FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

IT consultant insurance: what cover you actually need

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: Most UK IT consultants build their programme around technology professional indemnity (tech PI) for mistakes in advice, work or code that cost a client money, plus cyber cover for the data and systems they touch. Public liability covers client-site and premises risks, and employers' liability is a legal requirement once you employ anyone. Clients usually set the limits contractually.

If you advise clients on IT strategy, systems architecture, integration or implementation, your exposure looks nothing like a plumber's or a shop's. You rarely damage physical property. What you do carry is the risk that your recommendation, your configuration or your code causes a client to lose money, lose data or lose time — and that is exactly the sort of loss a general small-business policy is not designed to answer. This guide walks through the covers that matter for a technology consultancy, why each one is relevant to the way you actually work, and what your clients will typically insist on before they sign.

Why do IT consultants need specialist insurance at all?

The core problem is that your product is intangible and its failures are financial. A client hires you to redesign their systems, migrate them to the cloud, or advise on a platform choice. If your advice turns out to be wrong, or the implementation you signed off introduces a fault, the harm they suffer is usually pure economic loss — downtime, re-work, missed deadlines, a project that has to be unpicked and rebuilt. No one was injured and nothing was physically broken, yet the bill can be substantial and they may look to you to pay it.

Ordinary office or public liability cover does not respond to that. It is built for injury and property damage, not for a client's financial loss flowing from professional work. That gap is the reason technology firms buy specialist cover, and it is why a client's procurement team will ask you to evidence it. The rest of this page is really about closing that gap sensibly, layer by layer, without paying for cover you do not need.

What is technology professional indemnity (tech PI)?

Technology professional indemnity — often written tech PI, and the same thing insurers in the US call technology errors & omissions (tech E&O) — is the central cover for a consultancy. It responds when a client alleges that a negligent act, error or omission in your professional work caused them financial loss, and it funds both your legal defence and any damages or settlement. E&O and PI are not two different products to buy; they are two names for the same cover, so do not let a policy schedule confuse you.

What makes the technology version different from a standard accountant's or surveyor's PI is that it is drafted around how technology work goes wrong. A good tech PI wording contemplates defective software or code, failure of a system you designed or integrated to perform as intended, breach of an IT contract or service level, and losses arising from a project overrun. If you resell or bundle third-party products — a SaaS platform, a licence, hosted infrastructure — a technology wording is far better placed to deal with claims that straddle your advice and someone else's product.

It is worth being precise on one point: tech PI is almost never a statutory legal requirement. It is a contractual one. Clients, recruitment agencies and framework agreements routinely require it — and often specify a minimum limit of indemnity, commonly £1m, £2m or £5m depending on the size and sensitivity of the engagement. You are buying it because your contracts demand it and because a single disputed project can dwarf a year's fees, not because Parliament obliges you to. If you want to go deeper on wordings and limits, our guide to technology professional indemnity insurance unpacks it.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Not sure what limit your contracts actually require, or whether your current PI wording is genuinely a technology one? Talk it through with an Apex specialist before you renew.

Get a tailored quote →

Do IT consultants need cyber insurance as well as tech PI?

In most cases, yes — and the two covers answer different questions. Tech PI deals with a client's claim that your work was negligent. Cyber deals with what happens when systems and data — yours or a client's that you administer — are attacked, breached or knocked offline. As a consultant you often hold privileged access: admin credentials, client environments, backups, source code, personal data you process while delivering a project. That access makes you both a target and a potential route into your clients.

Cyber insurance is best understood as funding the response to an incident rather than as a magic wand. A strong policy typically pays for breach response — IT forensics, legal support, notifying affected individuals and the regulator, PR and credit monitoring — for your own business interruption when systems are down, and for third-party liability if a breach on your watch harms others. Where personal data is involved, UK GDPR and the Data Protection Act 2018 impose duties, and the Information Commissioner's Office (ICO) is the regulator you would notify.

One thing to be clear-eyed about: whether a UK GDPR or data-protection fine can lawfully be insured is legally uncertain and is frequently excluded or restricted. Do not buy cyber cover on the assumption it will simply pay your regulatory fines — treat that as unreliable. Its real value is meeting the immediate, expensive cost of responding to and recovering from an incident, and defending third-party claims. Our explainer on cyber insurance goes further into what is and is not covered.

