IT and telecoms
Yes: if you install, maintain or repair servers, PCs, storage, networks or peripherals for clients, you need professional indemnity insurance as well as public liability. Public liability deals with accidental injury and damage, such as a dropped monitor or a flooded comms room. PI usually deals with the downtime, lost data and rework a client blames on your configuration, diagnosis or repair. Engineers who only deliver kit to someone else’s design carry less PI risk, but few stop there.
Part of: Professional indemnity for IT professionals
In short
IT hardware engineers work inside clients’ systems, often against response and fix-time commitments. Claims come from downtime after an installation or repair, misconfiguration, data lost during repair, and damage to equipment while it is in your hands. For business clients the law implies a duty to work with reasonable care and skill; for consumer repairs the Consumer Rights Act 2015 does the same and stops you excluding that duty. If your work gives you access to personal data on devices, UK GDPR processor terms may apply. PI usually covers negligent work and advice, public liability covers physical damage, and cyber covers attacks on your own tools and systems.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
Hardware engineers work inside other people’s systems: installing servers and storage, swapping failed parts, upgrading firmware, building and moving desks, repairing laptops at a bench. Most visits end with the client back in business. The ones that go wrong tend to go wrong expensively, because the client’s operation stops while its systems are down, and data that was on a device can be gone for good.
Two different policies respond, depending on what happened. If you knock a monitor off a desk or your drill hits a water pipe, that is accidental physical damage and public liability is the usual home for it. If the office is offline for a day because a switch you configured created a network loop, or a database is lost because the wrong disk was pulled from an array, the client’s loss comes from your technical judgement. That is a professional indemnity (PI) claim.
Engineers who only deliver and connect equipment to someone else’s design carry less PI risk. Few stop there: diagnosing faults, choosing parts, configuring devices and deciding when to apply updates are professional decisions, and clients judge them that way.
The scenarios below are illustrative, not real claims. They show the allegations hardware engineers most often have to answer.
Disputes about hardware work turn on what the law implies into your contracts, what your terms say and how you handled any data you could reach. These are the reference points.
| Law or guidance | What it says | Why it matters to you |
|---|---|---|
| Supply of Goods and Services Act 1982, s.13 | In a business contract for services, a supplier acting in the course of a business must carry out the service with reasonable care and skill. | The baseline for business clients, even where your terms are silent. |
| Consumer Rights Act 2015, ss.49, 54 and 57 | Services to consumers must be performed with reasonable care and skill. If they are not, the consumer can require repeat performance or a price reduction. A term cannot exclude liability for failing to use reasonable care and skill, or restrict it so far that the consumer cannot recover the price paid. | If you repair devices for the public, a notice disclaiming responsibility does not remove that duty. |
| Unfair Contract Terms Act 1977, s.2(2) | In business contracts, a term excluding or restricting liability for negligence, other than for death or personal injury, is effective only if it is reasonable. | Your data loss disclaimers for business clients can be challenged on reasonableness. |
| UK GDPR, Articles 4 and 28 | Processing includes operations such as retrieval, consultation, storage and erasure of personal data. Where you process personal data on a client’s behalf, the contract must contain the Article 28 processor terms. | Work on devices holding personal data can bring you within data protection law, so expect processor clauses from larger clients. |
| ICO data protection audit framework | Organisations should store devices awaiting destruction securely, keep a log of them and their location, and document secure disposal methods. | Clients will expect you to handle replaced drives the same way. |
Damage to a client’s equipment while you have it is the most misunderstood risk in this trade. A server dropped in your workshop, a laptop crushed in your van or a storage shelf damaged during a rack move can fall between policies.
Many public liability wordings exclude damage to property in your care, custody or control, or to the specific item you are working on, unless an extension is added. PI policies, for their part, are aimed at financial loss and usually exclude physical damage to property. If neither is arranged with this in mind, the cost of the damaged equipment can end up with you.
Data is a separate question again. Public liability usually covers damage to tangible property, and data is often treated as intangible, so a client’s claim for lost data is more likely to be argued under PI. Check four things with your broker:
Many repair shops and engineers use terms or counter notices saying they accept no responsibility for data. Those notices do less than people think.
For consumers, the Consumer Rights Act 2015 says a term cannot exclude your liability for failing to use reasonable care and skill. For business clients, the Unfair Contract Terms Act 1977 says a term excluding liability for negligence must be reasonable to be effective. A blanket disclaimer may help with a client who refused a backup, but it is unlikely to protect you where an engineer simply made a mistake.
Better evidence comes from your process: record the device’s condition and serial number at intake, ask the client to confirm in writing whether a current backup exists, offer a backup before risky work, and log every action on the job. If a claim follows, PI may respond even where your disclaimer fails, subject to the policy terms.
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Downtime caused by negligent installation, configuration or repair | Service credits and fix-time rebates under maintenance contracts | Accidental damage to third-party property away from your work (public liability) |
| Data lost or corrupted during maintenance or repair | Physical damage to the client’s equipment you are working on | Client equipment in your care, custody or control (public liability extension or goods in trust cover) |
| Wrong diagnosis, wrong parts or wrong advice on equipment | Cost of replacing parts you supplied that were faulty | Faulty parts you supply that cause injury or damage (products liability) |
| Breach of confidentiality and data protection claims, where included | Contractual guarantees of uptime or fix times beyond reasonable care | Attacks on your own systems or remote access tools (cyber insurance) |
| Defence costs, including independent technical experts | Work subcontracted to engineers you have not declared | Tools and stock, and injury to your staff (property and employers’ liability) |
Every policy has its own wording and cover is subject to its terms. Technology packages often combine PI and public liability, which helps with the gaps above, but read how each section treats property in your care before you rely on it.
Engineers who mostly do hands-on work still hold the keys to their clients’ systems: remote access tools, admin passwords in the ticketing system, diagnostic laptops and USB tools that move between sites. That is why cyber insurance belongs alongside PI, which for IT businesses is usually written as technology errors and omissions cover.
If your remote access platform is compromised and attackers use it to reach your clients, cyber insurance pays your own costs to investigate, contain and recover, and supports you through notification. The clients’ claims that you failed to secure that access are a liability question for PI or the liability section of your cyber policy, depending on the wordings. A USB tool that carries malware from one client site to another raises the same split. Our guide to cyber insurance explained sets out what each part of a cyber policy does.
Your limit will usually be set by maintenance contracts and framework agreements. Larger clients and public bodies tend to specify a PI figure, often alongside a public liability requirement. Base the limit on the clients whose downtime would cost the most, not on the size of the job.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for IT hardware engineers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes, if you configure, diagnose, repair or advise rather than only delivering equipment. Downtime, data loss and rework caused by your technical decisions are financial losses that public liability does not cover. PI pays your defence costs and compensation when a client alleges your work was negligent, subject to the policy terms.
No law requires IT hardware engineers to hold PI. The requirement comes from clients: maintenance contracts, managed service providers who subcontract field work and public sector frameworks commonly ask for a minimum PI limit, usually alongside public liability, before you start work.
Usually neither, unless you arrange it. Many public liability wordings exclude property in your care, custody or control or being worked upon, and PI usually excludes physical damage. Ask for a care, custody and control extension or goods in trust cover, and check your PI for client data.
Not fully. For consumers, the Consumer Rights Act 2015 stops a term excluding liability for failing to use reasonable care and skill. For business clients, the Unfair Contract Terms Act 1977 requires negligence exclusions to be reasonable. Written backup confirmations and intake records are better evidence.
Service credits and fix-time rebates are usually excluded, because they are a contractual discount you agreed to give. If the missed fix was caused by your negligence and the client claims its wider losses, such as lost sales, PI may respond subject to the wording. Avoid promising guaranteed fix times without a sole-remedy clause.
Usually, yes. Remote access tools, stored admin passwords and diagnostic kit that moves between sites can all carry an attack to your clients. Cyber insurance usually pays your own investigation, recovery and notification costs. PI or the liability section of a cyber policy usually deals with your clients’ claims.
Apex arranges professional indemnity insurance for IT hardware engineers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.