You hold the keys to their whole environment
You make the calls on migrations, access policies and storage permissions, so when one of them goes wrong, whether it's a botched cutover, a misconfiguration, or a credential that should have been switched off, the client comes looking for you. Professional indemnity and cyber cover, built for cloud consulting.
Where a cloud consultant actually gets exposed
You're often handed broad, standing access to a client's entire environment. That's exactly why a single misconfiguration or a credential left active after a project ends can cause a loss far bigger than the engagement itself. Standard business insurance doesn't touch it.
The migration that dropped the environment
You lead a cutover to new cloud infrastructure for a client. A misstep during the migration causes extended downtime and partial data loss before it's caught and rolled back.
The client's operations are disrupted for days, and they argue a properly planned migration would have avoided it.
The bucket left open
A storage bucket you configured during a project is left with overly broad permissions. Months later, it's discovered exposed to the public internet, with client records inside it.
The client says your configuration was the cause and looks to you for the response and notification costs.
The credential that shouldn't have worked
A service account you set up during an earlier engagement is never revoked. It's compromised months later and used to access the client's production environment.
The client argues that access should have been cleaned up when the project ended, and holds you responsible for the breach.
Who's going to ask you for it
It's a condition of being an approved partner
For cloud consultants, cover is frequently a gate rather than optional risk management:
- Cloud partner programs. Certified partner status with the major providers often requires proof of professional indemnity and cyber cover.
- Enterprise and government transformation contracts set minimum PI and cyber limits given the scale of environments involved.
- System integrator subcontracts flow their own insurance requirements down to you before you can start.
The exclusion cloud consultants assume is covered
The most common trap is the shared responsibility model. When something goes wrong in the client's environment, it's tempting to assume the cloud provider is liable. But under the shared responsibility model, configuration, access control and architecture decisions are yours, and that's exactly what the client will claim against you for.
A misconfiguration you already knew about and hadn't flagged is also typically excluded.
Common questions
Isn't a cloud outage the provider's problem, not mine?
An outage of the provider's own infrastructure is on them. But under the shared responsibility model, how you configured access, storage and architecture is on you. That's usually what a client's claim actually targets.
Isn't this just professional indemnity?
PI is the core, but cloud consultants typically hold broad, standing access to a client's environment, so cyber exposure is significant. ICT cover combines professional indemnity with cyber so there isn't a gap between policies.
What limit should I get?
Match it to your partner program requirements or the client's contract. Enterprise and government cloud work often names $5M or more. If you're unsure, we'll read it with you before you buy.
Does it cover access I set up before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's worth having cover in place before a dispute surfaces.
A partner program needs a certificate of currency, how fast can I get one?
Once you're bound, a certificate is quick to issue. If your partner status is waiting on it, tell us and we'll prioritise it.