A software consultant sells judgement that turns into systems other businesses depend on. When it goes wrong the loss is financial rather than physical, which puts professional indemnity at the centre and makes the client contract the document that decides the cover.
The claim is economic loss, not damage
A late delivery, a system that does not do what was specified, a migration that loses data, a defect that takes a client's service down: none of these injures anybody or breaks anything physical, so public liability has nothing to say. Professional indemnity is the operative cover, written on a claims made basis, so the policy in force when the claim arrives is the one that responds and continuity across years of past work matters more than in most trades.
Where cyber and indemnity meet
A consultant who holds client data, has access to client systems, or whose code is the route an attacker takes, sits across two products. Professional indemnity answers for the failure of the professional service; cyber answers for a breach of data, a ransomware event, the response costs and the notification obligations. Insurers increasingly write them together for technology businesses precisely because arguing about which one responds helps nobody, and a combined technology policy avoids the gap between them.
The contract clauses that drive the purchase
Client contracts for software work typically name a professional indemnity limit, often require cyber cover at a stated figure, cap the consultant's liability at a multiple of fees, and allocate intellectual property. The cap is worth reading alongside the insurance clause, because a contract that names a high insurance limit while capping liability at the fee has asked for cover it also prevents being claimed. Where a client requires cover to be maintained for years after completion, that is a run off obligation with a cost attached.
Intellectual property, open source and what is excluded
Claims that delivered code infringed somebody's rights, or that an open source licence obligation was breached, are a real exposure for this trade and are treated inconsistently across wordings. Some professional indemnity policies include intellectual property infringement, some exclude it, and some cover it only for unintentional infringement. A consultant whose contracts include an intellectual property indemnity should check which of the three their policy is before signing another one.
Questions people ask about software consultant insurance
Does a software consultant need public liability?
Rarely for the actual risk, but client contracts routinely require it, and it applies when working at a client's premises.
Is professional indemnity enough, or is cyber needed too?
Both, where the consultant holds client data or has access to client systems. Indemnity answers for the service failing; cyber answers for a breach and its response costs.
Are intellectual property claims covered?
It varies. Some wordings include unintentional infringement, some exclude intellectual property entirely, so check before agreeing a contractual intellectual property indemnity.