Does Professional Indemnity Cover a System Outage Caused by an IT Consultant's Own Error?
Generally yes. Just not because it's a cyber claim. If the consultant's own build or configuration caused the outage, that's professional indemnity, not cyber liability.
By Jack O'Hagan, Co-Founder & Insurance Broker
Published 2 September 2026 · 4 min read
In this guide
- Does professional indemnity actually cover a system outage?
- Why isn’t that a cyber liability claim?
- How do you actually tell which cover applies?
- Does an IT consultant need both covers or just one?
- Does professional indemnity cover it if an attacker gets in through the consultant’s own access?
- Key Takeaways
Generally yes. Just not because it’s a cyber claim. If a system goes down because of an IT consultant’s own build, configuration or migration, that’s a professional indemnity exposure. Cyber liability is a different cover built for a different kind of event. Mixing the two up is one of the more common assumptions in this line of work.
What caused it, not what it looks like
the cause decides which cover applies, not the outage itself
Own error → PI
a bad build, config or migration is a professional indemnity claim
External attack → cyber
a breach or compromised access is a cyber liability claim
Does professional indemnity actually cover a system outage?
Generally yes, where the outage traces back to the consultant’s own work. A system that fails after going live because of a flawed build, a misconfiguration or a bad migration causes the client a real financial loss: downtime, lost revenue, the cost of fixing it. That’s exactly the kind of claim professional indemnity is built to respond to. It’s a claim about the quality of the work, not about an external event.
Why isn’t that a cyber liability claim?
Because cyber liability is built around a different trigger entirely. It responds to a breach, a ransomware event or unauthorised access, something done to the system from outside, not a mistake made while building or configuring it. A system that goes down because of the consultant’s own error hasn’t experienced a cyber incident at all. Confusing the two is an easy mistake to make, since both can look identical from the outside: the client’s system is down either way.
A client doesn't see the difference between a bad configuration and a breach. The claim does.
How do you actually tell which cover applies?
Start with what caused it, not what it looks like from the client’s side. A system going down looks the same to the client either way. An attacker getting in points to cyber liability. A mistake in the consultant’s own build, configuration or advice points to professional indemnity. The outage itself doesn’t tell you which one applies. The cause does.
Does an IT consultant need both covers or just one?
Most need both, because most carry both exposures on the same engagement. A consultant whose own build or configuration can cause a client’s system to fail has a professional indemnity exposure. A consultant who holds ongoing access to that same client’s systems, which is normal for this kind of work, carries a cyber liability exposure as well. Holding only one of the two covers means one entire category of claim has nothing to respond to it.
Does professional indemnity cover it if an attacker gets in through the consultant’s own access?
No. This is the reverse scenario. It sits with cyber liability rather than professional indemnity. If a consultant’s own credentials or remote access tooling are compromised and an attacker uses that access to reach a client’s systems, the entry point was the consultant’s. The event itself is still a cyber incident, not a professional error. The distinction is about what actually happened, not who was involved.
Key Takeaways
- A system outage caused by the consultant's own build, configuration or advice is generally a professional indemnity claim, not a cyber one.
- Cyber liability responds to an external or malicious event, a breach, ransomware or unauthorised access, not a mistake in the consultant's own work.
- What caused the outage decides which cover applies, not what the outage looks like to the client.
- Most IT consultants carry both exposures at once and generally need both covers rather than assuming one extends to the other.
The information in this article is general in nature and does not constitute legal, financial or insurance advice. Please speak with a qualified adviser about your specific circumstances.
Not sure how this applies to your situation?
Frequently asked questions
Does professional indemnity cover a system outage caused by an IT consultant's own error?
Generally yes. If a system goes down because of the consultant's own build, configuration or migration, that's a professional indemnity exposure. It's a financial loss caused by the work itself, not a cyber incident.
Why isn't a self-caused system outage a cyber liability claim?
Because cyber liability is built around an external or malicious event: a breach, ransomware attack or unauthorised access. Not a mistake in the consultant's own work. A system that fails because of a coding error or a bad configuration didn't experience a cyber incident. It experienced a professional error, which is what professional indemnity is designed to respond to.
How can an IT consultant tell which cover actually applies to an outage?
The starting question is what caused it, not what it looks like. A system going down looks the same to the client either way. An attacker getting in points to cyber liability. A mistake in the consultant's own build, configuration or advice points to professional indemnity. Getting this distinction right at the time of a claim matters more than it might seem.
Does an IT consultant need both professional indemnity and cyber liability or just one?
Most need both. A consultant whose own error can cause a system failure carries a professional indemnity exposure. A consultant who holds access to a client's systems carries a cyber liability exposure too, often at the same time on the same engagement. Relying on just one leaves the other kind of claim uncovered.
Does professional indemnity cover a cyberattack that happens through an IT consultant's access?
No, that's the reverse situation and it sits with cyber liability instead. If an attacker compromises a consultant's own credentials or remote access tooling and uses it to reach a client's systems, that's a cyber incident on both sides, not a professional indemnity claim, even though the entry point was the consultant's access.
What is a claims-made policy and why does it matter here?
Professional indemnity is typically arranged on a claims-made basis, meaning the policy in place when a claim is made and notified is the one that responds, not necessarily the policy that was current when the original build or configuration work took place. This makes continuous cover and the retroactive date carried over between insurers particularly important for IT consultants.
What information do insurers need to quote this kind of cover for an IT consultant?
Insurers typically ask for the services provided, whether the work involves ongoing access to client systems or a one-off build and handover, annual fee income and claims history. Being clear about which kind of exposure applies, a self-caused error versus third-party access, helps present the risk accurately to the market.
Keep reading
Where this guide fits
Business Insurance
This guide sits alongside our Business Insurance cover pages.
Browse Business InsuranceWritten by
Jack O'Hagan
Co-Founder & Insurance Broker
Jack spent 6+ years across law, finance and insurance, seeing the impact insurance can have on the growth of a business. With a strong focus on advocacy, he firmly believes insurance broking does not stop after the policy has been placed. It continues when a claim is lodged. He co-founded Cipher Insurance to help Australian businesses get the right broker experience.