Hedge/Coverage/Cyber and Tech E&O
Professional and Cyber

Cyber Liability and Technology E&O.

Cyber pays for the event. Tech E&O answers for the service failure. Many technology companies need both stories told.

Cyber coverage can address specified first-party incident costs and third-party claims arising from privacy, security, network, and cyber events. Technology errors and omissions can address covered claims alleging failure of a technology product or service. The two coverages solve different problems even when issued together.

Built forRetail insurance professionals
PurposeFrame the risk and build the first file
Reviewed2026-08-29
Placement context

Facts to confirm before applying.

The application is not the security story. We need to know what the company sells, what systems it touches, what data it holds, what customers depend on it, how a failure spreads, and whether the controls described on the application cover the whole environment.

Coverage scope

What the coverage may address.

01

Incident response, privacy, network security, interruption, cybercrime, extortion, media, and regulatory coverage have separate triggers.

02

Tech E&O focuses on the insured's product or service failure, including contract, dependency, and financial-loss exposure.

03

Social engineering, dependent business, system failure, bricking, bodily injury, and contractual liability need specific review.

Cyber controls checklist

Translate the application answers into evidence.

Use this checklist to scope the underwriting conversation. It is not a certification, security audit, promise of insurability, or substitute for the carrier's current application. CISA describes its performance goals as voluntary baseline practices; the actual insurer decides which controls and evidence affect a specific account.

Identity and access

  • MFA method and deployment for email, remote access, cloud administrators, privileged accounts, and critical applications
  • Separate administrator accounts, least-privilege process, joiner-mover-leaver controls, and privileged-access review
  • Password manager use, service accounts, shared credentials, and controls for vendors or managed service providers

Backups and recovery

  • Systems and data included in backups, frequency, retention, encryption, and responsibility
  • Offline, immutable, or otherwise isolated copy and the controls protecting backup administrators
  • Last restoration test, recovery time, recovery point, and dependencies needed to resume operations

Patching and exposure

  • Asset inventory, supported operating systems, patch timing, vulnerability scanning, and exception process
  • Internet-facing systems, remote access paths, cloud services, end-of-life technology, and segmentation
  • Endpoint protection or detection coverage across servers, workstations, laptops, and relevant cloud workloads

Detection and response

  • Central logging, alert review, endpoint monitoring, email protection, and security-operations responsibility
  • Incident response plan, named decision makers, legal and forensic contacts, and last tabletop exercise
  • Business continuity, customer communication, regulatory response, and cybercrime payment controls
Cyber first packet

Connect controls, contracts, incidents, and coverage.

Business and technology profile

  • Revenue split by software, services, managed services, hardware, consulting, and other operations
  • Customer types, largest contracts, service dependencies, uptime promises, and potential customer loss
  • Data types, record counts, payment activity, regulated information, hosting model, and geographic reach

Control evidence

  • Completed application reconciled to the entire environment, including subsidiaries and acquisitions
  • MFA, backup, patching, endpoint, logging, response, training, and vendor-control answers with scope and dates
  • Independent assessment, penetration test, vulnerability report, or remediation summary when available

Incidents, contracts, and coverage

  • Currently valued cyber, technology E&O, crime, and professional loss runs plus incident narratives
  • Material customer contracts, limitation of liability, indemnity, service level, privacy, and security obligations
  • Requested limits, retentions, retroactive date, dependent business, cybercrime, media, regulatory, and technology E&O needs
Control answers need scope and a date

State where each control is deployed, which entities and systems it covers, who owns it, and when the answer was last verified. A yes response without scope can hide the exact gap that controls underwriting.

Primary control sources

Use current CISA guidance.

CISA Cross-Sector Cybersecurity Performance Goals

CISA Small and Medium-Sized Business Resources

CISA Require Multifactor Authentication

CISA Use Logging on Business Systems

Sources reviewed 2026-08-29. Security guidance changes. Recheck the current source and the carrier's current application before relying on a control description.

Placement factors

Facts that affect placement.

  • Technology vendors, managed service providers, payment, data, or critical-infrastructure exposure
  • Weak controls, adverse claims, high limits, contractual liability, or unusual data volume
  • Blended cyber, technology E&O, media, crime, or professional-liability needs
  • Emerging technology, digital assets, artificial intelligence, or international operations
Coverage and access are separate questions

Coverage guidance does not confirm a current market route, quote, policy terms, or bind authority for a particular account.

Submission preparation

Prepare a consistent underwriting file.

Account narrative

Explain the business and the breach together: what the insured promises, what it touches, who depends on it, how it is secured, what failed before, and which losses need coverage.

Include these facts

  • Services, products, revenue, customer, contract, and data profile
  • Security controls including multifactor authentication, backups, patching, and response planning
  • Prior incidents, claims, contractual limits, and indemnification terms
  • Requested cyber, technology E&O, media, crime, and dependent-business coverages

Resolve these questions before market review

  • What services or products could fail and what would the customer lose?
  • What data and systems are controlled, hosted, or accessed?
  • Which security controls are deployed across the organization?
  • What contracts, incidents, or coverage overlaps could change the placement?
Submission errors

Avoid these three issues.

  1. A control answer that applies to headquarters but not subsidiaries, cloud systems, or remote access
  2. No revenue split between software, services, hardware, consulting, and managed services
  3. Treating cybercrime, social engineering, tech E&O, and cyber liability as interchangeable
Related coverage

Review related exposures.

Professional and Cyber

Miscellaneous Professional Liability

The insured's promise is the exposure. Define the service before trying to insure the mistake.

Open coverage
Management and Workforce

Management Liability

The cap table, boardroom, balance sheet, and employment history all show up in the policy wording.

Open coverage
Casualty and Excess

Products Liability

The product is the exposure. The supply chain tells us who owns the failure.

Open coverage
Hedge review

Send the account for review.

You do not need a perfect packet to start. Send the account, requested line, effective date, current applications, available loss information, and the fact making the placement difficult. Hedge will separate missing information from market-ready information before any account-specific route is confirmed.