Insurance for agencies that build — and run — software
The quiet change from projects to services
Most agencies do not decide to become a service provider; they drift into it. A client asks you to host what you built. Another asks for a support retainer. A third hands you the keys to their cloud account because it is easier than briefing you every time. Within a couple of years the firm that did discrete projects — build, hand over, invoice, leave — is running production systems that other businesses depend on every day. The revenue mix changed gradually. The insurance, in most cases, did not change at all.
Project PI and ongoing-service exposure are different animals
Professional indemnity for a project agency is built around a simple pattern: you advised or built negligently, the client suffered a loss, a claim arrives — one project, one dispute, one crystallised event. It is the right cover for design and development work and it remains essential.
Running a live service breaks the pattern. The exposure is continuous rather than project-shaped: an outage at two in the morning, a missed service level across a quarter, a backup that was not actually restorable, a security hole in a system you operate rather than one you handed over. The client’s loss flows from the operation of the service, not from a discrete piece of advice. This is the territory of technology errors and omissions — wordings written for firms whose product is uptime and performance — and a traditional PI form may respond awkwardly or not at all to a claim that is really about a service level. If part of your income is recurring fees for keeping things running, part of your cover needs to be shaped for that.
Cyber: your estate, and everyone else’s keys
An agency needs cyber cover for its own estate — its laptops, repositories, email and finances — like any modern business. But an agency that runs client systems holds something more dangerous: credentials. Admin access to client cloud accounts, deployment pipelines, databases and CMSs makes you a supply-chain target in exactly the way managed service providers are targeted — compromise the agency once and you reach every client it holds keys to.
That changes the questions that matter: does your cyber policy respond when the incident is on a client’s system that you operate? Does your PI or tech E&O respond to the client’s claim that your security failure caused their breach? Insurers draw those lines differently across wordings, and the join between the cyber policy and the E&O policy is precisely where a credential-compromise claim lands. It is a join to be engineered at placement, not discovered in an incident.
The contracts you sign shape the cover you need
Client MSAs increasingly negotiate your insurance for you. Liability caps are agreed — and then carved out: unlimited liability for breach of confidentiality, for data protection, for IP infringement, sometimes for security incidents generally. Each carve-out is a doorway to a claim far larger than the contract value, and your policy limits should be chosen with those carve-outs in mind, not just the fee income.
IP infringement deserves its own line: an allegation that your deliverable infringes someone else’s code, design or trade mark is a standard claim in this sector and cover for it varies widely between wordings. And every agency ships open-source and third-party components; licence obligations, abandoned dependencies and inherited vulnerabilities are part of the professional risk and part of what a well-chosen wording should contemplate.
What a fit-for-purpose programme looks like
For an agency with a genuine operational side, the programme usually has three legs. Professional indemnity or a combined technology E&O wording that expressly covers both project delivery and the ongoing services — hosting, support, maintenance, operation — at a limit set against the MSA carve-outs rather than the average project fee. Cyber cover arranged with the client-credential exposure disclosed, so the insurer knows an incident on your side can propagate into client environments, and the incident-response service is engaged on that basis. And the ordinary commercial covers underneath: office contents and kit, and employers' liability — a legal requirement with a £5 million statutory minimum — from the first hire. IT consultancies approaching renewal can also read about how we run IT consultant PI placements.
Whether the E&O and cyber sit with one insurer or two matters less than the joins being deliberate: who responds to a client outage, who responds to a breach that started in your repository, and where a claim that is both at once will land. Those are questions to settle in placement correspondence, while everyone is calm.
Agency, software house or MSP: the schedule decides
Insurers rate a creative agency, a software development house and a managed service provider as different businesses, because they are: their claims look different, their exposures accumulate differently, and their premiums are calculated differently. The description of business on your schedule is where your insurer learns which one you are. If it still says “digital marketing agency” or “website design” from the year the policy was first bought, and the claim arises from a hosting outage or a compromised client server, you have handed the insurer its first question: why were we never told the business does this?
The answer is never to select the least alarming label from an online form. It is to describe the whole operation — design, development, hosting, support, operation of client systems — in a sentence drafted for the purpose, placed with an insurer that has priced all of it. That is a broker’s job, and on this risk it is most of the job.
FAQ
We have PI already. Doesn’t that cover the hosting and support side?
Not reliably. PI responds to negligent professional work — and an insurer can argue that operating infrastructure, meeting SLAs and keeping a service online is not the professional activity described in your schedule. Claims arising from outages and service failures sit more naturally in technology E&O wordings. The honest test: read the description of business on your schedule and ask whether it mentions running anything.
Our clients’ systems are in their cloud accounts, not ours. Is that still our risk?
If you hold credentials and operate the systems, yes. A compromise that travels through your access into their environment produces a claim against you, and possibly incident costs of your own. Whether that lands on your cyber policy, your E&O, or in the gap between them depends entirely on wordings — which is why the two should be placed to fit together.
Our MSA caps our liability at the contract value. Doesn’t that limit what we need?
Read the carve-outs. Most negotiated MSAs make the cap subject to exceptions — confidentiality, data protection, IP, sometimes security — and those are exactly the claims most likely to be large. Your limit of indemnity should be set against the uncapped scenarios, not the capped ones.
Does it actually matter what the policy calls us — agency, software house, MSP?
Yes, materially. Those labels carry different rating, different question sets and different wordings. A policy priced for an agency doing project work has not priced continuous operational exposure, and the mismatch surfaces as a coverage argument at the worst time. The description of business should be drafted to match reality, then placed with an insurer that accepts all of it.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
