Sector · 04

Insurance for technology companies

The one sector where the product delivered takes up no space, the damage leaves no physical trace and the claim arrives, almost always, as purely financial loss.

01Overview

What it is

A technology company has the risk profile of an industrial one turned inside out. Its physical assets are modest and replaceable; what is valuable is the code, the data it holds on behalf of third parties and the continuity of the service it has promised under contract. Classic property covers therefore protect very little of what can actually go wrong, and the weight of the programme shifts towards cyber risk and towards liability for the service delivered.

The second particularity is its legal position. In most B2B contracts the technology company acts as processor of its client's personal data: it does not decide about that data, but it answers for how it is handled and for what happens to it. That status moves part of the regulatory risk of every client served onto its own balance sheet, multiplied by the number of clients.

Request a review of your cover

Speak to a technical adviser: 932 419 400

At a glance

Breach notification
72 hours
Maximum GDPR fine
€20M or 4%
Scope
Domestic and international
Broker registered with the DGSFP
J0140

A technology company inverts the usual risk profile. Its physical assets are modest and replaceable; what is valuable is the code, the data it holds on behalf of third parties and the continuity of a service promised under contract. Classic property covers therefore protect very little of what can actually go wrong.

Regulatory risk multiplies by client

In most B2B contracts the technology company acts as processor: it does not decide about the personal data, but it answers for how it is handled. That has a counter-intuitive consequence: a single breach in its infrastructure triggers the notification obligation of each and every affected client.

The General Data Protection Regulation allows 72 hours from becoming aware to notify the supervisory authority, and requires communication to the data subjects without undue delay where the risk to them is high. That clock runs for the controller —the client— but the party holding the facts and the forensic evidence is the supplier. Processing agreements tend to pass the consequence back up the chain.

It is also worth separating two penalty tiers that most commercial content conflates: failing to notify is sanctioned under article 83(4), up to €10 million or 2% of worldwide turnover; infringing the principles or data subjects' rights falls under 83(5), up to €20 million or 4%.

The typical loss leaves no physical trace

A failed implementation, a calculation error in an algorithm or a badly executed migration produce pure financial loss: cost overruns, delays, processes that have to be redone. No general liability policy responds to that, because it excludes it by definition.

And there is a boundary better written into the contract than into the policy: penalties for breaching a service-level agreement are commercial risk, not insurable loss, and policies exclude them. What is insurable is the loss the failure causes beyond the agreed penalty.

Selling to government changes the requirements

When the company bids for a public tender, three requirements arrive together and to a deadline: compliance with the National Security Framework, the definitive guarantee, and a liability certificate with minimum limits and the exact wording the tender documents call for. The last two are resolved within the insurance programme; the first is not, but it arrives in the same envelope.

Why through a broker

As a broker registered with the Spanish Directorate-General for Insurance and Pension Funds under reference J0140, New Brokers works on the client's mandate, not on behalf of any insurer.

In technology the work starts before the policy: in the client contracts. That is where it is settled what liability is assumed, which penalties are accepted and which data protection obligations are passed on. An insurance programme that has not been read alongside those contracts covers a different risk from the one the company has signed up to.

02Risk map

What this sector is exposed to

  • Client data breach

    Compromise of information the company holds on behalf of third parties. It multiplies regulatory risk by the number of clients served and triggers very short deadlines.

  • Service outage and service-level penalties

    The downtime that breaches a service-level agreement, with contractual penalties a policy rarely covers and which should be told apart from insurable loss.

  • Development or implementation error

    The functional failure that causes the client a financial loss with no physical damage. It is the central exposure and the one general liability excludes.

  • Ransomware on own and client infrastructure

    Encryption that halts not only the company's own operation but that of the businesses depending on the service, with a cascading effect.

  • Dependence on cloud providers

    The outage of an infrastructure provider the whole service relies on, which does not happen on the company's own premises and calls for an express extension.

  • Intellectual property and third-party components

    Claims for improper use of code, incompatible licences in dependencies or trademark infringement in the delivered product.

  • Key-talent loss and directors' liability

    Management decisions in companies with funding rounds and a board, where the arrival of a fund usually brings a requirement for directors' cover.

  • Collection and client concentration

    The subscription model concentrates recurring revenue in a few accounts, and one significant non-payment hits cash before it shows in the income statement.

03Obligations

What the law requires of you

The obligations that, in this sector, trigger the purchase of a specific cover.

