You're the one with write access to their data
As a DBA, you're the custodian of the client's most critical asset: the data itself. A maintenance job that corrupts records, a migration where a permissions error exposes data it shouldn't, or simply a lock that runs into business hours, any one of these can land on you. Professional indemnity and cyber cover, built for database administration.
Where a database administrator actually gets exposed
Your risk is closer to the data than almost any other tech role. You have direct write access to the systems that run the client's business, and standard business insurance doesn't cover the data loss, corruption or exposure that can come from routine maintenance gone wrong.
The migration that lost three months of records
You run an index rebuild as part of a database migration for a client. A bad assumption in the process corrupts a section of production data, and the backups available only cover part of what's lost.
The client can't reconstruct three months of records, and holds you responsible for the migration.
The permissions error during the migration
While migrating a client's database to new infrastructure, an access grant is misconfigured, exposing customer records to users who shouldn't have had access.
Under the Privacy Act, the client has to notify everyone affected, and they say your configuration was the cause.
The maintenance window that ran long
An overnight maintenance job you run locks key tables, and it isn't released before the client's business day starts. Their systems stall for hours during peak operations.
The client seeks the cost of the disruption and holds you responsible for the overrun.
Who's going to ask you for it
It's a condition of getting access to the data
For DBAs, cover is often the price of admission to production systems:
- Enterprise data contracts commonly require $2M–$5M professional indemnity before you're granted access.
- Government agencies handling sensitive data set high-limit PI and cyber requirements as standard.
- Staffing agencies placing DBAs won't put you on-site without a current certificate of currency.
The exclusion database administrators assume is covered
Having backups doesn't remove the exposure. The assumption that "we can restore it, so there's no real loss" ignores the disruption, lost transactions and remediation cost that happen before recovery. Cover responds to the loss caused in that window, not just what's ultimately unrecoverable.
A known or unpatched vulnerability you were told about and didn't act on is also typically excluded.
Common questions
We have backups, do I still need this?
Yes. Backups reduce how bad a loss gets, but they don't remove the disruption, lost transactions and remediation cost that happen before data is restored. That gap is exactly what a client can claim for.
Isn't this just professional indemnity?
PI covers the maintenance and configuration work, but as a DBA you're a direct custodian of the client's data, so cyber exposure is significant. ICT cover combines professional indemnity with cyber so there isn't a gap between policies.
What limit should I get?
Take it from the client's data access agreement or the agency's placement terms. It will usually name a minimum. If you're unsure, we'll read it with you before you buy.
Does it cover a database I administered before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's best to have cover in place before a dispute surfaces.
A client needs a certificate of currency before granting access, how fast?
Once bound, a certificate is quick to issue. If access is waiting on it, tell us and we'll prioritise it.