FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

IT contractor insurance

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: Most UK IT contractors need technology professional indemnity (tech PI) to cover mistakes in their work, cyber cover for the data and systems they handle, and public liability for on-site work. If you employ anyone, employers' liability is a legal requirement. Agencies and end clients routinely make these covers a condition of the contract.

Whether you work as a sole-trader freelancer or through your own limited company, contracting in IT means you carry real professional and commercial risk — often for organisations far larger than you. A single line of code, a misconfigured firewall or a piece of architecture advice that doesn't perform as promised can cost a client serious money, and they will look to you to put it right. Insurance is how you meet that exposure without it landing on your own balance sheet, and increasingly it's the paperwork that gets you through an agency's onboarding in the first place.

This guide walks through the covers that actually matter for a contract IT professional, why each one exists for your kind of work, and what clients tend to insist on before they'll let you near their systems.

What insurance does an IT contractor actually need?

There's no single "IT contractor policy" that magically covers everything, but for most people the shape is the same. You want technology professional indemnity for the advice and work you deliver, cyber cover for the data and systems you touch, and public liability for the physical, real-world side of visiting client sites. Add employers' liability the moment you take on staff, and consider media or intellectual property liability if your work involves content, branding or licensed material.

The reason it stacks up this way is that these covers respond to genuinely different events. Professional indemnity answers a client who says your work was negligent and cost them money. Cyber answers a breach or ransomware incident. Public liability answers someone tripping over your kit or your laptop damaging a client's boardroom table. One policy rarely does all three well, which is why contractors often hold a small, deliberate bundle rather than a single catch-all.

Why is technology professional indemnity the cover that matters most?

For an IT contractor, technology professional indemnity (tech PI) is usually the centre of gravity. It covers claims that your work or advice was negligent — a bug that took down a client's platform, an integration that corrupted data, a system that didn't do what you specified, or guidance that led a client down an expensive wrong turn. It typically funds both your legal defence and any damages or settlement, which matters because defence costs alone can be punishing even when you've done nothing wrong.

One point that confuses a lot of contractors: you'll see American clients and some agencies refer to "technology errors and omissions" or "tech E&O". That is the same thing as tech PI — E&O is simply the US term for professional indemnity. Don't let a contract that demands "E&O cover" send you hunting for a separate, unrelated product; a properly written technology PI policy is what they're describing.

It's worth being clear about status too: professional indemnity is not a statutory legal requirement for IT firms. It becomes effectively compulsory because clients and agencies write it into their contracts — often specifying a minimum limit of indemnity such as £1m, £2m or £5m. So while the law doesn't force you to hold it, your ability to win and keep contracts very often does. Our guide to technology professional indemnity insurance goes deeper on how limits and definitions are set.

Do IT contractors really need cyber insurance?

Yes — and it's the cover most often underestimated. As a contractor you frequently hold or access other people's data, credentials and infrastructure. If your own laptop, cloud account or dev environment is compromised, or if ransomware locks up systems you're responsible for, the fallout can spread to the client and back to you. Cyber insurance is built to fund the response to those incidents: forensic investigation, restoring data and systems, business interruption while you're offline, notifying affected parties, and third-party liability where someone else suffers loss.

A word of care on fines. It's tempting to assume cyber cover simply "pays your GDPR fine", but the insurability of UK GDPR and data-protection penalties is legally uncertain in the UK and is frequently excluded or restricted. The honest way to think about cyber insurance is as cover for breach response, business interruption and third-party claims — not as a guarantee that a regulator's fine will be picked up. UK data-protection law here means the UK GDPR and the Data Protection Act 2018, enforced by the Information Commissioner's Office (ICO). If you'd like the full picture, see cyber insurance explained.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Not sure whether your contracts call for tech PI, cyber, or both? Tell us how you work and we'll map the cover to your actual client requirements.

Get a tailored quote →

Why does a combined technology policy bundle tech PI and cyber?

For technology businesses the line between a professional mistake and a cyber event is genuinely blurred. If a configuration error you made leads to a data breach, is that a PI claim or a cyber claim? On two separate policies you can end up with insurers arguing about which one responds — exactly the wrong conversation to be having mid-incident. A combined technology policy is designed for this: it packages tech PI and cyber into one contract, usually with public liability available too, so the covers dovetail rather than collide.

