← All resources

Risk management & finance

The CFO's shield: navigating key liability insurance for your tech company

A strategic guide for Indian tech CFOs on the liability risks that actually reach the balance sheet — which policies cover what, where they overlap, and the questions worth asking before you sign.

Illustration of a business leader beside a large shield, deflecting risks shown as a cracked padlock, a broken chain and a falling figure

As the CFO, you're not only managing the finances — you're the one holding the company's downside. Insurance is where that job quietly gets real, and where the gaps are easiest to miss until a claim lands on your desk.

Your insurance portfolio deserves the same scrutiny as any other line on the balance sheet. This guide cuts through the complexity of the liability cover a growing tech company needs — moving from abstract risk to the tangible consequences a CFO has to plan for. Nothing here is advice on a specific policy or insurer; it's a way to judge any cover on its merits.

At a glance: your core policies

Six liability policies form the protective shield for most modern tech companies. Here's what each one is for, and the kind of day it's built for.

Commercial General Liability (CGL)

Your foundational liability cover. It responds to claims of bodily injury or property damage that happen on your premises or as a result of your operations.

Real-world scenario

A potential investor visiting your office slips on a wet floor and is seriously injured, then sues. CGL covers the legal defence costs and any settlement or medical expenses.

Directors & Officers (D&O)

Protects the personal assets of your directors and officers against lawsuits alleging wrongful acts, mismanagement, or breach of fiduciary duty in their role as leaders.

Real-world scenario

Shareholders sue your board, alleging financial misrepresentation in a quarterly report that led to investment losses. D&O funds the leadership team's legal defence and protects their personal wealth.

Cyber Insurance

Close to non-negotiable for a tech company. It covers the financial fallout from data breaches, network-security failures, and other privacy-related events.

Real-world scenario

A ransomware attack compromises sensitive customer data. Cyber cover pays for forensic investigation, notifying affected customers, credit monitoring, and potential regulatory penalties under the DPDP Act.

Crime Insurance

Protects the company from direct financial loss caused by fraudulent acts — employee dishonesty, embezzlement, theft, and forgery.

Real-world scenario

An employee in finance embezzles a significant sum over several months by creating fictitious vendors. Crime cover reimburses the company for the stolen capital.

Employees' Compensation Insurance

Covers two things at once: the statutory benefits — medical expenses and lost wages — for employees injured at work, and the potentially larger risk of employee lawsuits under common law.

Real-world scenario

An employee is seriously injured in what they allege were unsafe conditions and sues for negligence, well beyond the statutory limits. This policy covers the legal defence and any settlement.

Errors & Omissions (E&O) / Professional Indemnity

Vital for tech companies. It covers a third party's financial loss — usually a client's — caused by an error or failure in your professional services or product.

Real-world scenario

A critical bug in your platform causes a major client to lose significant revenue, and they sue for the damages. E&O is built to cover the settlement and legal costs of exactly this.

Understanding the overlaps and gaps

The hardest part for most CFOs isn't any single policy — it's how they interact. Misreading the boundaries is how coverage gaps quietly open up.

CGL vs E&O: tangible or intangible harm

The confusion:does CGL cover a client's financial loss if our product fails?

The clarification

Generally, no. CGL is for tangible harm — bodily injury, property damage. E&O is for intangible harm — financial loss from your professional services or a product failure. If your code causes a server to overheat and start a fire, CGL might respond. If your code costs a client revenue, you need E&O.

Cyber vs Crime: the nature of the theft

The confusion: an employee clicks a phishing link and a fraudulent wire transfer follows. Is that a cyber claim or a crime claim?

The clarification

It can be both — which is exactly why wording matters. A strong cyber policy often includes social-engineering fraud cover; a crime policy covers employee dishonesty and internal theft. The job is to structure both so there's no gap between them.

D&O vs Cyber: cause and consequence

The confusion: after a breach, the board is sued for failing to ensure adequate security. Which policy responds?

The clarification

They work in tandem. The cyber policy handles the direct, first-party costs of the breach — investigation, notification, and so on. The D&O policy then defends the directors and officers against the separate claim about their oversight and governance.

What a claim actually costs

The damage from a serious claim is rarely a single number — it arrives in layers, and the headline event is often the smallest part. Two examples make the shape of it clear.

The anatomy of a cyber claim

A single breach can set off several distinct costs at once:

  • Forensic investigation to establish what happened and what was exposed.
  • Legal and regulatory counsel to manage notification and compliance.
  • Regulatory penalties — under the Digital Personal Data Protection Act, 2023, these can be significant.
  • Business interruption for every week your systems are down.

The ransom or the technical fix is rarely the largest line; the investigation, the legal work, and the downtime usually are.

The anatomy of an E&O claim

When a client sues over a product failure, the cost stacks up in stages:

  • Initial legal defence, which begins long before any finding of fault.
  • A settlement or judgement — often the largest component.
  • Your own deductible or retention, paid out of pocket before cover responds.
  • The balance met by insurance — which is the whole reason for carrying the policy.

This is why the limit you choose, and the deductible you accept, matter more than the premium line alone.

Key terms to scrutinise before you sign

Before you sign any policy, get clear on four terms. The right questions here can be worth more than the premium you negotiate.

  1. Limit of liabilityThe most the insurer will pay for a claim.Ask your broker: is this limit adequate for a genuine worst case — a major breach, or a large client lawsuit?
  2. Deductible / retentionWhat the company pays out of pocket before cover responds.Ask: how does this sit against our risk appetite and cash flow — and can adjusting it improve the premium?
  3. Retroactive dateThe date from which past work is covered; claims arising from work done before it are excluded.Ask: does this go back far enough to cover all our past projects and client engagements?
  4. Key exclusionsThe specific risks the policy will not cover — for tech, often patent infringement, intentional fraud, and certain contractual liabilities.Ask: what are the top three exclusions that could hit our operations, and are there any buy-back options?

The takeaway

Your insurance portfolio is a strategic asset, not a commodity. Viewed in silos, these policies leave dangerous gaps; structured together — with clear triggers and minimal overlap — they become a single, coherent shield. A well-built programme also says something to investors, clients, and your own leadership: that the company is prepared for the risks that come with operating in a digital world.

Note The scenarios and cost layers here are illustrative, not predictions, and the exclusions shown are examples rather than a full list — what any policy actually covers depends on its wording and your circumstances. References to the Digital Personal Data Protection Act, 2023 are general and not legal advice.

What happens when you talk to us

A 20-minute video call with a Growth Advisor — no obligation, and no quote pushed. It opens with a five-minute video from our founder on how the benefits stack works and why Ethika exists; the rest is your questions. You'll leave with an honest read on your current cover and claims experience, and a straight answer on whether we can genuinely help — even if you never become a client.

Talk to us

20 minutes with a Growth Advisor. No obligation.

A note on this page. Everything here is general information, not insurance, legal, financial or tax advice, and nothing is an offer. For advice about your situation, talk to us.