Yes, and it is now part of the core stack rather than an add on. You hold customer production data, and a professional liability policy will not pay for forensics, notification, ransomware, or a fraudulent wire. Client contracts increasingly require it too. Who this is for: Software companies and development shops handling client data or client money.
The short version
- Cyber pays for incident response, business interruption, ransomware, and third party claims. Professional liability does not.
- Funds transfer fraud and social engineering are the most frequent losses, and they usually carry the lowest sublimits.
- Expect $1,500 to $9,000 a year for a small to midsize firm.
- Multifactor authentication and tested backups are now underwriting gates, not suggestions.
- Enterprise client contracts commonly require $1M in cyber liability before you can start work.
What you are holding
A software company typically holds customer production data, payment tokens, health or financial records depending on vertical, and source code. That is exactly the inventory a cyber policy exists to protect, and it is also what makes you a target. Attackers go after professional firms because you hold client data without a client's security budget.
What a cyber policy actually pays for
| Coverage part | What it does | Typical sublimit |
|---|---|---|
| Incident response | Forensics, legal counsel, and notification after a breach | Often the full limit |
| Business interruption | Lost income while systems are down | Full limit, with a waiting period of 6 to 12 hours |
| Ransomware and extortion | Ransom payment and negotiation, where lawful | $100K to full limit |
| Funds transfer fraud | Money you send because of a fraudulent instruction | $100K to $250K, often lower than you expect |
| Social engineering | Fraud where an employee is deceived into paying | $50K to $250K, frequently a separate sublimit |
| Third party liability | Claims by clients whose data you exposed | Full limit |
| Regulatory defense | Investigations and fines where insurable | Full limit or a sublimit |
The sublimits are where firms get surprised. A $1M cyber policy with a $100K social engineering sublimit pays $100K on a $340K wire fraud, and that is the most common cyber loss for professional services firms by frequency.
Where cyber and professional liability overlap
The same event can be both. If a breach at your firm exposes client data, the notification and forensics sit on cyber, while the client's claim that your negligence caused it can hit professional liability. For software companies and development shops specifically, a misconfigured storage bucket in a client environment is exactly the sort of event that involves both towers.
Buying both from one carrier, or at least aligning the retentions and the reporting requirements, avoids a coverage fight while you are already in the middle of an incident.
What carriers now require before they will quote
- Multifactor authentication on email and remote access. Without it, many carriers will not offer terms at all.
- Backups that are tested and stored separately from the production network.
- Endpoint detection and response on workstations and servers.
- Email filtering and a documented process for verifying payment instructions by phone.
- Timely patching, particularly of anything internet facing.
These are not best practice suggestions any more. They are underwriting gates, and putting them in place before you apply is usually worth more than shopping the price.
What this looks like in practice
Illustrative example. Numbers are typical of claims we see and are not a promise of how any specific claim would be handled.
The setup: A software company with a $1M cyber policy that carried a $100,000 social engineering sublimit.
The claim: The matter started with a misconfigured storage bucket in a client environment. 41,000 customer records were exposed and the client tendered the notification cost.
The cost: $78,000 in defense costs and $265,000 in settlement, $343,000 in total, paid inside the policy limit after the retention.
The lesson: The forensic and legal costs were covered in full, but the fraudulently transferred funds were capped at the sublimit. Reading the sublimits, not just the headline limit, is what makes a cyber policy useful.
Frequently asked questions
Q: Does a software company really need cyber insurance?
Yes, if you hold customer production data. Professional firms are targeted precisely because they hold valuable client data with smaller security budgets than their clients.
Q: Does my professional liability policy cover a data breach?
Rarely in full. Some forms include a small privacy sublimit, but incident response, notification, ransomware, and business interruption belong on a cyber policy.
Q: What does cyber insurance cost?
Commonly $1,500 to $9,000 a year for a small to midsize software company. Security controls now affect both price and whether a carrier will quote at all.
Q: What is the most common cyber claim for professional firms?
Funds transfer fraud and social engineering, where someone is deceived into wiring money to a fraudster. It is more frequent than ransomware and the sublimits for it are often much lower than the policy limit.
Q: Will my carrier require multifactor authentication?
Almost certainly. Multifactor authentication on email and remote access is now a baseline condition for most cyber quotes, and misrepresenting it on an application can void the coverage.
Q: Do my client contracts require cyber coverage?
Increasingly yes. Enterprise agreements and vendor security reviews commonly require $1M in cyber liability, and healthcare, financial, and public sector clients often require more.
How Morrow helps software companies and development shops
Morrow is a licensed independent commercial insurance brokerage that specializes in software developers & saas companies. Matching cyber sublimits to how your firm actually loses money is exactly the kind of question we answer every week, and because we place this coverage every day we know which carriers write it well, which forms are broad, and which contract language actually needs an endorsement behind it.
- We read the contract clause and tell you what your current policy already does and does not do.
- We market your account to carriers that have real appetite for software companies and development shops rather than whoever answers first.
- We issue certificates the same day a client asks, with the endorsements listed correctly.
- We stay on the file at renewal so limits, retroactive dates, and contract requirements do not quietly drift.
Get in touch and we will see how we can help. Tell us what you do, send over any contract that is driving the requirement, and send us the question and we will tell you where you stand. Start at morrowinsure.com or reach the team through the contact options on that page.
One more thing. This article is general information for software companies and development shops and is not legal advice, tax advice, or a statement of coverage. Policy wording controls in every case, and forms vary by carrier and by state. Have a licensed advisor review your own policy and your own contract before you rely on any of it.
Last updated: Reviewed by the Morrow commercial lines team. Last updated August 2026.
