Do You Need Business Insurance for a Side Project That Makes Money? (UK)

Insurance is one of those things that feels premature right up until the moment it would have mattered. For a solo developer with a live, paying product, almost nothing about insurance is legally mandatory, with one specific exception, but that doesn't make the question irrelevant, it makes it a genuine judgement call rather than a checkbox.

The one that actually is mandatory

If you employ staff (not contractors, actual employees, even one), Employers' Liability insurance is a legal requirement in the UK, with fines for operating without it. If you're a solo founder with no employees, this doesn't apply to you yet, but it's the one item on this list that stops being optional the moment it does.

Professional Indemnity: covers your advice or software being wrong

This is the one most relevant to a SaaS product: it covers claims that your software or advice caused someone financial loss, a calculation error, a missed deadline your tool was supposed to prevent, data your product mishandled that cost a customer money. Not legally required for most software businesses, but increasingly expected: some B2B clients and platform partners will ask for proof of cover before signing a contract, particularly at higher deal sizes.

Cost varies a lot by cover level and claims history, but entry-level cover for a solo developer often starts in the low hundreds of pounds a year for modest cover limits, rising with the amount of cover and the risk profile of what your product actually does. Get quotes from a broker who understands software rather than assuming a generic small-business policy fits; the specifics of what counts as a covered claim matter more than the headline price.

Cyber insurance: covers the breach itself, not just the claims from it

Where Professional Indemnity covers someone else's loss from your product being wrong, cyber insurance covers your own costs from a security incident, breach investigation and notification costs, ransomware, business interruption while you're locked out of your own systems. If you're processing customer personal data (see the GDPR guide), this is the policy that actually responds when the thing GDPR made you worry about happens. Worth pricing out once you have real customer data at stake, not necessarily before.

Public Liability: usually the least relevant one here

Covers third-party injury or property damage, the classic case is a client tripping over a cable in your office. For an online-only, no-physical-premises SaaS with no in-person client meetings, this is genuinely low priority, don't let a generic "every business needs this" checklist push you toward cover that doesn't match your actual risk.

How to actually decide

None of this is about buying every policy on day one. A reasonable sequence: get Professional Indemnity once you have real paying customers and real financial exposure if something breaks, add cyber cover once you're holding meaningful customer data or payment information, and treat Public Liability as relevant only if your business involves physical premises or in-person contact. Revisit annually as the product and its risk profile change, what was overkill at launch can become underinsured a year later.

Where this fits in the bigger picture

Insurance is one more piece of the unglamorous infrastructure that separates a side project from a real business, alongside company structure, contracts, and data protection. Qeetoto helps the developers we work with think through this properly rather than either skipping it or over-buying out of anxiety, as part of the broader compliance and legal work we take on in exchange for a share of revenue, while you keep your IP. Get in touch if you want a second opinion on what your project actually needs right now.

FAQ

Is insurance required to incorporate a limited company? No, forming a company and buying insurance are entirely separate decisions. See the company formation guide for the incorporation question.

Will a client actually ask to see proof of insurance? For B2B deals of any real size, increasingly yes, particularly Professional Indemnity. It's worth having in place before it's the thing blocking a contract, not scrambling for a quote when someone asks.

Does limited company status replace the need for insurance? No. Limited liability protects your personal assets from the company's debts and legal liabilities, it doesn't cover the company's own losses from a claim, a breach, or an error, that's what insurance is for.

Is £52 a year for the ICO fee the same as cyber insurance? No, they're unrelated. The ICO data protection fee (covered in the GDPR guide) is a regulatory registration cost. Cyber insurance is a separate, optional financial product that pays out if you actually have a breach or attack.