CoverTrade

    IT Consultant & Software Developer Insurance

    IT is the profession where two policies cover adjacent ground and the gap between them is where the claim lands.

    Two Policies, One Overlapping Risk

    Professional indemnity answers advice, code or a specification that failed. Cyber answers a breach: data taken, systems encrypted, a client's network compromised. A project that overran and cost the client money is the first. A system you built being breached and exposing their customers is arguably both, and which policy responds depends on wordings that were not written with each other in mind.

    On top of that sits the contract. More than almost any other profession, IT work is done under client terms that cap liability, demand indemnities, or require specific insurance limits, and those terms often matter more to your exposure than anything in the policy.

    What IT Consultant Insurance Covers

    Professional indemnity

    Claims that your advice, code, specification or project management caused a financial loss. Overrun, failed implementation, a system that does not do what was specified. Pays the defence as well as any settlement.

    Cyber and data

    Breach response, ransomware, data loss and the cost of notification. Essential where you hold client data or have access to their systems, because a compromise of you becomes a compromise of them.

    Technology errors and omissions

    Often where professional indemnity and cyber are combined into one tech wording. Usually the cleaner answer, because it removes the argument about which policy responds.

    Contractual liability

    Where a client contract imposes obligations beyond ordinary negligence. Usually excluded unless the insurer has seen the terms, so the contract needs to go to them rather than into a drawer.

    Public and employers' liability

    Visitors and staff. Employers' liability is compulsory from the first employee at a £5 million statutory minimum, including contractors working under your direction.

    Legal expenses

    Recovering unpaid invoices, which in project work is a live issue, plus employment disputes.

    Where The Cover Stops

    Wordings differ between insurers, so treat these as the usual position rather than as universal fact. Where one of them matters to you, it is worth checking on your own schedule before you need to.

    The gap between PI and cyber

    A breach of a system you built and maintain can be read as a professional failure or as a cyber event, and two separate insurers will each have a view. A combined technology wording removes the argument, which is usually worth more than a small saving on buying them apart.

    Liability assumed under contract

    Client terms frequently impose indemnities, uncapped liability or service credits. Most policies exclude liability you took on contractually beyond what the law imposes, unless the insurer has agreed to it.

    Claims made, with a retroactive date

    Professional indemnity responds to when the claim is made. A system delivered in 2026 that fails in 2029 needs a live policy then, reaching back to 2026. Gaps and lost retroactive dates remove past work.

    Open source and third party components

    Licensing claims and vulnerabilities inherited from components you did not write are a real exposure and are treated differently between wordings.

    Known circumstances

    A project already in dispute cannot be insured after the fact. Notify a circumstance when the relationship sours, not when the letter arrives.

    Read The Client Contract Before The Policy

    In most professions the policy defines your exposure. In IT the client contract usually does, and the policy is trying to keep up with it.

    The clauses that matter are the liability cap, which may be set at the contract value or removed entirely for data breaches; indemnity clauses requiring you to hold the client harmless for losses you did not cause; service credits and liquidated damages for downtime; and insurance requirements specifying limits you must hold. An uncapped data breach indemnity in a contract worth twenty thousand pounds is a genuinely serious exposure.

    Send the terms to your broker before signing. Insurers are generally comfortable with negotiated caps and standard indemnities, and far less comfortable with uncapped liability discovered at claim stage.

    Managed Services Changes The Shape Of It

    A project delivered and handed over is a bounded risk. A managed service, where you hold privileged access to a client's systems indefinitely, is not.

    Two things follow. Accumulation: one compromised remote access tool can reach every client you support, so a single incident is not one claim but many. And duration: you are responsible continuously rather than for a defined deliverable, which changes both the exposure and what insurers will ask about your own security.

    Expect questions about your own controls rather than your clients': multi-factor authentication on every administrative account, privileged access management, how credentials are stored, and whether your remote monitoring tool is segmented. Those answers now move terms materially, and they are the same measures that prevent the incident.

    Who Owns The Data Breach

    If a client's customer data is exposed through a system you built or maintain, the claim can arrive at you from two directions: the client suing for their losses, and the regulatory and notification costs flowing from the breach itself.

    Professional indemnity may answer the first if the cause was a professional failure. Cyber answers the second, and may answer the first depending on wording. Where the two policies sit with different insurers, each has an incentive to point at the other, and you are in the middle of it.

