Professional Consultant Risk – Cyber Liability Case Study
16th June 2026
This company is a UK-based building services consultancy, specialising in:
- Mechanical and electrical (M&E) design
- Building performance and energy consultancy
- Feasibility, modelling and full lifecycle project support
With over 25 years’ experience, the business operates across a range of sectors including education, residential and commercial projects, delivering design solutions from concept through to construction and completion.
From an insurance perspective:
- Industry: Engineering consultancy
- Turnover: £1m
- Employees: 10+
The Challenge
During a review of the client’s existing arrangements, the Cyber programme was identified as an area requiring attention.
- Existing Cover Considerations
The client’s current Cyber insurance with Aviva included:
- Total Cyber limit: £250,000
- Data loss / liability section: £100,000
- Business interruption included but with restricted sub limits (e.g. system failure limit £25,000)
Premium position:
- Annual premium: £404.53 (+ IPT)
- Market Context
From internal marketing activity:
- Existing insurer viewed as “cheap”/low premium placement
- Alternative markets presented challenges:
- CFC – Not competitive
- Chubb – Unable to quote
- Pen – Higher premium (c. £1,000+)
This highlighted a classic issue:
- The current policy was cost-effective, but
- Potentially limited in scope and breadth relative to modern cyber exposures
- Evolving Risk Profile
As a design-led consultancy operating in a digital-first environment, the client has increasing reliance on:
- Cloud-based project collaboration
- Digital drawings, BIM modelling and design data
- Client data and commercially sensitive project documentation
This creates exposure to:
- Cyber-attacks (malware, ransomware)
- Loss or corruption of project data
- Business interruption from system outage
- Third-party liability arising from data breaches
Broking Approach
A structured advisory and marketing strategy was implemented.
- Assessment of Existing Policy
A detailed analysis identified that whilst the Aviva policy provided:
- Core cyber protections (data breach, hacking, extortion)
- Business interruption cover
there were limitations in depth of cover, particularly:
- Lower sub limits on key exposures
- Limited flexibility around first party financial loss
- Less comprehensive cyber crime protection
- Full Market Exercise
A wide range of cyber insurers were approached as part of a fair analysis of the market, consistent with Caunce O’Hara’s advisory approach:
- Core composite insurers
- Cyber specialist providers
- MGA-led cyber solutions
This ensured:
- Competitive benchmarking of premium and coverage
- Identification of improved wording and extensions
- Consideration of both cost-saving and cover-enhancing options
- Development of an Alternative Solution
An alternative Cyber Liability placement was sourced with NMU, delivering a more rounded solution aligned with the client’s operations.
Key features included:
First Party Cover (Own Losses)
- Cyber incident response and forensic investigation
- Data restoration and system recovery
- Cyber extortion and ransomware response
- Business interruption (loss of income and increased cost of working)
Third Party Liability Cover
- Cyber liability (data breach damages and defence costs)
- Network security liability
- Media liability (defamation, IP-related digital exposures)
Cyber Crime Protection
- Optional cover for financial losses arising from:
- Fraudulent payment instructions
- Social engineering attacks
- Improvements vs Existing Cover
The alternative solution provided:
✅ Broader first party protections (including restoration and response costs)
✅ Enhanced third-party liability clarity
✅ Optional cyber crime cover not fully reflected in the existing policy structure
✅ Improved alignment with real-world cyber incident scenarios
- Commercial Position
The recommended solution was presented at:
- Approx. £610 total premium
This represented:
- A modest premium increase vs the incumbent insurer
- In exchange for materially broader and more flexible cover
Outcome
The engagement delivered:
✅ A clear comparison between incumbent and alternative cover
✅ A competitive alternative Cyber Liability solution
✅ Improved understanding of cyber exposure at client level
✅ A structured recommendation balancing cost vs protection
The client was able to:
- Evaluate value rather than headline premium
- Consider improved resilience against emerging cyber risks
- Align insurance more closely with operational exposures
Key Learning Points
- “Cheap” Cover Can Mask Gaps
Lower premium policies may:
- Provide core protection
- But include restricted limits or narrower triggers
- Cyber Risk Is Business-Critical for Consultancies
For engineering and design firms:
- Loss of data = loss of intellectual property
- System outage = immediate operational disruption
- Alternative Markets Provide Valuable Leverage
Even where incumbent cover is retained:
- Market testing strengthens negotiation position
- Highlights opportunities for coverage enhancement
- Insurance Is Only One Part of Cyber Strategy
The engagement also reinforced:
- Importance of ongoing risk management
- Alignment between IT controls and insurance provisions
Conclusion
This case demonstrates how a proactive broking approach can:
- Challenge existing placements
- Deliver meaningful alternative options
- Support clients in making informed, commercially balanced decisions
By combining:
- Detailed policy analysis
- Market engagement
- Sector-specific understanding
Caunce O’Hara positioned Cyber Liability not as a low-cost add-on, but as a core risk management tool for a modern engineering consultancy.