Should tech PI and cyber be one combined policy?

For a technology consultancy it very often makes sense to hold tech PI and cyber together in a combined technology policy rather than as two disconnected contracts. The practical benefit is fewer gaps. When something goes wrong in a technology business, it rarely files itself neatly into one bucket — a botched migration that also exposes data, or a coding error that leads to a breach, can trigger arguments about which policy responds. A combined wording written for technology firms is designed so those two covers sit alongside each other and dovetail, which reduces the risk of an insurer on one side pointing at the insurer on the other.

It is not automatically the right answer for everyone, and limits still need setting for each part, but it is a sensible default worth pricing. We compare the structures in combined technology insurance (tech PI and cyber), and if you are weighing which exposure matters more for your work, PI versus cyber for tech companies is a useful read.

What about public liability and working on client sites?

Public liability covers injury to a third party or damage to their property caused by your business activities. A lot of IT consulting is done remotely, which tempts people to dismiss it — but the moment you are on a client's premises, in their server room, or attending their offices for workshops and installs, the exposure is real. You trip a colleague, knock over expensive kit, or damage something during a hardware install, and the claim lands with you.

Two practical reasons make it hard to skip. First, client and landlord contracts frequently require a minimum level of public liability, often £1m, £2m or £5m, as a condition of letting you on site. Second, co-working spaces and serviced offices commonly demand it before you take a desk. It is usually inexpensive relative to the covers above, and it plugs the one gap your professional and cyber policies deliberately leave open: old-fashioned physical mishaps in the real world.

Do I need employers' liability if I hire staff or contractors?

This one is not optional. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are legally required to hold employers' liability insurance, with only narrow exceptions. It covers claims from employees who are injured or made ill as a result of their work. The requirement bites as your consultancy grows — your first hire, an apprentice, part-time admin support — and it is a legal duty, not a contractual nicety.

The nuance for technology firms is the blurry line between employees and subcontractors. If you bring in freelance developers or associate consultants, whether they count as your employees for insurance purposes depends on the working arrangement, not just the label on the invoice. It is worth checking rather than assuming, because getting it wrong leaves a genuine legal gap. A short conversation when you take someone on is the safest way to establish whether the duty applies to your set-up.

When do media and intellectual property liability matter?

Not every consultancy needs this, but some genuinely do. If your work involves producing content, building client-facing websites or apps, publishing material, or handling brand assets and code that could infringe someone else's rights, media and intellectual property liability becomes relevant. It responds to allegations such as infringement of copyright or a third party's IP, or defamation arising from material you produced or published on a client's behalf.

For a pure infrastructure or strategy adviser it may be surplus. For a consultancy that also designs, develops or ships digital products, it can be an important addition — and in many technology wordings some IP infringement cover already sits within the tech PI section, which is one more reason to read the schedule closely rather than assume. The right answer depends on exactly what you deliver, which is a good thing to map out with a broker who understands technology risk.

Does insurance affect my IR35 status?

No — and it is important not to conflate the two. IR35, the off-payroll working rules, is a tax matter about your employment status for tax when you work through your own company. Holding insurance does not change, improve or determine your IR35 position. Being properly insured is a normal feature of running a genuine business, but no policy makes you “outside IR35” and no broker should imply otherwise.

Your IR35 status turns on the reality of your working arrangements — substitution, control, mutuality of obligation and so on — and it should be assessed by a qualified accountant or tax adviser, not by your insurer. Buy insurance for the risks it actually covers, and get IR35 advice from the right professional. If you contract rather than run a consultancy, our page on IT contractor insurance is aimed at your situation.

How do I put the right programme together?

Start from your contracts and your actual work, not from a template. Read what your clients and any frameworks require — the covers named and the minimum limits — and treat that as the floor, not the ceiling. Then layer sensibly: tech PI as the backbone, cyber for the data and systems you touch, public liability for site work, employers' liability the moment you employ anyone, and media/IP cover only if what you deliver warrants it. A combined technology policy is often the tidiest way to hold the first two together.

The value of a broker here is matching the wording to how you really work, so you are neither exposed nor over-insured. If you want a broader map before you dive in, what insurance an IT company needs sets out the whole landscape.

Apex builds technology insurance around the way IT consultancies actually operate — the right limits for your contracts, the right covers for your work, no padding. Let's get yours right.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →