Cyber Insurance vs Tech E&O vs Professional Indemnity: What Actually Covers What
Cyber Insurance vs Tech E&O vs Professional Indemnity: What Actually Covers What
If you run a business that touches software or client data, sooner or later someone tells you that you need "cyber insurance". Then a broker mentions "tech E&O". Then a client contract demands "professional indemnity". These three policies overlap just enough to be thoroughly confusing, and buying the wrong one means discovering the gap at the worst possible moment: after the incident.
Here is the plain-language version of what each policy does, where they overlap, and how to decide what you need.
The three policies in one sentence each
Cyber insurance (also called cyber liability insurance) covers incidents involving your systems and data: hacking, ransomware, data breaches, and the costs that follow.
Technology errors and omissions (Tech E&O) covers claims that your technology product or service failed and caused your client financial loss: your software had a bug, your platform went down, your integration corrupted their data.
Professional indemnity (PI) (called professional liability or E&O in the US) covers claims that your professional advice or service was negligent: an accountant's error, a consultant's bad recommendation, an architect's flawed design.
The confusion exists because "cyber liability" and "cyber insurance" are the same thing, while "tech E&O" is essentially professional indemnity for technology companies. And modern policies increasingly bundle these together.
Which policy pays: incident by incident
| Incident | Cyber | Tech E&O | PI |
|---|---|---|---|
| Ransomware locks your systems | Yes | No | No |
| Employee clicks phishing, attacker steals client data | Yes | No | No |
| Your SaaS platform goes down, clients lose revenue | No | Yes | No |
| A bug in your code corrupts a client's database | No | Yes | No |
| Your consultant gives advice that costs the client money | No | No | Yes |
| Attacker breaches YOUR product and through it your clients | Partly | Partly | No |
| CEO fraud: finance wires money to a fake supplier | Cyber, if the policy includes cyber crime cover | No | No |
| Regulator fines you after a data breach | Cyber, where insurable | No | No |
The last rows show why the boundaries matter. A supply-chain attack through your product sits exactly on the border between cyber (a breach) and tech E&O (your product failed your clients). If you carry both policies with different insurers, expect them to argue about whose claim it is. This is the strongest practical argument for buying combined cover.
The overlap is real, and insurers know it
The market has responded to this confusion in a practical way: combined products. In the Ryskly catalog of 682 cyber insurance products across 57 countries, 24% include Tech E&O cover combined with the cyber policy. For technology companies this is increasingly the default recommendation: one insurer, one policy wording, no arguments about which policy responds.
For non-technology companies the equation is different. A manufacturer or a law firm does not need tech E&O, but may very much need both PI and cyber as separate policies.
How to decide what you need
You sell software, SaaS, IT services or development work. You need tech E&O and cyber, ideally combined. Your clients' contracts will often demand both anyway.
You sell professional services (consulting, accounting, legal, design). You need PI as your core policy, plus cyber, because you hold client data and email is your main attack surface.
You run any business with revenue, staff and data. Cyber is the baseline. Ransomware and payment fraud do not care what industry you are in.
A client contract demands "professional indemnity" from your software company. In practice they usually mean tech E&O. Ask the broker for tech E&O wording; it is written for exactly your failure modes.
Three details worth checking in any of these policies
First-party vs third-party cover. First-party pays your own costs (recovery, forensics, downtime). Third-party pays claims against you from others. Cyber policies typically include both; check the sub-limits separately, they often differ a lot.
Cyber crime and funds transfer fraud. Social engineering losses (fake invoices, CEO fraud) are not automatically covered by every cyber policy. In our catalog, only 49% of products include cyber crime or funds transfer fraud cover. If money leaves your account because someone was tricked, only this cover pays.
Retroactive date. E&O and PI policies cover claims made during the policy period for work done after the retroactive date. If you switch insurers carelessly, work done in past years can silently fall out of cover.
FAQ
Is cyber liability insurance the same as cyber insurance?
Yes. "Cyber liability insurance", "cyber insurance" and "cyber risk insurance" are marketing variations of the same product category. The exact scope always comes from the policy wording, not the name.
Can one policy cover cyber, tech E&O and PI together?
For technology companies, yes: combined cyber and tech E&O policies are common, and 24% of the products we track offer exactly that. Full three-way combinations exist but are rarer and usually mid-market or larger.
Which one does a freelancer or micro-business need?
Usually PI if clients can claim your work caused them loss, and a small cyber policy if you handle client data or invoices by email. Several insurers now sell simple bundles for exactly this segment.
Does professional indemnity cover data breaches?
Generally no. Some PI policies include a thin cyber extension, but it is usually limited. If data and systems matter to your business, a dedicated cyber policy is the reliable route.