Skip to content
Guide · Vetted RiskUpdated 2026-09-18

Guide

Technology E&O and cyber liability insurance for Massachusetts startups.

A software bug, a bad integration, or a breached client database can end a young company faster than a lawsuit over a slip and fall. General liability insurance was built for the slip and fall; it was not built for a client claiming your platform lost their data or your advice cost them a contract. Massachusetts doesn't force private tech companies to buy professional liability or cyber coverage, but its data-security and breach-notification laws create obligations that only these policies are designed to fund. This guide explains what tech E&O and cyber liability cover, and where the market stands right now.

Reviewed by Vetted Risk · Last updated 2026-09-18

Do software companies need E&O insurance in Massachusetts

Massachusetts does not have a statute forcing private technology companies to buy professional liability insurance, the way it forces drivers to carry auto coverage or employers to carry workers’ compensation. Some states require professional liability coverage for specific licensed professions, such as attorneys and doctors, but general technology and software work isn’t one of them. That doesn’t make the coverage optional in any practical sense.

Technology errors and omissions (E&O) insurance, a form of professional liability coverage, responds to claims that fall outside what a commercial general liability (CGL) policy will pay. CGL covers property damage and personal or advertising injury arising from your operations or employees, plus non-professional negligent acts. It does not cover a claim that your software gave bad output, that your implementation team missed a deadline that cost a client money, or that you misrepresented what your platform could do. E&O exists specifically for negligence, misrepresentation, violation of good faith and fair dealing, and inaccurate advice. If your company builds, licenses, implements, or advises on software, this is the policy that responds when a client says your work caused their financial loss, not your CGL.

Why claims-made policies work differently than your other coverage

Most professional liability policies, including tech E&O, are written on a claims-made basis rather than an occurrence basis. That distinction matters more than it sounds. An occurrence policy covers an event that happened during the policy period no matter when the claim is later filed. A claims-made policy only responds if the policy is in force both when the underlying event occurred and when the claim is actually filed. Let a claims-made E&O policy lapse, or switch carriers without the right tail or retroactive date language, and a claim tied to work you did years ago can fall into a gap with no coverage on either side.

E&O policies pay legal defense costs and judgments up to the policy limit, but they generally exclude non-financial losses and losses arising from intentional or dishonest acts. Deductibles on these policies typically range from $1,000 to $25,000, so a founder should expect to absorb the first layer of any claim before the policy responds. If your company designs, manufactures, or distributes a physical product alongside your software, understand that E&O and product liability are separate lines; a hardware defect claim needs product liability coverage, not just professional liability.

What 201 CMR 17.00 and the WISP requirement mean for your startup

Massachusetts regulation 201 CMR 17.00 sets minimum standards for anyone who owns or licenses personal information about a Massachusetts resident, in both paper and electronic form. The Office of Consumer Affairs and Business Regulation (OCABR), which confirms this regulation implements M.G.L. c. 93H, notes it applies broadly, including to banks, credit unions, and non-depository institutions, and its compliance checklist makes clear the regulation requires a written information security program, or WISP, covering all records containing personal information about a Massachusetts resident.

For a tech startup, this reaches further than your own servers. The checklist specifically asks whether you’ve taken reasonable steps to select and retain third-party service providers capable of maintaining appropriate security measures, and whether you require those providers by contract to maintain them. If your company runs on cloud infrastructure or SaaS vendors, and most do, your WISP obligations extend to vetting and contracting with those vendors. OCABR has said this expectation runs from large financial institutions down to small businesses and sole proprietors; company size does not exempt you.

What happens when you have a breach: M.G.L. c. 93H notification duties

Chapter 93H defines a breach of security as unauthorized acquisition or use of unencrypted personal information, or encrypted information along with its key, that creates a substantial risk of identity theft or fraud against a Massachusetts resident. Personal information includes a resident’s name paired with elements like a financial account or credit or debit card number that would allow account access.

The notification mechanics matter for any SaaS company handling client data. Under Section 3(a), a company that merely maintains or stores data without owning or licensing it, a common posture for a vendor processing a client’s data, must notify the data’s owner or licensor as soon as practicable once it learns of a breach. Under Section 3(b), the actual owner or licensor of the data must then notify the Attorney General, OCABR, and the affected residents, also as soon as practicable and without unreasonable delay. The notice to regulators must include the nature of the breach, the number of Massachusetts residents affected, and the entity’s name and address; the notice to residents is different by design and must not disclose the nature of the breach or the number affected, but must explain their right to a police report, how to request a free security freeze, and what mitigation services will be provided. Notice cannot be delayed just because the total number of affected residents isn’t yet known.

If the breach exposes a Social Security number, Section 3A requires the breached entity to contract with a third party to provide free credit monitoring for at least 18 months, extended to 42 months if the breached entity is itself a consumer reporting agency. A resident cannot be required to waive their private right of action in exchange for accepting that monitoring offer. Every one of these steps costs money and requires vendors on short notice, which is precisely what first-party cyber coverage is built to fund.

What a cyber liability policy actually pays for

First-party cyber coverage, per NAIC guidance, protects your own data, including employee and customer information, and typically funds legal counsel for notification and regulatory obligations, data recovery, customer notification and call-center services, lost income from business interruption, crisis management and PR, cyber extortion and fraud response, forensic investigation, and fines or penalties tied to the incident. Third-party cyber coverage protects you if a client or other party is harmed by an incident traced back to your company, which is the scenario most likely to intersect with your E&O exposure.

