Professional indemnity vs cyber insurance for tech firms
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you run an IT company, a software house or work as a technology contractor, two policies come up again and again: technology professional indemnity and cyber insurance. They sound like they might overlap enough that one could do the job of both. They don't. They're triggered by genuinely different things going wrong, and understanding that difference is the whole point of this page.
The short version: professional indemnity is about the work you deliver to a client. Cyber is about your own systems and data being attacked or breached. One looks outward at your contracts; the other looks inward at your infrastructure. Below we walk through each, show where they touch, and — most usefully — show where the gap sits if you only buy one.
What does technology professional indemnity actually cover?
Technology professional indemnity (tech PI) responds when a client alleges that your work — the software you built, the system you integrated, the advice you gave, the project you managed — was negligent, defective or fell short of what was promised, and that it caused them a financial loss. It covers the cost of defending that allegation and any damages or settlement you become liable for.
A quick note on terminology, because it trips a lot of people up: you'll see this cover called technology errors & omissions (tech E&O), especially in contracts drafted by US-headquartered clients. Tech PI and tech E&O are broadly the same thing — E&O is simply the American name for it. If a client's contract demands "E&O cover", your technology PI policy is almost certainly what satisfies it. Don't buy a second product thinking they're different.
Typical scenarios tech PI is built for:
- A bug in software you wrote takes down a client's order system during their busiest week, and they claim for lost revenue.
- A migration you ran corrupts or loses a client's data, and they hold you responsible for the recovery cost.
- You recommended and implemented a platform that doesn't do what you said it would, and the client sues to recover the fees and their wasted spend.
- A project overruns badly and the client alleges the delay flowed from your negligence, not their scope creep.
Crucially, tech PI is not a statutory legal requirement for IT firms — there's no UK law forcing you to hold it. In practice it's almost always a contractual requirement. Enterprise clients, public-sector frameworks, recruitment agencies and marketplaces routinely insist on a minimum limit of indemnity (often £1m, £2m or £5m) before they'll sign. So while nothing legally compels it, you may find you simply can't win the work without it. We go deeper on this in our guide to technology professional indemnity insurance.
What does cyber insurance cover that PI doesn't?
Cyber insurance responds when your own systems, network or data are hit — a ransomware attack, a hack, a phishing-led breach, a system outage caused by a malicious actor. Where tech PI is about failing your client through your work, cyber is about your business being the victim of an incident and dealing with the fallout.
A good cyber policy really does two jobs. First, it funds the response: the IT forensics to find out what happened, specialist breach lawyers, the cost of restoring data and systems, notifying affected individuals, credit-monitoring or PR support, and the business interruption while you're down. This first-party response is often the part firms value most, because a serious incident is expensive and chaotic long before anyone sues you.
Second, it covers third-party liability arising from the breach — for instance, if customers or partners bring claims because their personal data was exposed through your systems.
One thing to be precise about, because there's a lot of loose marketing out there: whether UK regulatory fines under data-protection law can be insured is legally uncertain, and many policies exclude or restrict them. So don't assume cyber insurance will simply pay an Information Commissioner's Office (ICO) fine — treat cyber as funding breach response, business interruption and third-party liability, and view any fines question as something to check carefully rather than take for granted. The relevant UK law here is the UK GDPR and the Data Protection Act 2018, with the ICO as regulator. Our cyber insurance explained page breaks the components down further.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure which claim scenarios your current cover would actually pay out on? An Apex technology specialist will map your contracts and your systems against both policies.
Get a tailored quote →Tech PI vs cyber: how do they compare side by side?
Here's the cleanest way to hold the distinction in your head. Ask: who was harmed, and by what?
- Trigger. Tech PI: your work, advice or product allegedly failed. Cyber: your systems or data were attacked or breached.
- Who suffers first. Tech PI: your client, financially, from your performance. Cyber: your own business first — then, sometimes, others.
