Public liability insurance for IT businesses
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06
What is public liability insurance, and what does it actually cover?
Public liability insurance (often shortened to PL) deals with the physical world rather than the digital one. It responds when someone outside your business — a client, a member of the public, a visitor, a contractor — suffers bodily injury, or has their property damaged, and they hold your business responsible. The policy typically pays the compensation you become legally liable for, plus the legal costs of defending or settling the claim.
For an IT firm, that sounds abstract until you picture the moments where your people and the physical world collide. An engineer runs a cable across a walkway at a client's office and someone trips. A laptop bag is set down on a client's desk and knocks a monitor to the floor. A consultant spills coffee over a customer's server rack during an on-site migration. A visitor to your own office slips on a wet floor by reception. None of these are about the quality of your code — they're about accidental harm to people or their things, and that is precisely the territory PL is built for.
It is worth separating this cleanly from your other covers. Public liability is not about a bug, a missed deadline, or a system that underperformed — that is the domain of technology professional indemnity (sometimes called technology errors & omissions, or tech E&O — the American term for broadly the same thing). PL is also not about a data breach or ransomware event; that is where cyber insurance comes in. PL sits alongside those covers and handles the tangible, accidental damage-and-injury risks that every business carries the moment it interacts with the outside world.
Do IT firms really need public liability if they just write code?
This is the objection we hear most often, and it's a fair one. If your developers work from home, deploy to the cloud, and never physically touch a client's kit, your day-to-day PL exposure genuinely is low. Public liability is not a statutory legal requirement, so there's no law compelling you to buy it. So why does a "we just write code" firm so often end up needing it anyway?
The answer is usually contracts and contact. As soon as your business grows past pure remote development, physical touchpoints creep in whether you planned for them or not. You attend a client's office for a kick-off workshop. You send someone on-site to troubleshoot an integration that won't behave over a screen-share. You take a stand at a technology expo to win new business. You host a client for a demo at your own premises. A prospective customer visits to sign off a project. Each of these is a moment where an accident could injure someone or damage property that isn't yours — and where you could be asked to pay.
The other driver is contractual. Many clients — particularly larger corporates, public-sector bodies, universities and NHS trusts — will not let you set foot on their premises, or sometimes won't sign a contract at all, without evidence of public liability cover at a stated limit. Their procurement teams treat it as a basic hygiene requirement. So even if your own risk assessment says the exposure is modest, the commercial reality is that PL becomes the price of entry to work you want to win. We regularly see IT firms come to us not because they felt exposed, but because a tender or master services agreement demanded a PL certificate before the ink could dry.
Not sure whether your contracts or site visits mean you need public liability? Tell us how your IT business actually operates and we'll map the cover to it.
Get a tailored quote →Already have a current schedule? Email it to info@apexinsurancebrokers.co.uk and a named broker will come back to you.
When would an IT business actually make a public liability claim?
It helps to move from theory to the situations that genuinely generate claims in technology firms. The common thread is always the same: accidental injury to a person, or accidental damage to property you don't own.
- On-site installation and support. Field engineers running cabling, mounting hardware, or moving equipment in a client's building are where most IT PL claims originate — trips over trailing leads, dropped kit, damage to a customer's fixtures or fittings.
- Damage to a client's property. Knocking over expensive equipment, marking a newly refurbished office, or accidentally damaging a customer's server or workstation while working on it.
- Visitors to your premises. Clients, couriers and candidates coming into your office are third parties; if one is injured on your floor, that's a PL matter.
- Events and trade shows. Exhibiting at a tech expo puts you in a public space with the public — a collapsing stand, a trailing cable, or a member of the public hurt at your stand can all lead to a claim, and organisers frequently insist on PL cover as a condition of exhibiting.
What these have in common is that the sums involved can be far larger than the incident feels at the time. A trip that results in a serious injury, or damage to specialist equipment, can produce a claim — and defence costs — that dwarfs a small firm's cash reserves. That is the gap PL is designed to close.
How much public liability cover does an IT company need?
