FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

IT and telecoms

Professional indemnity insurance for server hosting providers

Yes. If you rent dedicated servers, run managed servers or host customer hardware in your racks, you need professional indemnity insurance. Your customers run their businesses on your infrastructure, so an outage, a failed backup or a configuration mistake becomes their lost revenue, and they will look to you for it. PI, usually written as technology errors and omissions cover, responds to those claims. Cyber insurance covers an attack on your own platform, and a hosting business usually needs both.

In short

Server hosting providers sell availability and competence: hardware that stays up, backups that restore and configurations that keep customer data safe. Claims follow outages that breach an uptime commitment, backups that fail when needed and misconfigurations that expose data. How much falls on you depends on what you sold: on an unmanaged server the customer usually runs the operating system, while on a managed server you do. PI covers negligent service, subject to the policy terms, but service credits and uptime guarantees are usually excluded. If you sell scalable cloud servers and are not a small or micro business, the NIS Regulations 2018 may already apply to you.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why server hosting is a professional risk

Last reviewed 5 October 2026 by the Apex professional indemnity team.

Your customers are software companies, agencies, online retailers and businesses running their core applications on servers you provide. They choose you because they do not want to run hardware themselves, and on managed plans because they want your engineers to keep the servers patched, secured and backed up.

When that fails, the loss is rarely physical. It is a SaaS platform offline for a day, an online shop that cannot take orders, a database that has to be rebuilt, or a customer facing its own clients’ claims. Public liability (PL) insurance covers injury and damage to tangible property, such as a visitor hurt in your data hall. Lost data and lost trading are financial losses, and claims for them belong with professional indemnity (PI).

PI pays compensation and defence costs when a customer alleges your service was negligent, subject to the policy terms. Make sure the policy names hosting and managed infrastructure in its description of your business, and check for any exclusion of losses arising from power, utility or infrastructure failure.

How claims arise for server hosting providers

The scenarios below are illustrative. They show how claims against hosting providers can arise, not real cases or outcomes.

  1. Backups on the same array. A managed server’s nightly backups are written to the same storage array as the live data. The array fails and both are lost. The customer’s platform is down for days while data is reconstructed, and it claims lost subscriptions and the rebuild cost, alleging the backup design was negligent.
  2. A reboot at the worst moment. An engineer applies kernel updates and reboots a customer’s database server in the middle of its busiest trading period, outside the agreed maintenance window. Tables are corrupted and the customer claims a weekend of lost sales.
  3. An open port. The firewall template for a new managed server leaves the database port reachable from the internet. Customer records are scraped. Your customer, as controller, deals with the regulator and its own users, then claims its costs from you.
  4. The wrong server wiped. A decommissioning ticket for a cancelled server carries the wrong asset tag. A live server is wiped, and with it the customer’s only copy of a year’s records.
  5. A promise your supplier didn’t make. A power failure at the third-party data centre where you rent racks takes customers offline. Your contracts promised higher availability than the data centre promised you, and its liability to you is capped at a month’s fees. Your customers claim beyond their service credits, and the gap is yours.

The common thread is an allegation that you, as a hosting professional, did not deliver the care and skill your service promised.

Managed or unmanaged: where your responsibility stops

Many hosting disputes start with a disagreement about who was responsible for what. The split below is a common pattern, but only your contract and service description decide it, so write it down plainly.

TaskUnmanaged dedicated serverManaged serverCustomer hardware in your racks
Hardware, power and networkYouYouCustomer hardware; you provide power and network
Operating system patchingCustomerYou, within agreed windowsCustomer
Firewall and access configurationCustomer, unless you sell a firewall serviceUsually youCustomer
BackupsCustomer, unless bought from youYou, if includedCustomer
Applications and dataCustomerCustomer, unless agreed otherwiseCustomer

Even the NCSC treats this as shared ground. Its Cyber Essentials requirements list firewalls, secure configuration, security updates and malware protection on infrastructure as a service as the joint responsibility of the customer and the cloud provider, with user access control resting with the customer. The word “managed” on its own defines nothing, so attach a schedule of what you do and do not do to every plan.

Uptime promises and backups: where hosting claims are won or lost

Availability figures look similar and mean very different things. Over a 30-day month, 99.9% allows about 43 minutes of downtime and 99.99% about four minutes. Before you promise four nines, check that your upstream power, connectivity and data centre contracts support it, and that their liability caps are not lower than yours.

An uptime commitment is a contractual promise. If you miss it, the service credits you agreed are a price adjustment and PI usually won’t pay them. PI is designed for the larger claim that follows if a customer says the outage was caused by negligence, such as an untested change or a single point of failure you should have designed out.

