How to secure professional indemnity and cyber insurance
Protecting your business against legal claims and data breaches is a non-negotiable requirement for winning professional and enterprise clients.
To secure professional indemnity and cyber insurance, you must first identify the level of cover required by your potential clients—often between £1m and £5m—and then approach a specialist commercial insurance broker or provider to obtain a tailored policy. Having these in place doesn't just protect your finances; it acts as a badge of credibility that allows you to sign larger B2B contracts.
Understanding the two key policies
As a software-based business, you generally need two distinct types of protection that are often bundled together:
- Professional Indemnity (PI): This protects you if a client sues you for a mistake in your work. In the world of SaaS, this usually covers "errors and omissions." For example, if a bug in your code causes a client to lose significant revenue, PI insurance helps cover the legal costs and any compensation you might owe.
- Cyber Insurance: This covers the fallout from data breaches, hacking, and malicious attacks. If your system is breached and customer data is stolen, this policy covers the cost of notifying users, legal fees, data recovery, and even the cost of managing the PR crisis that follows.
Step-by-step guide to getting covered
- Check your contracts: Look at the draft Master Service Agreements or contracts from potential enterprise clients. They will almost always specify a minimum level of Professional Indemnity and Cyber cover. If they require £5m, a £1m policy won't suffice.
- Gather your documentation: To give you a quote, insurers will want to know how you handle data and write code. Have your Privacy Policy and Terms of Service ready. They may also ask if you use multi-factor authentication (MFA) and where your data is hosted.
- Contact a specialist broker: While you can use high-street providers, tech-focused brokers (such as those specialising in digital or SaaS risks) often understand the specific nuances of software errors better and can find more competitive rates.
- Review the exclusions: Not all policies are equal. Check if the policy covers international claims, especially if you have users in the US or EU, as some UK-based policies have geographic limitations.
- Finalise and store your certificates: Once you pay your premium, you will receive a "Certificate of Insurance." Keep this handy, as you will need to provide it as evidence during the procurement process with large clients.
Tips for better premiums
Insurers view risk as a sliding scale. You can often lower your premiums by demonstrating that you take security seriously.
Pro-tip: Implementing security measures like regular data backups, using encrypted hosting, and enforcing strong password policies across your team can make your business more attractive to insurers and may lead to lower quotes.
| Factor | Impact on Premium |
|---|---|
| Level of Cover (£1m vs £5m) | Higher cover equals higher premiums. |
| Revenue | Higher turnover usually increases the risk profile. |
| Security Certifications | Certifications like Cyber Essentials can often reduce costs. |
Remember that insurance is an annual commitment. Set a reminder to review your cover levels at least two months before your renewal date to ensure they still align with your growing client base and the complexity of your software.
Created by hatch. • Updated on April 29, 2026