Cyber & Technology Guide
What Cyber Insurance Does a SaaS Company Need?
There is no single "SaaS insurance" policy. A software company's program centers on two linked coverages — cyber liability and technology errors & omissions — that come online the moment you store customer data and sign your first contracts. This guide explains what each covers, what underwriters require, the limits SaaS companies carry at each revenue stage, and what it costs in 2026, using current figures from named industry sources.
The short answer
Most SaaS companies need a combined cyber liability and technology errors & omissions (Tech E&O) policy. Cyber covers breach response, ransomware, regulatory defense, business interruption, and funds-transfer fraud; Tech E&O covers claims that your software failed to perform. Limits typically start at $1M–$2M and scale with revenue, the data you hold, and what enterprise customer contracts require.
Do SaaS companies need cyber liability insurance?
Almost always. If you store customer data in the cloud, cyber liability is the core policy. It pays for breach response, ransomware, regulatory defense, and business interruption when an attack or outage takes your platform down. The stakes are large: the global average cost of a data breach reached a record $4.99M in 2026, up 12% in a single year. Median premium of about $2,900 a year, ranging from $1,000 to $8,800 (Vouch, 2026). Roughly half of startups carry it. For established small businesses, cyber runs a median of about $129 a month (Insureon).
What does Tech E&O cover for a SaaS company?
Technology errors & omissions covers claims that your product or service failed to perform — an outage, a defect, a missed SLA, or a data error that caused a customer financial harm. For a SaaS company this is the policy that answers a customer's breach-of-contract or failure-to-deliver claim, and enterprise buyers increasingly require it before signing. Median premium of about $3,700 a year, ranging from $1,300 to $12,400 (Vouch, 2026). Most SaaS companies buy it combined with cyber on a single form to keep premium efficient and avoid gaps between the two.
Should a SaaS company combine cyber and Tech E&O?
Usually, yes. Most carriers offer a combined cyber + Tech E&O form for technology companies. Bundling keeps premium efficient and removes the gap that can open between a standalone cyber policy and a standalone professional liability policy when a single incident — say, an outage that also exposes data — triggers both at once. Priced as a single combined form rather than two premiums; see our Tech E&O vs Cyber Liability comparison for how the two coverages overlap and where they differ.
Does cyber cover funds-transfer fraud and business email compromise?
Often through a sublimit, and it matters more than founders expect. Business email compromise (BEC) and funds-transfer fraud (FTF) — where an attacker impersonates a vendor or executive to redirect a payment — drove the majority of cyber claims in 2024. Confirm the social-engineering and funds-transfer sublimit on your cyber policy, and add crime coverage if the sublimit is thin. Usually a sublimit inside the cyber policy rather than a separate premium. Coalition reported 60% of 2024 claims came from BEC or FTF, with 29% of BEC events ending in a funds transfer — so the sublimit size is worth negotiating.
What cyber security controls do underwriters require?
Carriers now price cyber on the strength of your controls. Multi-factor authentication, endpoint detection and response (EDR), tested backups, a patching cadence, and an incident-response plan are the baseline most underwriters expect before they offer competitive terms — and companies that can prove SOC 2 or ISO 27001 controls can qualify for preferred pricing. Strong controls lower premium and widen capacity; weak controls raise both. See our Agency Controls Qualified Coverage program for how validated SOC 2 / ISO 27001 controls earn preferred Cyber + Tech E&O terms.
When does a SaaS company need D&O insurance?
Usually at a priced round. Directors & officers (D&O) insurance protects founders' and board members' personal assets against claims tied to running the company — investor disputes, governance decisions, and regulatory actions. It is not a cyber coverage, but investors typically require it as a condition of a priced funding round, so it lands on the SaaS program early. Median premium of about $6,300 a year, ranging from $3,000 to $16,800, driven mainly by how much capital you have raised (Vouch, 2026).
What cyber limits does a SaaS company need at each stage?
Pre-revenue / pre-seed — $1M combined — Storing the first customer data; early pilots — MFA, tested backups Early ARR (under $1M) — $1M–$2M — First paid customers and SaaS contracts — MFA, EDR, backups, patching cadence Growth ($1M–$10M ARR) — $2M–$5M — Enterprise MSAs requiring specific limits and AI language — EDR, incident-response plan, vendor management Scale ($10M+ ARR) — $5M–$10M+ — Regulated data, multi-tenant exposure, larger contracts — SOC 2 / ISO 27001, formal IR, penetration testing
What cyber limits does a SaaS company need at each stage?