    This is the clearest argument for a combined technology wording. One insurer, one claim, no coverage dispute to fund while the actual dispute is running.

    How To Choose A Broker For An IT Business

    IT is widely insured and poorly differentiated on price, so what separates placements is whether anyone has read the contracts and understood where PI ends and cyber begins. We are an FCA regulated broker and will not claim to be the best choice. These decide it.

    Do they offer a combined technology wording, or two separate policies?

    Two insurers covering adjacent ground is two chances for a coverage argument. Ask which they propose and why.

    Will they read your client contracts?

    Liability caps, indemnities and insurance requirements shape your exposure more than the policy does. A broker who has not asked to see them is guessing.

    Have they asked about your own security, not just your clients'?

    For a managed service provider, your admin access is the accumulation risk. MFA, privileged access management and segmentation are the questions that matter.

    Can they state your retroactive date?

    A system failing three years after delivery needs cover reaching back to when you built it.

    How is open source and third party code treated?

    Inherited vulnerabilities and licensing claims are handled differently between wordings, and most quotes never mention them.

    Factually, we quote technology risks as a combined wording where the market offers one, we ask to see client contract terms before placing rather than after a claim, we ask about your own administrative controls where you hold client system access, and we check the retroactive date when a business moves to us. We are a broker, so it goes to several insurers rather than one.

    We do not publish a starting premium for IT consultancy. We place the trade but hold fewer than ten policies in it, which is below the threshold where we are willing to put a figure on a page.

    What Moves The Price

    Every policy is priced on the business behind it. These are the things that move the premium:

    • Turnover and the size of your largest client contract
    • Whether you deliver projects, managed services, or both
    • The volume and sensitivity of client data you hold
    • Contractual liability caps and indemnities you have accepted
    • Your own security controls, particularly on admin access
    • The limit required, and claims or circumstances notified

    We are a broker, so we take it to several insurers rather than quoting one. Call 02382 000820 for a quote.

    What We Need To Quote

    • What you actually do: advisory, development, support, managed services
    • Annual turnover and your largest client by value
    • Whether you hold client data or privileged system access
    • Typical client contract terms, including liability caps
    • Your own controls: MFA, privileged access, backups
    • The retroactive date on your current policy, and any claims

    Cover that often goes with this

    The gaps we most often find sitting next to this policy.

    Common questions

    Do IT consultants need professional indemnity and cyber, or just one?+

    Realistically both, and often best bought as a single technology wording. Professional indemnity answers a project that failed or advice that was wrong. Cyber answers a breach, ransomware and notification costs. The problem with buying them separately from different insurers is that a breach of a system you built sits between the two, and each insurer has an incentive to point at the other. A combined wording removes that argument.

    Does my policy cover liability I accepted in a client contract?+

    Usually not, unless the insurer has seen and agreed the terms. Most policies exclude liability assumed under contract beyond what the law would impose. IT contracts routinely contain indemnities, uncapped liability for data breaches and service credits, so send the terms to your broker before signing. Negotiated caps and standard indemnities are generally acceptable to insurers; uncapped liability discovered at claim stage is not.

    What do insurers ask a managed service provider?+

    About your own security rather than your clients'. Multi-factor authentication on every administrative account, how privileged credentials are stored and managed, whether your remote monitoring and management tooling is segmented, and your patching routine. The reason is accumulation: one compromised admin tool can reach every client you support, turning a single incident into many claims at once.

    Who is liable if a system I built gets breached?+

    It depends on whether the breach flowed from a professional failure, such as a known vulnerability you did not address, or from an attack nobody could reasonably have prevented. The client's losses may be a professional indemnity claim; the notification, forensics and regulatory costs are cyber. Where those policies sit with different insurers you can end up funding a coverage dispute alongside the real one, which is the practical argument for combining them.

    How much is IT consultant insurance?+

    We place the trade but hold fewer than ten policies in it, which is below the threshold where we are prepared to publish a figure, so we will not invent one. What moves it is turnover, whether you deliver projects or ongoing managed services, the data you hold, the limits your contracts require, and your own security controls. Call 02382 000820 with those and you will get a real number.

    More food, drink and leisure we cover

    What our customers say on Google

    5.0average from 169 Google reviews