FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Cloud service provider insurance: what UK hosting and platform businesses actually need

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06

In short: A UK cloud or hosting provider usually needs technology professional indemnity (for errors in your service, software or advice that cost a client money) and cyber insurance (for the data and systems you hold). Add public liability if you visit client sites, and employers' liability once you have staff, which is a legal requirement. Many providers buy tech PI and cyber as one combined technology policy.

If you run infrastructure, host other people's applications, or sell platform or managed cloud services, you sit in an unusual position: you don't just advise on technology, you are part of your clients' operational backbone. When your platform has a bad hour, their business has a bad hour too. That is exactly why the insurance question for a cloud provider is different from the one facing a general IT reseller or a one-off software consultant, and why getting the cover right matters more than most owners assume until a claim or a contract review forces the issue.

This guide walks through the risks that are specific to hosting and platform work, the covers that respond to them, and what your own clients will almost certainly demand before they sign. It's written for founders, contractors and small-team providers who want to understand why each cover earns its place, not just tick a box.

What are the real risks of running a cloud or hosting business?

Start with what actually goes wrong. A configuration change takes a customer's environment offline during their trading peak. A migration you performed loses or corrupts data. A patch you deployed introduces a fault that breaks a client's integration. A shared component has a vulnerability, and an attacker moves through it to reach data you were storing on a customer's behalf. None of these require you to be negligent in the everyday sense; they're the ordinary hazards of being trusted with systems and data that belong to other people.

Two features make your risk profile distinctive. First, aggregation: because many clients rely on the same platform, a single incident can trigger multiple claims at once. Second, data custody: you routinely hold, process or have access to your customers' data, which pulls you squarely into cyber exposure and into UK data-protection obligations even when the data isn't yours. Your insurance needs to answer both the "we made a mistake in the service" problem and the "something happened to the data and systems" problem, because those are handled by different covers.

Why does a cloud provider need technology professional indemnity?

Technology professional indemnity (often written as tech PI, and called technology errors & omissions, or tech E&O, in the US market, it's broadly the same cover) responds when a mistake, oversight or failure in your professional work causes a client a financial loss and they hold you responsible. For a hosting or platform business that includes downtime attributed to your service, a botched migration, faulty configuration work, missed availability commitments, or advice that turned out to be wrong.

Crucially, it isn't only there for when you've genuinely got it wrong. A large part of the value is defence: if a client alleges your service caused their loss, tech PI funds the legal cost of investigating and defending the allegation, even where you're ultimately not liable. For a small provider, that defence cost alone can be existential, which is the practical reason the cover exists.

One point worth being precise about: professional indemnity is not a statutory legal requirement for IT and cloud firms. It is almost always a contractual one, written into your customer agreements, framework terms or reseller arrangements. That distinction matters because it means the limit you need is usually set by your contracts, not by law, so read what your clients are asking for before you choose a figure. Our overview of technology professional indemnity insurance goes deeper on how limits and retroactive dates work.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Not sure whether your contracts demand a £1m or £5m limit, or how your SLA commitments interact with cover? An Apex technology specialist will read your risk properly and build cover around it.

Get a tailored quote →

How does cyber insurance protect a hosting business specifically?

Cyber insurance is the cover most closely matched to what you do, because your business is built on the confidentiality, integrity and availability of systems and data. Where tech PI answers "did your professional work cause a client loss?", cyber answers "what happens when your systems, or the data you hold, are breached, encrypted, stolen or knocked offline?"

For a cloud provider, a well-structured cyber policy typically funds three things. It pays for breach response: the specialist IT forensics, legal support, and notification effort needed to investigate an incident, work out what was affected, and meet your obligations. It covers your own business interruption when an attack takes your platform down and revenue stops. And it provides third-party liability when customers or their end users bring claims because their data was compromised on your watch.

Be clear-eyed about one thing that is often misunderstood. It is tempting to assume cyber insurance simply "pays your GDPR fine". It doesn't work that neatly. Under UK GDPR and the Data Protection Act 2018, the Information Commissioner's Office (ICO) can impose monetary penalties, and whether such a regulatory fine is insurable at all is legally uncertain and frequently excluded or restricted by policies. The honest value of cyber cover is in funding the response, the interruption losses and the third-party claims, not in a guarantee that a regulator's fine will be met. Any broker who tells you otherwise is overselling it. Our cyber insurance explainer sets out what's typically covered and what isn't.

Should I buy tech PI and cyber together as a combined policy?

Very often, yes, and for a good reason. When a hosting incident happens, it rarely respects the neat line between "professional mistake" and "security event". Suppose a misconfiguration you introduced exposes a customer's data. Is that a professional error (tech PI territory) or a data breach (cyber territory)? Realistically it's both, and if those covers sit with two different insurers you can end up with each pointing at the other while you're stuck in the middle.

A combined technology policy bundles tech PI and cyber under one insurer and one claims process, which removes that gap and usually makes the whole thing simpler to buy and manage. For most cloud and hosting providers it's the natural home. It isn't the only route, and there are cases where standalone covers make sense, but if you value one point of contact when something goes wrong, the combined approach is worth serious consideration. We explain the trade-offs on our combined technology insurance page.

Do I need public liability if I work from a home office or data centre?

Public liability covers injury to other people or damage to their property arising from your business activities. A lot of cloud work is remote, so it's easy to dismiss, but consider the moments when you're physically present somewhere: installing or decommissioning kit in a colocation facility or client server room, visiting a customer's premises to scope a migration, or meeting clients in a space you're responsible for. If you damage a rack, or a visitor trips over your equipment, public liability responds.

Many clients and, in particular, data-centre and colocation operators will require you to hold a public liability limit before they let your people or hardware on site. So even where the day-to-day exposure feels low, it's frequently a condition of access to the very facilities your business depends on. Check your contracts and site-access agreements; the requirement is often already there in black and white.

Is employers' liability insurance a legal requirement for my team?

This one is not optional once you employ people. Under the Employers' Liability (Compulsory Insurance) Act 1969, if you have employees you are legally required to hold employers' liability insurance, with only narrow exceptions (for example, some businesses employing only close family members, or genuinely single-person companies where the sole employee owns most of the shares). It covers claims from staff who are injured or become ill as a result of their work.

Two traps catch technology firms in particular. First, the definition of "employee" can extend beyond your permanent payroll to some contractors and temporary staff, depending on how they work for you, so growing teams should check their position rather than assume. Second, it's a legal duty, not a contractual nicety, so it applies regardless of what your client agreements say. If you're taking on your first hire, put this in place before they start.

What about media, intellectual property and content risk?

Depending on what your platform does, media and intellectual property liability can be relevant, and it's easy to overlook. If you host user-generated content, publish materials, or your service touches areas where infringement or defamation claims could arise, this cover responds to third-party allegations such as intellectual property infringement or defamatory content. Many technology and combined policies include an element of IP and media liability already; the point is to check the scope against what your service actually does rather than assume it's covered. A provider that simply runs infrastructure has a lighter exposure here than one running a content-heavy platform, which is exactly the kind of nuance worth talking through with a broker who understands the model.

What will my own clients demand before they sign?

In practice, your insurance is often shaped less by your own risk appetite and more by your customers' procurement teams. Enterprise and public-sector clients routinely require, in writing, a technology professional indemnity limit (commonly expressed as £1m, £5m or £10m as illustrative options, set by the size of the contract), cyber cover reflecting the data you'll handle, and evidence of employers' and public liability. Master service agreements frequently name specific limits and ask you to maintain them for the life of the contract and sometimes beyond.

The practical lesson: don't buy in a vacuum. Line your cover up against your contract pipeline, because winning a larger client can quietly raise the limit you're contractually obliged to carry. If you're weighing which covers are genuinely essential versus nice-to-have, our guides on what insurance an IT company needs and the difference between PI and cyber cover for tech companies are good next reads.

A quick word on IR35 and status

If you operate as a contractor through a limited company, you'll have come across IR35. It's worth being clear, because it's widely misunderstood: IR35 is a tax matter, the off-payroll working rules about your employment status for tax purposes. Holding insurance, of any kind, does not change, improve or determine your IR35 status, and you should be wary of anyone who implies it does. Insurance and tax status are separate questions. For an assessment of your IR35 position, speak to a qualified accountant or tax adviser; for the covers your contracts require, that's where a specialist broker helps. If you contract solo, our IT contractor insurance guide is written for you.

What drives the cost of cover for a cloud provider?

Every provider is priced on its own risk, so rather than quote figures, it's more useful to know what moves the dial. Insurers typically weigh:

Because these factors interact, two providers of similar size can end up in quite different places. That's the argument for having a broker assemble the picture rather than buying a generic package that may leave a gap exactly where your business is most exposed.

Apex builds technology cover around cloud, hosting and platform businesses every week. Tell us how your service works and what your contracts demand, and we'll match cover to it, without the jargon.

Get a tailored quote →

Cloud and hosting is a business of trust: your clients hand you their systems and their data and expect them safe. The right insurance doesn't make incidents impossible, but it means that when the unexpected happens, you have the funds and the specialist support to respond, defend and recover, instead of absorbing the whole cost yourself. If you'd rather talk it through than fill in a form, speak to an Apex technology specialist and we'll start with your risk, not a template.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →