IT and technology business insurance checklist
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06
If you run an IT or technology business, insurance rarely feels urgent until a client's procurement team emails you a contract and asks for your certificates. Then it becomes very urgent indeed. This checklist walks you through what a properly covered tech firm looks like, in the order it actually matters, so you can win contracts without scrambling and sleep at night knowing a bad day won't sink the business. Work through it once now, and revisit it whenever you take on a bigger client or change what you do.
Does your technology PI match what your client contracts actually demand?
This is the first and most common trip-up, so start here. Technology professional indemnity insurance (often called technology errors & omissions, or tech E&O — the same cover under the American name) responds when a client alleges your work caused them a financial loss. A missed integration deadline, code that behaves differently in production, advice that turned out to be wrong, an SLA you couldn't meet: these are professional-indemnity claims, and they are the claims tech firms face most.
Professional indemnity is not a statutory legal requirement for IT firms. What makes it non-negotiable is your clients. Almost every meaningful contract — and virtually every framework, agency placement or enterprise deal — requires you to carry tech PI at a stated limit, commonly £1m, £2m or £5m, sometimes £10m for public-sector or large corporate work. The mistake firms make is buying a comfortable-sounding limit once and assuming it's fine forever. It isn't. The correct limit is whatever your most demanding current contract says it is. If one client requires £5m and your policy is £2m, you are technically in breach of that contract the moment you sign it, and if that client claims, you could be exposed for the gap personally.
So the checklist item is concrete: pull out your live contracts, note the PI limit each one requires, and confirm your policy meets the highest. Then check the basis of cover. Most tech PI is written on a "claims made" basis, meaning the policy that must respond is the one in force when the claim is made, not when you did the work. That's why continuous cover and getting your retroactive date right both matter — a gap can leave old projects uninsured. Our guide to technology professional indemnity insurance goes deeper on how these limits and dates work.
Is your cyber cover sized to the data and systems you actually touch?
Tech firms hold a strange position: you are often the party your clients trust with their most sensitive systems and data, which makes you both a target and a single point of failure for them. Cyber insurance exists for when that trust is tested — a ransomware hit on your own infrastructure, a business-email-compromise fraud, a breach that exposes client or personal data, or an outage that stops you delivering.
Be clear about what cyber cover is for. It funds breach response: the IT forensics, legal advice, notification of affected individuals, and PR support you need in the first chaotic 48 hours. It covers business interruption when your systems are down, and third-party liability when someone sues over a breach involving their data. What it does not reliably do is pay regulatory fines. Under UK GDPR and the Data Protection Act 2018, the insurability of fines from the Information Commissioner's Office is legally uncertain and is often excluded or restricted — so never assume a cyber policy will simply settle an ICO penalty for you. Treat cyber as the mechanism that funds your response and recovery, not a get-out-of-jail card for regulatory action.
The sizing question matters as much as having the cover at all. If you host client data, run managed services, hold admin credentials to customer environments, or process personal data at volume, your exposure is far larger than a firm that writes code and hands it over. Match your cyber limit and the breadth of cover to what you genuinely touch. Many clients now also require cyber cover contractually alongside PI, especially where you have access to their systems. Because tech PI and cyber overlap at the edges — a data breach caused by your faulty work can look like both — a lot of tech firms buy them together to avoid gaps and arguments over which policy responds. Our page on combined technology insurance (tech PI and cyber) explains how that pairing works, and cyber insurance explained covers the mechanics.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure whether your PI and cyber limits line up with the contracts you're chasing? Send us the requirements and we'll map your cover against them.
Get a tailored quote →Already have a current schedule? Email it to info@apexinsurancebrokers.co.uk and a named broker will come back to you.
Do you employ anyone — and therefore need employers' liability?
This one is a genuine legal duty, not a contractual one. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you must hold employers' liability (EL) insurance, with only narrow exceptions. It covers claims from employees who are injured or become ill because of their work. If you've grown from a solo consultancy into a team — even one or two people — this moves from "nice to have" to "required by law".
The area that catches tech firms out is who counts as an employee. Bringing in a contractor, a part-time developer, or someone working under your direction and control can trigger the requirement even if you don't think of them as staff. If you're unsure, treat it as a question to raise with your broker rather than a judgement to make alone, because getting it wrong leaves you both legally exposed and personally liable for an injured worker's losses. The safe checklist action: if anyone works for you under your direction, confirm whether EL applies before they start.
