Cyber & Technology E&O Insurance — Policy Feature Checklist

Cyber & Technology E&O Policy Feature Checklist

What to confirm in a cyber & technology e&o policy — what's standard, what's often limited, and what to add if needed — plus the gap most often missed.

Pull out your current cyber policy and check the box next to each feature you can confirm it includes — anything unchecked is worth a quick conversation with your advisor.

Standard should be included · Often limited frequently sublimited or excluded · If needed depends on your operations

Tick each feature you can confirm your policy includes — anything left unticked is a good question for your next policy review.

Confirm?Policy featureWhat to confirmPriority
Social Engineering / Funds Transfer FraudCovers payments sent to criminals after fake emails or invoices — often a small sublimit.Often limited
Ransomware & Cyber Extortion (Full Limit)Confirm ransomware is covered at the full limit, not a reduced sublimit or coinsurance.Standard
Business Interruption & Waiting PeriodCovers lost income during an outage — confirm the waiting period (hours before coverage starts).Standard
Breach Response CostsCovers forensics, notification, and legal counsel — confirm whether they reduce the policy limit.Standard
Data RestorationPays to restore or recreate lost data and systems.Standard
Dependent Business InterruptionCovers lost income when a key vendor or cloud provider has an outage.Often limited
Regulatory Fines & PCI AssessmentsCovers regulatory defense and fines where insurable, and card-brand assessments after a breach.If needed
Technology E&OCovers claims that the applicant's technology products or services failed — needed for tech companies.If needed

The gap most often missed in this coverage

The most commonly missed gap in this coverage is social engineering. Business email compromise cost U.S. victims $3.05 billion in 2025 — the costliest cybercrime businesses routinely face — yet many cyber policies cover payment fraud only through a small sublimit or not at all. Businesses should confirm the limit, verify every payment change by phone, and require two approvers for large transfers.

Not sure you have everything on this list?

Send us the checklist and we'll review your cyber & technology e&o coverage line by line, then market it across multiple carriers that compete for your account.

Frequently asked questions

What should a cyber & technology e&o policy include?

Standard features to confirm in a cyber & technology e&o policy include Ransomware & Cyber Extortion (Full Limit), Business Interruption & Waiting Period, Breach Response Costs, Data Restoration. This checklist also flags the features that are often limited or sublimited and the ones to add if needed, with a plain-English note on each.

Is this checklist insurance advice?

No. It is a free educational tool to help you have a more informed conversation with a licensed professional. It affords no coverage and is not insurance, legal, or financial advice — only your actual policy language governs what is and isn't covered.

Can Cory Washington & Co. review my cyber & technology e&o coverage?

Yes. Share your checklist and we'll review your program line by line, market your account across multiple carriers, and explain the trade-offs in plain English. Cory Washington & Co. LLC is licensed in all 50 states.

This checklist is a free educational tool from Cory Washington & Co. to help you review your own coverage and have a more informed conversation with a licensed insurance professional. It is general information only — not insurance, legal, or financial advice, and not a recommendation to buy, change, or cancel any policy. Coverage terms, availability, limits, and requirements vary by policy, carrier, and state, and only the language in your actual policy governs what is and isn’t covered. Checking or leaving blank any item above does not indicate that you are adequately insured or under-insured. Using this checklist does not create a client, agency, or fiduciary relationship. Always consult a licensed professional about your specific situation.

Protect What You’ve Built

When everything you’ve built is on the line, a quote isn’t enough. Tell us about your business and receive a considered assessment — not a form letter.