RuleWhat it requires
General Data Protection Regulation, arts. 33 and 34View the legislationRequires notification of a security breach to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to rights and freedoms, and communication to the data subjects without undue delay where the risk to them is high.
General Data Protection Regulation, art. 83View the legislationIt draws a distinction between two penalty tiers that are routinely conflated: failing to notify a breach is sanctioned under article 83(4), up to €10 million or 2% of total worldwide annual turnover; infringing the principles of processing or data subjects' rights falls under 83(5), up to €20 million or 4%. The higher amount applies.
Royal Decree 311/2022, National Security FrameworkView the legislationGoverns the Spanish National Security Framework (ENS) in the field of electronic administration. It reaches technology suppliers serving the public sector, whose certification or compliance conditions access to those contracts.
Act 34/2002, on information society servicesView the legislationSets out the information, commercial communications and electronic contracting duties of information society service providers, along with the liability regime for intermediaries.
Directive (EU) 2022/2555, NIS2View the legislationIt does not require anyone to buy insurance. It raises cybersecurity risk-management requirements and reinforces the responsibility of the management bodies of entities within its scope, which is what connects cyber risk to the directors' policy.

New cover

Request a proposal and terms

We analyse your activity and your real exposure before approaching the market.

Request a proposal

Existing client

Download your certificate

Your certificates, policies and requests are available in the client area.

Go to the client area
04Use cases

When you will be asked for it

  1. Breach at the supplier, obligation on the client

    An incident in the technology company's infrastructure exposes personal data belonging to several of its clients, who are the ones holding controller status.

    What it means

    The 72-hour clock runs for the controller, but the party holding the facts is the processor. The quality and speed of the forensic work determine whether the client can meet its obligation, and the contract between them usually passes that consequence back to the technology company.

  2. Implementation error with cost overrun and no physical damage

    A badly executed migration forces the client to redo processes, buy in external hours and delay its own launch.

    What it means

    There is no physical damage, so general liability does not respond. This is professional indemnity territory, and the most disputed item is usually whether the policy covers only the loss caused or also the rectification of the supplier's own work.

  3. Public-sector contract and ENS compliance

    The company bids for a public tender requiring compliance with the National Security Framework and, in the same tender documents, a definitive guarantee and minimum liability limits.

    What it means

    The three requirements arrive together and to a deadline. The guarantee is arranged through surety without consuming a bank line, and the liability certificate must be issued with the exact wording the tender documents call for.

06Common questions

Frequently asked questions

What insurance does a software company need?

The core is two contracts: cyber risk, covering data breach, ransomware and business interruption, and professional indemnity, which answers for the financial loss a development or implementation error causes the client. On top of that come D&O where there is a board or investors, credit and surety where the company sells to the public sector or has concentrated billing, and property cover for the offices. The scope of each is governed by the specific terms of each policy.

We are processors, not controllers. Does the GDPR still affect us?

Yes, and in a particular way: the notification deadline runs for the controller —your client— but the party holding the facts and the forensic evidence is you. In practice, processing agreements pass much of that consequence to the supplier, so a breach in your infrastructure becomes a contractual exposure towards as many clients as you have. That is why regulatory risk multiplies in this sector.

Does insurance cover penalties for breaching a service-level agreement?

Normally not. Agreed contractual penalties are commercial risk, not insurable loss, and policies tend to exclude them expressly. What can be covered is the financial loss the failure causes the client beyond the penalty, and the costs of responding to the incident. Telling the two apart when negotiating client contracts matters as much as the policy itself.

What does the National Security Framework require of a supplier?

Royal Decree 311/2022 governs the National Security Framework in the field of electronic administration, and its scope reaches technology suppliers serving the public sector. In practice, compliance or certification becomes a condition of access to those contracts, and it arrives in the same tender documents as the guarantees and the minimum liability limits.

Does NIS2 oblige us to buy any insurance?

No. Directive (EU) 2022/2555 does not require anyone to buy insurance. What it does is raise cybersecurity risk-management requirements and reinforce the responsibility of the management bodies of entities within its scope. That heavier duty on management is precisely what connects cyber risk to the directors' policy.

What documentation do you need to prepare a proposal?

A description of the services and the product, the volume and type of personal data processed and on behalf of how many clients, the infrastructure and cloud providers relied on, the security measures and backup policy, standard client contracts with their service-level agreements, and turnover with its concentration by client.

Related analysis

This information is for guidance only and is not binding. Covers, limits and exclusions are governed in all cases by the specific terms of each policy. New Brokers Correduría de Seguros, S.L., registered with the DGSFP under reference J0140.