Start smart. Scale strong. Stay protected.
Start smart

ICT and SaaS Insurance: A Complete Guide for Australian Tech Founders

This article is general in nature. For advice specific to your situation, book a call with the Pocket team.

What insurance does a tech business actually need?

Tech businesses face risks that standard insurance was never designed to cover. A bug that costs a client six figures. A data breach that triggers a regulatory investigation. A patent dispute that forces you to rebuild your codebase. None of these are covered by a generic business policy.

The cover you need starts with ICT Insurance (IT Liability) — Professional Indemnity and Public Liability built for tech, with IP protections usually sitting within the PI section. Cyber cover (which generally includes media liability) may be packaged into the same policy or arranged separately, depending on the insurer.

This guide explains what ICT Insurance is, what it covers (and what sits separately), how it changes at each stage of growth, and one wording trap worth watching for.

TL;DR

At its core, ICT Insurance (also called IT Liability) is Professional Indemnity and Public Liability built for technology businesses — covering your professional service failures and third-party injury or damage. IP protections typically sit within the PI section itself. Cyber cover (which generally includes media liability) may be packaged into the IT Liability policy or arranged as its own separate policy, depending on the insurer. Pocket can arrange it either way. If you're building software for clients, storing customer data, or operating a SaaS platform, you need this cover from Day 1, and your requirements grow materially as your business scales.

Key facts:

  • ICT Insurance (IT Liability) is Professional Indemnity + Public Liability at its core: IP protections usually sit within the PI section, and cyber cover (which generally includes media liability) may be packaged in or arranged as a separate policy, depending on the insurer.
  • Watch the wording: some IT Liability policies carry a full cyber exclusion, which can create problems when a claim sits in the grey area between a professional error and a cyber event. Checking for this is exactly where a broker earns their keep.
  • When you raise or sign enterprise clients, insurance often becomes a precondition — but which cover depends on who's asking. Investors typically require Directors & Officers (D&O) cover before a round closes (often $2-5M by Series A); enterprise clients typically require PI and cyber before they'll sign. It's a commercial prerequisite, not just risk management.
  • Under Australia's Privacy Act, many businesses must notify affected individuals and the OAIC of eligible data breaches, and the notification, response, and legal costs add up quickly — often well before any fine is considered.
  • The average self-reported cost of cybercrime for a small Australian business is $56,600 (Source: ASD Annual Cyber Threat Report 2024-25).
  • ICT Insurance is not the same as standard Professional Indemnity. Most standard PI policies explicitly exclude cyber events, IP claims, and technology-specific risks.

What is ICT Insurance?

Who this is for

ICT Insurance (Information and Communications Technology Insurance) is purpose-built cover for businesses that build, sell, or operate technology products and services. It's the right policy if you:

  • Build software for paying customers (SaaS, apps, platforms, APIs)
  • Provide IT consulting, implementation, or managed services
  • Store, process, or transmit customer data
  • Develop products that integrate with or depend on third-party systems
  • Provide cloud, hosting, or infrastructure services
  • Operate e-commerce platforms that handle payments

Standard Professional Indemnity is not a substitute. Most generic PI policies contain explicit exclusions for cyber events, intellectual property disputes, and technology-specific failures. If you're a tech business buying a standard PI policy, you may be uninsured for your most likely claims.

Do you need it?

Yes, from Day 1 if: you have any paying customers, users (even free), client data, or contractual obligations around software performance or data handling.

Probably not, if: you're a pure consulting business with no software product, no customer data, and no contractual deliverables involving technology. (A standard PI policy likely suffices.)

Get an ICT Insurance quote from Pocket →

What ICT Insurance covers

It helps to think of ICT cover in two layers: the core (what an IT Liability policy is built on) and cyber (which may be packaged in or arranged separately, depending on the insurer).

A quick note on how the pieces fit, because it trips people up: IP cover usually sits within the PI section of the IT Liability policy itself, while media liability can fall into either PI or cyber depending on the circumstances. Cyber cover itself may be packaged into the IT Liability policy or arranged separately, depending on the insurer.

The core: Professional Indemnity + Public Liability

This is what "ICT Insurance" or "IT Liability" fundamentally is. Every tech business building or servicing for clients needs these two.