Backups are the other battleground. UK GDPR Article 32 requires controllers and processors to have, where appropriate, “the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident”. If you sell backup as part of a plan, insurers and customers will expect:

The rules and standards hosting providers work under

Rule or standardWhat it saysWhy it matters to your PI
UK GDPR, Article 28A processor acts only on the controller’s documented instructions, takes the security measures Article 32 requires, and deletes or returns personal data at the end of the service.Hosting customer data usually makes you a processor. Your terms should contain these clauses.
UK GDPR, Article 82(2)A processor is liable for damage caused by processing only where it breached obligations aimed at processors or acted outside or contrary to the controller’s lawful instructions.Narrows your exposure to data subjects, but Article 32’s security duty is expressly placed on processors as well as controllers.
Network and Information Systems Regulations 2018Apply to cloud computing services, defined as digital services enabling access to “a scalable and elastic pool of shareable computing resources”. Providers in scope must register with the ICO and report incidents with a substantial impact within 72 hours where feasible. Small and micro businesses are exempt.If you sell virtual or cloud servers from a shared pool, you may be a relevant digital service provider with security and reporting duties.
ISO/IEC 27017:2026Information security controls for cloud services, including how responsibilities are divided between cloud service customers and providers.A recognised benchmark for the controls a competent provider would operate.

What PI covers for a hosting provider, and what it doesn’t

Usually covered by PIOften excluded or limitedNeeds a different policy
Negligent configuration, patching and changes on managed serversService credits and uptime guaranteesYour own response and recovery costs after an attack (cyber)
Backup services that were badly designed or never workedFailure of power, utilities or upstream connectivity, on some wordingsYour own lost income while the platform is down (cyber or business interruption)
Data loss caused by your engineers, such as wiping the wrong serverIndemnities and liabilities beyond reasonable skill and careBreakdown of your own servers and storage (equipment or engineering cover)
Compensation claims arising from your breach of processor obligations, where includedFines and penalties, where the law does not allow them to be insuredDamage to customer-owned hardware in your racks (public liability or goods in custody)
Defence costs, including forensic and storage expertsCircumstances you knew about before the policy beganInjury to your own staff (employers’ liability)

Cover is always subject to the insurer’s acceptance and the policy terms.

PI and cyber: one outage, two possible causes

For a hosting provider, the same outage can fall under either policy depending on why it happened.

Because one hypervisor or storage failure can hit hundreds of customers at once, check how both policies treat a series of claims with one cause, and whether your limit is aggregate. Buying technology PI and cyber together from one insurer can reduce the risk of one incident being argued over between two.

How much cover, and for how long

Your PI limit should match the liability cap in your own terms and the demands of your largest customers, who may ask for a specific limit before signing. Remember that a platform-wide incident produces many claims at once.

PI is claims-made: the policy in force when the claim is made responds. Data loss can go unnoticed for weeks or months, until a customer tries to restore. Keep cover continuous, keep your retroactive date when you change insurer, and if you sell the business or close it, arrange run-off cover.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for server hosting providers, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do server hosting providers need professional indemnity insurance?

Yes. Customers run their businesses on your servers, so outages, failed backups and configuration errors cause them financial loss, and they will claim it from you. PI covers allegations that your service was negligent, plus defence costs, subject to the policy terms. Cyber insurance usually covers attacks on your own platform.

Is PI a legal requirement for server hosting providers?

No law requires hosting providers to hold PI. If you provide a cloud computing service and are not a small or micro business, the NIS Regulations 2018 impose security, registration and incident reporting duties, but not insurance. In practice larger customers ask for PI and cyber cover in their contracts.

Does PI pay out when we miss our uptime SLA?

Not for the service credits. Those are a price reduction you agreed in advance, and most PI wordings exclude them along with other guarantees. PI is for a customer’s claim that the outage was caused by your negligence and cost it money beyond the credits, subject to the terms.

Are we liable if a customer loses data on an unmanaged server?

Usually the customer is responsible for its own operating system, backups and data on an unmanaged server, but only if your contract says so clearly. Claims still arrive, and PI pays to defend them, subject to the terms. A clear schedule of responsibilities makes those claims much easier to answer.

Does PI cover outages caused by our data centre provider?

Your liability to customers may be covered, subject to the terms, but some wordings exclude losses from power, utility or infrastructure failure. Check your policy, and check whether your contract with the data centre gives you any meaningful recovery when it fails.

Are we a data processor under UK GDPR?

Usually, for the personal data your customers store on your servers. Article 28 requires a contract with processor terms, and Article 82 makes a processor liable where it breaches obligations aimed at processors or acts outside the customer’s instructions. Your PI and cyber cover should reflect that role.

Ready to compare cover?

Apex arranges professional indemnity insurance for server hosting providers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.