Insurance is the least interesting item in a software firm's operations and it appears in almost every enterprise contract. Buyers require suppliers to carry specified cover at specified limits, and the requirement is easy to agree to and awkward to discover you do not meet — typically at the point of signature, when the deal is waiting and the policy takes weeks to arrange.
The one most relevant to this business is professional indemnity, sometimes called errors and omissions. It covers claims arising from the professional service itself: negligent advice, a defect causing a client loss, a project that fails in a way for which you are held responsible. Contracts frequently name it explicitly with a minimum limit, and general business insurance does not substitute for it. If you build software for other companies and hold no professional indemnity, you are carrying that risk personally.
Cyber liability is the second and increasingly the one buyers ask about first. It covers your own incident costs — investigation, notification, legal advice, business interruption — and claims from third parties whose data was affected. For a firm holding client data or operating client systems, the exposure is not theoretical, and the notification obligations under DPDP and sectoral rules mean the response costs are real even when the underlying breach is modest.
Read what the policy excludes rather than what the brochure emphasises, because that is where the differences live. Common exclusions worth checking: prior known circumstances, work performed before the policy began, contractual liabilities you accepted voluntarily, and subcontractor acts. Note also whether the policy is claims-made — most professional indemnity is — which means it covers claims notified during the policy period, so lapsing cover leaves you exposed to claims arising from work you did while insured.
Match the limits to the contracts you sign rather than to a comfortable premium. If your enterprise agreements cap liability at a figure, or specify a minimum cover level, your policy should meet the highest of them. It is also worth checking whether your contracts accept unlimited liability for any category, since insurance does not, and an uninsurable commitment is a personal risk to the owners rather than a business one.
The practical sequence is unremarkable and rarely followed: read the liability and insurance clauses of your three largest contracts, list what they require, compare with what you hold, and close the gap before the next negotiation rather than during it. It takes an afternoon with a broker who works with technology firms, and it removes a category of delay that otherwise arrives at the worst moment in a sales cycle.