Professional Indemnity for tech. Standard PI covers advice errors. ICT-specific PI extends to the full range of technology service failures:

Cover area What it means
Software bugs and errors A flaw in your code causes client financial loss
Failed implementations Your system integration doesn't work as contracted
Missed deadlines and deliverables Client claims loss from a project running late
Breach of contract You failed to meet agreed SLAs or deliverables
System downtime Your platform is unavailable, costing clients revenue
Data loss or corruption Your system loses or damages client data
Poor advice or consulting Your technical recommendations caused harm
Faulty workmanship in code Defects in delivered software cause downstream claims
Third-party financial loss A third party suffers loss from your services — lost data recovery, client business interruption, consequential loss
IP infringement (unintentional) You unknowingly used patented code or methods
Copyright disputes A third party claims copyright over elements of your product
Patent infringement defence Defending claims you've infringed an existing patent
Trade secret breaches Allegations you used confidential information

IP protections like the last four typically sit within the PI section of an IT Liability wording, but it's worth confirming on your specific policy, as the exact inclusions vary.

Public Liability. Covers third-party injury or property damage connected to your business — for example, a client injured at your office, or damage caused during an on-site implementation. Standard for any operating business, and part of the IT Liability core. Note the PL limit typically doesn't match your PI limit — it's usually a minimum of $10M, and can be $10-20M depending on the insurer.

Cyber cover: packaged in, or arranged separately

Here's the part that trips people up. Cyber cover is not automatically part of an IT Liability policy. Some insurers package it into a single tech policy; many others cover PI/PL only, and cyber is arranged as its own separate policy. Pocket can arrange it either way — the right structure depends on the insurer and your risk.

Cyber and Privacy Liability:

Cover area What it means
Data breaches and hacking Costs of responding to an external breach
Privacy Act violations (OAIC) Regulatory investigation and fine defence
Customer data theft Notification, credit monitoring, and legal costs
Ransomware attacks Ransom, IT forensics, system restoration and extortion response costs
Security failures Claims from clients whose data was exposed
GDPR breaches If you have EU customers, EU regulatory exposure
Notification costs Contacting affected individuals as required by law
Media and content liability Defamation in user-generated content, copyright in published material, privacy from published content — generally a cyber inclusion
Regulatory fines Where insurable by law

The wording trap worth watching for

There's one thing worth checking on any IT Liability policy: some carry a full cyber exclusion. That's more than just "cyber isn't included" — it means the policy can decline to respond where a claim touches on a cyber event at all.

The problem is the grey area. Plenty of real-world claims sit somewhere between "a professional error or omission" and "a cyber event" — a coding mistake that also exposes data, for example. With a full cyber exclusion in place, an insurer may decline the whole claim simply because a cyber element was involved, even where your professional work was the root cause.

Not every insurer applies this exclusion, but it's common enough to look for. This is exactly the kind of wording a broker checks before you buy, and exactly the kind of gap you don't want to discover at claim time.

What's not covered

Not covered What to use instead
Deliberate IP theft or fraud Not insurable
Work done before insurance starts Retroactive cover must be arranged — speak to your broker
Your own business losses Business Interruption insurance
Bodily injury or property damage Public Liability insurance
Hardware theft or damage Business Property insurance
Employee injuries Workers Compensation
Motor vehicles Commercial Motor insurance

Important gap to know: ICT Insurance doesn't cover losses to your own business from a cyber incident, only third-party claims. If you want cover for your own income lost while recovering from a breach, you need a separate Cyber Insurance policy with a first-party Business Interruption extension. Pocket can combine these — talk to the team.

Who needs ICT Insurance and when

You need it from Day 1 if you are:

  • Building software for paying customers
  • Handling any customer data (even a free tier)
  • Providing SaaS, PaaS, or cloud services
  • Developing mobile or web applications
  • Offering IT consulting or implementation services
  • Taking online payments
  • Storing user information

The question isn't revenue, it's exposure. A pre-revenue startup with 500 beta users has privacy liability from the moment it stores their email addresses. A bug in a free beta that corrupts user data can still generate claims.

A note on the Privacy Act (and why it's tightening)

There's a common misconception that privacy obligations only kick in once you're a big company. The reality is more nuanced, and it's changing:

  • The threshold today: the Notifiable Data Breaches (NDB) scheme has historically applied to businesses with annual turnover over $3 million.
  • But the exceptions catch many tech businesses regardless of size: the small business exemption does not apply if you handle health information, hold tax file numbers, trade in personal information, or are a government contractor. A health-tech or fintech startup, or any business whose product effectively deals in personal data, can be caught well under the $3M threshold.
  • And it's tightening: privacy reform is progressively narrowing the small business exemption, bringing far more small businesses into scope over the coming period. Building good data-handling practices early is far easier than retrofitting them, and it's often the same moment you're signing enterprise contracts and raising capital that assume you're already compliant.

