Insurance for a new IT or software business
What a new IT or software business is exposed to
The exposure follows what you do rather than what you call yourself, and the range inside “IT” is wide. Bespoke development risks a system that does not do what the specification said, or does it too slowly to be usable. Migration work risks losing or corrupting data on the way across. Managed services mean a client’s systems go down and their business stops with them. Hosting and SaaS carry availability risk against a service level the contract has already fixed. Advisory work carries the ordinary professional exposure: the client built what you recommended and it was wrong.
Two more run underneath all of them. Intellectual property: code you did not write, and licence terms that did not permit what the client now does with the output. And security: if a flaw in what you built lets an attacker into your client, their loss is real and you are the obvious defendant. Separately, you are a business with your own systems, and as attackable as anyone else.
Professional indemnity and cyber: two policies, two questions
Professional indemnity answers: our work was wrong and it cost the client money. Third-party liability cover for the services you provide. The trigger is a claim alleging negligence or breach of a professional duty — a project that did not deliver, a system that did not perform, advice that led the client somewhere expensive. In technology it is usually written together with technology errors and omissions cover, so the product itself, and not only the advice about it, sits inside the insuring clause. Technology professional indemnity in more depth.
Cyber answers: something happened to systems or data. A first-party half pays your own costs after an incident — forensics, incident response, restoring data, legal and regulatory support, lost income — and a third-party half responds to claims arising from a breach of data you were holding. Cyber insurance is explained here.
Neither substitutes for the other. A cyber policy will not pay a client whose project failed because the build was wrong. A professional indemnity policy will not pay for a forensic investigation of your own network after ransomware. And where a client contract names both, one policy with a generous limit does not satisfy it.
The overlap is real, which is why placement matters. Take a defect in software you wrote that lets an attacker reach your client’s customer data: a failure of your professional work and a data incident in the same event. Placed well, the two policies interlock. Placed carelessly — different insurers, different retroactive dates, a data exclusion on one and a professional services exclusion on the other — both carriers can point at each other while you fund the response.
Regulatory obligation sits alongside the insurance rather than inside it. A personal data breach likely to result in a risk to people’s rights and freedoms must be reported to the Information Commissioner’s Office without undue delay and not later than 72 hours after you become aware of it. That clock runs whether or not you have cover.
What cover a new IT business typically needs
Professional indemnity written for technology. Check the wording reaches the product and not only the advice, and check the definition of professional services against what you actually sell. A wording built for management consultants does not necessarily cover a software licence.
Cyber, both halves. For a small business the first-party incident response is often the part that earns its keep, because it puts a specialist on the phone on day one.
Public liability if you go to client sites, install anything, or have visitors at your premises — field engineering and on-site installation raise this well above a formality — and employers’ liability as soon as anyone works for you, at a legal minimum of at least £5m under the Employers’ Liability (Compulsory Insurance) Act 1969.
Cover for equipment, including kit away from your premises. If you also resell or install hardware, raise product liability separately — supplying physical goods is a different exposure from writing software and is not automatically picked up.
What clients and contracts typically require
Technology contracts are more specific than most. A master services agreement will usually name professional indemnity and cyber separately, set a limit for each, and require cover to be maintained for a defined period after termination. Enterprise and public sector buyers run supplier due diligence before onboarding, and ask for certificates rather than assurances.
Two clauses deserve attention before signature. The liability cap: if the contract caps your liability at a figure, your limit should be at least that, and if it caps nothing, that is worth negotiating rather than insuring around. And the intellectual property indemnity, often uncapped where everything else is capped, and only useful if your policy reaches IP infringement at all. Buyers increasingly want evidence of security practice alongside the insurance — the Cyber Essentials scheme, developed by the National Cyber Security Centre, sets out five technical controls and is asked for before a supplier can bid. Underwriters look at the same controls.
What an underwriter wants to see from a business with no trading history
What the software or service does, and what it controls. A scheduling tool for a small office and a system that moves money, dispenses medication or manages building access are not the same risk, whatever the income says. The client sector matters too — financial services, healthcare and critical infrastructure raise the bar.
Where the team did this work before, on what systems and at what scale — the most useful thing a new technology business can offer in place of accounts — and expected income for the first twelve months, split between development, managed services, licensing, hosting and hardware if you do more than one.
How you contract and how you deliver. Written terms, acceptance testing, change control, defined specifications and recorded sign-off — the difference between a dispute that ends at the acceptance certificate and one that ends in court.
Your own security posture — multi-factor authentication, patching, backups tested by restoring from them, access control, and how you separate client environments. For cyber this is most of the rating. Third-party code and licensing practice, and any claims or circumstances including from previous employment, belong on the form too.
Getting cover in place before the first project
Professional indemnity is claims-made: it responds to the claim brought while the policy is live, not to the work done while it was live. Software claims arrive late, once a system has been in production long enough for the problem to become undeniable, so cover needs to start before the first billable line of code and keep running afterwards.
The retroactive date matters particularly for developers who have been contracting through an agency and are now setting up their own company. That earlier work does not follow you into the new entity unless the underwriter agrees a retroactive date reaching back to it, so ask at quote stage. Cyber is the other way round in one respect: most wordings will not respond to an incident that had already begun, so buy it while nothing is happening.
Frequently asked questions
Do I need both professional indemnity and cyber insurance?
If you write software, run systems or hold client data, yes. Professional indemnity answers a claim that your work was wrong and cost the client money. Cyber answers an attack on your own systems and a breach of the data you hold. Neither covers the other.
Does cyber insurance cover a bug in my software?
Not as a professional failure. If a defect means the client’s system does not work and they sue for their losses, that is a professional indemnity claim. Cyber becomes relevant where the defect leads to unauthorised access or a data breach.
Does professional indemnity cover a ransomware attack on my own business?
No. Your own incident response, forensics, data restoration and lost income are first-party cyber costs. Professional indemnity is third-party liability cover.
What is technology errors and omissions cover?
Professional indemnity written so it reaches the technology product and the service, not only the advice about them. For a software business it is the right starting point, because the thing most likely to fail is the thing you built.
I am a contractor going limited. Does my cover follow me?
No. Work done under a previous arrangement stays with whatever covered it then. Your new company needs its own policy, and bringing earlier work inside it requires a retroactive date the underwriter has agreed.
Related reading: Insurance for a new business · IT and technology business insurance · IT professionals’ PI guide · What you need to get a quote · Cover before you start trading
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
