Technology companies face a coverage question that doesn’t exist in traditional professional services: when your software fails, is it a professional liability claim (E&O) or a cyber liability claim? The answer is almost always both, and carrying one without the other leaves a gap that surfaces during the exact scenario both were designed for — a service failure that also involves a data breach.
Technology E&O costs $4,000 to $35,000 per year for mid-market SaaS and IT services companies with $10M–$100M in revenue. Cyber liability adds $3,000 to $25,000 on top of that. Combined, a mid-market tech company’s professional liability + cyber program runs $7,000 to $60,000 annually — a fraction of what a single data breach costs. IBM’s Cost of a Data Breach Report puts the 2024 average at $4.88 million, and technology sector breaches average higher due to the volume of records involved. Our commercial cyber insurance cost guide breaks those cyber premiums down by industry, revenue band, and security posture.
E&O vs. Cyber: What Each Covers
- Tech E&O covers: Software doesn’t perform as promised, missed delivery deadlines, code defects causing client losses, professional negligence in IT consulting, failure to meet SLA obligations
- Cyber covers: Data breach notification and forensics, regulatory fines (GDPR, CCPA, HIPAA), credit monitoring for affected individuals, ransomware payments and recovery, business interruption from a cyber event
- Both respond when: A system failure (E&O trigger) also exposes client data (cyber trigger). Example: SaaS platform goes down, exposing 50,000 client records during the outage.
When E&O and Cyber Overlap — and When They Don’t
| Scenario | E&O Responds? | Cyber Responds? |
|---|---|---|
| Software bug causes client to lose revenue | ✅ Yes | ❌ No |
| Ransomware shuts down your platform | ❌ No | ✅ Yes |
| Platform outage + client data exposed | ✅ Service failure | ✅ Data breach |
| Bad IT consulting advice causes financial loss | ✅ Yes | ❌ No |
| Employee clicks phishing link, client PII stolen | ❌ No | ✅ Yes |
| Failed migration loses client data permanently | ✅ Service failure | ✅ Data loss |
The scenarios where both policies respond are the ones most tech companies get wrong. They buy E&O or cyber — not both — and discover the gap when a dual-trigger event occurs. Enterprise clients increasingly require proof of both coverages before signing MSAs, and SOC 2 auditors flag the gap during compliance reviews.
For mid-market tech companies selling to enterprise clients, the combined E&O + cyber program isn’t a cost center — it’s a sales enablement tool. The COI that shows $5M E&O and $5M cyber removes a procurement objection that can stall a six-figure deal for weeks. Structuring both policies with the same carrier or through a single broker ensures coordinated claims handling when a dual-trigger event fires both policies simultaneously.
Disclaimer: This article is for informational purposes only and does not constitute insurance advice. Coverage requirements vary by contract and regulatory jurisdiction. Consult with our licensed insurance advisors.
Tech E&O + Cyber Program Design
We structure combined E&O and cyber programs for SaaS, IT services, and technology companies with $10M–$100M+ in revenue. Coordinated placement ensures no gaps between policies when both need to respond.
Request Tech Program Review