IT liability insurance. The policy behind most contract clauses telling an IT business it must be insured.
Most IT businesses buy this because a client, an agency or a tender said they had to. This page explains what that clause is actually asking for.
IT liability insurance is professional indemnity plus public and products liability in one policy, built for IT businesses. Cyber is a separate question.
Not sure this is the right cover for you? See who this is for.
If your worry is an incident inside your own systems rather than a clause in a contract, that is a different policy, cyber, not this one. See cyber insurance.
What IT liability insurance is, and why some insurers call it ICT liability insurance
Quick answerIT liability insurance is two covers written into one policy for technology businesses: professional indemnity for the advice, code and work you deliver, and public and products liability for injury or property damage. ICT liability insurance is the same product under an older name. What any policy actually includes is decided by its wording and schedule, not by the label on the front.
Start with the two halves, because nearly every mix-up about this product comes from treating them as one thing.
The professional indemnity half answers for your work. A client says the system you specified, the code you wrote, the migration you ran or the advice you gave has cost them money. That is a claim for financial loss caused by your professional work, and it is what the professional indemnity insuring clause inside the policy is there for.
The public and products liability half answers for injury and damage. Somebody is hurt, or property is damaged, because of your business. Cabling you left across a walkway, a rack you brought down in a client's server room, a visitor injured at your own premises. None of that is about the quality of your advice, and it needs an insuring clause of its own.
The two halves do not work the same way, and that catches people out. The professional indemnity half is written on what the trade calls a claims made basis: the policy that answers is the one running on the day the claim is made against you, not the one that was running when you did the work. The liability half is written per occurrence, which means the policy running when the incident happened is the one that answers. One policy, two clocks. What a claims made policy needs from you, including the date your cover reaches back to and what happens to old work after you stop trading, is set out on our professional indemnity insurance page.
ICT and IT mean the same thing here. ICT stands for information and communications technology and it is the older label. The same class of cover is sold as ICT liability insurance, IT liability insurance and information technology liability insurance, and the choice of words is not the difference between one policy and another. The wording is. Two policies with the same name on the front can carry different insuring clauses, different automatic extensions and different exclusions, which is why the useful question is never what a product is called, it is what its wording actually says.
Why the contract in front of you asks for this, and what it is protecting your client from
Quick answerBecause your client is not insuring your business, they are insuring their own exposure to it. If your work stops their systems, their staff cannot work and they cannot trade, and that loss builds by the hour. It is their loss, not yours, which is why they want to know a policy stands behind you before they sign.
Most IT businesses meet this product the same way. A client sends through a services agreement with an insurance clause in it. A recruitment agency will not place you until you produce a certificate. A tender lists insurance among the things you must hold before you can bid. Or a client's own insurer has told them to stop treating subcontractors as if they were covered by the client's policy. None of that is personal. It is ordinary risk management by the party paying you.
What sits behind the clause is a chain your client has already thought through. Your work fails. Their systems go down. Their staff sit idle. They cannot trade. The loss accumulates by the hour, and it traces straight back to you. That chain does not need a large business at the far end of it to get expensive, and the size of the loss has very little to do with the size of your fee. This is the honest reason IT and consulting work needs good cover: not because the work is careless, but because a small mistake in it can stop somebody else's business.
The important thing about that loss is whose it is. It is your client's, not yours. That is the distinction people miss when they try to solve this with one product. Cover for a cyber incident is built to answer for what happens inside your own business, so your own systems, your own data, your own downtime and your own recovery costs. It is not built to answer for a financial loss your client suffers because of the work you did for them. That claim is professional indemnity territory. It is also why the standard product for IT businesses puts professional indemnity and liability in the same policy: one incident routinely produces both halves, on the same day, from the same cause.
The requirement you are responding to is contractual. The limit is set by the client, the panel or the tender in front of you, and it moves from one agreement to the next, which is why there is no single right answer to "how much do I need". The useful next step is reading the clause you have been sent rather than looking up a standard figure, because the clause is the only thing that binds you.
What government and corporate IT contracts actually require
Quick answerNew South Wales publishes real numbers: its ICT Services Scheme rules, version 2.2 of August 2023, still current as at August 2026, set a floor of $1 million professional indemnity, and $5 million or $10 million public liability depending on your registration tier, plus workers compensation. Queensland's standard IT contract requires insurance but publishes no figure at all. Large private clients commonly demand more than either. The clause in your hand is the only number that counts.