(Privacy law is actively reforming — treat this as general guidance and check your current obligations, or get advice, rather than assuming your status.)

Contracts and investors will require it

Many client contracts, particularly with enterprise customers, government, and large corporates, specify minimum insurance requirements. Common requirements:

Contract requirement Typical minimum
Professional Indemnity $2M-$10M depending on contract value
Cyber Liability $1M-$5M
Public Liability $10M-$20M

A note on who requires what: investors typically require Directors & Officers (D&O) cover before a round closes — by Series A, term sheets commonly specify $2-5M D&O limits. Enterprise clients are the ones who typically require PI and cyber before they'll sign. So if you're approaching a raise, D&O is the one to have in place; if you're closing enterprise deals, PI and cyber. Getting either sorted late can stall the deal.

ICT Insurance by founder stage

Start smart — pre-launch to Year 1

Typical program:

  • $1-2M Professional Indemnity (ICT-specific), with IP cover typically sitting within the PI section
  • Public Liability typically $10-20M (it doesn't match the PI limit; usually a $10M minimum)
  • $1M Cyber cover packaged with the above by some insurers, or arranged as a separate policy

You need this from Day 1 when: you have users (paid or free), client contracts, or any data obligations.

Scale strong — growing and hiring

Your cover needs to increase when:

  • Revenue exceeds $1M
  • You're storing thousands of customer records
  • You're signing enterprise clients with higher PI requirements
  • Contracts specify $5M+ cover
  • You're processing sensitive data (health records, financial data)
  • You're expanding internationally — GDPR, CCPA, and other jurisdictions
  • You're raising significant capital

Typical program at this stage: $5M-$10M PI, $2M-$5M Cyber. Note the cover doesn't broaden as you scale — the limits grow with your PI and cyber limits (IP sits within PI, media within cyber, so they rise with those). Many businesses at this stage also start asking about D&O / Management Liability and Commercial Legal Expenses — not necessarily part of a typical ICT program, but worth a conversation.

Stay protected — established and optimising

Review your cover when:

  • You launch new products or services with different risk profiles
  • You change your tech stack significantly
  • You've had a near-miss — a bug, a security incident, a client complaint
  • You're being acquired or merging (representation and warranty exposure)
  • You enter regulated markets (health, finance, government)
  • Your data holdings grow materially

At this stage, your program is custom. The right limits, structures, and extensions depend on your specific business. Talk to the team rather than trying to work it out from a product page.

Coverage questions tech founders actually ask

"Isn't this just Professional Indemnity?"

Partly. ICT/IT Liability is built on Professional Indemnity, but it's PI designed for technology work. A generic PI policy covers advice errors ("I gave you bad advice and you suffered loss"); ICT-specific PI extends to software failures, system downtime, failed implementations, and data corruption, and is paired with Public Liability, with IP protections usually sitting within the PI section. Cyber (which generally includes media liability) is the piece that some insurers package in and others leave separate. And watch for a full cyber exclusion on some IT Liability policies — it can bite when a claim blurs the line between a professional error and a cyber event.

"What if we use open source code?"

You're still liable if open source components in your product lead to a third-party claim. IP cover may respond to infringement claims arising from open source use, but licence compliance breaches (like failing to open-source your own code as required, or misattributing authorship) sit in a genuine grey area under most wordings. This is worth confirming rather than assuming, and it's exactly the kind of clause a broker should check before you rely on it.

"Does this cover us if AWS goes down?"

Indirectly. If you have contractual SLA obligations to customers and your platform is unavailable due to infrastructure failure, ICT Insurance may cover client claims against you for the resulting loss. It doesn't cover your own lost income — that's a separate BI extension. It also doesn't cover you suing AWS (your ability to do that depends on AWS's terms of service).

"What about employee IP theft — taking code to a competitor?"

Most ICT policies include a fidelity component covering employee theft of IP and trade secrets. Prevention through strong IP assignment clauses, NDAs, and access controls remains the more practical first line of defence, but insurance covers the legal costs and losses when it does happen.

"Do VCs require this?"

