The practical issue.
A SaaS agreement does not create the same cyber exposure in every engagement. Appropriate coverage and limits depend on the information handled, connectivity, service criticality, incident obligations, liability allocation and potential concentration of loss.
Questions that change the answer.
- What personal, confidential or regulated information is handled?
- Is the service connected to critical systems or operational technology?
- Could one incident affect many customers?
- How do indemnities and liability caps treat privacy, security and service failure?
- Does the requested policy scope match cyber, technology errors and omissions (E&O), or both?
Common decision positions.
- Scale limits to the exposure rather than contract value alone.
- Read insurance, indemnity and liability cap provisions together.
- Separate privacy/security coverage from professional service failure where needed.
- Confirm survival and claims made continuity where obligations extend after termination.