IT and telecoms
Yes. If you rent dedicated servers, run managed servers or host customer hardware in your racks, you need professional indemnity insurance. Your customers run their businesses on your infrastructure, so an outage, a failed backup or a configuration mistake becomes their lost revenue, and they will look to you for it. PI, usually written as technology errors and omissions cover, responds to those claims. Cyber insurance covers an attack on your own platform, and a hosting business usually needs both.
Part of: Professional indemnity for IT professionals
In short
Server hosting providers sell availability and competence: hardware that stays up, backups that restore and configurations that keep customer data safe. Claims follow outages that breach an uptime commitment, backups that fail when needed and misconfigurations that expose data. How much falls on you depends on what you sold: on an unmanaged server the customer usually runs the operating system, while on a managed server you do. PI covers negligent service, subject to the policy terms, but service credits and uptime guarantees are usually excluded. If you sell scalable cloud servers and are not a small or micro business, the NIS Regulations 2018 may already apply to you.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
Your customers are software companies, agencies, online retailers and businesses running their core applications on servers you provide. They choose you because they do not want to run hardware themselves, and on managed plans because they want your engineers to keep the servers patched, secured and backed up.
When that fails, the loss is rarely physical. It is a SaaS platform offline for a day, an online shop that cannot take orders, a database that has to be rebuilt, or a customer facing its own clients’ claims. Public liability (PL) insurance covers injury and damage to tangible property, such as a visitor hurt in your data hall. Lost data and lost trading are financial losses, and claims for them belong with professional indemnity (PI).
PI pays compensation and defence costs when a customer alleges your service was negligent, subject to the policy terms. Make sure the policy names hosting and managed infrastructure in its description of your business, and check for any exclusion of losses arising from power, utility or infrastructure failure.
The scenarios below are illustrative. They show how claims against hosting providers can arise, not real cases or outcomes.
The common thread is an allegation that you, as a hosting professional, did not deliver the care and skill your service promised.
Many hosting disputes start with a disagreement about who was responsible for what. The split below is a common pattern, but only your contract and service description decide it, so write it down plainly.
| Task | Unmanaged dedicated server | Managed server | Customer hardware in your racks |
|---|---|---|---|
| Hardware, power and network | You | You | Customer hardware; you provide power and network |
| Operating system patching | Customer | You, within agreed windows | Customer |
| Firewall and access configuration | Customer, unless you sell a firewall service | Usually you | Customer |
| Backups | Customer, unless bought from you | You, if included | Customer |
| Applications and data | Customer | Customer, unless agreed otherwise | Customer |
Even the NCSC treats this as shared ground. Its Cyber Essentials requirements list firewalls, secure configuration, security updates and malware protection on infrastructure as a service as the joint responsibility of the customer and the cloud provider, with user access control resting with the customer. The word “managed” on its own defines nothing, so attach a schedule of what you do and do not do to every plan.
Availability figures look similar and mean very different things. Over a 30-day month, 99.9% allows about 43 minutes of downtime and 99.99% about four minutes. Before you promise four nines, check that your upstream power, connectivity and data centre contracts support it, and that their liability caps are not lower than yours.
An uptime commitment is a contractual promise. If you miss it, the service credits you agreed are a price adjustment and PI usually won’t pay them. PI is designed for the larger claim that follows if a customer says the outage was caused by negligence, such as an untested change or a single point of failure you should have designed out.
Backups are the other battleground. UK GDPR Article 32 requires controllers and processors to have, where appropriate, “the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident”. If you sell backup as part of a plan, insurers and customers will expect:
| Rule or standard | What it says | Why it matters to your PI |
|---|---|---|
| UK GDPR, Article 28 | A processor acts only on the controller’s documented instructions, takes the security measures Article 32 requires, and deletes or returns personal data at the end of the service. | Hosting customer data usually makes you a processor. Your terms should contain these clauses. |
| UK GDPR, Article 82(2) | A processor is liable for damage caused by processing only where it breached obligations aimed at processors or acted outside or contrary to the controller’s lawful instructions. | Narrows your exposure to data subjects, but Article 32’s security duty is expressly placed on processors as well as controllers. |
| Network and Information Systems Regulations 2018 | Apply to cloud computing services, defined as digital services enabling access to “a scalable and elastic pool of shareable computing resources”. Providers in scope must register with the ICO and report incidents with a substantial impact within 72 hours where feasible. Small and micro businesses are exempt. | If you sell virtual or cloud servers from a shared pool, you may be a relevant digital service provider with security and reporting duties. |
| ISO/IEC 27017:2026 | Information security controls for cloud services, including how responsibilities are divided between cloud service customers and providers. | A recognised benchmark for the controls a competent provider would operate. |
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Negligent configuration, patching and changes on managed servers | Service credits and uptime guarantees | Your own response and recovery costs after an attack (cyber) |
| Backup services that were badly designed or never worked | Failure of power, utilities or upstream connectivity, on some wordings | Your own lost income while the platform is down (cyber or business interruption) |
| Data loss caused by your engineers, such as wiping the wrong server | Indemnities and liabilities beyond reasonable skill and care | Breakdown of your own servers and storage (equipment or engineering cover) |
| Compensation claims arising from your breach of processor obligations, where included | Fines and penalties, where the law does not allow them to be insured | Damage to customer-owned hardware in your racks (public liability or goods in custody) |
| Defence costs, including forensic and storage experts | Circumstances you knew about before the policy began | Injury to your own staff (employers’ liability) |
Cover is always subject to the insurer’s acceptance and the policy terms.
For a hosting provider, the same outage can fall under either policy depending on why it happened.
Because one hypervisor or storage failure can hit hundreds of customers at once, check how both policies treat a series of claims with one cause, and whether your limit is aggregate. Buying technology PI and cyber together from one insurer can reduce the risk of one incident being argued over between two.
Your PI limit should match the liability cap in your own terms and the demands of your largest customers, who may ask for a specific limit before signing. Remember that a platform-wide incident produces many claims at once.
PI is claims-made: the policy in force when the claim is made responds. Data loss can go unnoticed for weeks or months, until a customer tries to restore. Keep cover continuous, keep your retroactive date when you change insurer, and if you sell the business or close it, arrange run-off cover.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for server hosting providers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes. Customers run their businesses on your servers, so outages, failed backups and configuration errors cause them financial loss, and they will claim it from you. PI covers allegations that your service was negligent, plus defence costs, subject to the policy terms. Cyber insurance usually covers attacks on your own platform.
No law requires hosting providers to hold PI. If you provide a cloud computing service and are not a small or micro business, the NIS Regulations 2018 impose security, registration and incident reporting duties, but not insurance. In practice larger customers ask for PI and cyber cover in their contracts.
Not for the service credits. Those are a price reduction you agreed in advance, and most PI wordings exclude them along with other guarantees. PI is for a customer’s claim that the outage was caused by your negligence and cost it money beyond the credits, subject to the terms.
Usually the customer is responsible for its own operating system, backups and data on an unmanaged server, but only if your contract says so clearly. Claims still arrive, and PI pays to defend them, subject to the terms. A clear schedule of responsibilities makes those claims much easier to answer.
Your liability to customers may be covered, subject to the terms, but some wordings exclude losses from power, utility or infrastructure failure. Check your policy, and check whether your contract with the data centre gives you any meaningful recovery when it fails.
Usually, for the personal data your customers store on your servers. Article 28 requires a contract with processor terms, and Article 82 makes a processor liable where it breaches obligations aimed at processors or acts outside the customer’s instructions. Your PI and cyber cover should reflect that role.
Apex arranges professional indemnity insurance for server hosting providers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.