Usually the first contract requirement
A client says the work failed
A defect, an integration that broke something, a recommendation that cost money, a milestone missed. The allegation is about the service itself and the loss is the client’s.
Moon Insurance Managers, Inc. · TDI license #5595
Most technology companies arrive at this subject the same way: a customer contract lands, it names two coverages nobody in the building has heard of, and the deal is waiting.
There is no single “technology insurance” policy. There is a set of decisions a technology company faces, answered by separate coverages. This page sorts them and points each one at the page that answers it properly.
If something is happening right now
A live security incident is not a quoting conversation. Follow your own response plan, preserve evidence, tell your current insurer under its reporting terms, and get legal advice — the cyber liability page sets out the order and the Texas reporting duty. Then call us on (281) 484-8320.
The two the contract names
Contracts routinely require technology E&O and cyber, and it is not duplication. They answer different questions, and the dividing line is what caused whose loss:
The reason contracts ask for both is that a single incident can be both. A defect in your software that also exposes customer records is one event and two very different allegations, arriving from two different directions. Neither policy is a substitute for the other, and neither page is repeated here.
Sources: NAIC — cybersecurity topic; NAIC — insurance for small business. Verified .
The whole list
Not all of these apply to every firm, and working out which do is the entire point of a review. Each one is answered somewhere else on this site, in proper depth.
Usually the first contract requirement
A defect, an integration that broke something, a recommendation that cost money, a milestone missed. The allegation is about the service itself and the loss is the client’s.
The other half of the same contract
A breach, ransomware, business-email compromise, a privacy event, the cost of restoring data, or downtime caused by a security incident rather than by damage to a building.
Still applies to software companies
An office, a client site, a conference stand, a visitor. Contracts frequently require it regardless of how little physical work the business does.
Laptops travel
Leased space, tenant improvements, servers, and a fleet of laptops that mostly live in other people’s buildings. Often packaged with liability for smaller firms.
A Texas decision, not a default
Whether to carry compensation coverage is genuinely optional for most private employers in Texas, and the consequences of each choice are specific enough to be worth reading rather than assuming.
Arrives with headcount
Applicants, employees and former employees. Technology firms hire fast, restructure often, and are not exempt from any of it.
Field service, mostly
Relevant for firms whose people drive to client sites, and worth a question about employees using their own cars for work even where the business owns none.
Once governance exists
Allegations about leadership and governance decisions become a live question as soon as there are outside shareholders or a formal board.
One more that catches growing firms out: if a covered event ever closes the office or damages the equipment, the lost-income question belongs to business interruption insurance — a different trigger from cyber downtime, and a different conversation.
Worth checking early
Technology companies routinely end up holding other people’s regulated information without having worked out what that obliges them to. Two of the common ones are worth naming, because both come with duties that exist whether or not anyone bought insurance.
If your product or service touches health information on behalf of a covered entity, the business-associate rules are likely to be relevant to you directly. If you serve financial-services customers, the FTC Safeguards Rule sets information-security obligations and treats service providers as part of that picture. Neither of these is something we can determine for you — but knowing to ask changes what the insurance conversation looks like, and it changes what the application will ask you to attest to.
Sources: HHS — HIPAA business associates; FTC — Safeguards Rule guidance. Verified .
Before you sign
The limit is the part everyone reads and rarely the only requirement. A serious clause may also name specific coverages, set a retroactive date no later than a given point, require additional insured status, ask for primary and non-contributory wording, or set notice-of-cancellation terms.
And the order of operations matters: a certificate evidences insurance and cannot alter, amend or extend what a policy provides. If the contract requires something, the policy and its endorsements have to actually provide it before the certificate can report it.
Source: TDI — certificates of insurance FAQ. Verified .
No obligation
The review goes quickly when it starts from the operation rather than from a product list:
From that we can tell you which of these decisions actually apply to your firm, which you can skip, and what a submission would need — which is usually the more useful half of the answer. The phone is fastest: (281) 484-8320, or use the form below.
Monday to Thursday, 9:00 to 5:00; Friday, 9:00 to 4:00. 360 FM 1959, Houston, TX 77034. Policies written statewide — you do not have to be local.
No. It is a shorthand for the set of decisions a technology company faces, and the decisions are answered by separate policies. Some of them can be packaged together, which is a structural question rather than a change to what each coverage does. Anyone selling you "technology insurance" as a single product is naming a bundle, and it is worth asking exactly which coverages are inside it.
What caused whose loss. If a client says the work, the advice or the delivery failed and cost them money, that is a professional liability question. If the event was a breach, ransomware, a privacy incident or a network-security failure, that is a cyber question. One incident can raise both — a defect that also exposes customer records is the standard example — which is exactly why customer contracts increasingly require both rather than treating them as alternatives.
Start with the two the contracts name: the professional liability question and the cyber question. Then work outward — general liability, the premises and equipment, whether compensation coverage is being carried, employment allegations as headcount grows, vehicles if anyone drives for work, and governance coverage once there is outside money or a board. Not all of them apply to every firm, and the point of a review is finding out which do.
The contracts, above all. Managed-services agreements tend to set obligations about uptime, access, data handling and required insurance that shape every other answer. Beyond that: what you manage versus what you advise on, which client systems you can reach, whose data passes through your tools, and whether your people work at client sites.
No. Using a major provider changes where some of the risk sits; it does not transfer your obligations to your own customers, and an outage or incident at a provider can still stop your service and generate your claims. Whether a policy responds to a third party’s incident is a form question, and it is one of the more important ones to ask before binding.
Read the whole insurance clause rather than the limit in it — it may also require specific coverages, a retroactive date, additional insured status or notice terms. And note the order of operations: a certificate evidences insurance and cannot alter, amend or extend what a policy provides. The coverage has to exist first; the certificate reports it.
Moon Insurance Managers, Inc. — 360 FM 1959, Houston, TX 77034 — (281) 484-8320