always specify a PI limit, and professional bodies expect members in practice to hold it. If you sign contracts, you are already carrying, or should be carrying, PI.
Where professional indemnity stops and cyber begins
PI answers one question: did the firm make a professional mistake that harmed a client? It pays for the defence and the damages when a design error, a missed calculation or bad advice leads to a claim. That is essential, but it is silent on the incidents that now cause the most disruption to design firms.
A PI policy generally will not respond to:
- Ransomware and extortion. If your CAD or BIM files are encrypted and a criminal demands payment, PI does not cover the ransom, the specialist negotiation, or the cost of rebuilding models from backups.
- Business interruption from an attack. The revenue lost while your studio cannot open drawings or issue work is a first-party loss that PI ignores.
- Data breach handling. Architects and engineers hold client contact details, site plans, and sometimes occupant data. A breach triggers UK GDPR duties: notifying the ICO within 72 hours, informing affected people, and often paying for forensic and legal support. Our guide on who enforces GDPR in the UK covers who must notify the ICO.
- Payment and invoice fraud. Business email compromise, where a fraudster impersonates a supplier or a director to redirect a payment, is a fast-growing loss for project-based firms handling large invoices. PI does not touch it.
There is a second trap: silent cyber. Many PI insurers have added explicit cyber exclusions so that a data or systems incident cannot be claimed under the professional policy at all. That closes the door from both sides, which is precisely why standalone cyber cover has moved from nice-to-have to expected. For the wider picture of what a cyber policy does and does not include, see what cyber insurance actually covers.
How the two policies fit together for a design firm
Think of them as covering different halves of your risk. PI protects the output of your work, the design and advice. Cyber protects the systems and data you use to produce it, and the money and time an attack drains. A well-insured practice carries both, sized to the projects it takes on.
A practical setup for most small and mid-sized studios:
- PI at or above the ARB or RIBA minimum for your turnover, on a civil liability basis, with run-off arranged for when you eventually close.
- Cyber with first-party cover for ransomware, data restoration and business interruption, plus incident-response support and social engineering or BEC cover added as an endorsement rather than assumed.
- The security controls insurers now ask for, because a cyber quote depends on them: multi-factor authentication, tested backups, and staff phishing awareness. Our cyber security checklist for businesses lists the controls underwriters look for.
If you are comparing the general categories of business cover before you buy, our explainer on professional indemnity versus public liability shows where each one applies, and the cyber insurance for UK small businesses guide walks through a full policy. For the regulator’s own wording, the ARB Architects Code is the authoritative source on the PI requirement.
Frequently asked questions
Is professional indemnity insurance a legal requirement for architects? It is a condition of ARB registration under Standard 8, so in practice a UK architect must hold adequate PI cover to remain on the register and use the title. Engineering firms are not ARB-regulated but are almost always required to hold PI by their client contracts.
What is the minimum professional indemnity cover for architects in the UK? The ARB floor is £250,000 for any one claim, with a higher minimum for sole principals and partnerships above a published turnover threshold. RIBA and CIAT set higher minimums on a sliding scale tied to turnover, so most practices carry well above the ARB floor.
Does architects’ professional indemnity insurance cover cyber attacks? Generally no. PI covers professional errors and negligence. It does not pay for ransomware, data restoration, business interruption or breach-notification costs, and many PI policies now carry explicit cyber exclusions. Those risks need a separate cyber policy.
Do engineers need professional indemnity insurance too? Yes, in almost all cases. Although engineers are not registered by ARB, client appointments, framework agreements and tenders routinely require a stated PI limit, so a practising engineering consultancy needs cover to win and deliver work.
What is run-off cover and why do architects need it? Run-off cover keeps your PI live after a practice closes, because claims can arise years after a project finishes. ARB expects it to run for a period matching the statutory limitation, usually at least six years, protecting a retired or former principal.
Why do architects need cyber insurance as well as PI? Because the two cover different risks. PI answers claims about your designs and advice; cyber answers attacks on your systems and data, including ransomware on BIM files, GDPR breach costs and invoice fraud. With cyber often excluded from PI, only a standalone cyber policy closes the gap.