Skip to main content

Tech E&O vs Cyber Insurance: Which One Does Your IT Business Actually Need?

IT consultants and MSPs are routinely sold one and assume it covers the other. Here is the practical difference, and what happens when the wrong one is in place.

Written and reviewed by Irfan Usman, Insurance Broker at HIFA

RIBO licensed · Commercial broker at HIFA, focused on technology, warehousing and manufacturing risks.

Last reviewed July 2026 · 6 min read

An IT consultancy calls because a client's procurement team has asked for proof of insurance. They have a policy. What they usually do not have is the right one — or they have one of the two and believe it does the work of both.

Technology Errors and Omissions

E&O responds when your product or service fails to perform as promised and the client suffers financial loss as a result. A failed migration, a defect that corrupts data, an integration that misses the specification, advice that turns out to be wrong. The trigger is a claim by your client that your work cost them money.

Cyber liability

Cyber responds to the security incident itself. Forensic investigation, legal advice, notifying affected individuals, regulatory response, extortion costs where permitted, credit monitoring, and your own lost income while systems are down. The trigger is a breach, whether or not any client alleges you did anything wrong.

Where they overlap, and why that matters

A single incident routinely triggers both. Ransomware enters a client environment through a remote access tool you administer: the cyber policy addresses your own forensics, notification and downtime; the E&O policy addresses the client's claim that your negligence let it in. Carrying only one leaves half the exposure open — which is why many technology firms buy them as a combined policy from a single insurer. It also removes the argument about which policy responds.

The retroactive date is the detail that catches people

Both coverages are normally written on a claims-made basis. They respond to claims made during the policy period, arising from work performed after the retroactive date. If you change insurers and the new policy sets a fresh retroactive date, everything you delivered before that date stops being covered — silently, and usually without anyone mentioning it.

For a consultancy whose work has a long tail, this is the most consequential thing a broker does on a renewal or a move. Ask what your retroactive date is. If your business is five years old and the date is last January, you have a problem worth fixing.

What underwriters will ask you

Cyber underwriting has tightened considerably. Expect questions about multi-factor authentication on email and all remote access, whether backups are offline or immutable and when they were last tested by restore, endpoint detection and response, privileged access management, and patching cadence. Answering accurately matters twice: it determines the price, and an inaccurate answer can affect whether the policy responds.

Contractual liability caps do not remove the need for limits

A cap in your MSA helps, but it does not bind third parties who never signed it, and defence costs accrue regardless of the eventual outcome. Set limits against the realistic cost of defending a dispute, not only against the cap.

General information only. Coverage varies materially between insurers — review your own wording with a licensed broker.

Coverage availability, eligibility, limits and pricing vary by insurer and individual circumstances. Information on this website is general and is not a substitute for reviewing policy wording or speaking with a licensed insurance broker. Nothing on this site binds coverage or constitutes an offer of insurance.