Do you visit client sites, and is public liability in place?
Plenty of IT work happens on your own screen, but the moment you're on a client's premises — installing hardware, running a workshop, attending a data-centre, meeting a customer in their office — you create a different kind of risk. Public liability (PL) insurance covers injury to a third party or damage to their property arising from your business activities. Trip over a cable and knock a client's monitor off the desk, or worse, and it's PL that responds.
If you're purely remote and never set foot on a client site, PL may be a low priority. But many clients ask for it as a standard line in their contract regardless, and if you do any on-site work it's worth having. The checklist item here is simple: list the ways your work puts you or your kit in someone else's space, and make sure PL is in place at a limit that reflects the sites you attend. For a broader view of how these covers fit together for a technology business, see what insurance does an IT company need.
Are you reviewing your limits as you grow and win bigger contracts?
Insurance that fitted you two years ago quietly stops fitting. Every time you land a larger client, move upmarket, add a new service line, or start handling more sensitive data, your risk profile shifts — and the cover that was generous becomes tight. The firms that get caught out are usually the ones that set up a policy at incorporation and never looked again.
Build a habit of reviewing cover at the moments that matter, not just at renewal:
- You win a contract that needs a higher PI or cyber limit than you currently hold.
- You start hosting client data or managing systems you previously only advised on.
- You hire your first employee or bring on contractors.
- Your turnover jumps — premiums and appropriate limits both tend to track revenue and headcount.
- You expand into a new sector (finance, health, public sector) with stricter requirements.
None of these should be a surprise to your insurer. Telling your broker as things change keeps your cover matched to reality and avoids the nasty discovery, mid-claim, that you'd outgrown your policy. If you contract through your own limited company, the way you scale cover is a little different again — our IT contractor insurance page addresses that case directly.
Are you reading the insurance schedule in every new contract before you sign?
The single most useful habit on this whole list is boringly practical: whenever a new contract lands, find the insurance clause and read it properly before you sign. Client contracts and agency terms almost always specify the covers you must hold, the minimum limits, and sometimes wording details — whether cover must be on an "each and every claim" basis, how long you must maintain PI after the work ends (run-off), and occasionally named additional requirements.
Signing first and checking later is how firms end up in breach of a contract they can't actually satisfy, or paying for a limit increase they could have negotiated. Catch it before signature and you have options: adjust your cover, ask your broker whether the requirement is reasonable, or push back on a term that's out of step with the value of the work. A two-minute read at the right moment saves a great deal of grief. If a contract's requirements look onerous or unusual, that's exactly the point to speak to an Apex specialist rather than guess — we deal with these schedules constantly and can tell you quickly whether a demand is standard or worth challenging.
What about IR35 — does insurance affect my status?
It's worth being crystal clear here because it's a common muddle. IR35, the off-payroll working rules, is a tax matter about your employment status for tax purposes. Holding insurance — PI, cyber or anything else — does not change, improve, or determine your IR35 status. Some contracts require insurance and separately concern IR35, which is why the two get mentioned in the same breath, but they are entirely different questions. Buy the right cover for the right reasons, and for anything to do with your IR35 status itself, speak to a qualified accountant or tax adviser. That's not our field, and we'd rather point you to the right one than pretend otherwise.
Putting the checklist to work
You don't need to solve all of this in an afternoon. Run down the six checks — PI matched to your biggest contract, cyber sized to the data you touch, EL if you employ anyone, PL where you attend sites, limits reviewed as you grow, and every new contract's schedule read before signing — and note where you're solid and where there's a gap. Most tech firms find they're broadly covered but slightly behind their own growth: a limit that hasn't kept pace, or a new service line the policy never heard about. Those are quick to fix once you spot them.
The value of a broker who works with technology firms is that we translate a client's contract language into the cover you actually need, flag the gaps you can't see, and make sure the whole thing still fits next year. If you'd like a second pair of eyes on where you stand, start a tailored quote and we'll take it from there. You can also read our overview of IT and technology business insurance for the bigger picture.
Working through a new client contract or scaling up? Talk to an Apex technology specialist and we'll make sure your cover matches what you're signing.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
