The short version
- Cyber: your costs and liability when your systems or data are attacked or exposed.
- Technology errors and omissions (tech E&O): liability when the technology products or services you sell fail or cause a client a financial loss.
- Professional liability (E&O) for non-tech firms: liability for mistakes in your professional services, such as accounting, design, or consulting.
- Crime: your own money, securities, and property stolen, including by employees, plus certain fraudulent transfers.
- The overlaps are where claims go wrong. Wire fraud can fall under cyber, crime, both, or neither. A client's breach caused by your IT work can fall under cyber, tech E&O, or both. Coordinating the policies matters more than having all of them.
The three policies side by side
| Cyber | Tech E&O | Crime | |
|---|---|---|---|
| Core question | Were our systems or data attacked or exposed? | Did our technology product or service fail a client? | Was our money or property stolen? |
| Whose loss | Yours (first-party) and claims against you (third-party) | Your clients' financial losses, claimed against you | Yours |
| Typical events | Ransomware, data breach, system outage, privacy lawsuit | Software bug, failed implementation, missed deadline, security failure in a product you provide | Employee embezzlement, forged checks, computer or funds transfer fraud |
| Covers employee theft | No | No | Yes |
| Covers wire fraud | Often, under a social engineering or funds transfer sublimit | No, unless it causes a client claim | Often, under computer fraud, funds transfer fraud, or a social engineering endorsement |
| Typical buyers | Nearly every business | Software, SaaS, IT services, managed service providers, developers | Businesses with employees handling money, and anyone moving large payments |
Where the overlaps are
Wire fraud and fake invoices
Business email compromise is one of the most expensive frauds businesses face. The FBI's Internet Crime Complaint Center logged 21,442 business email compromise complaints in 2024, with reported losses of more than $2.77 billion. Coverage can sit in two places:
| Scenario | Cyber policy | Crime policy |
|---|---|---|
| A hacker gets into your bank portal and sends money out | Funds transfer fraud, if included | Computer fraud or funds transfer fraud |
| An employee is tricked by a fake "vendor" email into wiring money | Social engineering, if included, usually sublimited | Social engineering endorsement, if added, usually sublimited |
| Your hacked email sends customers a fake invoice and they pay the criminal | Invoice manipulation, if included | Usually not covered |
| An employee steals by sending payments to themselves | No | Employee theft |
Because both policies often carry sublimits and different conditions, such as requiring a call-back to verify payment changes, line up the wording so a loss is not denied by both. Some businesses put social engineering under one policy deliberately and leave it off the other.
A client's breach caused by your work
For technology companies, one incident can trigger both policies:
| What happens | Policy that usually responds |
|---|---|
| Your own network is breached and your client data is exposed | Cyber (breach response, privacy liability) |
| Your software flaw lets attackers into a client's systems, and the client sues | Tech E&O, and possibly cyber network security liability |
| Your IT outage stops your client's operations, and the client sues for lost income | Tech E&O |
| Your own systems are down and you cannot serve clients | Cyber (business interruption) |
This is why most insurers sell combined tech E&O and cyber policies to technology businesses. One form avoids arguments between two insurers about which one owes the claim. Check whether the combined limit is shared between the two parts.
Professional services firms
Accountants, attorneys, consultants, architects, and agencies carry professional liability for mistakes in their services. Two cyber-related exposures can fall between policies:
- A client wires money to a criminal after receiving fake instructions from your hacked email. The client may claim you were negligent. Professional liability may or may not respond, and some forms exclude cyber-related claims.
- Your firm's breach exposes client data. That is generally a cyber claim, not a professional liability claim.
Ask your broker how your professional liability and cyber policies treat each one. See the law firm story and CPA firm story for how this plays out.
Which combination fits your business?
| Business | Cyber | Tech E&O or professional liability | Crime |
|---|---|---|---|
| Retail shop or restaurant using a payment processor | Recommended | Not usually needed | Worth considering if staff handle cash or deposits |
| Medical, dental, or wellness practice | Strongly recommended (health data) | Medical malpractice is separate | Worth considering for billing staff |
| Accounting, law, or consulting firm | Strongly recommended | Professional liability needed | Recommended if you handle client funds or a trust account |
| Software, SaaS, or IT services company | Strongly recommended | Tech E&O needed, often combined with cyber | Recommended as headcount grows |
| Contractor or trades business | Recommended if you take deposits or wire payments | Not usually needed | Recommended for payment and payroll fraud |
| Property manager or real estate office | Strongly recommended (wire fraud risk on deposits and closings) | Professional liability often needed | Recommended |
| Nonprofit | Recommended (donor and client data) | Directors and officers is the related policy | Recommended (employee theft and donation fraud) |
This is a starting point, not a recommendation for any particular business. Contracts often settle the question: client agreements frequently require specific limits for cyber, professional liability, or both.
How to buy them so they work together
- Start with an inventory of how money moves: who can send wires, approve vendors, and change bank details.
- Decide where social engineering lives, cyber or crime, and make sure the sublimit is meaningful.
- For tech businesses, prefer a combined tech E&O and cyber form, or at least the same insurer for both.
- Check the "other insurance" clauses so two policies do not each point to the other.
- Match retroactive dates on claims-made policies when you renew or switch.