IT and Software Company
Risk profile for an IT and software company (software development, IT consulting or managed services): the risk attributes typically assessed in underwriting and the resulting commercial insurance programme architecture.
Risk picture
An IT and software company’s exposure centres on the systems it builds, operates or has privileged access to on behalf of its clients, rather than on physical premises or plant. Typical loss drivers are a ransomware or intrusion incident affecting the company’s own infrastructure or, via third-party system access, a client’s environment; software defects or delivery failures that trigger professional liability claims from clients; and business interruption from an outage of development, hosting or client-facing systems. Where the company processes personal data at scale or serves clients across borders (including the US and Canada), regulatory exposure and cross-border liability add a further layer to the risk picture on top of the direct cyber and professional liability drivers.
Risk attributes to capture
The table below is generated from this profile’s linked risk attributes and grouped by category; see the individual attribute pages for underwriting logic, evidence requirements and mitigation measures.
Coverage architecture
Cyber cover is the anchor of the programme, responding to first-party costs (incident response, business interruption, data restoration) and third-party liability following a network security or privacy breach. Employee accident cover is compulsory in Switzerland (UVG) wherever staff are employed. Professional indemnity (Berufshaftpflicht) covers claims that software defects, delivery delays or advisory errors caused a client a financial loss, while general liability (Betriebshaftpflicht) addresses conventional third-party bodily injury or property damage. A financial loss liability (Vermögensschadenhaftpflicht) extension is relevant where consulting or integration work creates financial loss exposure not otherwise captured by the professional indemnity or cyber sections.
Prevention
Loss prevention priorities are multi-factor authentication on all privileged and remote access, a disciplined patch-management cadence for both the company’s own systems and client-facing platforms, a tested backup strategy with offline or immutable copies to support recovery from ransomware, and a documented incident response plan that is rehearsed and covers both the company’s own breach scenarios and its obligations when accessing client systems as a third party.
- Kind
- Business
- Classification
- NOGA 62 – Computer programming, consultancy and related activities, NACE J62
Risk attributes to capture
IT/Cyber
- Backup Strategy and Offline Copy — Backup strategy and offline copy records how frequently an organisation backs up critical data and whether at least one copy is kept offline, air-gapped or immutable, a decisive control against ransomware queried in cyber proposal forms.
- Multi-Factor Authentication — Multi-factor authentication records whether privileged, remote and email access to an organisation's systems requires more than one independent authentication factor, a baseline control queried in virtually every cyber insurance proposal form.
- Patch Management — Patch management records how systematically an organisation identifies and applies security updates to operating systems, applications and network devices, and within what timeframe, a control central to limiting exploitable vulnerability exposure.
- Incident Response Plan — Incident response plan records whether an organisation has a documented, tested procedure for detecting, containing and recovering from a cyber security incident, and how quickly it can be activated.
- Third-Party Access to Systems — Third-party access to systems describes which external vendors, suppliers or service providers hold network or system access into an organisation's IT environment, and under what controls, a frequent source of indirect cyber exposure.
- Personal Data Processing — Personal data processing records the volume and sensitivity of personal and special-category data an organisation collects, stores or processes, a primary driver of breach notification duties, regulatory exposure and third-party liability.
Liability/Products
- Liability Activity Description — The liability activity description records the precise operations, products and services an insured performs, as declared in general and product liability proposal forms to define the scope and rating basis of the cover.
- US/Canada Revenue Share — US/Canada revenue share records the percentage of an insured's turnover generated in or attributable to the United States and Canada, which underwriters treat separately from other export markets due to the materially higher liability litigation exposure in these jurisdictions.