New South Wales publishes a baseline, and it is lower than most suppliers expect. The NSW Government ICT Services Scheme Rules, version 2.2 of August 2023 and still the current version as at August 2026, set out the insurances a supplier must show before entering an agreement with NSW Government: professional indemnity of $1 million for both Registered and Advanced Registered suppliers, public liability of $5 million for Registered suppliers and $10 million for Advanced Registered suppliers (the threshold is contract engagement value over $150,000 ex GST, or a high-risk engagement), and workers compensation. Two sentences in the same clause matter more than the table itself. The scheme calls those levels a minimum and notes that the core terms of the high-risk and high-value purchasing framework require greater levels of insurance. And it says that insurance requirements specified in the agreement of any engagement override the requirements in the scheme rules. So the published number is a floor, not an answer.
Cyber cover is not part of that baseline. The same clause says agreements may specify, where relevant, that additional insurances are required, such as for cyber security or data breaches. Read plainly, that means the scheme does not set a standing cyber requirement for ICT suppliers at all. Whether you need it for a particular New South Wales engagement is decided in that agreement.
Queensland runs it the other way round, and this is the one that catches Brisbane suppliers. The QITC General Contract Conditions, version 2026.01, are the standard terms behind Queensland Government ICT contracts. Clause 4(r) requires a supplier, at its own cost and by the start date of the contract, to hold the insurance policies described in the Details, with an insurer authorised and licensed in Australia or otherwise rated A minus or better. The template names no insurance type and no dollar figure anywhere in it. We read all 47 pages: insurance appears seven times and never once with an amount attached. Every actual requirement lives in the Details, a schedule the buying agency fills in for that contract. There is no Queensland figure to look up. There is only the contract you have been sent, and the insurance clause in it is the part most suppliers sign without reading.
One clause in those Queensland conditions is worth knowing before a job ends rather than after. Where a required policy is written on a claims made basis, and professional indemnity almost always is, the supplier must maintain it for a minimum of four years after the contract ends, or for whatever period the Details specify. That is a government contract asking you to keep paying for cover over work you have already finished and been paid for. Cover for past work after a policy ends is called run-off cover, and how it works is on our professional indemnity insurance page.
Private contracts are usually the bigger number. A $10 million limit is a common contractual requirement on tenders and head contracts, and it tends to arrive inside standard terms that a supplier has no realistic ability to negotiate. Published government minimums are the floor of this market rather than the middle of it, so a business that has sized its cover against the government baseline can still be short of what a corporate client will demand.
The limits we can place. We arrange this cover at $1 million, $2 million, $5 million and $10 million. Which one is right is decided by the contracts you sign and the work you actually do, not by picking the middle of the list.
And the number on its own does not tell you what you have bought. Three mechanics decide what a limit is actually worth. Whether it applies to each claim separately or in the aggregate, meaning one pool for the whole policy year that earlier claims eat into. Whether your legal defence costs come out of that limit or sit on top of it, because on a costs-inclusive policy every dollar spent defending you is a dollar less available to pay the claim. And whether the sub-limits inside the policy, the smaller caps that sit under the headline number for particular kinds of loss, are themselves inclusive of defence costs. Which way your policy falls on each of those is one of the first questions worth asking, and it is answered in the wording and your schedule rather than on the certificate. The mechanics are set out in full on our professional indemnity insurance page.
Professional indemnity, cyber or IT liability: which one is your contract asking for?
Quick answerProfessional indemnity answers for financial loss your client suffers because of your work. Cyber answers for what happens inside your own systems. IT liability is professional indemnity and public and products liability written together for technology businesses. The standard IT liability wordings we place carry no cyber insuring clause in the base wording, so cyber is a separate decision rather than an assumed inclusion.
Most IT businesses arrive at this question in professional indemnity language, because that is the phrase their contract used. It is a reasonable place to start. It is just rarely the whole answer.
Professional indemnity on its own covers the advice and work half. If a client says your design, your code, your integration or your recommendation cost them money, that is the insuring clause that responds. What it does not do is answer for a person being injured or property being damaged, and most client agreements and site access rules ask for both in the same paragraph. How professional indemnity works across every profession, including the details that decide whether it protects you at all, is on our professional indemnity insurance page.
Cyber covers what happens inside your own business. A breach of your systems, ransomware that stops you trading, restoring your own data, the cost of getting back up and the notification obligations that follow. It is real and for a lot of IT businesses it is essential. It is simply pointed at your losses rather than at your client's claim against you. See cyber insurance for what that cover does.
