X Close Icon
Blog

Professional Consultant Risk – Cyber Liability Case Study

16th June 2026

This company is a UK-based building services consultancy, specialising in:

  • Mechanical and electrical (M&E) design
  • Building performance and energy consultancy
  • Feasibility, modelling and full lifecycle project support

With over 25 years’ experience, the business operates across a range of sectors including education, residential and commercial projects, delivering design solutions from concept through to construction and completion. 

From an insurance perspective:

  • Industry: Engineering consultancy 
  • Turnover: £1m 
  • Employees: 10+

The Challenge

During a review of the client’s existing arrangements, the Cyber programme was identified as an area requiring attention.

  1. Existing Cover Considerations

The client’s current Cyber insurance with Aviva included:

  • Total Cyber limit: £250,000 
  • Data loss / liability section: £100,000 
  • Business interruption included but with restricted sub limits (e.g. system failure limit £25,000) 

Premium position:

  • Annual premium: £404.53 (+ IPT) 
  1. Market Context

From internal marketing activity:

  • Existing insurer viewed as “cheap”/low premium placement 
  • Alternative markets presented challenges: 
    • CFC – Not competitive 
    • Chubb – Unable to quote 
    • Pen – Higher premium (c. £1,000+) 

This highlighted a classic issue:

  • The current policy was cost-effective, but
  • Potentially limited in scope and breadth relative to modern cyber exposures
  1. Evolving Risk Profile

As a design-led consultancy operating in a digital-first environment, the client has increasing reliance on:

  • Cloud-based project collaboration
  • Digital drawings, BIM modelling and design data
  • Client data and commercially sensitive project documentation

This creates exposure to:

  • Cyber-attacks (malware, ransomware)
  • Loss or corruption of project data
  • Business interruption from system outage
  • Third-party liability arising from data breaches

Broking Approach

A structured advisory and marketing strategy was implemented.

  1. Assessment of Existing Policy

A detailed analysis identified that whilst the Aviva policy provided:

  • Core cyber protections (data breach, hacking, extortion) 
  • Business interruption cover

there were limitations in depth of cover, particularly:

  • Lower sub limits on key exposures
  • Limited flexibility around first party financial loss
  • Less comprehensive cyber crime protection
  1. Full Market Exercise

A wide range of cyber insurers were approached as part of a fair analysis of the market, consistent with Caunce O’Hara’s advisory approach:

  • Core composite insurers
  • Cyber specialist providers
  • MGA-led cyber solutions

This ensured:

  • Competitive benchmarking of premium and coverage
  • Identification of improved wording and extensions
  • Consideration of both cost-saving and cover-enhancing options
  1. Development of an Alternative Solution

An alternative Cyber Liability placement was sourced with NMU, delivering a more rounded solution aligned with the client’s operations.

Key features included:

First Party Cover (Own Losses)

  • Cyber incident response and forensic investigation
  • Data restoration and system recovery
  • Cyber extortion and ransomware response
  • Business interruption (loss of income and increased cost of working)

Third Party Liability Cover

  • Cyber liability (data breach damages and defence costs)
  • Network security liability
  • Media liability (defamation, IP-related digital exposures)

Cyber Crime Protection

  • Optional cover for financial losses arising from: 
    • Fraudulent payment instructions
    • Social engineering attacks
  1. Improvements vs Existing Cover

The alternative solution provided:

Broader first party protections (including restoration and response costs)
Enhanced third-party liability clarity
Optional cyber crime cover not fully reflected in the existing policy structure
Improved alignment with real-world cyber incident scenarios

  1. Commercial Position

The recommended solution was presented at:

  • Approx. £610 total premium 

This represented:

  • A modest premium increase vs the incumbent insurer
  • In exchange for materially broader and more flexible cover

Outcome

The engagement delivered:

A clear comparison between incumbent and alternative cover
A competitive alternative Cyber Liability solution
Improved understanding of cyber exposure at client level
A structured recommendation balancing cost vs protection

The client was able to:

  • Evaluate value rather than headline premium
  • Consider improved resilience against emerging cyber risks
  • Align insurance more closely with operational exposures

Key Learning Points

  1. “Cheap” Cover Can Mask Gaps

Lower premium policies may:

  • Provide core protection
  • But include restricted limits or narrower triggers
  1. Cyber Risk Is Business-Critical for Consultancies

For engineering and design firms:

  • Loss of data = loss of intellectual property
  • System outage = immediate operational disruption
  1. Alternative Markets Provide Valuable Leverage

Even where incumbent cover is retained:

  • Market testing strengthens negotiation position
  • Highlights opportunities for coverage enhancement
  1. Insurance Is Only One Part of Cyber Strategy

The engagement also reinforced:

  • Importance of ongoing risk management
  • Alignment between IT controls and insurance provisions

Conclusion

This case demonstrates how a proactive broking approach can:

  • Challenge existing placements
  • Deliver meaningful alternative options
  • Support clients in making informed, commercially balanced decisions

By combining:

  • Detailed policy analysis
  • Market engagement
  • Sector-specific understanding

Caunce O’Hara positioned Cyber Liability not as a low-cost add-on, but as a core risk management tool for a modern engineering consultancy.