Technology & tech E&O
Technology businesses carry a professional indemnity exposure that a general consultant does not: your work is software, systems and advice that clients build their own operations on, so when it fails the losses can be large and can land on many clients at once. This page explains what technology professional indemnity — tech errors & omissions — actually covers, the crucial difference between it and cyber insurance, and the distinct exposures across each part of the sector.
Part of: Professional indemnity at Apex
In short
Technology professional indemnity — usually written as technology errors and omissions, or tech E&O — covers a technology business when its work, product or advice fails and causes a client a financial loss, funding the legal defence and any damages. It is distinct from cyber insurance: tech E&O answers for your work failing a client, while cyber answers for your own systems being breached — and most technology firms need both, arranged so neither leaves a gap. Cover responds on a claims-made basis, so the policy in force when a claim is made is the one that matters, and the limit is set by your contracts rather than by a regulator. Different parts of the sector carry very different exposures — defective code, a breached service-level agreement, aggregation across a managed client base, a missed vulnerability, an intellectual-property or media claim, or a wrong AI output — so the cover should be matched to what your business actually does.
Technology professional indemnity — almost always written as technology errors and omissions, or tech E&O — is the cover a technology business relies on when something it designed, built, hosted, managed or advised on fails and causes a client a financial loss. It funds the cost of defending the client’s claim and any damages or settlement you become liable to pay.
Like all professional indemnity, it is built around the legal standard of reasonable skill and care: you are judged against what a competent provider would have done, not against perfection. It is written on a claims-made basis, so the policy that responds is the one in force when the claim is made against you — not the one you held when you did the work — which makes your retroactive date and continuous cover important. The limit you need is not set by any regulator; for technology firms it is driven by the contracts you sign.
The single most common and most costly misunderstanding in technology insurance is the assumption that one policy does both jobs. Tech E&O and cyber answer different questions, and most technology businesses need both.
| Technology E&O (professional indemnity) | Cyber insurance | |
|---|---|---|
| Answers for | Your work, product or advice | Your own systems and data |
| Triggered by | A client alleging your service failed and caused them a loss | A breach, ransomware or outage affecting you |
| Who is harmed | A third party — your client | First-party (you), plus third parties from your breach |
| Typical claim | Defective software, missed spec, negligent advice, a missed vulnerability | Hacked network, stolen data, business interruption, extortion |
| Funds | Defence costs and damages for the client’s loss | Incident response, forensics, notification, your own downtime |
The boundary is cause and victim, not technology. A bug you wrote that loses a client’s data is a professional failure (tech E&O); an attacker breaking into your network and stealing that data is a security incident (cyber). A single event can have both faces, which is why the two wordings should be arranged to meet rather than leave a gap between them. Handling personal data also brings duties under the UK GDPR and the Data Protection Act 2018.
Different parts of the technology sector carry very different professional indemnity exposures. We place cover across the sector, and each of these has its own detailed guide.
| Sub-sector | The defining exposure |
|---|---|
| Software developers | Code that fails, misses the spec, or is delivered late — and the fitness-for-purpose trap |
| SaaS companies | A continuing service many customers rely on at once — service levels, downtime and aggregation |
| Managed service providers | Privileged access to many clients — one mistake or a compromised tool hitting all of them |
| Cybersecurity firms | Failure to detect or prevent — being blamed when a client is breached anyway |
| Digital agencies | Media liability — intellectual-property, content and advertising claims on top of project work |
| AI & machine-learning companies | Wrong, biased or “hallucinated” outputs a client relies on — an evolving risk |
If your firm spans more than one of these — a software house that also hosts and manages, say — the cover needs to reflect the whole picture, not just your headline activity.
For technology firms, the contract is where the real liability is set. Three points decide how well your insurance responds.
The safest habit is to have a specialist broker read the liability, indemnity and insurance clauses of a major contract against your wording before you sign — not after a claim.
It is worth asking us to re-market your cover when:
We would rather say so than waste your time. We are probably not for you if:
It is professional indemnity written for technology businesses — covering claims that your work, product or advice (software, systems, hosting, managed services or consultancy) failed and caused a client a financial loss. It funds the defence and any damages. ‘Technology errors and omissions’ (tech E&O) is the name the same cover usually takes in the technology market.
Tech E&O answers for your work failing a client — a defect, a missed specification, negligent advice — and pays the client’s loss. Cyber answers for your own systems being breached — ransomware, stolen data, downtime — and pays the incident response and your own losses. The trigger and the victim are different, which is why they are separate policies.
Most technology businesses do. A single incident often has both faces — a coding flaw that also leads to a breach, for example — and relying on one policy to do both jobs usually leaves a gap. The two should be arranged to interlock, sometimes within one combined technology wording, so a claim cannot fall between them.
There is no regulatory minimum for technology firms; the limit is set by your contracts. Your cover should meet the highest limit required across your live client agreements, on the basis — each-and-every-claim or in the aggregate — that those contracts demand. A broker can size it to the agreements you actually sign.
Professional indemnity responds on a claims-made basis: the policy that pays is the one in force when a claim is made against you, or when you notify a circumstance — not the one you held when the work was done. This makes your retroactive date and continuous cover important, and makes run-off cover worth arranging if you close or sell the business.
Across the sector — including software developers, SaaS providers, managed service providers, cybersecurity and penetration-testing firms, digital and creative agencies, and AI and machine-learning companies, as well as IT consultants and systems integrators. Each has its own distinct exposures, and we match the cover to what your business actually does.
Tell us what your technology business does, the contracts you sign and the limits your clients require, and a specialist broker can place technology errors & omissions and cyber cover together — matched to your work, with no gap between them. Or call 0117 325 0027.
Get a quote Request a callbackApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.