The cover investors require is usually Directors & Officers (D&O), not PI. Most institutional investors want D&O in place before a round closes — by Series A, term sheets commonly specify $2-5M D&O limits, because incoming board members want personal liability protection as a condition of joining. PI and cyber are more often required by enterprise customers before they'll sign. So arrange D&O ahead of a raise, and PI/cyber ahead of enterprise sales. (D&O sits under Management Liability — ask us if you're approaching either milestone.)

Quick reference: ICT insurance program by business type

Indicative only. Your specific requirements depend on contract values, data volumes, and client requirements.

Business type Core covers Typical starting limit
SaaS startup (pre-revenue) PI (ICT, IP within) + PL core; Cyber packaged or separate $1M PI / $1M Cyber
SaaS (>$1M ARR) PI (ICT) + PL; Cyber (media within) $2M-$5M PI / $2M Cyber
IT consulting / implementation PI (ICT) + Public Liability $2M PI
Marketplace / platform PI (ICT) + PL; Cyber (media within) $5M+ PI / $2M+ Cyber
Health tech / fintech PI (ICT) + PL + Cyber; regulatory exposure Talk to broker
Managed service provider PI (ICT) + PL + Cyber $5M PI / $5M Cyber

Your tech business needs tech-specific insurance

Standard insurance wasn't built for software failures, data breaches, or IP disputes. Pocket works with tech founders at every stage, from pre-launch to post-Series A, to build the right ICT program for where you are now and where you're going.

Book a free call with the team →

Or go straight to a quote: Get an ICT Insurance quote →

With Pocket is a business name of Insurance Services Holdings Pty Ltd (ABN 36 612 629 295, AFSL 491165). Member of NIBA. Part of the Steadfast Group. This article is general in nature and does not constitute financial or legal advice.

Frequently asked questions

What is ICT Insurance in Australia?

ICT Insurance (or IT Liability) is specialised cover for technology businesses. At its core it's tech-specific Professional Indemnity and Public Liability covering software bugs, failed implementations, and third-party financial loss from tech failures that standard business insurance excludes. IP protections usually sit within the PI section; cyber cover (which generally includes media liability) may be packaged in or arranged separately, depending on the insurer.

Does a SaaS business need different insurance from a consulting firm?

Not so much different insurance as a different underwriting profile — both sit under IT Liability, but they're assessed differently. A SaaS business carries product-type exposure for software failures, cyber exposure for data breaches, and IP exposure from code. A consulting firm's exposure is weighted more toward PI for advice and service errors.

What's the difference between ICT Insurance and standard Professional Indemnity?

Standard PI covers errors in professional advice. ICT-specific PI extends to software bugs, system failures, failed implementations, third-party financial loss, and IP protections which typically sit within the PI section itself. Cyber is the piece that may be packaged with your IT Liability policy or arranged separately, depending on the insurer.

When should a tech startup first get ICT Insurance?

From Day 1 if you have users (paid or free), client contracts, or any personal data. Privacy liability can exist from the moment you store a user's email address. Contractual liability exists from the moment you sign a client agreement. Waiting until you're revenue-generating is a common and costly mistake.

Do VC investors require ICT Insurance?

Usually what investors require is Directors & Officers (D&O) cover, not ICT/PI. Most institutional investors want D&O in place before a round closes, and by Series A term sheets commonly specify $2-5M D&O limits. ICT/PI and cyber are more often required by enterprise clients before they sign.

What does ICT Insurance cost for a small tech startup?

Premiums vary significantly based on revenue, data volumes, client types, and claims history. A pre-revenue startup with basic cover ($1M PI, $1M Cyber) could have premiums between $1,500-$4,000 per year. Costs increase materially as revenue, data volumes, and contractual requirements grow.

Does ICT Insurance cover GDPR breaches?

GDPR only applies if you have EU-based users or customers. An Australia-only SaaS generally isn't caught, but the moment you take EU users, you are. Where GDPR applies, many policies include cover for regulatory investigations and fines arising from breaches — check your policy wording explicitly, as it varies between insurers.

What happens if a client claims my software caused them financial loss?

This is the core scenario ICT Insurance is designed for. The PI component covers your legal defence costs and any settlement or judgment, subject to policy limits and terms. Notify your insurer promptly — late notification can affect your ability to claim.

Is open source software use covered under ICT Insurance?

IP cover may respond to infringement claims arising from open source use. But licence compliance breaches — like failing to open-source your own code where a licence requires it — sit in a genuine grey area under most wordings. Don't assume it's covered; it's worth having a broker check before you rely on it.