Incident response, privacy, network security, interruption, cybercrime, extortion, media, and regulatory coverage have separate triggers.
Cyber Liability and Technology E&O.
Cyber pays for the event. Tech E&O answers for the service failure. Many technology companies need both stories told.
Cyber coverage can address specified first-party incident costs and third-party claims arising from privacy, security, network, and cyber events. Technology errors and omissions can address covered claims alleging failure of a technology product or service. The two coverages solve different problems even when issued together.
Facts to confirm before applying.
The application is not the security story. We need to know what the company sells, what systems it touches, what data it holds, what customers depend on it, how a failure spreads, and whether the controls described on the application cover the whole environment.
What the coverage may address.
Tech E&O focuses on the insured's product or service failure, including contract, dependency, and financial-loss exposure.
Social engineering, dependent business, system failure, bricking, bodily injury, and contractual liability need specific review.
Translate the application answers into evidence.
Use this checklist to scope the underwriting conversation. It is not a certification, security audit, promise of insurability, or substitute for the carrier's current application. CISA describes its performance goals as voluntary baseline practices; the actual insurer decides which controls and evidence affect a specific account.
Identity and access
- MFA method and deployment for email, remote access, cloud administrators, privileged accounts, and critical applications
- Separate administrator accounts, least-privilege process, joiner-mover-leaver controls, and privileged-access review
- Password manager use, service accounts, shared credentials, and controls for vendors or managed service providers
Backups and recovery
- Systems and data included in backups, frequency, retention, encryption, and responsibility
- Offline, immutable, or otherwise isolated copy and the controls protecting backup administrators
- Last restoration test, recovery time, recovery point, and dependencies needed to resume operations
Patching and exposure
- Asset inventory, supported operating systems, patch timing, vulnerability scanning, and exception process
- Internet-facing systems, remote access paths, cloud services, end-of-life technology, and segmentation
- Endpoint protection or detection coverage across servers, workstations, laptops, and relevant cloud workloads
Detection and response
- Central logging, alert review, endpoint monitoring, email protection, and security-operations responsibility
- Incident response plan, named decision makers, legal and forensic contacts, and last tabletop exercise
- Business continuity, customer communication, regulatory response, and cybercrime payment controls
Connect controls, contracts, incidents, and coverage.
Business and technology profile
- Revenue split by software, services, managed services, hardware, consulting, and other operations
- Customer types, largest contracts, service dependencies, uptime promises, and potential customer loss
- Data types, record counts, payment activity, regulated information, hosting model, and geographic reach
Control evidence
- Completed application reconciled to the entire environment, including subsidiaries and acquisitions
- MFA, backup, patching, endpoint, logging, response, training, and vendor-control answers with scope and dates
- Independent assessment, penetration test, vulnerability report, or remediation summary when available
Incidents, contracts, and coverage
- Currently valued cyber, technology E&O, crime, and professional loss runs plus incident narratives
- Material customer contracts, limitation of liability, indemnity, service level, privacy, and security obligations
- Requested limits, retentions, retroactive date, dependent business, cybercrime, media, regulatory, and technology E&O needs
State where each control is deployed, which entities and systems it covers, who owns it, and when the answer was last verified. A yes response without scope can hide the exact gap that controls underwriting.
Use current CISA guidance.
CISA Cross-Sector Cybersecurity Performance Goals
CISA Small and Medium-Sized Business Resources
CISA Require Multifactor Authentication
CISA Use Logging on Business Systems
Sources reviewed 2026-08-29. Security guidance changes. Recheck the current source and the carrier's current application before relying on a control description.
Facts that affect placement.
- Technology vendors, managed service providers, payment, data, or critical-infrastructure exposure
- Weak controls, adverse claims, high limits, contractual liability, or unusual data volume
- Blended cyber, technology E&O, media, crime, or professional-liability needs
- Emerging technology, digital assets, artificial intelligence, or international operations
Coverage guidance does not confirm a current market route, quote, policy terms, or bind authority for a particular account.
Prepare a consistent underwriting file.
Explain the business and the breach together: what the insured promises, what it touches, who depends on it, how it is secured, what failed before, and which losses need coverage.
Include these facts
- Services, products, revenue, customer, contract, and data profile
- Security controls including multifactor authentication, backups, patching, and response planning
- Prior incidents, claims, contractual limits, and indemnification terms
- Requested cyber, technology E&O, media, crime, and dependent-business coverages
Resolve these questions before market review
- What services or products could fail and what would the customer lose?
- What data and systems are controlled, hosted, or accessed?
- Which security controls are deployed across the organization?
- What contracts, incidents, or coverage overlaps could change the placement?
Avoid these three issues.
- A control answer that applies to headquarters but not subsidiaries, cloud systems, or remote access
- No revenue split between software, services, hardware, consulting, and managed services
- Treating cybercrime, social engineering, tech E&O, and cyber liability as interchangeable
Forms and class guidance.
Hedge forms
Review the form and download a fillable PDF.
Class guidance
Public, directional appetite to help prepare for account-specific review.
Review related exposures.
Miscellaneous Professional Liability
The insured's promise is the exposure. Define the service before trying to insure the mistake.
Open coverageManagement Liability
The cap table, boardroom, balance sheet, and employment history all show up in the policy wording.
Open coverageProducts Liability
The product is the exposure. The supply chain tells us who owns the failure.
Open coverageSend the account for review.
You do not need a perfect packet to start. Send the account, requested line, effective date, current applications, available loss information, and the fact making the placement difficult. Hedge will separate missing information from market-ready information before any account-specific route is confirmed.