FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

Insurance for established software and technology companies

An established technology company should review Tech E&O and cyber as a coordinated program, not as interchangeable labels. Enterprise contract obligations, outage scenarios, cloud dependencies, customer concentration, acquisitions, and new AI features determine which terms and limits deserve attention. Higher limits are individually evaluated brokerage options and remain subject to placement availability.

Who this page is for

For a revenue-generating software or technology company with $10M+ in annual revenue, insurance decisions increasingly follow enterprise contracts, service dependencies, acquisitions, and changing products. A senior broker can examine how the company operates, compare policy wording, and explore individually evaluated limits where the exposure supports them.

This review is different from buying a standardized startup policy. It starts with the actual services, data, customer promises, and revenue concentrations that could turn one failure into a material claim.

Discuss your technology program with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

Translate enterprise contracts into insurance questions

An enterprise master service agreement can change the insurance review before a policy application is opened. The broker should map indemnity obligations, insurance minimums, additional insured requests, and limits-of-liability caps. These clauses do different work: indemnity allocates responsibility between the parties; an insurance clause asks for evidence of a policy; an additional insured request seeks rights under another party's policy; and a liability cap limits contractual damages only to the extent its wording applies. A certificate does not reconcile inconsistencies among them.

The review should identify whether a customer asks for $5M per claim or a $5M annual aggregate of Tech E&O, whether cyber may share that amount, and whether defense costs reduce it. It should also compare the contract's description of the service with the policy's insured-services definition. More limit does not broaden a definition that omits implementation, analytics, managed services, or a newly launched feature.

Contract terms establish one floor, but concentration changes the scenario. If one enterprise customer represents a large share of annual revenue, an outage, failed deployment, or dispute with that customer can create both lost income and a demanding claim. The review therefore considers termination rights, service credits, indemnity carve-outs, and liability-cap exceptions alongside insurance requirements.

Model service failure, outage, and cloud dependencies

Tech E&O generally addresses allegations that a technology product or service failed to perform as promised, subject to the form's definitions and exclusions. Cyber coverage commonly addresses defined security, privacy, response, and interruption events. A single outage can implicate both: customers may allege service failure while the company incurs its own restoration costs and lost income. The broker should test how the policies allocate that event rather than assume both headline limits apply.

Cloud hosting, identity, payments, source-code repositories, and other critical vendors create dependent exposure. For each dependency, the review asks which provider and event qualify, whether a waiting period applies, how long loss is measured, and whether contingent or dependent business interruption carries a sublimit. A $5M cyber annual aggregate is not $5M for a cloud outage if that coverage has a lower sublimit.

Operational evidence matters. Architecture diagrams, recovery objectives, vendor contracts, incident plans, and a realistic daily-income calculation help turn a general outage concern into a limit discussion. The NIST Cybersecurity Framework is a useful risk-management reference, but following a framework does not establish that a particular policy responds.

Treat AI features as changes to the insured service

Adding an AI feature can change what the product does and what information it handles. A feature that summarizes customer records, generates decisions, or sends data to a model provider may alter the service definition, data flows, contractual warranties, and dependency map. The insurance review should not treat “AI” as one generic hazard; it should document the feature, its users, human oversight, inputs, outputs, and third parties.

Product and legal teams should flag launches before renewal and material midterm changes when reporting is required. The broker can then examine whether the declared services remain accurate, whether exclusions or intellectual-property provisions affect the feature, and whether privacy and network-security coverage reflects newly handled data. This is policy analysis, not a conclusion that every output error or data dispute is insured.

Changes in release cadence also matter. A company moving from a narrow workflow tool to an embedded decision platform may have a different severity profile even if annual revenue has not changed. Customer testing, contractual acceptance, rollback controls, and concentration among users of the new feature belong in the submission narrative.

Should cyber and Tech E&O share a limit?

Cyber and Tech E&O may be written in one policy with a shared annual aggregate, in one policy with separate limits, or through two carriers. A shared $5M annual aggregate means a covered cyber event can reduce the amount left for a later E&O claim. Separate limits can preserve capacity, but definitions, retentions, notice provisions, and exclusions still need comparison. Two carriers create an additional coordination question when one event could implicate both policies.

The broker should compare claims-made reporting rules, defense-cost treatment, consent provisions, retroactive dates, and other-insurance wording. With two carriers, the company needs a notice protocol that does not rely on one carrier to notify the other. With one carrier, administrative simplicity does not eliminate the possibility of a shared aggregate or a dispute over which coverage section applies.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.

