Cyber Insurance vs Tech E&O vs Crime Insurance: Which Do You Need?

Cyber insurance covers breaches, ransomware, system downtime, and privacy claims. Technology errors and omissions covers claims that software or IT services you provide failed or caused a client a loss. Crime insurance covers stolen money and property, including employee theft. Most businesses need cyber; tech companies usually add tech E&O; anyone moving large payments should coordinate cyber with crime.

By Trella Commercial · Updated October 3, 2026

The short version

  • Cyber: your costs and liability when your systems or data are attacked or exposed.
  • Technology errors and omissions (tech E&O): liability when the technology products or services you sell fail or cause a client a financial loss.
  • Professional liability (E&O) for non-tech firms: liability for mistakes in your professional services, such as accounting, design, or consulting.
  • Crime: your own money, securities, and property stolen, including by employees, plus certain fraudulent transfers.
  • The overlaps are where claims go wrong. Wire fraud can fall under cyber, crime, both, or neither. A client's breach caused by your IT work can fall under cyber, tech E&O, or both. Coordinating the policies matters more than having all of them.

The three policies side by side

CyberTech E&OCrime
Core questionWere our systems or data attacked or exposed?Did our technology product or service fail a client?Was our money or property stolen?
Whose lossYours (first-party) and claims against you (third-party)Your clients' financial losses, claimed against youYours
Typical eventsRansomware, data breach, system outage, privacy lawsuitSoftware bug, failed implementation, missed deadline, security failure in a product you provideEmployee embezzlement, forged checks, computer or funds transfer fraud
Covers employee theftNoNoYes
Covers wire fraudOften, under a social engineering or funds transfer sublimitNo, unless it causes a client claimOften, under computer fraud, funds transfer fraud, or a social engineering endorsement
Typical buyersNearly every businessSoftware, SaaS, IT services, managed service providers, developersBusinesses with employees handling money, and anyone moving large payments

Where the overlaps are

Wire fraud and fake invoices

Business email compromise is one of the most expensive frauds businesses face. The FBI's Internet Crime Complaint Center logged 21,442 business email compromise complaints in 2024, with reported losses of more than $2.77 billion. Coverage can sit in two places:

ScenarioCyber policyCrime policy
A hacker gets into your bank portal and sends money outFunds transfer fraud, if includedComputer fraud or funds transfer fraud
An employee is tricked by a fake "vendor" email into wiring moneySocial engineering, if included, usually sublimitedSocial engineering endorsement, if added, usually sublimited
Your hacked email sends customers a fake invoice and they pay the criminalInvoice manipulation, if includedUsually not covered
An employee steals by sending payments to themselvesNoEmployee theft

Because both policies often carry sublimits and different conditions, such as requiring a call-back to verify payment changes, line up the wording so a loss is not denied by both. Some businesses put social engineering under one policy deliberately and leave it off the other.

A client's breach caused by your work

For technology companies, one incident can trigger both policies:

What happensPolicy that usually responds
Your own network is breached and your client data is exposedCyber (breach response, privacy liability)
Your software flaw lets attackers into a client's systems, and the client suesTech E&O, and possibly cyber network security liability
Your IT outage stops your client's operations, and the client sues for lost incomeTech E&O
Your own systems are down and you cannot serve clientsCyber (business interruption)

This is why most insurers sell combined tech E&O and cyber policies to technology businesses. One form avoids arguments between two insurers about which one owes the claim. Check whether the combined limit is shared between the two parts.

Professional services firms

Accountants, attorneys, consultants, architects, and agencies carry professional liability for mistakes in their services. Two cyber-related exposures can fall between policies:

  • A client wires money to a criminal after receiving fake instructions from your hacked email. The client may claim you were negligent. Professional liability may or may not respond, and some forms exclude cyber-related claims.
  • Your firm's breach exposes client data. That is generally a cyber claim, not a professional liability claim.

Ask your broker how your professional liability and cyber policies treat each one. See the law firm story and CPA firm story for how this plays out.

Which combination fits your business?

BusinessCyberTech E&O or professional liabilityCrime
Retail shop or restaurant using a payment processorRecommendedNot usually neededWorth considering if staff handle cash or deposits
Medical, dental, or wellness practiceStrongly recommended (health data)Medical malpractice is separateWorth considering for billing staff
Accounting, law, or consulting firmStrongly recommendedProfessional liability neededRecommended if you handle client funds or a trust account
Software, SaaS, or IT services companyStrongly recommendedTech E&O needed, often combined with cyberRecommended as headcount grows
Contractor or trades businessRecommended if you take deposits or wire paymentsNot usually neededRecommended for payment and payroll fraud
Property manager or real estate officeStrongly recommended (wire fraud risk on deposits and closings)Professional liability often neededRecommended
NonprofitRecommended (donor and client data)Directors and officers is the related policyRecommended (employee theft and donation fraud)

This is a starting point, not a recommendation for any particular business. Contracts often settle the question: client agreements frequently require specific limits for cyber, professional liability, or both.

How to buy them so they work together

  1. Start with an inventory of how money moves: who can send wires, approve vendors, and change bank details.
  2. Decide where social engineering lives, cyber or crime, and make sure the sublimit is meaningful.
  3. For tech businesses, prefer a combined tech E&O and cyber form, or at least the same insurer for both.
  4. Check the "other insurance" clauses so two policies do not each point to the other.
  5. Match retroactive dates on claims-made policies when you renew or switch.

Common questions

What is the difference between cyber insurance and tech E&O?

Cyber insurance covers your losses and liability when your own systems or data are attacked or exposed. Tech E&O covers claims that the technology products or services you provide to others failed or caused them financial loss. Technology companies usually need both and often buy them combined.

Does cyber insurance cover employee theft?

No. Theft of money or property by your own employees is covered by a crime policy under employee theft coverage. Cyber insurance focuses on outside attacks, data breaches, and privacy claims.

Does crime insurance cover wire fraud?

Often, depending on the insuring agreements. Computer fraud and funds transfer fraud coverage respond when an outsider moves money without your authorization. When an employee is tricked into sending money, most crime policies require a social engineering endorsement, usually with a lower sublimit.

Do I need both cyber and crime insurance?

If your business moves meaningful amounts of money by wire or ACH, or employees handle funds, the two together close gaps neither closes alone. Cyber covers the breach, ransomware, and liability side; crime covers employee theft and many fraudulent transfers.

Is professional liability the same as tech E&O?

Tech E&O is professional liability written for technology businesses. It covers failures of software, systems, and IT services. Other professional liability forms cover mistakes in accounting, legal, design, consulting, and similar services, and they often exclude technology and cyber claims.

Sources

This page is general information. How a loss is covered depends on the wording of your actual policies. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.