Massachusetts Division of Insurance materials describe additional endorsements worth understanding before you bind: dependent business interruption, which triggers if a malicious event at a cloud or hosting provider you rely on interrupts your operations; system failure and dependent system failure coverage, which respond to non-malicious outages rather than only malicious attacks; social engineering coverage; and client account or invoice manipulation coverage, aimed at fraudulent invoices sent from a compromised company email account. Multimedia liability coverage, also described in DOI materials, covers defense and resolution costs for claims tied to online content, such as copyright or trademark infringement, which matters for companies with active marketing or content platforms.

Why cyber rates are shifting and what that means for renewal

The cyber market moved in 2024 in ways worth knowing before your next renewal. NAIC reports the U.S. cyber insurance market saw its first-ever reduction in direct written premium that year, roughly $9.14 billion, a 7% decrease from $9.84 billion in 2023. U.S.-domiciled insurers wrote $7.08 billion, down slightly from $7.25 billion, while policies in force were essentially flat. At the same time, reported cyber claims rose almost 40%, to nearly 50,000, even as average ransom payments among Aon’s broking clients dropped 77%. Aon’s combined cyber and E&O claims data showed 1,228 reported incidents in 2024, a 22% increase year over year. Cyber rates declined an average of 5% in the fourth quarter of 2024, the first quarterly rate decrease after seven years of increases. For a startup shopping coverage now, that mix, softer pricing alongside rising claim frequency, is a reason to compare carriers carefully rather than assume last year’s quote still reflects the market; our cyber liability coverage review guide walks through how to evaluate a tower once you have options in hand.

Other coverage a Massachusetts tech startup can’t skip

E&O and cyber solve for your product and data exposure, but they don’t touch employer obligations. Massachusetts requires all employers to carry workers’ compensation insurance regardless of employee count or hours worked, with the sole exception of domestic employees working fewer than 16 hours a week. LLC members, LLP partners, and sole proprietors are not required to cover themselves, and corporate officers owning at least 25% of the corporation can request a personal exemption, but any non-owner employee must be covered regardless of the entity’s structure. Out-of-state employers with staff working in Massachusetts must provide coverage for those employees as well.

If your startup ships a physical product alongside software, whether a device, sensor, or piece of hardware, that exposure sits outside both E&O and general liability. Product liability coverage is the separate line built for claims arising from a product you design, manufacture, distribute, or sell.

Building the right tech insurance package: next steps

A Massachusetts tech startup’s real exposure sits across three policies that rarely overlap: technology E&O for negligence and bad-advice claims, cyber liability for breach response and network liability, and workers’ compensation for your team. None of these substitutes for the others, and a CGL policy alone leaves the professional and data exposures uncovered entirely. As your company grows, revisit limits and endorsements at every renewal rather than letting a policy auto-renew unchanged; our commercial insurance renewal checklist covers what to reexamine each cycle. Vetted Risk shops these lines directly with carriers that understand technology risk and can help structure a program across Professional Liability, Cyber Liability, and Workers’ Compensation that matches how your company actually operates.

Work with us

Have a coverage question for your business?

Tell us how to reach you. A licensed broker can help you review your business coverage.

Discuss business coverage

Ask a broker about this guide

Related

Keep us in your results

Find these guides useful? Set Vetted Risk as a preferred source on Google and our coverage guidance shows up more often in your search results.

FAQ

Common questions.

Is cyber liability insurance required by law in Massachusetts?

No statute or Division of Insurance mandate requires private technology companies to purchase cyber liability insurance in Massachusetts. The state's approach instead centers on 201 CMR 17.00, which sets data-security standards, and M.G.L. c. 93H, which sets breach-notification duties; cyber insurance is the mechanism most companies use to fund compliance with those obligations, not a separate legal requirement.

What's the difference between technology E&O and cyber liability insurance?

Technology E&O, a form of professional liability insurance, responds to claims that your product or service was negligent, that advice was inaccurate, or that you misrepresented what your technology would do. Cyber liability responds to data breaches and network security incidents, covering first-party costs like breach notification and forensic investigation and third-party liability if a client is harmed by an incident traced to your systems. Many startups carry both because a single incident, such as a data breach caused by a coding error, can trigger claims under each.

Does a Massachusetts startup need a written information security program?

Yes. 201 CMR 17.00 requires a comprehensive written information security program, or WISP, for any business that owns or licenses personal information about a Massachusetts resident, in both paper and electronic form. This applies regardless of company size, and the regulation also expects businesses to vet third-party vendors, including cloud and SaaS providers, and require those vendors by contract to maintain appropriate security measures.

How long do I have to notify Massachusetts residents after a data breach?

M.G.L. c. 93H requires notice to the Attorney General, the Office of Consumer Affairs and Business Regulation, and affected residents as soon as practicable and without unreasonable delay once the breach is discovered. Notice cannot be delayed on the grounds that the total number of affected residents isn't yet known, and if the breach exposes a Social Security number, the breached entity must arrange free credit monitoring for affected residents for at least 18 months, or 42 months if the entity is itself a consumer reporting agency.

Do I need workers' compensation insurance if my tech startup only has a few employees?

Yes. Massachusetts requires all employers to carry workers' compensation insurance for their employees regardless of headcount or hours worked, with the only exception being domestic employees working fewer than 16 hours a week. LLC members, LLP partners, and sole proprietors are not required to cover themselves, and corporate officers owning at least 25% of the corporation can request a personal exemption, but any employee who is not an owner must still be covered.

Does general liability insurance cover a software bug or bad advice from my product?

No. A commercial general liability policy protects against property damage and personal or advertising injury arising from operations or employees, and it covers non-professional negligent acts, but it is a separate policy from errors and omissions coverage. Claims alleging negligence, misrepresentation, or inaccurate advice tied to your professional services or software are the domain of technology E&O, not general liability.