There's no single correct figure — the right limit is driven by the kind of clients you work with and what your contracts demand. Common limits offered are £1m, £2m, £5m and £10m, and these are best thought of as illustrative options rather than a menu you pick from blind. Smaller firms working with other SMEs may find a lower limit perfectly adequate; the moment you're bidding for public-sector, financial-services or large-corporate work, you'll often see a £5m or £10m requirement written into the contract.
The practical approach is to work backwards from your contracts. Pull the insurance clauses from your key client agreements and framework tenders, note the highest limit any of them requires, and make sure your cover meets or exceeds it. It's far cheaper to hold an adequate limit from the outset than to scramble to increase it — or worse, discover mid-tender that your existing cover disqualifies you. If your contracts are a patchwork of different requirements, that's exactly the sort of thing worth talking through with a broker who can set a single limit that satisfies all of them.
How does public liability fit with the other cover an IT firm needs?
Public liability is one piece of a technology firm's insurance picture, and it works best when you understand where it stops and the neighbouring covers begin. Knowing the boundaries is what stops you from either double-buying or, more dangerously, assuming a risk is covered when it isn't.
Technology professional indemnity handles claims arising from your professional work — a defect, error, or failure to deliver that causes a client financial loss. It's rarely a legal requirement, but it's almost always a contractual one: clients and agencies insist on it before they'll engage you. This is a different animal to PL and the two are not interchangeable.
Cyber insurance steps in for data breaches, ransomware and network security failures — funding your breach response, business interruption, and third-party liability arising from an incident. One important caveat: whether UK regulatory or data-protection fines can lawfully be insured is legally uncertain and such fines are often excluded or restricted, so treat cyber as covering breach response and liability rather than as something that pays your fines. For a fuller comparison, our guides on professional indemnity versus cyber and what insurance an IT company needs lay the pieces out side by side.
Employers' liability is different again, and this one is genuinely compulsory: under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are required by law to hold it, with only narrow exceptions. If your IT firm has employees, that isn't optional. PL protects third parties; employers' liability protects your own people.
Many technology firms find the tidiest answer is a combined arrangement that brings public liability together with tech PI and cyber under one roof, which is why combined technology insurance is a popular route. It reduces the risk of a gap opening up between separate policies and gives you a single renewal to manage.
What about IT contractors and one-person firms?
Independent contractors and single-director companies are just as exposed to the physical-world risks above — arguably more so, because so much contractor work happens on the client's site. If you're a contractor working through your own limited company, an end client or agency will very often make public liability part of the contract, sitting alongside professional indemnity and, increasingly, cyber. Our IT contractor insurance guide goes into the specifics of contracting arrangements.
One point that causes genuine confusion, so it's worth being blunt about it: your insurance has nothing to do with your IR35 status. IR35 is a tax matter — the off-payroll working rules that determine your employment status for tax purposes — and holding public liability, professional indemnity or any other cover does not change, improve or determine how you sit under those rules. Contracts sometimes list insurance among factors pointing to being genuinely in business on your own account, but insurance is not a fix for status. For an actual assessment of your IR35 position, speak to a qualified accountant or tax adviser, not your broker.
How do I get the right public liability cover in place?
The honest answer for most IT firms is that public liability rarely lives in isolation — it makes sense as part of a package built around how your business actually operates: where your people go, who visits you, what your contracts demand, and what you're doing with client data and systems. The value of talking to a broker is that we can look at the whole picture, read the insurance clauses buried in your client contracts, and make sure the limits and the mix of covers line up with the work you're winning — rather than leaving you to guess and hope at renewal.
At Apex we work with technology and IT businesses day in, day out, from solo contractors to growing software and managed-service firms, so we understand the specific ways these risks show up in your world. If you'd rather talk it through than fill in a form, start a quote and ask to speak to an Apex technology specialist — we'll help you get the cover right first time.
Ready to put the right public liability cover in place for your IT business — on its own or as part of a combined technology package? Apex will tailor it to your contracts and how you work.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
