Cyber and Technology Professional Indemnity
Safeguarding operations against digital and operational threats
Data is today’s most valuable asset. Protecting it is becoming increasingly complex as threat actors refine their techniques. Server-level cyber security will, in most cases, sit with tenants – but operators and landlords can still be exposed to significant liability where their operational technology (OT), infrastructure or managed services are compromised.
All modern facilities and environments will be monitored and controlled centrally via data centre infrastructure management platforms (DCIM). But this can be leveraged as an access point for hackers. And where an operator is responsible for cooling, ventilation, power or environmental controls, a cyber event affecting can have severe consequences.
Disruption to cooling systems, power feeds or uninterruptible power supplies (UPS) can cause servers to overheat, fail or shut down entirely. Every additional internet-connected endpoint increases the attack surface available for exploitation. Exploitation of these systems in an attack can cause physical damage, loss of data, service interruption penalties, reputational damage and more. If physical access control systems, surveillance or threat detection platforms are compromised, unauthorised individuals may gain access to critical infrastructure or operational controls, significantly increasing both cyber and operational risk.
Traditional real estate and property policies now exclude cyber risk, so a dedicated cyber and tech PI solution is needed. Equally important is robust cyber risk management – not only to reduce exposure, but to secure favourable terms and conditions.
The solution
Cyber and tech PI insurances are both core components of a data centre risk transfer programme, protecting against claims arising from privacy and network breaches, as well as failures in the delivery of the contracted technology services or products.
While cyber insurance primarily responds to first‑party costs and third‑party liability arising from security and privacy breaches, tech PI addresses the failure to provide services, whether caused by a malicious or non‑malicious event, where a customer alleges financial loss due to negligence, error or omission in service delivery. Given the mission‑critical nature of data centre services, even minor disruptions can have disproportionate downstream impacts for customers and subsequent financial loss for operators and customers
Standalone tech PI policies typically exclude losses arising from a cyber incident – leaving a major key gap in coverage. Given the reliance on digital systems, we strongly recommend placing cyber and tech E&O coverages within a single, coordinated policy structure, reducing coverage gaps or exclusions that could otherwise preclude contractual or liability cover following a cyber‑triggered outage.
Typical cyber and tech E&O risk scenarios include:
- Breach of client and employee data leading to claims from both regulators and customers
- Malicious attack against a data centre leading to network failure and inability to operate
- Outages or degradation of service caused by configuration errors, maintenance activities or human error
- Failure to meet service level agreements (SLAs) for availability, latency or redundancy
- Cooling, power or environmental control failures (where under the control of the insured) leading to service interruption or equipment damage
- Errors in migration, provisioning, commissioning, decommissioning or change management activities
- Failure to deliver services in line with contractual specifications.
These policies respond to breach event costs, defence costs, and damages associated with third‑party claims from customers who suffer financial loss as a result of these events.
Contractual penalties
The widespread use of contractually defined service credits and rent reductions within colocation, hosting and compute contracts is another exposure to manage. They are often triggered automatically following outages or failures to meet predefined performance thresholds.
Off-the-shelf Tech E&O policies will typically exclude indemnification for such contractual penalties, only being triggered by a formal claim alleging negligence. However, when structured correctly, a strong policy can be extended to indemnify contractually agreed penalties, provided they:
- Are clearly defined and evidenced within customer contracts
- Represent a genuine pre‑estimate of loss rather than a punitive fine
- Are fully disclosed to insurers at placement.
This extension is particularly valuable for operators servicing large enterprise or hyperscale customers, where penalty exposure can escalate rapidly following prolonged or repeated outages.
Why cyber and tech E&O are critical
As data centres become ever more integral to business continuity and regulatory compliance, service interruptions can trigger substantial financial losses – all of which can crystallise into claims against the operator.
A coordinated insurance programme provides essential protection by:
- Transferring high‑severity, low‑frequency risks away from the balance sheet
- Supporting commercial negotiations with sophisticated, risk‑aware customers
- Addressing both cyber‑triggered and non‑cyber operational failures.
Practical considerations and recommendations
To ensure coverage responds effectively, operators should:
- Review and assess both IT and OT equipment for cyber resilience
- Adopt a robust cyber risk framework integrated into the wider security posture
- Translate cyber and operational risks into financial terms and remediate any gaps alongside making use of insurance risk transfer solutions
- Undertake crisis and incident response exercises to deepen understanding of an incident and improve response
- Regularly patch and update software applications, particularly those classified as high or severe risk.
- Consider segmentation of OT networks from corporate IT environments
- Ensure policy limits reflect worst‑case outage and aggregation scenarios.
