FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Why IT companies need their own cyber insurance

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06

In short: IT firms hold their clients' data, credentials and system access, which makes them a high-value target and a single point of failure. If you are breached, the damage can spread to every client you serve, generating large third-party claims. Technical skill reduces the odds of an incident but does not fund the response, so IT companies need their own cyber cover.

There is a comfortable assumption inside a lot of technology businesses: we are the people who lock everything down for everyone else, so we are the last firm that would ever get caught out. It is an understandable instinct, and it is exactly the wrong one. The firms with the deepest technical knowledge are also the firms holding the richest concentration of other people's data, credentials and remote access, and that combination is what attackers actually shop for. This page walks through why that is, what a breach of an IT provider tends to cost, and why your expertise and your insurance do two completely different jobs.

Why are IT and security firms a prime target rather than a safe one?

Attackers are rational. They go where the return on effort is highest, and an IT services company, a managed service provider (MSP) or a security consultancy sits at a structurally attractive point in the chain. Compromise one accountancy practice and you have one victim. Compromise the MSP that runs IT for forty accountancy practices and you have a route into all forty, often through legitimate management tools that no one flags as suspicious. You are, in effect, a master key.

Think about what a typical IT firm holds that a normal small business does not. Administrator credentials for client environments. Remote monitoring and management (RMM) agents deployed across hundreds of endpoints. VPN and privileged access into networks you do not own. Backups, configuration data, sometimes client personal data you process on their behalf. Each of those is an asset to you and a liability if it leaks, because it is a door into someone else's business. Being technically excellent lowers the probability that any given door is left open. It does nothing to change the fact that you are holding an unusually large ring of keys.

There is also a targeting reality that is easy to underplay. Sophisticated attackers deliberately hunt for suppliers and providers precisely because they are trusted and connected. The trust that wins you the contract is the same trust that makes a compromise of your firm so valuable to someone else.

What is supply-chain contagion, and why does it fall on the IT provider?

Supply-chain or contagion risk is the scenario where an incident that starts inside your business does not stay inside your business. Because your systems are connected to your clients' systems, a compromise can propagate outward: malware pushed through a management tool, credentials reused to reach a client tenant, a poisoned update, or an attacker moving laterally from your network into theirs. The incident begins with you and lands on everyone you serve.

This is not a hypothetical category. Real-world supply-chain and managed-provider compromises have caused exactly this pattern of downstream damage, and they are a recognised and growing area of concern for regulators and security bodies. We are deliberately not going to quote you a headline breach statistic, because the numbers that circulate are often unreliable and you do not need a scary figure to see the shape of the problem. The point is structural: when your infrastructure is the delivery mechanism for your clients, your failure becomes their failure.

Now consider who carries the liability when that happens. Your clients will look to the contract you signed and to the duty of care you owed them. You may face claims for their business interruption, their breach-response costs, their regulatory exposure, and the reputational and commercial fallout, all flowing from a single incident on your side. A first-party loss (your own downtime and recovery) is painful. A third-party loss multiplied across your entire client base is what turns a bad week into an existential one. That third-party, cascading exposure is the specific reason an IT firm's risk profile is heavier than an ordinary business of the same size.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

If a breach of your systems could reach your clients, it is worth ten minutes with someone who insures technology firms for a living. Apex can map your exposure to the right cover.

Get a tailored quote →

Already have a current schedule? Email it to info@apexinsurancebrokers.co.uk and a named broker will come back to you.

Doesn't being the IT experts mean we don't need cover?

This is the argument we hear most often, and it conflates two things that are genuinely separate: reducing the chance of an incident, and paying for one when it happens. Your expertise is excellent at the first. It is worth nothing for the second.

Skill is a probability lever. Good patching discipline, least-privilege access, MFA everywhere, tested backups and staff who do not click the wrong link all lower the odds of a serious event. They do not lower the odds to zero, because a large part of your attack surface is outside your control: a supplier's compromised software, a zero-day in a tool you rightly trusted, a client who ignored your advice, or simply a determined and well-resourced attacker who only needs to be right once. The best-run IT firm in Bristol can still have a genuinely bad day through no obvious fault of its own.

When that day comes, expertise does not pay the specialist forensic team who confirm what was taken. It does not fund the legal advice on your notification duties, the credit-monitoring you may offer affected individuals, the PR support, or the round-the-clock incident-response retainer. It does not compensate a client for their downtime or settle the third-party claim they bring against you. Insurance exists to fund that response and absorb that liability. The two things are complements, not substitutes. Being the expert is exactly why you are worth attacking; it is not a reason to self-insure the consequences.

What does cyber insurance actually pay for?

It helps to be precise about what cyber cover funds, because there is a lot of loose talk about it. Broadly, a well-structured cyber policy for a technology firm is built to do three things:

One area to be honest about: regulatory fines. If personal data is involved, UK GDPR and the Data Protection Act 2018 apply, and the Information Commissioner's Office (ICO) can take enforcement action. Whether a monetary penalty is insurable at all in the UK is legally uncertain and is frequently excluded or restricted by policies. So do not buy cyber cover on the belief that it will simply pay your fine — it may not. Buy it because it funds the response, the interruption and the liability, which in practice are where most of the actual money goes and where an uninsured firm gets hurt most. If you want the mechanics in plain terms, our cyber insurance explained guide breaks it down without the jargon.

How does cyber sit alongside technology professional indemnity?

Cyber is not the whole picture for a technology business, and it is worth understanding where it stops and where your professional indemnity begins. Technology professional indemnity (tech PI) — the same cover US clients and contracts call technology errors & omissions, or tech E&O; they are broadly the same product under two names — responds when your advice, your work or your product allegedly falls short and a client suffers a financial loss as a result. A missed requirement, a project that fails, negligent advice, an integration that breaks something downstream.

Cyber, by contrast, responds to security and data incidents: breaches, ransomware, extortion, data loss and the response those demand. There is a grey zone where a single event looks like both — a coding error that causes a client data breach, for instance — which is precisely why many technology firms hold the two together and why the interaction between the wordings matters. A broker's job is to make sure the two policies mesh rather than leave a gap between them. We go deeper into the distinction on our professional indemnity vs cyber insurance for tech companies page, and our technology professional indemnity insurance page covers the PI side in full.

One point on PI worth stating plainly, because it is widely misunderstood: professional indemnity is not a statutory legal requirement for IT firms. It is, however, almost always a contractual requirement — your clients, and the agencies or frameworks you work through, will typically require you to hold it at a specified limit before they will sign. That contractual pressure is usually what forces the decision, not any law.

What else should an IT company have in place?

Cyber and tech PI are the two headline covers, but they sit within a wider programme, and a couple of points are worth flagging so you do not conflate different obligations.

If you employ staff — anyone on your payroll beyond, in most cases, a genuine sole director-owner — employers' liability insurance is a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969, subject to narrow exceptions. That is a genuine statutory duty, and it is separate from everything discussed above. Beyond that, most technology firms will also want public liability, and larger operations will look at directors' and officers' cover and other lines depending on how they are structured.

A word for contractors specifically, because the questions get tangled. Your contractual insurance requirements (usually PI, often cyber and public liability) are a completely different matter from your tax position. IR35, the off-payroll working rules, is about your employment status for tax — whether an engagement should be treated as employment for tax purposes. Holding insurance does not change, improve or determine your IR35 status, and anyone who implies it does is misleading you. For your IR35 position, speak to a qualified accountant or tax adviser; for the insurance a contract demands, that is our side of the fence. If you are working out the full picture, our guides on what insurance an IT company needs and IT contractor insurance are good next reads.

How much cover, and what drives the cost?

We are not going to quote you a price, because a meaningful cyber premium depends on your specific profile and any figure plucked from the air would be worse than useless. What we can do is tell you honestly what an insurer is actually looking at. The main factors include: the volume and sensitivity of the data you hold and process; the number and type of clients whose systems you touch, which is where your contagion exposure lives; your revenue and how it is distributed; the security controls you have in place (MFA, backups, patching, endpoint protection, access management); your incident history; and the limits and structure you choose.

On limits, the right number is driven by your contractual commitments and the realistic scale of a worst-case third-party claim, not by picking a round figure that feels reassuring. Illustrative options such as £1m, £5m or £10m are common starting points for conversation, but for an IT firm the contagion question — how far could one incident spread across your client base — usually matters more than the headline number. This is exactly the kind of judgement worth talking through with a specialist rather than guessing, and where combined arrangements can be efficient; our combined technology insurance page explains how tech PI and cyber can be packaged together.

Every IT firm's exposure is a little different, and contagion risk in particular rewards a proper conversation. Talk to an Apex technology specialist and we will build cover around how your business actually works.

Get a tailored quote →

The short version is this. Your technical skill is real, and it genuinely lowers your odds — but it is a probability tool, not a payout. The moment an incident reaches your clients, you stop being the expert and become the defendant, and the bill is measured across every business you touch. Cyber insurance is what funds the response and absorbs that third-party liability so a single bad day does not take the firm down with it. If you would rather get the structure right than hope, start a tailored quote or speak to an Apex specialist who works with technology firms every day.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Ready to look at cyber cover?
Our online proposal takes about ten minutes — you can save and come back any time, and a broker reviews every submission personally. Prefer to talk it through first? Call 0117 325 0027.
Start your cyber proposal →
Get a quote →