FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

VoIP provider insurance

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: UK VoIP and hosted-telephony providers typically need technology professional indemnity (also called tech E&O) for claims arising from outages and service failures, cyber insurance for toll fraud, subscriber-data breaches and attack response, plus public liability and — once you employ staff — employers' liability, which is a legal requirement. Because your platform carries clients' phone lines, including calls to emergency services, insurers treat VoIP as a distinct, higher-scrutiny technology risk.

Why is insuring a VoIP business different from insuring a typical IT firm?

Most technology businesses sell something their clients could, at a pinch, live without for an afternoon. You don't. When a hosted-telephony platform goes down, every client on it loses inbound and outbound calling at the same moment — sales lines go quiet, support desks vanish, and for some clients (care providers, taxi firms, medical practices, alarm-receiving centres) the phone is the business. That concentration of dependency is what makes VoIP a different underwriting conversation from, say, a web agency or a software house.

Three exposures dominate. First, availability: an outage or degraded call quality translates directly into measurable financial loss for your clients, and measurable losses become claims. Second, fraud: VoIP infrastructure is a standing target for toll fraud, where attackers compromise accounts or PBX endpoints and pump premium-rate or international traffic through them — often at your clients' expense, sometimes at yours. Third, regulation: providing voice services in the UK brings you inside Ofcom's regulatory framework, with duties that most IT firms never have to think about, including obligations around access to emergency services. A generic "IT business" policy bought online rarely reflects any of this properly. This page walks through what a well-built VoIP insurance programme looks like and why each part matters.

What happens if an outage takes down my clients' phone systems?

This is the claim scenario every VoIP provider should plan around, because it is the one your clients will plan around too. Suppose a failed platform update, a misconfigured SBC, a DDoS attack or an upstream carrier fault knocks out service for a morning. A client who missed a day of inbound sales calls, or breached their own service commitments to their customers, may come to you for their losses — and unlike many software failures, telephony downtime produces losses that are easy to evidence: call logs, abandoned-call reports, lost bookings.

The cover that responds here is technology professional indemnity — tech PI. It covers claims alleging that your professional service failed: negligent configuration, defective implementation, failure of the service to perform as contracted, breach of a service-level commitment. It pays your defence costs and any damages or settlements, which matters even when you've done nothing wrong, because defending an outage claim from an aggrieved client still costs real money.

Two points deserve care when the policy is placed. Your terms of business and SLAs should line up with your cover — if your contracts promise service credits or accept liability for consequential loss, your insurer needs to have seen and accepted that wording, because unagreed contractual liability is a classic gap. And the policy should be written for a business that operates a service continuously, not one that delivers discrete projects; the trigger and territorial wording differ, and it's exactly the kind of detail a specialist broker checks and a comparison site doesn't.

Is technology professional indemnity the same as tech E&O?

Yes — and it's worth being clear because VoIP providers often work with US carriers, resellers and channel partners whose contracts demand "errors & omissions insurance". Technology professional indemnity (the UK term) and technology errors & omissions (the US term) are the same product: cover for financial loss caused to a third party by the failure of your professional services or technology. If a partner agreement requires E&O, a properly worded tech PI policy satisfies it; you do not need to buy two products.

One more thing to state plainly, because it's often misunderstood: professional indemnity is not a legal requirement for a VoIP or IT business. It is almost always a contractual requirement — imposed by enterprise clients, public-sector frameworks, carrier interconnect agreements and channel programmes, usually with a minimum limit written into the contract. In practice that distinction changes little: if you want the contracts, you need the cover. But it means the right limit is driven by what your contracts demand and what your worst realistic outage claim looks like, not by any statutory floor.

How does toll fraud become my problem as the provider?

Toll fraud — also called call fraud or dial-through fraud — is one of the oldest and most persistent forms of telecoms crime, and VoIP made it dramatically easier to industrialise. An attacker compromises a SIP trunk credential, an exposed PBX, a softphone account or a poorly secured API, then routes high volumes of calls to premium-rate or expensive international destinations, harvesting a share of the termination revenue. It frequently runs overnight or over a weekend, precisely when nobody is watching the traffic graphs, and the charges rack up fast.

The awkward question is who bears the loss. If a client's own credentials were phished, they may still argue that you should have detected the anomalous traffic, enforced rate limits or flagged the destination pattern — that's a professional-negligence allegation, and it lands on your tech PI. If the compromise happened inside your platform — your provisioning system, your session border controllers, your customer portal — you may face both the fraudulent carrier charges themselves and claims from every affected client, which pulls in your cyber policy and, for the direct financial theft element, crime or cybercrime cover.

This is the area where off-the-shelf policies most often disappoint. Standard cyber wordings vary enormously in how they treat telephony fraud: some cover it under a specific "telephone hacking" or cybercrime extension, some exclude fraudulent use of telecoms services outright, and some are simply silent — which you don't want to discover during a six-figure fraud weekend. When Apex places cover for a VoIP business, confirming exactly how toll fraud is treated, at what sub-limit, and with what security conditions attached, is one of the first things we do.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Not sure whether your current policy would actually respond to a toll-fraud incident or an outage claim? Tell us what you run and we'll build cover around it.

Get a tailored quote →

What does cyber insurance actually cover for a VoIP provider?

