Decision brief - 16 September 2026
Bottom line
Viewee should buy a combined technology professional indemnity (tech PI / technology E&O) and cyber policy before any live pilot receives identifiable care-sector feedback, not wait for the first paid customer. The policy should cover both Viewee's own breach response costs and third-party claims arising from security, privacy, software or service failure. For the first pilot, ask for quotes at £1m tech PI and £1m cyber. Treat £500k as a fallback only if the pilot customer accepts it. £2m may be needed when a larger care group's contract requires it.
Care-sector feedback is not automatically special-category data, but free text can reveal health, disability, ethnicity, religion or sexual orientation. Underwriters should therefore be told that Viewee may process identifiable feedback that includes health and safeguarding-related information. Do not describe the dataset as generic survey data.
Recommended buying specification
| Item | Recommended starting position | Why it matters |
|---|---|---|
| Structure | Combined tech PI / E&O plus cyber, preferably one coordinated wording | Reduces gaps and disputes when a software failure causes a privacy incident |
| Tech PI limit | £1m each claim; quote £2m as an option | Covers client financial loss from errors, outages, failed implementation, breach of contract/confidentiality and negligent service, subject to wording |
| Cyber limit | £1m aggregate; quote £2m as an option | Gives meaningful headroom for incident response, legal advice, notification, restoration, interruption and third-party privacy/network claims |
| Excess | Compare £500, £1,000 and £2,500 | A higher excess may reduce premium but must remain affordable during a crisis |
| Incident response | 24/7 hotline; insurer-funded forensic, legal, PR and notification support from discovery | The ICO reporting clock can be 72 hours, so immediate expert access matters |
| Business interruption | Include cloud/system interruption and dependent-provider interruption if available | Viewee depends on hosting and other cloud services |
| Privacy liability | Include regulatory defence/investigation and civil claims; check treatment of fines "where insurable by law" | Fines are not the main reason to buy; defence, investigation and response costs are more dependable benefits |
| Contract fit | Worldwide territory/jurisdiction as needed, defence costs wording, subcontractors, IP/media, confidentiality and retroactive date | These are common areas where a certificate's headline limit can hide gaps |
| Security representations | Only state controls that are actually operating and documented | NCSC warns inaccurate security information can jeopardise a claim |
1. What cover matters and where cyber and tech PI overlap
Cyber liability
Cyber should pay Viewee's first-party costs after an incident: forensic investigation, containment, data/system restoration, specialist legal advice, notification and affected-person support, PR/crisis management, cyber extortion response where covered, and business interruption. It should also cover third-party liability: defence and damages arising from privacy breaches, loss of personal data, or failure of network security.
This matters before revenue. An incident can create forensic and legal costs even when no customer has paid and no one sues. The ICO says a reportable personal-data breach must be reported without undue delay and within 72 hours of discovery. NCSC says cyber insurance can support recovery, legal/regulatory action and incident-response services, but is not a substitute for basic security.
Professional indemnity / technology E&O
Tech PI protects against a customer alleging that Viewee's software or professional service caused financial loss. For Viewee this includes defects, inaccurate or unavailable outputs, failed implementation, missed specifications, negligent advice, breach of confidentiality, and some IP/media claims where included. Ordinary consultant PI can be too narrow. The activity description and wording should expressly cover SaaS/software development, hosting or provision, data processing and professional services.
The overlap
The same event can trigger both. Example: a software defect exposes resident feedback. Viewee incurs forensics and notification costs (cyber), while the care group claims breach of contract, confidentiality and business loss (cyber third-party liability and/or tech PI). A combined wording with one insurer or coordinated broker placement is preferable because it can reduce arguments over which section responds. Check whether the policy has one shared aggregate limit. A £1m + £1m certificate may still provide only £1m total if the limits are shared.
2. Credible UK options for an early-stage tech company
These are a shortlist for quotations, not endorsements. Compare actual wording and insurer security rating, not just the broker's website.
