Key Takeaways
- Four insurance lines touch software risk, and each is built around a different trigger. Technology professional liability turns on failure in the service delivered to a client, cyber on an information security event, directors and officers on the personal liability of management, and crime and fidelity on funds that left the company.
- The most important seam runs between professional liability and cyber. A platform that produces a wrong calculation and harms a client is examined under the professional line even where the security environment is entirely sound, while an intrusion exposing client data is examined under cyber. That very same fault can carry both labels when it begins with a security event and continues as a faulty service.
- The management layer joins later and with growing force. The SEC’s 2023 disclosure rules require public companies to describe how the board exercises oversight of cyber risk, and a 2026 report found that the number of AI related claims in the United States grew by 978% between 2021 and 2025.
- Israel adds a separate layer of duties alongside the contractual demands. The Privacy Protection (Data Security) Regulations set duties covering access management, incident record keeping and reporting a severe security incident to the Privacy Protection Authority, and Amendment 13 to the Privacy Protection Law widened enforcement powers. In parallel, the insurance addendum in the client contract determines which lines are required and at what limits, and a certificate of insurance shows the match.
The Map of Lines: What Each One Is Built to Respond To
Every insurance line has its own trigger, and that trigger derives from the definitions in the wording rather than from the feelings of whoever absorbs the loss. A software company selling to business clients carries operational, professional, management and financial exposure at once. The map below sets out the four central lines alongside two adjacent lines that appear in client insurance addenda.
Cyber Insurance
This line responds to an event originating in information security. It is built to carry the immediate costs of forensic investigation, legal counsel, client notification and regulatory response, alongside third party liability for unauthorised access to data. Its boundary runs through the nature of the event: where the origin lies in the delivery of the professional service itself, the discussion moves to another line, subject to the policy wording.
Technology Errors and Omissions (Tech E&O)
This line responds to a client’s claim that the product or service delivered fell short of professional standards. Defective code, a failed implementation, a missed availability target or a fault that caused the client financial loss all fall inside this area even where the security environment remained intact. Where the cover stops is loss originating outside the professional act, such as bodily injury or damage to physical property.
Directors and Officers Liability (D&O)
This line responds to the personal liability of directors and officers for management decisions and for representations. In a technology context it enters the picture when investors or a regulator allege inadequate disclosure, weak oversight of cyber risk, or a representation that diverged from the state of controls on the ground. The SEC’s 2023 disclosure rules require public companies to report a material incident within four business days of the materiality determination and to describe how the board exercises oversight of cyber risk, while the proposal to require disclosure of board level cyber expertise was dropped from the final rule.
Crime and Fidelity
This line responds to theft of company funds or assets, whether by an external party or by an employee. The common scenario is an email impersonating a senior executive or a supplier, leading to a bank transfer into an account the attacker controls. The boundary runs through the definition of fraud and through who executed the transfer, so the distinction between a deceived employee and the attacker changes which clause responds.
General Liability
This line responds to bodily injury and damage to third party property arising from the company’s physical activity. Software companies meet it mainly through insurance addenda in client contracts and lease agreements, which is why it appears in certificate of insurance requirements even where the whole operation is digital.
Employment Practices Liability (EPLI)
This line responds to claims by employees and candidates alleging discrimination, harassment, wrongful dismissal and related grounds. At technology companies it enters the picture during rapid hiring and rapid reduction cycles, and at times in parallel with a management liability file opened against the same officers.
The four central lines and the two adjacent ones, by trigger, exposure and limitation:
| Insurance line | What it is built to respond to | Example of exposure | The limitation worth knowing |
| Technology Errors and Omissions (Tech E&O) | Failure in the delivery of the technology service or product measured against professional standards, including a missed availability target | A SaaS platform produces incorrect financial reports through a calculation error, and clients claim business loss | Scope is set by the definition of technology services in the wording, alongside the enhanced contractual undertaking exclusion |
| Cyber Insurance | An information security event: intrusion, ransomware, data leakage and outage originating in a network event | An attacker encrypts the production environment, and the company needs forensics, client notification and restoration | The definition of the network event and its start date govern application, and fines are examined under applicable law and the wording’s exclusions |
| Directors and Officers Liability (D&O) | Personal liability of officers for management decisions, representations and disclosure duties | Investors allege that the funding round representation on controls diverged from what the incident revealed | Cover turns on the definition of a claim and the notification date, and exclusions apply against proven fraud |
| Crime and Fidelity | Theft of company funds or assets by an external party or by an employee | A payroll controller sends a payment to a fraudulent supplier account after an impersonation email | The distinction between a transfer made by a deceived employee and one made by the attacker changes which clause responds, and client funds are examined separately from company funds |
| General Liability | Bodily injury and third party property damage arising from the company’s physical activity | A visitor is injured at the company’s offices, or client equipment is damaged during installation on site | The area is aimed at physical loss, so pure financial loss originating in a software failure is examined under the professional liability line |
| Employment Practices Liability (EPLI) | Employee and candidate claims alleging discrimination, harassment and wrongful dismissal | A former employee sues following a rapid reduction carried out after an incident hit revenue | Cover focuses on employment grounds, while a derivative claim against the same managers is examined under the directors line |
One Incident, Four Insurance Lines
A single incident at a software company generates a client claim, an investor claim, a loss of funds and response costs all at once. Each component lands with a different line, so allocation between the policies becomes part of managing the claim. The scenario below illustrates the seam.
A cloud payroll platform serving two hundred business clients absorbs a ransomware attack that encrypts its production environment. The service is down for five days, and the company brings in external investigators, legal counsel and a client notification operation. During the restore from backup part of the data comes back corrupted, and in the following month twelve clients issue incorrect payroll payments. In parallel, an attacker holding access to the finance director’s mailbox sends a payment request in the name of an existing supplier, and the money leaves the account. Three weeks later investors ask why the representation made in the last funding round described controls that were only partly operating. By the end of the quarter the company is running four files against four insurers. Every one opens on the same first day.
The loss is one, while the record that determines who pays sits split across four wordings.
Allocating the components of the loss between lines, and the counter argument that creates the dispute:
| Component of the loss | The line called on to respond | The argument that allocates the loss elsewhere | What governs in the wording |
| Forensics, legal counsel, client notification and system restoration | Cyber, as the first file opened | Improvements carried out at the same time are argued to be upgrades rather than restoration | The definition of response costs against the definition of betterment, and the start date of the network event |
| Client claim over a missed availability target and financial loss from the outage | Technology errors and omissions | The counter argument ties the outage to the network event and directs it to the cyber policy | The definition of technology services, and the enhanced contractual undertaking exclusion |
| Incorrect payroll payments produced by data corrupted during restoration | Technology errors and omissions | The counter argument treats restoration as part of handling the incident and directs the loss to cyber | The chain of causation between the event and the wrongful act, and the definition of the professional act in the wording |
| Investor claim over the funding round representation on the state of controls | Directors and officers | The counter argument presents the loss as a direct result of the incident and directs it to cyber | The definition of a claim, the notification date and the personal profit exclusion in the D&O wording |
| Funds transferred to a fraudulent supplier account while the attacker held mailbox access | Crime and fidelity | The counter argument directs the transfer to the cyber policy because of the origin of the intrusion | The definition of fraud, the identity of whoever executed the transfer, and the email fraud clauses in both wordings |
| A fine or enforcement process following information security shortcomings | Examined under applicable law and under the cyber and D&O wordings | The counter argument separates a fine on the company from defence costs of an individual officer | Whether the fine is insurable under the law, and the scope of defence cost cover per wording |
Where the Gaps Between Wordings Fall
Most disputes fall in three fixed places: the definition of the event, the notification date, and exclusions written to prevent double cover. Buying cyber and professional liability from the same insurer narrows the room for argument, while buying separately calls for a comparison of definitions before signature. The coverage basis adds a layer: most of these lines are sold on a claims made basis, so an event in one period and a claim in another demand attention to the retroactive date and the discovery period. Changing insurer midway creates exactly this gap.
The gap between wordings almost always surfaces after the incident, once it is too late to change a definition.
The broker (LAMDA Broking) compares the definitions across the cyber, professional liability and directors wordings within the same programme, in order to locate scenarios that fall between covers. Working through the Lloyd’s market allows wordings and dedicated endorsements to be tailored for software companies, subject to underwriting and to policy terms. Run off cover for professional liability is examined in the same breath, because exposure to a service delivered in the past outlasts the engagement.
Contractual and Regulatory Seams
The client contract effectively determines which lines are required and at what limits. The insurance addendum in an enterprise contract usually asks for cyber and professional liability together, at times general liability as well, and a certificate of insurance is the document showing that the policy matches the requirement. Israel runs a separate layer of duties in parallel: the Privacy Protection (Data Security) Regulations require access management, incident record keeping and reporting a severe security incident to the Privacy Protection Authority, and Amendment 13 to the Privacy Protection Law widened enforcement powers. On the management side, the Companies Law governs the limits of exemption and indemnity for officers, so the directors policy is examined against the indemnity undertakings the company actually issued. A company listed in Israel adds the requirements of the Israel Securities Authority, and one listed in the United States the SEC disclosure rules.