Beyond fraud, a VoIP provider is a data business. Your platform holds subscriber records, call detail records, call recordings, voicemail, and often payment details — personal data under the UK GDPR and the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO). Call recordings in particular can be sensitive: a breach that exposes recorded conversations from a client's medical practice or law firm is a very different incident from a leaked mailing list.

A good cyber policy does four jobs for a business like yours:

One honest caveat that some sellers of cyber insurance skip: whether regulatory fines under UK data-protection law can be insured at all is legally uncertain, and policies commonly exclude or restrict them. Treat cyber as funding your breach response, your lost revenue and your liability to others — not as a mechanism that pays regulatory penalties. If you want the fuller picture of how these policies are built, our guide to cyber insurance explained goes deeper, and because outage claims and cyber incidents so often overlap for VoIP firms, many providers buy combined tech PI and cyber cover so a single insurer handles an incident from both angles without arguing over which policy responds first.

What regulatory obligations do UK VoIP providers have — and how does insurance fit?

Providing voice services in the UK is a regulated activity in a way that most software businesses never encounter. Communications providers operate within Ofcom's regulatory framework, which imposes general conditions on how services are provided — including duties around network resilience and continuity of service, and obligations concerning access to emergency services. The precise duties that apply depend on the nature of the service you provide, and this page deliberately stays general: understanding exactly which obligations attach to your service is a matter for your own regulatory and legal advice, not an insurance article.

What insurance can and can't do here is worth spelling out. Insurance does not discharge a regulatory duty and it does not make a non-compliant service compliant — nothing does that except compliance. What a well-arranged programme does is respond to the consequences that flow from incidents: the client claims that follow an outage, the costs of investigating and responding to a security incident, the legal costs of dealing with the fallout. Some tech PI and cyber policies also include cover for legal representation costs in regulatory investigations; the scope of that cover varies significantly between insurers and is another item worth checking rather than assuming.

There's a practical underwriting point too. Insurers looking at a VoIP risk will want to understand your resilience posture — redundancy across carriers and data centres, failover behaviour, how emergency-call routing is handled, incident-response process. A provider who can describe this crisply presents as a better risk and it shows in the terms offered. Part of our job as your broker is presenting your business to underwriters properly, so the maturity you've actually built gets priced in.

Do I still need public liability and employers' liability?

Yes, though for different reasons. Public liability covers injury to third parties or damage to their property arising from your operations — and unlike a pure SaaS business, VoIP providers are often physically present at client sites: installing handsets, mounting equipment in comms rooms, running cabling, working in racks. An engineer who damages a client's server during an installation, or leaves a trailing cable someone trips over, creates exactly the kind of claim PL exists for. Clients and site operators will usually require evidence of it before letting your engineers through the door.

Employers' liability is different in kind: once you employ staff, it is a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969, with only narrow exceptions, and it covers your liability if an employee is injured or made ill through their work. Field engineers working at height, lifting equipment or driving between sites make this more than a formality for a telephony business. If you're mapping your wider obligations, our overview of what insurance an IT company needs sets these building blocks out in full.

What limits and policy features should a VoIP provider look for?

There's no universal right answer, but there is a right method. For tech PI, start from your contracts: enterprise clients and framework agreements typically specify a minimum limit, commonly at illustrative levels like £1m, £5m or £10m. Then sanity-check against your realistic worst case — which for a VoIP provider is not one unhappy client but an outage affecting your whole subscriber base at once. A limit that looks comfortable against your largest single contract can look thin against a platform-wide event, and that aggregation is the distinctive feature of your risk.

Beyond the headline number, the features that matter most for this sector: how the policy defines your professional services (it must clearly capture operating and hosting a communications service, not just "IT consultancy"); whether contractual liabilities such as SLA commitments are covered; how cyber and crime sections treat telephony fraud and at what sub-limit; whether DDoS-driven downtime is covered as business interruption; and how the policy responds when the root cause sits with an upstream carrier or infrastructure supplier you depend on. Retroactive cover matters as well — PI policies work on a claims-made basis, so continuity of cover back to when you started trading protects you against claims arriving years after the work.

None of that requires you to become an insurance expert — it requires your broker to be one. If you'd rather talk it through than fill in forms, speak to an Apex technology specialist and we'll go through your contracts and platform with you.

How does Apex arrange cover for VoIP and hosted-telephony businesses?

Apex is a Bristol-based, FCA-authorised broker that specialises in technology businesses, and telephony providers are a risk we genuinely understand — SIP trunking, hosted PBX, UCaaS platforms, wholesale voice, and the MSPs who bundle telephony alongside IT support. We start with what you actually run and what your contracts actually promise, then place cover with insurers whose wordings fit a business that operates critical, always-on infrastructure — checking the details this page has flagged: outage and SLA exposure, toll-fraud treatment, subscriber-data cover, and the liability lines that get your engineers on site.

Just as importantly, we're there when something goes wrong. An outage weekend or a fraud incident is not the moment to be navigating an insurer's claims line alone; as your broker we manage the claim, argue the wording and keep the process moving while you keep your platform running. You can start a quote online in a few minutes, or ask us to review your existing policies against the exposures above — it's common for us to find that a "tech package" bought elsewhere is silent on the risks that matter most to a voice provider.

Your clients trust you with their phone lines. Get insurance built for that responsibility — tech PI, cyber with proper fraud cover, PL and EL, arranged by a broker who knows telephony.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →