Two coverage lines come up constantly when a SaaS company starts shopping for insurance: technology errors & omissions (Tech E&O) and cyber liability. They sound similar, they're sometimes bundled together in a single "tech package" policy, and it's genuinely easy to assume one covers what the other doesn't. It's worth understanding the actual split, because the wrong assumption can leave a real gap.
The Simplest Way to Split Them
Tech E&O covers performance failures. Cyber liability covers security failures.
If your platform goes down because of a bug and a client loses revenue as a result, that's a Tech E&O claim — your product didn't do what you promised, and it cost someone money. If an attacker breaches your systems and steals customer data, that's a cyber liability claim — a security failure, not a product failure.
What Tech E&O Actually Responds To
Tech E&O is a professional liability policy for technology work. It responds when a client alleges that your software, platform, API, or professional services caused them financial harm. Common triggers include:
- A software bug or defect that keeps a customer from using your product as promised
- A failed API integration or data-sync error that disrupts a client's operations
- Incorrect output or calculations a client relied on for a business decision
- Failure to deliver contracted implementation or customization work
Tech E&O is third-party coverage — it responds to claims brought against you by someone else, not your own internal costs.
What Cyber Liability Actually Responds To
Cyber liability is structured differently. It combines first-party coverage (your own costs) with third-party liability (claims from others):
- First-party: forensic investigation, legal counsel, customer and regulatory notification, and business interruption from an attack
- Third-party: claims from customers or partners whose data was exposed through your systems, and regulatory defense costs
Where They Overlap
The overlap shows up when a single incident touches both categories. A ransomware attack that also takes your platform offline for a week can trigger a cyber liability claim (the attack itself, the extortion response, the notification costs) and a Tech E&O claim (clients who lost revenue because your service was unavailable). This is the scenario that trips up companies who assume one policy covers everything — it often takes both to fully respond.
Do You Need Both?
Most SaaS companies handling any real volume of customer data or running any customer-facing infrastructure need both policies, not one or the other. Enterprise clients, investors, and vendor security questionnaires increasingly ask about both coverages by name, sometimes alongside a SOC 2 report. If you're deciding where to start, prioritize based on which risk is more active in your business right now — a company just starting to sign paying customers often prioritizes Tech E&O first, while a company handling sensitive data (health records, payment information, PII at scale) often can't reasonably skip cyber liability even at an early stage.
Getting the Right Program
SaaS Coverage is a division of Contractors Choice Agency, founded in 2005. We build Tech E&O and cyber liability programs specifically for SaaS and software companies, sized to your product, your data exposure, and what your contracts actually require. Call us at 844-967-5247 or request a quote online to talk through what fits your stage.
