For most business owners, "call my insurance agent" and "call my IT provider" have always been two separate conversations that happen at two separate times. That's changing fast. What an underwriter is willing to cover, and what they'll charge for it, now depends directly on what's actually protecting your systems.
We see that play out constantly through our relationship with Lakeside Insurance, an independent Colorado agency we've partnered with for more than 15 years. Lakeside was built on the same principle we were: risk management comes first, and insurance comes second.
That connection matters more for architecture firms than almost anyone else. Ask most firms about professional liability insurance for architects and you'll hear the same assumption: our policy already has us covered. In practice, that policy and your cyber exposure only work together when somebody is coordinating them, and most firms find out the hard way that nobody was.
No. Professional liability insurance, also called errors and omissions coverage, responds when a client claims your firm made a professional mistake: a design error, missed code requirement, bad advice. It was never built to respond when an outside attacker breaks into your systems. Many firms don't realize their professional liability policy simply doesn't include cyber protection.
The distinction comes down to fault. Professional liability only applies when a third party's loss traces back to your firm's negligence in doing your job, as Gallagher's breakdown of the gap explains. If a skilled attacker gets past your defenses despite reasonable precautions, that's not a professional error, and your E&O policy has no reason to respond to it.
This is also why the coverage only ever looks at claims from the outside. It was never designed to reimburse your own firm for the costs a breach creates, and that gap catches almost every architecture firm that assumes one policy has them handled.
We already broke down the infrastructure side of this in our post on IT support for architects, including the 44% year-over-year jump in construction and design ransomware attacks in early 2026. The insurance side of that same problem is just as stark.
Roughly 60% of engineering firms have already experienced a cyberattack, firms in this sector face more than double the ransomware risk of other industries, and nearly a third get hit again within 16 months of the first attack. The average breach now costs an engineering firm close to $400,000.
Attackers target architecture firms for reasons specific to the work you do. A firm three weeks from a permit submission or tied to a construction deadline feels immediate pressure to pay a ransom just to keep the project moving. Blueprints, engineering specs, and unreleased building designs also carry standalone value, which means an attacker can encrypt your systems and threaten to leak the designs at the same time, a dual-pressure play that's fairly unique to this industry.
Cyber insurance is built to pay for the costs your own firm takes on after an attack: breach response, data recovery, ransom negotiation, business interruption, and the legal and regulatory costs that follow. The overlap between the two policy types has gotten blurrier as firms move more of their work into cloud tools and shared platforms, but the core split still holds.
|
What Professional Liability Covers |
What Cyber Insurance Covers |
|
|
|
|
|
|
|
|
The median cost of cyber liability coverage for a small business runs about $145 a month, and professional liability covers errors in the services you deliver, while cyber liability covers what happens when someone else forces their way in. They're two different jobs, and a firm needs both to actually be covered.
Underwriting has tightened considerably, and carriers won't just take your word for your security anymore. Before issuing a policy, most now require:
If your firm can't check every box on that list today, you're not just under-protected. You may not be insurable at the rate you're expecting, or insurable at all.
We've seen firsthand what it takes to get security sized right for a small architecture team without overbuilding or underbuilding it, the kind of work you'll find across our architecture and engineering case studies. That means managed cybersecurity that satisfies what a carrier is asking for, tested data backup and recovery built around CAD and BIM files specifically, and audit-ready documentation a broker like Lakeside can hand straight to an underwriter.
We also keep an eye on the credential side of this, since a stolen login is still one of the fastest ways into a firm's project files. Our breakdown of session hijacking and why MFA alone isn't stopping it covers the piece most policies quietly assume is already handled.
Flat-rate pricing through our fractional IT department means none of this shows up as a surprise add-on later. It's built in from day one, and it's exactly what makes the conversation with teams like Lakeside a short one instead of a scramble. If you're not sure whether your current setup would get you a cyber policy, or keep a professional liability claim from turning into a bigger mess, reach out to TMGC to get started.
Does professional liability insurance cover a data breach?
No. Professional liability, or E&O insurance, only responds to claims that your firm made a professional error. A data breach caused by an outside attacker requires a separate cyber liability policy.
How much does cyber liability insurance cost for an architecture firm?
Architects pay an average of roughly $84 a month for cyber liability coverage, on top of an average $141 a month for professional liability, according to Insureon's data.
What will my insurance carrier require before issuing a cyber policy?
Most carriers now require multi-factor authentication, tested offline backups, endpoint detection and response tools, email security controls, and a documented incident response plan before they'll write a policy.
What's the difference between professional liability insurance and cyber liability insurance?
Professional liability insurance covers claims that your firm's work caused a client's loss through negligence. Cyber liability covers the costs your firm takes on when an outside attacker breaches your systems, regardless of fault.
Do clients require architects to carry cyber insurance?
Increasingly, yes. Clients are starting to require proof of cyber coverage in contracts the same way they've long required proof of professional liability coverage.