IT liability puts professional indemnity and public and products liability into one policy, written for technology trades. That is the product most contract clauses are reaching for when they tell an IT business to hold cover, because most clauses ask for professional indemnity and public liability in the same breath, and buying them separately usually means two wordings that were never designed to meet in the middle.
What it does not automatically bring with it is cyber. The standard IT liability wordings we place carry no cyber insuring clause, so there is nothing in the base wording that pays for a cyber incident inside your own business. That is a structural point rather than a criticism. An extension modifies an insuring clause the policy already has; it cannot create a class of cover the policy was never written to give, which is why counting extensions is a poor way to compare two policies. The standard wordings can carry more numbered extensions than the packaged technology products do. What any particular policy says about cyber is then a question of its own schedule and any endorsements sitting on it, and that is one of the first things worth checking on a policy you already hold rather than assuming either way. Where cyber is built in as its own insuring clause, you are looking at a combined technology package, which is a different class of product with its own page.
Who IT liability insurance is built for, and when a growing IT business has outgrown it
Quick answerIt is built for IT contractors, sole traders and small consultancies: people who advise, build, configure and support, and whose insurance question arrived as a contract clause. You have outgrown it when you hold sensitive client data at scale, when your revenue stops the moment your systems stop, when contracts start demanding cyber as well, or when you have moved from advising on systems to running them.
The businesses this product was written for. IT consultants and contractors, small development and integration shops, break-fix and support businesses, and sole traders placed onto client sites through recruitment agencies. The common thread is that the work is advice, build and support delivered to somebody else's business, and that the insurance question arrived as a requirement in a contract rather than as a worry about your own systems.
The signals that you have moved past it. These are worth being honest about, because they change the class of cover you need rather than just its price. You hold sensitive third-party data, or a lot of personal information about other people's customers. Your own revenue stops when your own systems stop. Your client contracts have started demanding cyber cover alongside professional indemnity and public liability. Or you have moved from advising on systems to running them, holding the keys to other people's networks and data every day.
That step up is a different class of cover, not a bigger version of the same policy. This is where businesses lose money by assuming. It is tempting to think a package is the same policy with more bolted on, so the answer must be more extensions. It is not. A combined technology package builds cover for an incident inside your own business as its own insuring clauses: responding to a breach, notifying the people affected, the income you lose while your systems are down, restoring your own data, and extortion demands. None of those can be reached by extending a policy that was never written to give them. One small piece of market evidence tells you the same thing plainly: some insurers only offer their technology package to businesses that actually operate in the technology sector, which is not how you treat two versions of the same product. Where your business sits on that line, and what the package class actually answers for, is on our technology insurance page.
If you run other people's systems, you are in a different conversation again. A managed service provider holds administrative access to client networks, and the shape of that risk, including the possibility of one incident reaching many clients at once, is not what a standard IT liability wording was written to price. The managed services section of our technology insurance page deals with it properly.
None of this means bigger is better. A sole trader consultant with no client data to speak of, no systems of their own that anyone depends on, and a contract asking for professional indemnity and public liability is exactly who the standard product was written for, and moving that business into a package it does not need is not better broking. The judgement is which side of the line your business is actually on, and that is a conversation rather than a calculation.
IT Liability Insurance Australia: your questions answered
What is IT liability insurance?
Is ICT liability insurance the same as IT liability insurance?
Does IT liability insurance include cyber insurance?
What is the difference between IT liability insurance and professional indemnity insurance?
Is professional indemnity insurance mandatory for IT contractors and consultants in Australia?
What insurance do I need to win a government IT contract?
How much professional indemnity insurance does an IT contractor need?
My client's contract demands $10 million of cover. Do I really need that much?
Is the insurance included with my ACS membership enough for my IT business?
Do I need public liability insurance if my IT business only works remotely?
When has an IT business outgrown IT liability insurance?
How much does IT liability insurance cost?
Related cover and reading
The information on this page is general in nature and does not take into account your objectives, financial situation or needs. Before acting on it, consider whether it is appropriate for your circumstances. Where the information relates to a particular insurance product, consider the relevant Product Disclosure Statement before making a decision.
Last reviewed: 23/08/2026
Send us the clause before you sign it.
Tell us your name, your number and what you need. We reply to new enquiries within 90 minutes, 8am to 6pm Monday to Friday. From there we will read the insurance clause in your contract and tell you what it actually requires, including whether it is asking for cover you do not hold yet.
Call now, most enquiries are settled in one conversation - or leave your details and we'll ring within 90 minutes on a new enquiry (8am–6pm Mon–Fri).