Combined technology insurance: tech PI and cyber
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
What is a combined technology insurance policy?
A combined technology policy is a single insurance product designed around how technology and IT businesses actually work. Instead of buying professional indemnity from one insurer, cyber from another, and public liability from a third, you hold one policy that bundles the covers a tech firm typically needs. The two components that do the heavy lifting are technology professional indemnity (tech PI) and cyber, and most combined products also fold in public liability, and often employers' liability where you have staff, plus optional extras like business interruption or intellectual property cover.
The word "combined" is doing real work here. These policies are written for software houses, MSPs, IT consultants, SaaS providers, systems integrators, resellers and contractors — businesses whose product, advice and data handling are tangled together. A single job can involve writing code, hosting a client's data, giving advice and connecting to third-party systems. When something goes wrong, it rarely respects the neat boundaries between separate insurance policies. A combined policy is built to sit across those boundaries.
What does technology professional indemnity actually cover?
Technology professional indemnity protects you when a client alleges your professional work caused them a financial loss. That covers negligence, mistakes, missed deadlines that breach contract, defective code, a project that fails to deliver what was promised, or advice that turns out to be wrong. If a client sues, tech PI is designed to fund your legal defence and any damages or settlement you're liable for, up to the limit you choose.
One point worth clearing up early: you may see this called technology errors and omissions (tech E&O). Tech PI and tech E&O are broadly the same thing — E&O is simply the American term for the same cover. If a US client or a contract references E&O, they're asking about the cover UK insurers call professional indemnity. Don't let the label make you think you need a separate, additional product.
It's also worth being precise about why you'd hold it. Professional indemnity is not a statutory legal requirement for IT firms in the UK. In practice, though, it's almost always a contractual one: client contracts, framework agreements and recruitment agencies routinely require you to carry tech PI to a set limit — commonly £1m, £2m or £5m — before they'll sign or let you start. So while no law forces you to buy it, you'll often find you simply can't win the work without it. Our page on technology professional indemnity insurance goes deeper on limits and how claims are triggered.
What does the cyber side of the policy do?
Cyber cover responds when your own systems — or systems you're responsible for — are attacked, breached or disrupted. For a technology firm this is not a nice-to-have bolted onto the side; you hold, process and move data as a core part of the job, which makes you both a target and a custodian of other people's information.
A cyber section is generally built to fund three things. First, breach response: the specialist help you need in the hours and days after an incident — IT forensics to work out what happened, legal support, notifying affected individuals, and managing the reputational fallout. Second, business interruption: the income you lose and the extra costs you carry while ransomware or an outage keeps you offline. Third, third-party liability: claims from clients or individuals whose data was compromised because of an incident on your watch.
One thing cyber insurance is often misunderstood to do is pay your regulatory fines. Be careful here. Under UK GDPR and the Data Protection Act 2018, the Information Commissioner's Office (ICO) can impose penalties for serious data-protection failures — but whether such a fine is insurable at all is legally uncertain in the UK, and cyber policies frequently exclude or restrict it. Treat cyber cover as funding your breach response, your business interruption and your liability to others; do not assume it will settle a regulatory fine. Our explainer on cyber insurance walks through what typically is and isn't included.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure whether a combined policy or separate covers fits your contracts and client data exposure? An Apex technology specialist will map it to how your firm actually operates.
Get a tailored quote →Why does one incident often trigger both covers at once?
This is the heart of why the combination exists. Technology incidents don't tend to stay in a single lane, and the same event can create two very different claims at the same time.
Picture a scenario. You're an MSP managing a client's cloud environment. A misconfiguration during a migration you carried out leaves a database exposed, and an attacker exfiltrates customer records. From that single mistake, two things fire simultaneously. There's a professional-negligence dimension — your client argues the migration was performed negligently and they've suffered a financial loss, which is tech PI territory. And there's a data-breach dimension — personal data has been compromised, individuals need notifying, forensics are needed, and third parties may bring claims, which is cyber territory.
Now imagine those two exposures sit with two different insurers on two separate policies. The awkward, expensive question becomes: which policy responds? Each insurer has an incentive to argue the loss belongs to the other's cover. You can end up caught in the middle of a coverage dispute at exactly the moment you can least afford one — mid-crisis, with a client demanding answers and a regulator's clock ticking.
How does a combined policy close the gap between separate covers?
When tech PI and cyber sit within one product from one insurer, the boundary between them is defined inside a single contract rather than negotiated across two. That does a few practical things.
- Fewer coverage gaps. With separate policies, it's easy to end up with a sliver of exposure that neither policy clearly picks up — the classic "falls between two stools" problem. A combined policy is drafted so the covers interlock, reducing the risk of a claim that neither side owns.
- One insurer, one claim, one conversation. When an incident spans both covers, you notify once and deal with one claims team rather than refereeing a dispute between two.
- Aligned definitions and limits. Separate policies can define the same event differently, or set retroactive dates and territorial limits that don't line up. A single product keeps those consistent.
- Usually better value and simpler admin. One renewal date, one proposal, one point of contact — and often a more efficient premium than assembling the same cover piecemeal.
None of this means a combined policy is automatically right for every firm — a business with unusual or very large exposures might still want standalone covers with bespoke wordings. But for the majority of IT and technology SMEs, the combined route is designed precisely around the overlap that trips people up. If you want to see the two covers side by side, our comparison of professional indemnity vs cyber insurance for tech companies lays out where each begins and ends.
What else is usually bundled in, and what's genuinely separate?
Beyond the tech PI and cyber core, most combined technology policies let you add covers that reflect the rest of your operation:
- Public liability — for injury or property damage you cause to third parties, for example when you're on a client site installing hardware.
- Employers' liability — if you employ anyone, this is a genuine legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969, with only narrow exceptions (such as some family-only or single-director companies). This is not optional the way the others are; once you have staff, you need it.
- Intellectual property and media — for allegations that your work infringed someone's IP, increasingly relevant for software and content businesses.
- Business interruption and equipment — protecting income and kit, sometimes tied to the cyber section, sometimes standalone.
A couple of things that people sometimes expect insurance to solve, but it doesn't. Insurance does not affect your IR35 position. IR35, the off-payroll working rules, is a tax matter about your employment status for tax purposes — holding any insurance policy neither changes nor determines it. If you're a contractor weighing up status, that's a question for a qualified accountant or tax adviser, not a broker. And insurance won't substitute for good data-protection practice: cover funds the response to an incident, but you still carry your own obligations under UK GDPR and the Data Protection Act 2018.
How do I know if a combined technology policy is right for my firm?
Start with two questions: do you give advice, build, configure or deliver technology that a client relies on — and do you hold, process or have access to data that isn't yours? If the answer to both is yes, your exposure genuinely spans professional work and cyber, which is exactly the overlap a combined policy is built for. Almost every software developer, MSP, IT consultant, SaaS business, integrator and IT contractor answers yes to both.
From there, the detail matters more than the label. The right structure depends on your contract requirements (what limits your clients demand), your annual turnover, the sensitivity of the data you touch, whether you work on-site, and how many people you employ. Two firms doing broadly similar work can need quite different arrangements once you look at their contracts and client base. That's the part worth talking through with someone who arranges these policies day in, day out — it's easy to over-buy in one area and leave a real gap in another. You can start a quote online, or speak to an Apex technology specialist who'll pressure-test the structure against your actual contracts before anything is placed.
For a broader tour of the covers an IT business tends to need, see what insurance does an IT company need.
Tell us how your firm works — the contracts you win, the data you hold, the people you employ — and we'll build a combined technology policy that fits, with no gaps left for a bad day to fall through.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
