What insurance does an IT company need?
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you run an IT business, "what insurance do I actually need?" is a fair and surprisingly hard question. The market is full of overlapping product names, US terminology creeping into UK quotes, and clients who bury cover requirements deep in a master services agreement. This page walks you through the core stack, explains what each part is really for, and shows how the emphasis shifts depending on whether you're a solo contractor, a managed service provider, or a software house.
We'll be precise about what's a legal duty, what's a contractual demand from your clients, and what's simply sensible. Getting that distinction right is half the battle.
What are the core insurances an IT company needs?
For a typical UK technology firm, five covers do most of the work. Not every business needs all five, but this is the shortlist worth understanding before you buy anything:
- Technology professional indemnity (tech PI) — responds when a client alleges your work caused them a financial loss: a bug, a missed spec, late delivery, negligent advice, or a service that didn't do what you promised. If you see "technology errors & omissions" or "tech E&O" on a US-influenced contract, that's broadly the same cover — E&O is simply the American term for professional indemnity, not a separate product.
- Cyber insurance — funds your response when you suffer a breach, ransomware attack, or serious IT outage: incident response specialists, forensics, notifying affected people, business interruption, and third-party claims from customers whose data was exposed.
- Public liability — covers injury to a third party or damage to their property connected with your business, for example on a client site or if a visitor is hurt at your office.
- Employers' liability — a legal requirement once you employ staff (more on that below).
- Media & intellectual property liability — relevant where your work involves content, branding, or you could be accused of infringing someone else's IP.
Many tech firms buy tech PI and cyber together in a combined policy, because the line between "we made a mistake in the software" and "that mistake led to a data breach" can be blurry. You can read more in our guide to combined technology insurance (tech PI and cyber).
Is professional indemnity a legal requirement for IT firms?
No — this trips up a lot of people. Unlike solicitors or accountants, IT firms have no statutory obligation to carry professional indemnity. In practice, though, it's almost unavoidable, because your clients require it. Look at any decent B2B contract, framework agreement, or agency onboarding pack and you'll usually find a clause stating you must hold tech PI to a specified limit — often £1m, £2m, or £5m — for the life of the engagement and sometimes for years afterward.
So the honest framing is this: tech PI isn't a legal requirement, it's a contractual one. That distinction matters because it changes how you choose your limit. You're not guessing at what feels safe; you're often meeting a number written into a client agreement. If you sign a contract promising £5m of cover and hold £1m, you're in breach regardless of whether anything ever goes wrong. Our page on technology professional indemnity insurance goes deeper on how these limits and requirements work.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Not sure which limits your client contracts actually demand? An Apex specialist can read the clauses with you and build cover that matches.
Get a tailored quote →Do I legally need employers' liability insurance?
Yes — this is the one genuinely compulsory cover for most IT firms with people. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you must hold employers' liability insurance. It exists so that if an employee is injured or becomes ill because of their work, there's money available to meet a claim. There are narrow exceptions — for instance, some businesses employing only close family members, or a genuine single-director company with no other staff — but the safe assumption is that if you have employees, you need it.
A common grey area is contractors and freelancers. If you bring in people who work under your direction and control, they may count as employees for these purposes even if you think of them as contractors. It's worth checking rather than assuming, because the duty is triggered by the working relationship, not the label on the invoice.
What does cyber insurance actually cover for a tech business?
Cyber cover is widely misunderstood, so it's worth being exact. Its real value is in response and recovery. When you're breached, a good cyber policy funds the specialists who get you back on your feet: incident response coordinators, IT forensics to work out what happened, legal support, and the cost of notifying affected individuals. It typically covers business interruption when systems are down, and third-party liability if customers or partners bring claims because their data was compromised.
One thing cyber insurance should not be sold to you as: a way to pay regulatory fines. The insurability of UK GDPR and data-protection fines is legally uncertain, and such fines are frequently excluded or restricted by policy wording. The relevant law here is the UK GDPR and the Data Protection Act 2018, and the regulator is the Information Commissioner's Office (ICO). Treat cyber cover as funding your breach response, interruption, and third-party liabilities — not as a guarantee that a regulator's penalty will be picked up. If a broker tells you cyber "pays your fines," be sceptical.
For a tech firm, cyber and tech PI sit close together, and understanding where one ends and the other begins is genuinely useful. Our explainer on professional indemnity vs cyber insurance for tech companies maps that out, and cyber insurance explained covers the mechanics.
How does the right mix change for a contractor, an MSP, or a software house?
"IT company" covers wildly different risk profiles, and your ideal stack shifts with what you do and who you sell to.
The independent IT contractor. If you're a one-person limited company placed through agencies, your world revolves around the client and agency contract. Tech PI is nearly always mandated, usually at £1m or £2m, and often you'll be asked for public liability and — surprisingly to many — employers' liability, because some agency terms require it as a blanket condition even for solo directors. As a single-director company with no staff you may fall within an EL exception, but if the contract insists on it, you provide it. Our IT contractor insurance page is written specifically for this situation.
A quick, important word on IR35: that's a tax matter. The off-payroll working rules are about your employment status for tax, and holding any insurance does not change, improve, or determine your IR35 position. Don't let anyone imply otherwise. For your actual IR35 status, speak to a qualified accountant or tax adviser — not your insurance broker.
The managed service provider (MSP). If you hold the keys to other businesses' systems, your exposure is amplified: a mistake or an outage you're responsible for can cascade across every client you support. Tech PI and cyber both matter heavily here, and limits tend to be higher because a single incident can affect many customers at once. MSPs also carry real supply-chain risk — you may be the route through which a client is compromised — so how your policy treats network security and third-party claims deserves close attention.
The software house or SaaS business. If you build and sell your own product, tech PI responds to defects, failures, and disappointed client expectations. But you also carry heightened intellectual property and media exposure — code, content, branding, and open-source components can all give rise to infringement allegations — so media/IP cover moves up the list. If you handle significant volumes of user data, cyber becomes central rather than optional.
Across all three, the same principle holds: let your contracts and your actual activities drive the specification, not a generic package. Two firms with the same headcount can need very different cover.
Why do my clients keep dictating my insurance?
Because your risk is their risk. When a large organisation engages a small tech supplier, they're accepting that your mistakes could hit their operations, their data, and their reputation. Requiring you to carry specified insurance limits is how they make sure there's substance behind any claim they might need to bring. That's why the numbers in your policy schedule often come straight from someone else's procurement template.
The practical upshot: before you renew or buy, gather your live and prospective contracts and check what they actually require — the cover type, the limit, whether it must be maintained after the contract ends, and any specific wording. It's far cheaper to build the right policy once than to discover a shortfall halfway through a deal. This is exactly the kind of review where talking to a broker who knows the tech sector pays off, rather than working through a self-serve form alone.
How do I put the right package together?
Start with the compulsory piece — employers' liability if you have staff — then layer on what your contracts demand (usually tech PI, often public liability), then add cover for the risks specific to your work (cyber for data-heavy firms, media/IP for product and content businesses). Keep your limits aligned to your largest contractual requirement, and revisit the whole picture whenever you win a bigger client or change what you deliver.
If you'd rather not untangle it alone, that's what we're here for. Apex works with IT contractors, MSPs, and software businesses across the UK, and we'll match your cover to the contracts in front of you. Explore our broader IT and technology business insurance guidance, or start a tailored quote whenever you're ready.
Whether you're a solo contractor or scaling an MSP, we'll help you get the tech insurance stack right the first time — no jargon, no over-selling.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
