IT support company insurance
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you run helpdesk, break-fix or managed IT support for other businesses, you sit inside your clients' operations in a way few suppliers do. You hold admin credentials, touch their servers and endpoints, configure their backups and, increasingly, advise them on what to buy and how to secure it. That access is exactly why your clients trust you — and exactly why a single mistake, misconfiguration or missed patch can have consequences far larger than the invoice you sent. Insurance for an IT support company is really about matching cover to that unusual level of access and responsibility.
This guide walks through the covers that genuinely matter for helpdesk and support firms, why each one applies to the work you actually do, and what your own clients will typically insist on before they sign a contract. It is written for owners and contractors who want to understand the shape of their cover, not just tick a box.
What insurance does an IT support company actually need?
There is no single "IT support policy" that magically covers everything, but for most helpdesk and break-fix firms the sensible core is a combination of four things: technology professional indemnity, cyber, public liability, and — the moment you employ anyone — employers' liability. Depending on what you do, media and intellectual property liability can matter too, particularly if you build or badge software, or produce content and websites alongside your support work.
The reason these are usually bought together is that a real support engagement rarely breaks cleanly along one line. Push a bad Group Policy change and lock a client out of their systems, and you have both a professional error and a potential business-interruption claim. That overlap is why we spend time understanding exactly what your firm does before recommending limits — the mix for a two-person break-fix outfit looks very different from a managed service provider running clients' entire estates. If you want the broader picture across the sector, our overview of what insurance an IT company needs is a good companion to this page.
Why is technology professional indemnity the cover IT support firms lean on most?
Technology professional indemnity (often called tech PI, and sold in the US as technology errors & omissions, or tech E&O — they are broadly the same cover) responds when something you did, advised or delivered professionally causes a client financial loss and they come after you for it. For an IT support company this is the workhorse policy, because your day-to-day is full of judgement calls: which firewall rule to apply, whether a backup restore is safe, how to migrate a mailbox without data loss, what security posture to recommend.
Picture a routine job that goes wrong. You run a scripted update across a client's fleet and it corrupts a line-of-business application; the client loses two days of trading and hands you a bill for the downtime and the specialist recovery consultant they had to call in. Or you advise a client that their existing backup is fine, it isn't, and when ransomware hits there is nothing clean to restore from. Tech PI is designed to fund the defence costs and any damages or settlement in situations like these, whether the allegation is fair or not — and defending an unfair claim can be expensive on its own.
One point worth being precise about: professional indemnity is not a statutory legal requirement for IT firms. What makes it close to unavoidable is that your clients demand it contractually. It is common to see managed service agreements and larger corporate contracts specify a minimum PI limit — £1m, £2m or £5m are typical illustrative figures — before they will let you near their systems. In practice, the contract, not the law, sets your floor. We go deeper on this cover on our dedicated technology professional indemnity insurance page.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure whether your PI limit meets what your biggest client's contract demands? Send us the requirement and we'll tell you straight.
Get a tailored quote →Do IT support companies really need cyber insurance if they're the ones securing everyone else?
It's a fair question, and the honest answer is that IT support firms often need cyber cover more than their clients do — precisely because they are a high-value target. If an attacker compromises your remote monitoring and management tool or your admin credentials, they don't reach one business; they reach every client you connect to. You are a supply-chain gateway, and criminals know it.
Cyber insurance is best understood as funding the response to an incident rather than a magic shield. A good policy typically pays for the breach-response machinery you'll suddenly need: incident-response and forensic specialists to work out what happened, legal support, notification of affected parties, credit or identity monitoring where relevant, and PR help. It usually covers your own business interruption when your systems are down, and third-party liability if a client sues you because their data was exposed through you.
Two things to be clear-eyed about. First, cyber cover deals with the data and systems you touch — because as an IT support company you are a data processor for your clients under UK GDPR and the Data Protection Act 2018, and the Information Commissioner's Office (ICO) is the regulator you'd be answering to. Second, on regulatory fines: the insurability of UK GDPR and data-protection fines is legally uncertain and often excluded or restricted, so it is a mistake to assume a cyber policy simply "pays your ICO fine." Treat cyber as cover for the response, the downtime and the third-party claims — not as a guarantee against a regulator's penalty. If you want the mechanics laid out, see our cyber insurance explained guide.
How do tech PI and cyber fit together in a combined technology policy?
Because IT incidents blur the line between "we made a professional error" and "we suffered a data breach," many insurers now package technology professional indemnity and cyber into a single combined technology policy. For a support firm this is usually the neatest arrangement: one policy, one renewal, and — crucially — fewer arguments at claim time about which section responds when an incident has elements of both.
Take a misconfigured client firewall that lets an attacker in. Is that a professional error (your work was defective) or a cyber event (data was breached)? In reality it is both, and having the two covers sitting inside one policy from one insurer removes the gap a claim can otherwise fall into. It isn't automatically the right structure for every firm — sometimes standalone covers give you higher or better-tailored limits — but for most helpdesk and managed-support businesses a combined approach is worth looking at first. We compare the trade-offs on our combined technology insurance page.
What about public liability when you're on client sites?
Support work isn't purely remote. You're on client premises racking hardware, running cable, swapping kit, and sometimes hosting clients or visitors at your own office. Public liability covers your legal liability if you injure someone or damage their property in the course of that work — you knock a server rack over, a visitor trips over a cable you left across a walkway, you damage a client's fit-out while installing equipment.
It won't be the cover you claim on most, but it's frequently a contractual requirement for site access, and building owners or clients with their own health-and-safety regimes may ask for a specific limit before they let your engineers in. For a firm that does regular on-site work, it's inexpensive peace of mind and often the thing that gets you through a client's supplier-onboarding checklist.
If I employ staff, what am I legally required to have?
This is the one area where the law, not a contract, forces your hand. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are legally required to hold employers' liability insurance, subject to some narrow exceptions. It covers your liability if an employee is injured or becomes ill because of the work they do for you — a support engineer hurt lifting equipment, say, or an office-based issue over time.
The practical trigger points are worth flagging for growing IT firms. Take on your first employee, or bring in staff beyond certain close family or single-director exemptions, and the obligation generally applies. Because the exemptions are specific and can catch people out, it's worth confirming your position rather than assuming — a short conversation is usually all it takes to get it right.
Hiring your first engineer, or scaling the team? Talk to an Apex specialist and we'll make sure your employers' liability and everything around it is set up correctly from day one.
Get a tailored quote →When do media and IP liability come into it?
Plenty of IT support firms do more than support. If you build or resell software, badge a product as your own, develop client websites, or produce content and documentation, you take on risks that plain support work doesn't carry — chiefly intellectual property infringement and, for published content, defamation. Media and IP liability responds to allegations like accidentally infringing a third party's copyright or trademark in something you delivered.
You don't need to guess whether this applies to you. The simplest test is to look at what you actually deliver beyond the helpdesk: if any of it involves creating, publishing or licensing content or software, it's worth raising with your broker so cover matches the real breadth of your work rather than a generic idea of "IT support."
What do clients typically demand before they'll sign a contract?
Most disputes about "how much cover do I need" are settled not by the law but by your clients' procurement teams. Before a business hands you the keys to its systems, it will often ask for evidence of specific covers at specific limits. Commonly that means:
- A minimum technology professional indemnity limit — often £1m, £2m or £5m depending on the client's size and the value of what you're protecting.
- Cyber cover, increasingly named explicitly now that supply-chain risk is front of mind for larger buyers.
- Public liability at a stated limit for any on-site access.
- Employers' liability, which they may ask to see simply because you're legally required to hold it.
The trap to avoid is buying to the last contract you signed and then winning a bigger client whose requirements you no longer meet — or, just as awkward, discovering your limit is too low halfway through a tender. It pays to know your numbers before you're asked.
Does insurance have anything to do with IR35?
For IT contractors this comes up constantly, so it's worth stating plainly: no. IR35 — the off-payroll working rules — is a tax matter about your employment status for tax purposes. Holding insurance, of any kind, does not change or determine your IR35 status, and any suggestion that it does is simply wrong. Insurance and IR35 are separate questions that happen to sit near each other in a contractor's paperwork.
What insurance does do is help you meet the professional and contractual expectations of the clients and agencies you work with, which is a genuine reason to hold it regardless of your tax position. For an assessment of your actual IR35 status, speak to a qualified accountant or tax adviser — that's their expertise, not ours, and not something any policy can settle. If you work independently, our IT contractor insurance guide covers the practicalities.
What affects the cost of IT support insurance?
We won't quote a headline price here, because a realistic figure depends entirely on your firm. The factors that move it are the ones worth understanding, so you can see why two similar-looking businesses pay differently. Insurers weigh things like your annual turnover and the type of work in it (pure break-fix versus full managed services versus software development), the limits of indemnity your contracts require, the size and sensitivity of the client data and systems you access, your claims history, and the security controls you run internally — multi-factor authentication, tested backups and sensible access management all help.
The takeaway is that cost follows your risk profile, and a well-presented picture of how you actually operate can work in your favour. That's a large part of what a specialist broker does: framing your firm accurately to insurers rather than letting a generic questionnaire define you. If you'd like to compare where PI ends and cyber begins before deciding on structure, our note on professional indemnity vs cyber insurance for tech companies is a useful read.
Getting it right for your firm
The strongest position for an IT support company is a joined-up programme — tech PI and cyber (often combined), public liability, employers' liability where you have staff, and media/IP cover if your work reaches into content or software — sized to the contracts you actually hold and the access you actually have. Get that right and insurance stops being a box on a tender and becomes something that quietly protects the business you've built.
At Apex we work with IT and technology firms every day, and we'd rather understand your specific setup than sell you a template. Start a tailored quote, or talk it through with a specialist who knows the sector.
Ready to make sure your IT support firm is covered for the work it really does? Let Apex build cover around your contracts, not a checklist.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
