Technology insurance. One policy for the claim a client makes, and the day your systems stop.
It is a different class of cover from a standard IT liability policy, not a bigger version of one, and the difference shows up on the day you need it.
Technology insurance puts professional indemnity, public liability and cyber cover in one policy. Which parts you actually hold is set by your schedule.
Not sure this is the right cover for you? See who this is for.
If you are a sole trader or a small IT consultant buying cover because a client contract asks for a certificate, the cover you want is the other one. See IT liability insurance.
What does technology insurance actually cover, and what does a standalone policy leave out?
Quick answerTechnology insurance is one contract holding three things: professional indemnity for the technology services you provide, public and products liability, and cover for your own losses after a cyber event, meaning incident response, business interruption, restoring your data, extortion response and cyber crime. A standalone professional indemnity or IT liability wording does not grant that last group in its base wording, and what your particular policy says about cyber is a question of its schedule and any endorsements on it.
The two parts most technology businesses already recognise. Professional indemnity answers the client who says your work, your advice or your code cost them money. Public and products liability answers injury to someone outside your business, or damage to their property. Both exist as policies in their own right, and what they cover, where their edges sit and how they are priced are set out on our professional indemnity insurance and public liability insurance pages. This page does not repeat any of it.
The part that defines the class. The third group is cover for your own losses, what the trade calls first party cover: the incident response and forensic work when something gets in, the cost of notifying the people whose data was exposed, your lost income while systems are down, restoring your own data, responding to extortion and ransomware, and fines from a privacy regulator where they are insurable. Those are the covers that fire in almost every real cyber claim, and they are the reason this product class exists at all. A combined policy of this kind is what brokers call a technology package.
An extension cannot manufacture a cover class. This is the point most owners miss when someone tells them their existing policy "can be extended for cyber". An insuring clause is the part of a policy that says "we will pay for this". An extension modifies an insuring clause the policy already has, and it cannot write in a promise to pay your own losses where the wording never made one. If the base wording contains nothing that pays your own losses, there is nothing for an extension to widen, and what you end up with is a broader liability cover rather than the cover that pays the forensic bill, the lost revenue and the data rebuild. That is a difference in class, not a difference in generosity.
Breaking a client contract is treated differently in this class. Standard professional indemnity wordings have traditionally reached liability you took on in a contract only by writing an exception back into an exclusion. Here, some wordings cover an unintentional breach of a client contract outright, as a section in its own right, and others make the contract exclusion simply inapplicable to the professional indemnity section. Cover written in as its own clause and cover reached only by an exception carved into an exclusion are not the same thing to read to a client. Two qualifiers do most of the work in that sentence. The first is unintentional: a deliberate or knowing breach sits outside the cover. The second is structural, because where that outright cover is built as a policy-wide exclusion with named sections written back in, a claim that lands outside those named sections is not covered. A separate exclusion for extended warranties can bite across the professional indemnity clause as well.
Your own unpaid fees are sometimes part of the deal, with a haircut. Several wordings in this market will pay fees you have not recovered, or have had to give up, to settle a dispute before it becomes a claim. The mechanics differ far more than the brochures do. Some strip nothing. Some cap the recovery at half the fee. Some strip the profit, the mark-up and the tax so that only your cost comes back, and at least one applies the same strip to fees you refund as to fees you recover, so a fee never comes back with margin on it in either direction. At least one pays only if you first obtain the client's written confirmation that they will not sue. None of that is visible from the name of the cover.
What a package is not. It is not a property policy wearing a different label. In one technology wording the cover that pays to reconstruct lost data requires a cyber event to have caused the loss, so records destroyed by a fire, or a box of files that goes missing, sit outside it. Property covers can be included in a package, but they are bought section by section like everything else in it, and often they are not bought at all.
And the schedule, not the wording, decides what you hold. Every product in this class is schedule driven. "The wording contains it" is never the same statement as "you have it", because the insuring clauses are purchased individually. The same rule settles the management liability question: some packages grant those covers, some have no grant at all, and at least one excludes the capacity outright, so the only honest answer is that the schedule decides. If that is the cover you are chasing, management liability insurance explains it properly.
Two doors: your occupation decides which technology cover an insurer will offer
Quick answerOccupation decides which product class you are shown, before price is ever discussed. Some insurers only offer their technology package to businesses operating in the technology sector, so a business outside it is not being judged harshly, it is outside the product. How your activity is described decides which door opens.
There are two doors here, not one product at two prices. Standard IT and ICT liability wordings sit behind the first. They are built for the contract-driven buyer: a client asks for professional indemnity of a certain amount, the certificate is what closes the deal, and the wording answers claims made against you about your work. Technology packages sit behind the second. They are built for the business whose whole operation stops when its systems stop, and whose clients' data is sitting on its servers. IT liability insurance covers the first door in full, and this page is about the second.
Occupation gating is real, and it happens first. Whether an insurer will put its technology package in front of your business at all is a product availability decision, not a pricing one, and it is made before anyone looks at your revenue, your controls or your claims history. In the same way, how your activities are described drives both how the risk is rated and, on some products, whether it can be quoted at all. Getting that description accurate is not paperwork, it is the thing that decides which products your business is even eligible for.
You cannot see the doors from outside. The occupation classes that open one product and close another are not published anywhere a buyer can read them. That is why the same business can be told no by one insurer and quoted comfortably by the next, and why "I got a quote online and it looked expensive" is usually a statement about which door the form put you through rather than about your risk. Our job is to know which door your business fits through, and to put the risk in front of underwriters who keep that door open.
These are different classes of cover, not a good version and a cheap version. It would be neater to say the two classes serve completely different markets, and it would not be true. On occupation they overlap heavily, and a fifteen-person software firm is a live prospect for both. What actually separates them is the problem you are solving and what the contract grants: a certificate that satisfies a client, or an integrated response to the day your systems stop. Compare the two on price alone and you are comparing two different things that happen to be sold by the same industry.
Who has outgrown a standard IT liability policy?
Quick answerNo revenue figure answers this. The markers are structural: you hold client data, your income stops when your systems stop, clients now ask for evidence of cyber cover rather than a professional indemnity certificate alone, your contracts carry service credits or warranty obligations, or you hold administrative access to other businesses' systems.
You hold client data, and losing it is your problem before it is theirs. A liability wording answers what you owe someone else once they claim. It does nothing about the first two weeks: the forensic investigation, the legal advice on whether the breach is notifiable, the notifications themselves, the call centre, the credit monitoring, the regulator. Those costs land immediately, they land on you, and they land whether or not anybody ever sues.
Your income stops when your systems stop. For a business that sells its time, an outage is an inconvenience. For a business whose product is delivered through its own systems, an outage is the revenue. A standard liability wording has nothing to say about your own lost income, because that is not what it was built to do.
Your clients have started asking a different question. The contracts that used to ask for a professional indemnity limit now ask for evidence of cyber cover, incident notification timeframes, and sometimes for specific covers by name. When your clients' procurement teams have moved on and your policy has not, the certificate you hold stops being the one you are being asked for.
Your contracts carry teeth. Service credits, delay penalties and warranty obligations turn an ordinary project overrun into a defined sum of money you owe. Whether any of that is insurable is a genuinely open question that depends on the wording in front of you, which is why it has its own answer further down this page.
You hold administrative access to other businesses' systems. That is a different risk shape from everything above, and it gets its own section below.
One caution, because it runs both ways. This class is not a superset of a standard wording, and nobody honest will tell you it is. Standard IT and ICT wordings in this market can carry defence costs in addition to the limit rather than inside it, long lists of automatic extensions, tiered discovery periods and a one-off reinstatement of the limit. Those are real advantages, and this class does not match them uniformly. Moving a business that is well served where it is, purely because a package sounds more complete, is an expensive way to change nothing. The judgement is which problem you are actually solving, and that is a conversation rather than a calculation.
If your business is content-led rather than systems-led, a production company, a publisher, an agency or an events business, the weighting you want sits somewhere else again. See media liability insurance. And if you are not in the technology sector at all but want cover for a data breach, cyber insurance is the standalone version of the cyber covers described on this page.
The four questions that separate one technology package from another
Quick answerThe product name tells you almost nothing. Four questions separate these wordings: whether the cyber crime cover reaches staff who are deceived as well as systems that are broken into, whether business interruption triggers on your own mistakes and not only on attacks, whether limits stack across sections or one ceiling governs, and which covers carry a smaller cap than the headline number.
One. Does the cyber crime cover reach social engineering, or only hacking? These are two different events and only one of them involves a break-in. A staff member deceived by a convincing email into paying a fake invoice has used their own legitimate access, correctly, on the wrong instruction. Nothing was hacked. In this market some package wordings reach social engineering as standard and others reach it only by endorsement, which means the most common loss of the lot can sit outside a policy that was sold as covering cyber crime. Some wordings also condition the cover, above a threshold, on the payment having carried a documented authorisation, and a typed name at the foot of an email is not one. Knowing which of those your wording does is worth more than knowing the limit. The generic version of this question, for any business rather than a technology one, is answered on our cyber insurance page.
Two. Does business interruption trigger on your own mistakes, or only on an attack? Packages in this class generally carry a trigger for non-malicious events somewhere in the wording, so a failed migration or a configuration error can respond. The reach is narrower than the phrase suggests, and this is where "covers human error" becomes a half-truth. In one technology wording the non-malicious triggers reach only the income-loss sections: a botched migration produces cover for your lost revenue, but not the cost of rebuilding the data or replacing hardware that will not restart. In the same wording, operator error expressly excludes errors in the design or architecture of systems, which is a large part of what a technology business does all day. Anyone describing a package as covering human error owes you the second half of that sentence.
Three. Do the limits stack, or does one ceiling govern? Clients hear a limit and assume it is available section by section. The convention across this market runs the other way: where a single claim is covered under more than one section, the highest single limit applies rather than the sum of them. Beyond that, the same headline number is built differently across these wordings. In one it is a ceiling across every responding section. In another, two sections share it and the professional indemnity agreement is capped at half. In a third, each section carries its own limit beneath a combined single limit. Then the endorsement page can cap what the schedule appears to give. And whether defence costs sit inside the limit or on top of it is, on some of these products, a schedule election rather than a feature of the product, which is one of the questions someone has to ask on your behalf before the policy is bound.