For a contractor placed through agencies, a combined policy also makes the admin simpler — one renewal, one certificate to send when a new client asks for evidence. It's not automatically the right answer for everyone, but it's often the neatest fit. We compare the approaches in combined technology insurance (tech PI and cyber).

What about public liability and working on client sites?

Plenty of IT contracting is remote now, but if you ever set foot on a client's premises — installing hardware, attending a war-room, running an on-site migration — public liability matters. It covers injury to other people or damage to their property arising from your work: knocking a server rack, a visitor tripping over cabling you've laid, or your equipment damaging the client's property. Many landlords and larger corporate clients won't grant site access without it, and some frame a specific minimum limit in the contract.

If you're weighing up the full picture of what a contracting or product IT business should carry, what insurance does an IT company need lays out the same covers from a company's perspective.

When do you legally need employers' liability insurance?

This is the one genuinely compulsory cover, and it kicks in as soon as you employ people. Under the Employers' Liability (Compulsory Insurance) Act 1969, most UK businesses that employ staff must hold employers' liability insurance to cover claims from employees who are injured or become ill because of the work they do for you. There are narrow exceptions — for example, some family-only companies — but if you grow your PSC into something with employees, or take on someone to help with delivery, this stops being optional and becomes a legal duty.

It's an easy one to overlook as a solo contractor, because for a long time it simply doesn't apply. The trigger point is employment. If you're a one-person limited company with no staff, it generally isn't required; the day you hire, it is. If you're unsure whether a particular arrangement counts as employment for this purpose, it's worth a quick conversation rather than a guess.

Does insurance affect my IR35 status?

No — and this is important to get right. IR35, the off-payroll working rules, is a tax matter. It determines your employment status for tax purposes on a given engagement. Holding professional indemnity, cyber or any other insurance does not change, improve or determine your IR35 position. Insurance is evidence of how you run your business, but it is not a status test, and no policy will move you from inside to outside IR35.

What's true is that agencies and end clients very commonly require you to hold PI, public liability and — where relevant — employers' liability as a condition of the contract. That's a commercial requirement about risk, sitting entirely separately from the tax question. Keep the two ideas apart: buy insurance to meet contractual and risk needs; for your actual IR35 status on a contract, take advice from a qualified accountant or tax adviser who can assess the specific working practices.

What do agencies and end clients typically demand in the contract?

When you read a new contract or agency framework, the insurance clause usually asks for a familiar set of things. Knowing what you're looking at makes onboarding far quicker.

Two things to watch. First, some contracts ask you to maintain cover for a period after the work ends — because a claim about your work can surface long after the project closes. Second, check the required limit before you sign; buying to the level a contract actually specifies avoids an awkward gap on day one.

Do I need media or intellectual property liability too?

For some contractors, yes. If your work strays into content, design, branding, marketing technology or anything involving third-party material — code libraries, fonts, images, licensed components — you can face allegations of infringing someone's intellectual property or defaming them. Media and IP liability responds to that kind of claim. It's not essential for every contractor, but if part of what you deliver is creative or content-driven, or you're reusing licensed material inside client deliverables, it's worth raising when you set your cover up.

How should an IT contractor put the right cover together?

Start from how you actually work: what you deliver, whose data and systems you touch, whether you visit sites, whether you employ anyone, and — crucially — what your live and prospective contracts require. From there the covers assemble logically: tech PI as the core, cyber alongside it (often combined), public liability where there's site work, employers' liability the moment you hire, and media/IP where your work warrants it. Because the tech PI and cyber pieces overlap, it's worth having someone who understands technology risk look at the definitions rather than buying on limit alone. If you're weighing the two directly, professional indemnity vs cyber insurance for tech companies sets out where each responds.

Every contractor's exposure is slightly different, which is exactly why an off-the-shelf answer rarely fits neatly. A short conversation about your engagements usually settles it faster than working through a form. You can start a tailored quote online, or speak to an Apex technology specialist who can read your contract clauses with you and make sure the cover lines up.

Apex is building its reputation as the broker IT contractors and technology firms rely on. Send us the insurance clause from your next contract and we'll make sure your cover meets it.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →