You have to escape the single quote, so if you're using PHP, something like:
$query = "insert ... var='Tom\'s', ..."
or using your example directly, you could alternatively use:
$variable = "Tom's";
addslashes($variable);
to do the same thing. addslashes is an internal PHP function:
PHP: addslashes - Manual