Who it’s for
- Software developers and SaaS companies
- Managed service providers and IT support firms
- IT, data and systems consultants
- Web developers, app developers and digital agencies
- Independent tech contractors working through their own corporation
What it covers
Technology firms have two big exposures that ordinary business policies don’t address: the work you deliver to clients, and the systems and data you hold. A technology insurance program usually combines:
Technology errors and omissions (E&O):
- Claims that your software, system, integration or advice failed to perform and caused a client a financial loss.
- Missed deadlines, project failures and errors in code or configuration.
- Some policies include intellectual property claims, such as alleged copyright infringement in software or content. Patent claims are commonly excluded.
- Defence costs, which are often the biggest part of a claim.
Cyber liability:
- Breach response: forensics, breach lawyers, notification and credit monitoring.
- Ransomware and extortion response.
- Restoring your systems and data, and income lost while you’re down.
- Network security and privacy liability: claims from clients or others when an attack on you spreads to them or exposes their data.
Plus the basics: general liability for injury and property damage, and office contents and equipment, which are often packaged with the above.
Tech E&O is usually written on a claims-made basis, so continuous coverage with a stable retroactive date matters.
What it doesn’t cover, and common gaps
- Contract promises. Service levels, performance promises and indemnity clauses in your contracts can go beyond what the policy will cover. Read them before signing.
- Patent claims. Often excluded or very limited.
- Your own fixes. The cost of redoing your own work or refunding fees is usually excluded.
- Fraud by email. Fake invoices and payment redirection are often sublimited or need to be added.
- Subcontractors. If you use offshore developers or freelancers, the policy may need to address their work, and your contracts with them matter.
- Separate policies from separate insurers. If E&O and cyber are with different insurers, one incident can trigger arguments about which one pays.
- Activities not disclosed. Hosting client data, handling payments or working in health or financial sectors all need to be on the application.
Where your business and family policies overlap
Many tech firms are small and work from home, so the lines blur quickly.
- Home offices and home networks. Say you run a three-person development shop, mostly from your basement. Client code and credentials sit on machines connected to the family Wi-Fi, alongside your kids’ gaming consoles. Your cyber policy needs to recognize those devices and that network as part of the business.
- Family devices. If you or your staff ever log in to client systems from a personal or shared family device, that device is part of your attack surface, and part of the conversation about coverage.
- Equipment at home. Servers, workstations and test hardware at home may be well beyond the business-property limit on a home policy.
- One-person corporations and personal exposure. Independent consultants are often named personally in claims. Your personal umbrella generally won’t respond to professional services, so the E&O limit is what stands between a claim and your personal assets.
- Directors’ exposure. If you have investors or a board, directors and officers coverage is a separate conversation worth having.
Steve asks where your team works, which devices touch client systems, and how your corporation and personal policies are set up, then checks that they fit together.
How Steve works on this
Tech applications ask detailed questions about security controls, revenue by service and client contracts. Steve goes through them with you so the answers are accurate, explains how the E&O and cyber pieces work together, and points out where the wording falls short, especially for contract requirements. He gives you options and his opinion on what he’d do. Before you sign a major client contract, he can review the insurance clauses. At renewal, he calls to talk through new services, new clients, growth in staff and changes in where people work.
If you’d like a second set of eyes on your current coverage, book a review.
Common questions
How is technology insurance different from cyber insurance?
Cyber insurance covers a breach or attack on your own business. Technology E&O covers claims that your product or service failed and caused a client a financial loss. A tech firm usually needs both, and many insurers offer them together so one incident that touches both doesn't fall between two policies.
My clients' contracts require E&O and cyber. What should I look for?
Check the required limits, whether they want to be named on your policy, how long you must keep coverage after the contract ends, and any indemnity clause that has you accept more liability than you normally would. Steve can review the insurance sections before you sign.
I'm an independent contractor. Do I need this?
Often, yes, especially if a client or staffing agency requires it. Even a one-person corporation can be sued for a failed project, a missed deadline or a security incident that started on your laptop.
Does technology E&O cover a client's lost revenue if our software goes down?
It can, if the claim alleges your product or service failed and the loss falls within the policy terms. That's exactly the kind of claim the coverage is built for, but limits, exclusions and contract terms all matter.
If we're hacked and the attacker gets into a client's network through us, who covers that?
That's where cyber and technology E&O meet. Depending on the wording, network security liability under the cyber section or the E&O section may respond. This is one of the best reasons to buy the two together and read how they interact.