What additional revenue and operational scale change

Additional revenue often arrives with more enterprise contracts, users, data, employees, and geographic reach. Those changes can increase customer concentration or reduce it; revenue alone does not reveal which. A senior review updates peak transaction volume, outage-loss estimates, record counts, largest customers, service commitments, and critical vendors, then checks whether retentions, sublimits, and a $3M or $5M per-claim and annual-aggregate structure still fit those scenarios.

Acquisitions require prompt attention. The broker should identify the acquired entity, date, revenue, products, historical services, claims, and prior insurance. Automatic-acquisition provisions may be limited by size, activity, or a reporting window. The company also needs to understand whether prior acts of the acquired business are covered, whether its entities are named insureds, and whether run-off coverage remains necessary.

Revenue reporting to carriers should match the policy's basis and the organization's current structure. Estimates, audited figures, and acquired revenue may be treated differently. A material change should be reported when the policy or acquisition provision requires it; waiting for renewal can jeopardize clarity over terms without creating any assurance that a carrier will accept the change.

Scale can also change governance exposure. New investors, a larger leadership group, or a transaction may justify a separate D&O review, but a D&O limit should not be added to Tech E&O or cyber to describe one pool of coverage. Each policy answers a different allegation and has its own insureds, exclusions, retention, and aggregate.

Established-company review versus startup-stage needs

An early-stage company may reasonably need a fast, standardized way to satisfy its first customer contract. The site's separate $1M/$2M cyber and Tech E&O program serves that earlier stage under its stated terms. It must not be described as a source of $3M, $5M, or higher limits.

An established revenue-generating company usually needs a different process: contract sampling, claims and acquisition history, customer and vendor concentration analysis, service-definition review, and deliberate coordination of cyber and Tech E&O. Individually evaluated higher-limit brokerage options may use primary and excess policies, but availability, attachment, and wording must be confirmed.

For limits, distinguish a $5M per-claim Tech E&O limit from a $5M annual aggregate and from a $5M excess layer. The appropriate comparison asks what the enterprise contract requires, what a multi-customer failure could cost, whether defense erodes the limit, and whether cyber shares it. No one amount is implied by the company's revenue.

Hypothetical scenario: Hypothetical review: a $60M B2B software company

A hypothetical B2B software company with roughly $60M in annual revenue is renewing its largest enterprise contract. That customer requires a $5M per-claim Tech E&O limit and a $5M cyber limit. The review should determine whether the limits must be separate, whether annual aggregates and defense costs satisfy the wording, and whether an umbrella is incorrectly being assumed to apply.

The broker would also examine the customer's indemnity and liability-cap provisions, the policy's insured-services definition, cloud-dependent interruption sublimits, and whether this customer's revenue concentration changes the failure scenario. Recent AI features and any acquisition must be reported accurately. This is a list of what needs review, not a statement that a policy would respond.

What your senior broker should examine

  • Which enterprise contracts impose indemnity, insurance minimums, additional insured requests, or exceptions to limits-of-liability caps?
  • What would a multi-day outage cost, and which cloud or service-provider failures are subject to a waiting period or sublimit?
  • How much annual revenue depends on the largest customers, and could one service failure affect several of them at once?
  • Do new AI features change the insured service, data handled, warranties, or third-party dependencies?
  • Are cyber and Tech E&O limits shared or separate, and how would notice work if two carriers could receive the same matter?
  • Have acquisitions, acquired revenue, new entities, and prior acts been reported within applicable policy deadlines?

Questions businesses ask

Does a commercial umbrella increase Tech E&O or cyber limits?

Ordinarily, a casualty umbrella sits above scheduled liability policies such as general liability, auto liability, and employers liability. Tech E&O and cyber require their own limits or excess layers where available; the underlying schedule and wording control.

Is one combined cyber and Tech E&O policy preferable?

Not automatically. One policy may simplify administration, but it can carry a shared annual aggregate. Separate policies may preserve limits but require careful coordination of definitions, notice, and overlapping events.

When should an acquisition be reported?

Review the policy before closing and follow its acquisition notice requirements. Automatic coverage may depend on the acquired company's size or activities and may last only for a stated period, so the specific provision controls.

Does adding an AI feature require a new policy?

Not necessarily, but it requires review. The feature may change the insured service, information handled, vendor dependencies, and contractual promises, all of which should be compared with current definitions and exclusions.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.