Four. Which covers carry a smaller cap than the headline number? The architecture differs at the root. One wording in this market states no dollar sublimits at all and defers every amount to the schedule, while others cap named covers inside the wording itself. Either way the consequence is the same: the name of a cover tells you nothing about the money behind it. The same cover name can carry very different limits in different sections of one policy. The only document that answers this is your schedule, read alongside the wording rather than instead of it.
Four mechanics that are easy to miss. One policy can run three different triggers side by side, so some clauses respond to when the event happened, some to when you discovered it, and some to when the claim was made against you, which changes what has to be reported and by when. Some wordings make the incident response limit available in addition to the overall limit rather than inside it. Some cap what you pay in excesses across a whole policy year at the single highest section excess, which matters in a year with more than one claim. And a service written into the wording is a policy entitlement, while a service that appears only in the brochure is marketing.
Insurance for managed service providers
Quick answerA managed service provider holds administrative access to other businesses' systems, so one compromise runs through every client at once. Most of the resulting loss belongs to the clients, which makes it a liability exposure and not only a loss of your own, and an ordinary small business cyber policy is not written for it.
You hold the keys. In our experience managed service providers are one of the fastest growing groups in technology and one of the riskiest, for a reason that is not complicated: you hold the keys to all of your clients' information systems. Every efficiency that makes the model work, one management platform, one set of privileged credentials, one deployment tool that reaches every client at once, is the same thing that makes a single compromise expensive.
One event, many claims, all at the same time. Most cyber losses run in sequence: something gets in, you find it, you fix it, you count the cost. For a managed service provider the chain runs in parallel. A compromise of the management plane takes down every client's systems at once. Every client's staff sit idle at once. Every client stops trading at once, from a single event. And most of that loss is not yours. It belongs to your clients, and they will come looking for it. That is precisely why a cyber policy written to protect your own data does not answer this exposure. It answers your loss, not theirs.
Why an ordinary small business cyber policy is the wrong answer here. Standard small business cyber wordings are written for a business that uses IT, not for one that sells it. Read the liability section of a widely used Australian wording of that type and you find an exclusion for actions brought against you because information technology services you provide, maintain, service or manage for a third party for a fee have failed, which is close to a definition of managed services. Be precise about where that sits: the exclusions applying across the whole of a policy like that are the narrower ones, covering recall, redesign or rectification of what you supply and warranties you have given, while the broad exclusion sits in the liability section, which is exactly where a managed service provider would be relying on it. There is a structural tell as well. Products of that kind are drafted from the point of view of a business that has an IT contractor, down to cover for a cyber event inside your IT contractor's business. The insured they imagine is your client, not you.
You are on both sides of the dependency. You are the supplier whose outage interrupts your clients. You are also a dependent business, because your own cloud vendors, your remote monitoring platform and your backup provider can take you down without anyone touching your network. A wording that answers one direction and not the other leaves half of the real exposure outside the policy.
The packages answer the one-event-many-clients problem in three different ways. Some route widespread or systemic events into their own smaller caps. Some exclude systemic causes outright. At least one grants dependent business interruption, which is cover for an outage at a supplier you rely on, as an explicit clause. Which of the three your wording does is a wording question, and it is not answered in a brochure.
Expect harder questions, and answer them exactly. The proposal questions put to a managed service provider go further than most technology businesses see: patching, how a change of bank details gets verified, who is allowed to authorise a payment. Some products in this market go further again and make cover conditional on controls of that kind. Whether yours does is in the wording rather than the brochure, and an answer given loosely at proposal is the answer an insurer reads again after a loss.
There is no separate managed service provider policy in this market, and no page here pretending there is one. What a managed service provider buys is a technology package arranged around the concentration risk that comes with holding other people's systems, and whether the dependency is answered in both directions is one of the wording questions to settle before the policy is bound.
Technology Insurance Australia: your questions answered
What is technology insurance?
What is the difference between technology insurance and IT liability insurance?
Does technology insurance include cyber insurance?
Do I still need a separate cyber policy if I have a technology package?
What insurance does a managed service provider need?
Why won't every insurer quote my business for a technology package?
Does a technology package cover human error and system failure, or only attacks?
Why don't the limits in a technology package add up?
Does a technology package cover a staff member being tricked into paying a fake invoice?
Does a technology package cover liquidated damages and service credits?
How much does technology insurance cost?
Related cover and reading
The information on this page is general in nature and does not take into account your objectives, financial situation or needs. Before acting on it, consider whether it is appropriate for your circumstances. Where the information relates to a particular insurance product, consider the relevant Product Disclosure Statement before making a decision.
Last reviewed: 23/08/2026
Find out which door your business fits through.
Tell us your name, your number and what you need, and we will take it from there. If a standard IT liability policy is still the right cover for your business, we will say so.
Call now, most enquiries are settled in one conversation - or leave your details and we'll ring within 90 minutes on a new enquiry (8am–6pm Mon–Fri).