- What it pays for. Tech PI: legal defence plus damages for the client's loss. Cyber: incident response, data restoration, business interruption, and breach-related third-party claims.
- The core question a claim turns on. Tech PI: "Did you do your job properly?" Cyber: "Were you attacked or breached, and what did it cost?"
The reason this comparison matters is that a single bad week can involve both at once — which is exactly what the next section is about.
Where do the two policies overlap?
There's a genuine grey zone, and it's worth being honest about it because it's where firms get caught out. Imagine you're a managed service provider. An attacker gets into your systems and, through the access you have into a client's environment, their data is exposed too. Now you potentially have a cyber event (the breach of your systems) and a professional indemnity exposure (the client arguing your security practices were negligent and that's why they were harmed).
A claim like that can straddle the line between the two policies. Which one responds — or whether both do — depends on how each is worded, what's included, and what's carved out. This is precisely the situation where having both, ideally arranged so they work together rather than pointing at each other, saves you from a coverage argument at the worst possible moment. Many technology firms address this with a combined technology insurance package that puts tech PI and cyber together, which reduces the risk of a gap opening up between two separately-bought policies.
If I only buy one, what's the gap?
This is the question that decides it for most people, so let's make it concrete.
Buy only tech PI, skip cyber. You get ransomware. Your systems are locked, you're paying forensics and lawyers, you can't invoice for a week, and you're legally obliged to notify affected people. Tech PI wasn't built for any of that — it responds to allegations about your work, not to an attack on your own network. You'd be funding the response yourself.
Buy only cyber, skip tech PI. A client says the platform you delivered was defective and it cost them six figures in lost trading. There's no breach, no attacker, no data incident — just an allegation that your work was negligent. Cyber has nothing to bite on. You'd be defending that claim, and paying any settlement, out of your own pocket. On top of which, you likely couldn't have signed the contract in the first place, because the client demanded PI cover.
That's why the honest answer for most tech firms is: you need both. They're not competing products where you pick the better one; they're two halves of the risk a technology business actually carries. If you want the wider picture of everything an IT business typically needs, our overview of what insurance an IT company needs sets it in context.
Does this change if I'm a contractor rather than a company?
The logic is the same, but a couple of things are worth flagging for independent IT contractors and small consultancies. First, agencies and end-clients frequently make tech PI (and often cyber) a condition of the contract, so for you it's usually about winning the placement, not just protecting yourself. Second — and this catches people out — insurance has nothing to do with your IR35 status. IR35 is a tax matter about employment status for tax purposes under the off-payroll working rules; holding or not holding a policy does not change or determine where you sit. If you need to understand your IR35 position, that's a question for a qualified accountant or tax adviser, not your insurance. Our IT contractor insurance page is written specifically for how contractors buy.
One more thing for the moment you take on staff: once you employ people, Employers' Liability insurance becomes a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969, with only narrow exceptions. That sits alongside tech PI and cyber rather than replacing either — worth folding into the conversation as you grow.
How do I decide the right limits for each?
We won't quote prices here, because a sensible figure depends entirely on your situation — and anyone giving you a number without asking questions isn't being straight with you. The factors that actually move the decision are things like: the limits your contracts contractually demand, the size and sensitivity of the client data you touch, your annual turnover, the type of work (safety-critical or financial systems carry more exposure than a brochure website), and how deeply you're plugged into clients' own environments.
The practical approach is to start from your contracts — the minimum limits clients insist on give you a floor — and then sense-check that floor against the realistic worst case if a project went badly wrong or your systems were breached. That's a conversation, not a form. It's exactly the kind of thing a specialist broker is for: we translate your work into the exposures that matter and match the cover to them.
Tell us what you build, who your clients are, and what your contracts demand — and Apex will structure tech PI and cyber so they work together, with no gap in the middle.
Get a tailored quote →If you'd rather talk it through than fill anything in, speak to an Apex technology specialist — we deal with software firms, MSPs, consultancies and contractors every week, and we'll tell you plainly which risks your current cover does and doesn't reach.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
