Skills / Closing the deal / The insurance stack

What insurance do we need at seed — E&O, cyber, D&O — and what should it all cost?

Four policies, four different jobs, and each has an event that should trigger it.

cyber-insurance-stack

SKILL.md · 921 words

Verified Sept 2026

Download the folder
What your agent reads.
name
cyber-insurance-stack
description
The insurance a seed-stage cybersecurity vendor needs and when: directors and officers, errors and omissions or technology liability, cyber liability, key person, and general business liability, which the firm requires of portfolio companies and which it only recommends, why a security vendor's errors and omissions posture differs from generic software, why the policy limit becomes the contract liability cap, what drives premium, the exclusions to read, and the event that triggers each purchase. Use when a founder is asked for a certificate of insurance by a buyer, is negotiating a liability cap, is closing a priced round, or is quoted a bundle. No prices are printed. Also written as COI, certificate of insurance, E&O, tech E&O, or cyber liability. Not for the contract terms themselves (security-vendor-contract-norms) or the questionnaire (security-questionnaires).
title
The insurance stack
question
What insurance do we need at seed — E&O, cyber, D&O — and what should it all cost?
subtitle
Four policies, four different jobs, and each has an event that should trigger it.
summary
You buy each policy when the event that needs it arrives, and the policy that matters most to a security vendor is the one whose limit becomes your liability cap in every enterprise contract. We ask every company we back for directors and officers cover and key person cover, your first enterprise contract will require the rest, and we print no prices because premiums move every year.
group
close
verified
2026-09-08
order
57

877 / 1024 characters

This is the top of the SKILL.md file, exactly as it downloads. Your agent reads the description field to decide when to load this skill. The rest of this page is for you.

You will be quoted a bundle and told it is what startups buy, and the bundle is written for a company whose failure does not cause anyone's breach. Yours could. That changes which policy matters, when you buy it, and what the buyer's lawyer will read in it. We print no prices, because premiums move with the market every year and with what your product touches. The shape holds.

Four policies do four jobs.

You buy each policy for a different reason, and confusing them is how founders end up covered twice for one risk and not at all for another. Directors and officers cover protects the people on your board personally, including their defense costs in regulatory and criminal matters. Errors and omissions cover, which is sold to software companies as technology liability, covers professional negligence: the failure to perform, the error, or the omission in the product you sold. Cyber liability cover pays for the breach itself, the response, the notifications, and third-party claims when data you held leaks. Key person cover pays the company for losing someone it cannot operate without. General business liability covers the ordinary claims that come with having an office and attending events.

What your investor asks for, and what your buyer requires.

We ask every company we back for directors and officers cover and key person cover from the priced round, because the first protects the people we ask to sit on your board and the second protects the investment against the one risk no diligence can price. Errors and omissions, cyber, general liability, and workers' compensation are the buyer's asks rather than ours, and the first enterprise contract will name all four. The line between what your investor asks for and what your buyer requires is the useful one.

Your policy limit becomes your liability cap.

You will discover in the first enterprise negotiation that the buyer's counsel asks for unlimited liability, and the only honest answer is your insurance limit. For a security vendor, the errors and omissions policy and the cyber policy together are that limit, and they are the real number in every contract negotiation you will ever have. A generic software company can buy them late. You buy them before the first enterprise contract, because the policy ends the redline cycle that would otherwise consume a quarter, and because a security buyer asks for the certificate before procurement starts, not after.

What drives the premium.

You are priced on what your product touches. Revenue is the base, and on top of it the underwriter reads the privileges your product runs with, the data it sees, whether it sits inline, and whether a failure of yours takes the customer offline. An agent with root access on a customer's fleet is a different policy from a dashboard, and the underwriter asks the same questions a buyer's security engineer asks. Answer them from the same architecture page you give buyers: what the product touches, what privileges it needs, what data it sees and stores, where it runs, the tenant boundary, how it fails, and what the buyer must run themselves.

Read the exclusions before a buyer does.

You read the exclusions with the contract in your other hand, because the buyer's counsel will. The one that matters for a security vendor is any language excluding claims that arise from a failure to prevent a security incident, which is exactly the claim a security customer would bring. Read for exclusions on contractual liability, because your liability cap is a contractual promise and the policy has to respond to it. Read the notice requirements and the retroactive date, because a claim about last year's version is still a claim. And confirm the policy is written to the legal entity that signs your contracts.

Buy each policy on its event.

You buy directors and officers cover at the priced round, when there is a board to protect. You buy errors and omissions, cyber, general liability, and workers' compensation before the first enterprise contract, because the certificate of insurance is a condition of signature, not a courtesy, and workers' compensation is required by law once you have an employee. Read the buyer's contract for the required limits and the endorsements it names, additional insured, waiver of subrogation, primary and non-contributory, and get them from the broker in the same week, because a broker takes days and a redline takes a quarter. You buy key person cover when an investor asks for it, which for us is the priced round. A bundle bought before any of those events is premium paid for coverage that nothing has triggered.

Working the question.

  1. Name the event in front of you, whether a priced round or a first enterprise contract, and buy the policies that event needs.
  2. Carry the certificate of insurance, with the endorsements the buyer's contract names, into every enterprise negotiation, and treat the liability limit as your cap.
  3. Give the underwriter the same architecture page you give a security buyer.
  4. Read the exclusions with the contract open, and strike any failure-to-prevent language before you sign.
  5. Revisit the limits when the product gains privileges or an inline position, not on the renewal date.

Working with an agent.

Give your agent your three largest customer contracts. Ask it what insurance limits and endorsements each one requires you to carry. Your policy limit becomes your liability cap in the next negotiation, so buy the policy knowing that.

Install the skill.

You are reading the skill itself — this page and the download are the same files. Unzip it into ~/.claude/skills/ (or a project’s .claude/skills/) and Claude Code loads it when the question comes up; so does any agent that reads Agent Skills.

mkdir -p ~/.claude/skills && cd ~/.claude/skills && curl -sLO https://techoperators.com/skills/cyber-insurance-stack.zip && unzip -oq cyber-insurance-stack.zip && rm cyber-insurance-stack.zip

cyber-insurance-stack/SKILL.md

No terminal? Download cyber-insurance-stack.zip and drop into your assistant’s project files.

Kevin Skapinetz

Tell us what you see.

Whether you’re thinking about starting a company, building one in stealth, or raising a round: send Kevin or Dan what you see on LinkedIn, in your words.