You're in the server room, hands on their hardware
Network engineering is hands-on work, in firewalls, cabling, server rooms and comms cupboards, and it doesn't take much to go wrong. A rule left open, an upgrade that fails overnight, or a knock to the wrong piece of equipment, and you're the one the client comes looking for. Professional indemnity and public liability cover, built for on-site infrastructure work.
Where a network engineer actually gets exposed
Your risk is two-sided: the configuration decisions that protect or expose the network, and the physical, on-site work that comes with the job. Standard business insurance rarely covers both properly, and a network engineer needs it to.
The firewall rule that let the ransomware in
You make a change to a client's firewall during a project and leave a port open. Weeks later, ransomware enters through it, encrypting the client's systems.
An investigation traces the entry point back to your change, and the client seeks the cost of the incident.
The upgrade that took trading down
You run a network upgrade overnight for a retail client. Something goes wrong during the cutover, and the point-of-sale and back-office systems are down when the doors open.
The client loses trading time across every location and holds you responsible for the failed rollback.
The server room mishap
While working in a client's comms cupboard, a miscue disconnects the wrong cable and damages a piece of network equipment, taking part of the office offline for a day.
The client seeks the cost of the damaged equipment and the disruption to their operations.
Who's going to ask you for it
You often need it just to get through the door
For network engineers, cover is frequently a condition of site access, not just contract terms:
- Client site-access and security policies often require proof of insurance before you're granted badge access to work on-site.
- MSP and IT support subcontracts commonly require $1M–$5M professional indemnity and $10M–$20M public liability.
- Enterprise infrastructure panels set minimum limits given the criticality of the systems involved.
The exclusion network engineers assume is covered
The most common trap is assuming "it's just config work, so I don't need public liability". On-site network engineering routinely involves physical work in server rooms and comms cupboards. Property damage or injury on a client's premises is exactly what public liability responds to, and a pure professional indemnity policy won't.
A vulnerability you already knew about and hadn't remediated is also typically excluded.
Common questions
I mostly do config work, do I really need public liability too?
Yes, if you're ever on a client's site working on physical equipment. Professional indemnity covers your configuration decisions; public liability covers the property damage or injury that can come from hands-on work in a server room or comms cupboard.
Isn't this just professional indemnity?
PI is the core for configuration and advice, but network engineering carries both cyber exposure (a misconfigured firewall is a classic breach entry point) and public liability exposure from on-site work. ICT cover is built to carry all three.
What limit should I get?
Take it from the client's site-access requirement or subcontract terms. Commonly that's $1M–$5M PI and $10M–$20M PL. If you're unsure, we'll read the requirement with you before you buy.
A client's site-access policy needs a certificate of currency, how fast?
Once bound, a certificate is quick to issue. If site access is waiting on it, tell us and we'll prioritise it.
Does it cover a network I configured before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's best to have cover in place before a dispute surfaces.