The right time to read the policy is before you need it.
Cyber, technology E&O and general liability are the core of a technology company's programme — and the exclusions matter more than the premium.
- Cyber liability$1M – $5M by stage
- Technology E&O$1M – $5M, often a shared limit
- Dependent business interruptionCheck the sublimit and waiting period
- Social engineeringFrequently sublimited well below the policy limit
- Commercial general liability$1M / $2M
- Crime / fidelityWhere funds are held or moved
Ranges commonly seen. Your contracts and exposure decide the answer.
If any of these are true right now, this is the situation you're in.
- You hold customer data and have never read your own cyber policy
- You're pursuing SOC 2 or answering security questionnaires
- You had a near miss — a phishing attempt, an exposed bucket, a vendor breach
- Your product now sits in a customer's critical path
- Renewal is coming and last year's programme was bought in a hurry
Nothing happened yet. That's the point.
Most of what can seriously damage a technology company is covered by two policies. Cyber responds when data or systems are compromised: forensics, breach counsel, notification, the ransom decision, the revenue lost while you were down, and the liability when a customer says the breach was your fault. Technology E&O responds when your product or service fails to do what you said it would and a customer suffers financial loss.
Many real claims are both, which is why we generally place them on one combined form with a shared limit. It removes the argument about which policy responds while your engineering team is trying to restore production.
The differences between forms are where the value is. Dependent business interruption, waiting periods, social engineering sublimits, contractual liability wording, regulatory coverage — these are the terms that decide whether a claim pays, and they are almost never compared on a premium indication. We compare them when we place cover and put the exclusions in front of you at binding, while you can still act on them.
The coverage this situation calls for
In priority order, with the reason each one is on the list.
Specifically, in this situation.
- Place cyber and technology E&O on a combined form where it serves you
- Compare form language across markets, not only premium
- Flag sublimits and waiting periods that would matter in a real claim
- Report claims and potential claims the same day and stay in them through resolution
- 01
Submission reviewed
Same business dayYou tell us about the business once. We read it the day it arrives and come back with anything still outstanding.
- 02
Coverage & requirements reviewed
Same business dayContracts, exposures, limits and requirements checked against what you actually need to carry — and what you don't.
- 03
Markets approached
Typically within 48 hoursWe approach carrier and wholesale markets suited to the risk, with a submission built to be read rather than skimmed.
- 04
Options compared
Typically 3–10 business daysCoverage, terms and pricing reviewed side by side — including the exclusions that decide whether a claim pays.
- 05
Bind & certificates
Promptly after approvalIssued promptly once you approve, with a plain-English summary of what you bought.
Answered.
Yes. Cloud providers cover the security of the cloud; you are responsible for security in the cloud — your configuration, access controls, application and data. Almost every breach we see at software companies is customer-side.
No, but they are usually bought together. E&O answers a product or service failure; cyber answers a data or systems compromise. Many claims are both.
Frequently a great deal — dependent business interruption, waiting periods, social engineering sublimits, contractual liability wording and regulatory coverage. That comparison is the work.
Get covered without the runaround.
Tell us what changed. A broker reads it the same business day and comes back with what it means and what it costs.