The hardest technology risk to underwrite.
Security vendors carry an unusual exposure: when your customer is breached, you are the first defendant. That requires a specialist placement, not a general technology form.
Broker response
Same business day
Answered by a broker, in writing.
Quote turnaround
3–10 business days
From a complete submission to terms in hand.
Certificates
Same day
Standard requests issued without an email chain.
Renewal process
Begins 90 days out
Not the week before your policy expires.
What actually goes wrong at companies like yours
Not a generic risk list. These are the exposures underwriters ask about and the ones that produce claims.
Failure-to-detect claims
A customer breach becomes an allegation that your product should have prevented it.
Efficacy representations
Marketing claims about detection and prevention rates become the basis of the complaint.
Privileged access
Agents with kernel or admin access make a compromise of your product catastrophic for customers.
Update and signature deployment
A bad update pushed at scale can take down thousands of customer environments simultaneously.
Offensive security services
Pen testing, red teaming, and IR work require specific coverage extensions and careful contracting.
Regulated customer base
Financial services and healthcare customers impose their own insurance and audit requirements on you.
What we typically place
A starting structure for cybersecurity. Your contracts, data footprint and headcount move it — which is exactly what the submission is for.
Build your programmePlacing security vendors
A generalist technology form is usually the wrong instrument for a security company. The exposure profile — high severity, correlated across customers, tied directly to product efficacy — sits with a smaller group of markets who actually understand it.
We also review your own marketing and contractual representations as part of the placement. The gap between what the website promises and what the MSA warrants is frequently where the claim starts.
What your customers will ask you to carry
The limits that show up most often in insurance exhibits for cybersecurity. Send us the exhibit before you sign and we'll tell you whether you comply, what compliance costs, and what is worth negotiating.
| Requirement | Typical ask |
|---|---|
| Technology E&O | $5M – $20M |
| Cyber liability | $5M – $20M |
| General liability | $1M / $2M |
| Umbrella | $5M – $10M |
| Crime | $1M+ where handling customer funds or credentials |
Cybersecurity, answered
Anything else, send it to a broker and get a written answer within the business day.
Yes. IR and offensive security engagements need explicit coverage for those services, and your engagement letters need authorization language that holds up. We review both.
Get a programme built for cybersecurity.
Tell us about the business once. A broker reviews it the same day and comes back with a plan, a timeline and what we need to take it to market.