The numbers explain why the three central lines are reviewed together. Data from 2026 points to an average cost of roughly 5 million dollars per data breach, a record, up 12%, and a 2026 report found that the number of AI related claims in the United States grew by 978% between 2021 and 2025. A software company embedding AI components in its product sits at the point where professional exposure and management exposure grow alongside operational exposure.
Common Mistakes
- Assuming a cyber policy covers every software risk scenario, and discovering the seam when a client brings a contractual claim.
- Buying cyber and professional liability from two different insurers without comparing the definitions and the notification dates.
- Reporting an incident to one line and waiting to see what happens, instead of notifying every line that may respond.
- Overlooking the retroactive date when changing insurer, then finding that a claim about an older service falls in a period no longer covered.
- Winding down an activity or selling a product line without examining run off cover for the professional liability period.
- Signing an insurance addendum in a client contract without checking whether the policies carry the limits and lines demanded.
- Treating the fraud definition in the crime policy and the email fraud clause in the cyber policy as two separate subjects.
- Assuming an indemnity undertaking for an officer removes the need for a directors policy, without examining the limits of the Companies Law and the company’s liquidity.
Frequently Asked Questions
We bought cyber insurance. Do we also need technology professional liability?
The two lines are built around different triggers. Cyber deals with an information security event, while professional liability deals with a client’s allegation of failure in the service or product. A platform that calculates incorrectly and harms a client is examined under the professional line even where security is intact, which is why software companies selling to business clients usually buy both, subject to the policy wording.
What happens when the same incident falls between two policies?
An allocation dispute opens, and each insurer examines the scenario against the definitions in its own wording. The outcome rests on the chain of causation, the start date of the event and the date the claim was brought. Buying both lines from the same insurer, or a difference in conditions clause between the wordings, shortens the discussion, subject to underwriting and to policy terms.
Does the cyber policy respond to money transferred after an impersonation email?
The answer depends on the wording. Some cyber wordings include an email fraud clause at a relatively low sub limit, while a crime and fidelity policy is built specifically for loss of funds. The distinction that decides matters in practice is between a transfer made by a deceived employee and one made by the attacker, so both wordings should be read together before an incident.
When does directors cover enter the picture in a cyber incident?
When the allegation is directed personally at officers rather than at the company alone. The usual allegations are inadequate disclosure, weak oversight of cyber risk, or a representation that diverged from the state of controls. The SEC’s 2023 disclosure rules require public companies to describe how the board exercises oversight of cyber risk, and private companies meet a similar expectation from investors during due diligence.
What does a claims made basis mean for these lines?
The policy responds to claims brought during the policy period rather than to events that occurred in it. The retroactive date therefore sets how far back acts are examined, and the discovery period allows notice of a claim arriving after the period ends. Changing insurer without preserving the retroactive date is the quickest way to create a gap, so it is checked at every renewal.
What does Israel require beyond the contractual demands?
The Privacy Protection (Data Security) Regulations set duties covering access management, incident record keeping and reporting a severe security incident to the Privacy Protection Authority, and Amendment 13 to the Privacy Protection Law widened enforcement powers. On the management side, the Companies Law governs the limits of exemption and indemnity for officers. These requirements sit in parallel with the contract’s insurance addendum and the certificate of insurance derived from it.
Do AI components in the product change the coverage picture?
They add a question that is tested at every renewal. Some wordings introduced broad artificial intelligence exclusions in recent years, and how these sit against the product a company sells calls for careful reading. In parallel, marketing representations about model capability can reach the directors line, so it pays to keep marketing material aligned with what the product actually does.
Software risk spreads across four insurance lines built around different triggers, so the quality of the protection is set by how the definitions in the wordings fit together rather than by how many policies sit in the file.
The above is general information only and does not constitute insurance, legal or other professional advice. Terms of cover, exclusions and duties are determined by the specific policy wording and subject to applicable law. Each case should be examined on its own facts against the policy wording and with a qualified adviser.




















































































































