| Option | Route | Best use for Viewee | Evidence status |
|---|---|---|---|
| PolicyBee | UK small-business broker with online quote route | Fast baseline quote; publishes SaaS-specific PI and cyber examples | Verified from provider pages |
| Superscript | UK broker / digital platform with advised service | Startup-friendly route and useful when contract requirements need advice rather than a simple online purchase | Verified from provider page |
| Marsh Commercial | UK commercial broker with a technology practice | Useful second advised quote, especially when larger client limits and contract review matter | Verified from provider page |
| Capsule | UK specialist broker focused on high-growth businesses | Worth asking for a combined tech/cyber placement that can scale with investment and enterprise customers | Verified as specialist provider; exact Viewee terms require quote |
| Get Indemnity | UK digital commercial insurance broker | Has a SaaS / technology E&O package; useful for comparing combined wording | Verified from provider page |
| CFC | Specialist cyber/technology insurer, usually accessed through a broker | Strong cyber specialism and incident-response proposition; ask brokers whether CFC will quote at Viewee's stage | Verified as market option; eligibility/price unverified until quote |
| Coalition | Specialist cyber insurer offering UK technology/cyber coverage through brokers | Useful comparison for active cyber monitoring and coordinated tech E&O/cyber cover | Verified from provider pages; eligibility/price unverified until quote |
| Hiscox UK | Direct insurer / broker channel | Recognised direct-market comparison for cyber and data cover; test wording against specialist combined options | Verified from provider page |
Suggested quote process: ask PolicyBee and Superscript for quick benchmarks, then ask one specialist broker (Capsule, Get Indemnity or Marsh Commercial) to compare combined wordings including CFC/Coalition where available. Use the same completed fact sheet for every quote.
3. Premium and cover benchmarks
Verified published anchors
PolicyBee's SaaS page advertises PI from £8.14/month for £100k cover and cyber from £10.66/month for £100k cover, based on annual income up to £25,000 and including 12% IPT. These are entry prices, not Viewee quotes.
The same page says PI is available up to £5m and names turnover, contract size, cover amount and technology/activity as price factors.
Insure24's December 2025 guide gives broad software-company ranges of £500-£3,000+ a year for PI and £800-£5,000+ a year for cyber. It states that healthcare applications and health records cost more, and gives a £50k-turnover startup example of £400-£600 PI and £600-£900 cyber. This is broker-published guidance, not an insurer quote or market survey.
Viewee planning estimates
| Stage / limit | Working annual budget | Confidence |
|---|---|---|
| Minimal £100k PI + £100k cyber | Roughly £225+ at advertised floors | Verified floor, but likely inadequate for care-group due diligence and not a Viewee quote |
| Pre-revenue / pilot, £500k each | £700-£1,500 | Estimated |
| Pre-revenue / pilot, £1m each | £1,000-£2,500 | Estimated; recommended quote target |
| Early paid customers, £2m each | £1,800-£5,000+ | Estimated; depends heavily on contracts, data and controls |
The estimates deliberately sit above mass-market advertised floors because Viewee may process identifiable care-sector free text that reveals health or safeguarding information. Actual prices may fall outside these ranges. Only broker/insurer quotations can verify the premium.
What pushes price up
More identifiable records, health/special-category data, safeguarding material or children/vulnerable-person data.
Higher revenue, customer count, largest contract value and contractual liability caps.
Higher limits, lower excess, broad US/Canada exposure, and broad dependent-business-interruption cover.
Weak or absent MFA, backups, patching, endpoint protection, tested incident response, encryption, access reviews or staff training.
Subcontractors and cloud dependencies without clear controls or contracts.
Prior incidents/claims, rapid scope change, regulated/high-impact customer uses, or software making care/clinical decisions.
Before quoting, document MFA, least privilege, encryption, backups, logging, vulnerability/patch process, secure development, incident response, retention/deletion, staff training, subcontractors, hosting location, expected record volumes and whether feedback is identifiable. Cyber Essentials can help with both underwriting and buyer confidence, but does not replace insurance.
4. What care-group due diligence will typically ask
There is no single care-group questionnaire. The list below is a practical synthesis of public-sector supplier assurance, NHS supplier guidance and common contract onboarding. The insurance section usually asks:
Insurer, policy number, renewal/expiry date and certificate.
Tech PI/professional indemnity, cyber, public liability and employers' liability limits.
Whether limits are each claim or aggregate; whether defence costs sit inside or outside the limit.
Excess/deductible and material sublimits, especially notification, forensics, interruption, ransomware and regulatory costs.
Territorial and jurisdiction cover, retroactive date and how long PI cover will be maintained after the contract.
Whether SaaS, software development, hosting, data processing, subcontractors and breach of confidentiality are within the insured business description.
Claims, incidents or circumstances in the last three to five years.
Whether the insurer can meet a proposed £1m or £2m contractual minimum and provide evidence before go-live.
The broader security and data questionnaire will still ask for evidence that insurance cannot answer: UK GDPR roles, data-processing agreement, subprocessor list, hosting/data locations, special-category lawful basis and Article 9 condition where relevant, DPIA support, retention/deletion, access controls and MFA, encryption, backups, penetration/vulnerability testing, secure development, incident response, breach notification times, business continuity/disaster recovery, staff training, Cyber Essentials/ISO 27001/DSPT status, audit rights and flow-down to suppliers.
NHS England's DSPT supplier guidance expects organisations to manage suppliers contractually and assess their data-security arrangements. The NHS supplier cyber charter also focuses on cyber standards and incident response. A certificate of insurance is therefore supporting evidence, not a substitute for a security pack.
Policy wording questions to answer before purchase
Ask the broker to answer these in writing:
If a coding error causes a privacy breach and client loss, which section responds?
Are incident-response costs paid from day one and is prior insurer consent required?
Is there 24/7 access to forensic and privacy counsel, and may Viewee use its own adviser?
Does cover include notification to data subjects, ICO response, restoration, PR, cyber extortion, business interruption and dependent cloud failure?
Are contractual liability, confidentiality, IP/media, unencrypted devices, insider acts and social engineering excluded or sublimited?
Are regulatory fines covered only where legally insurable, and are investigation/defence costs covered even if a fine is not?
Are tech PI and cyber limits separate or shared? Are defence costs inside the limit?
Does the business description match Viewee's actual product and care-sector data processing?
5. When to buy
Buy before live-data pilot
For Viewee, the sensible trigger is before a pilot accepts identifiable or real resident/family/staff feedback. The risk starts when Viewee stores or processes the data, not when an invoice is issued. Buying before live processing also avoids a customer procurement delay and ensures an earlier retroactive date for claims-made PI/cyber wording.
A policy can wait only while the product uses synthetic, fully anonymised test data, has no external users, gives no advice/service under contract, and no pilot or customer requires a certificate. Even then, obtain indicative quotes early so security gaps or exclusions are found before go-live.
Practical sequence
Now: prepare one accurate underwriting fact sheet and request matched £500k/£1m/£2m quote options.
Before signing the pilot or receiving live identifiable data: bind £1m tech PI + £1m cyber unless the pilot terms support a different limit.
Before the first larger care-group contract: compare the required limits and contractual liability cap against the policy; increase to £2m if required.
At every material change and annual renewal: tell the broker about new data categories, record volumes, services, countries, large contracts, incidents and controls.
Do not let a contract promise broader liability than the insurance covers. Insurance requirements, indemnities, liability caps and exclusions should be reviewed together.
Caveats
This is commercial research, not regulated insurance or legal advice.
Premiums and appetite change quickly. The prices above are published examples and planning estimates, not quotations.
"Care-sector data" is not a legal category. Whether feedback is special-category data depends on its content and how Viewee processes or infers it.
Regulatory fines may be uninsurable or limited. Buy for response, defence, restoration, interruption and third-party liability, not on the assumption that every fine will be paid.
Read the full wording, schedule, endorsements and proposal answers. A certificate alone is not enough.
Sources
National Cyber Security Centre, "Cyber insurance guidance" (updated 28 July 2026): https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance
Information Commissioner's Office, "72 hours - how to respond to a personal data breach": https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/72-hours-how-to-respond-to-a-personal-data-breach/
ICO, "What is special category data?": https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/
PolicyBee, "Insurance for SaaS developers": https://www.policybee.co.uk/insurance-for-saas-developers
PolicyBee, "Cyber insurance": https://www.policybee.co.uk/cyber-insurance
Marsh Commercial, "Technology company insurance": https://www.marshcommercial.co.uk/for-business/technology.html
Superscript, "Startup insurance": https://gosuperscript.com/business-insurance/business-type/startup-insurance/
Capsule, company and product overview: https://capsulecover.com/
Get Indemnity, "SaaS insurance & technology E&O package": https://getindemnity.co.uk/saas-insurance
CFC, cyber insurance overview: https://www.cfc.com/en-gb/products/cyber/
Coalition, technology industry cyber cover: https://www.coalitioninc.com/en-gb/industry/technology
Coalition, coverage overview: https://www.coalitioninc.com/en-gb/coverages
Hiscox UK, cyber and data insurance: https://www.hiscox.co.uk/business-insurance/cyber-and-data-insurance
Insure24, "How much does software company insurance cost in the UK?" (8 December 2025): https://www.insure24.co.uk/blog/how-much-does-software-company-insurance-cost-in-the-uk/
UK Government, Cyber Security Model Supplier Assurance Questionnaire Level 1: https://assets.publishing.service.gov.uk/media/69aff1f4c78869bf8eb8a5bc/CSM_SAQ_Level_1_for_GOV.UK.pdf
NHS England Digital, "Cyber security charter for suppliers to the NHS": https://digital.nhs.uk/cyber-and-data-security/guidance-and-resources/cyber-security-charter-for-suppliers-to-the-nhs
NHS England Digital, DSPT guide, "Your suppliers and contracts": https://digital.nhs.uk/cyber-and-data-security/guidance-and-assurance/data-security-and-protection-toolkit-assessment-guides/guide-10---accountable-suppliers/your-suppliers-and-contracts/