- Pre-revenue / pre-seed — $1M combined — Storing the first customer data; early pilots — MFA, tested backups
- Early ARR (under $1M) — $1M–$2M — First paid customers and SaaS contracts — MFA, EDR, backups, patching cadence
- Growth ($1M–$10M ARR) — $2M–$5M — Enterprise MSAs requiring specific limits and AI language — EDR, incident-response plan, vendor management
- Scale ($10M+ ARR) — $5M–$10M+ — Regulated data, multi-tenant exposure, larger contracts — SOC 2 / ISO 27001, formal IR, penetration testing
Typical SaaS insurance premiums.
- Cyber Liability — Median $2,900; $1,000 – $8,800.
- Technology E&O / Professional Liability — Median $3,700; $1,300 – $12,400.
- Directors & Officers (D&O) — Median $6,300; $3,000 – $16,800.
- Employment Practices Liability (EPLI) — Median $4,300; $1,330 – $13,400.
The SaaS coverage stack, answered.
- Cyber Liability — Almost always. If you store customer data in the cloud, cyber liability is the core policy. It pays for breach response, ransomware, regulatory defense, and business interruption when an attack or outage takes your platform down. The stakes are large: the global average cost of a data breach reached a record $4.99M in 2026, up 12% in a single year.
- Technology E&O — Technology errors & omissions covers claims that your product or service failed to perform — an outage, a defect, a missed SLA, or a data error that caused a customer financial harm. For a SaaS company this is the policy that answers a customer's breach-of-contract or failure-to-deliver claim, and enterprise buyers increasingly require it before signing.
- Combined Cyber + Tech E&O — Usually, yes. Most carriers offer a combined cyber + Tech E&O form for technology companies. Bundling keeps premium efficient and removes the gap that can open between a standalone cyber policy and a standalone professional liability policy when a single incident — say, an outage that also exposes data — triggers both at once.
- Funds-Transfer Fraud / Social Engineering — Often through a sublimit, and it matters more than founders expect. Business email compromise (BEC) and funds-transfer fraud (FTF) — where an attacker impersonates a vendor or executive to redirect a payment — drove the majority of cyber claims in 2024. Confirm the social-engineering and funds-transfer sublimit on your cyber policy, and add crime coverage if the sublimit is thin.
- Controls-Qualified Coverage — Carriers now price cyber on the strength of your controls. Multi-factor authentication, endpoint detection and response (EDR), tested backups, a patching cadence, and an incident-response plan are the baseline most underwriters expect before they offer competitive terms — and companies that can prove SOC 2 or ISO 27001 controls can qualify for preferred pricing.
- Directors & Officers (D&O) — Usually at a priced round. Directors & officers (D&O) insurance protects founders' and board members' personal assets against claims tied to running the company — investor disputes, governance decisions, and regulatory actions. It is not a cyber coverage, but investors typically require it as a condition of a priced funding round, so it lands on the SaaS program early.
Frequently asked questions
How much does cyber insurance cost for a SaaS company?
It depends on revenue, the data you hold, and your security controls, but across 3,000+ startups in 2026 Vouch reports a median cyber premium of about $2,900 a year (range $1,000–$8,800) and a median Tech E&O premium of about $3,700 (range $1,300–$12,400). Most SaaS companies buy the two combined, so a typical early-stage combined program often runs in the low-to-mid four figures, rising with ARR and limits.
What is the difference between cyber insurance and Tech E&O?
Cyber insurance covers losses from a security incident — a breach, ransomware, or data exposure — including your own response costs and third-party claims. Tech E&O covers claims that your product or service failed to perform as promised, such as an outage or a defect that caused a customer financial harm. Most SaaS companies need both, which is why carriers usually combine them. See our full Tech E&O vs Cyber Liability comparison for a side-by-side.
What cyber security controls do underwriters require?
The baseline most carriers expect is multi-factor authentication on all access, endpoint detection and response (EDR), tested and offline backups, a regular patching cadence, and a documented incident-response plan. Companies that can demonstrate SOC 2 or ISO 27001 controls can qualify for preferred pricing — that is the basis of our Agency Controls Qualified Coverage program.
What cyber limits do enterprise SaaS contracts require?
Enterprise master service agreements (MSAs) commonly require specific cyber and Tech E&O limits — often $1M–$5M depending on the data involved — plus additional-insured or waiver-of-subrogation language. The fastest way to know is to share the insurance section of the contract; an advisor can map each requirement to the coverage and endorsements your policy needs.
Does cyber insurance cover funds-transfer fraud and business email compromise?
Usually through a sublimit rather than the full policy limit. Because business email compromise and funds-transfer fraud drove 60% of cyber claims in 2024 (Coalition, 2025), the size of that social-engineering and funds-transfer sublimit matters — confirm it on your policy and add crime coverage if it is thin.
When should a SaaS startup buy cyber insurance?
Usually as soon as you store customer data or sign your first software contract — often before a customer's security review or SOC 2 questionnaire forces it. A combined cyber + Tech E&O form is typically the first technology policy a SaaS company buys, with D&O following at the first priced round.