Get Help With Insurance Buying and Renewals.
Get help buying coverage and managing renewals, with less paperwork for your team. Start with a free consultation.
Get help buying coverage and managing renewals, with less paperwork for your team. Start with a free consultation.
Consider general liability, professional errors and omissions (E&O), technology errors and omissions (E&O), cyber liability, and tools, equipment and inland marine. Start with the coverages tied to your day-to-day operations, then use the situations and buying questions below to compare your options.
Staff guard a site, install access controls or cameras, patrol premises or visit customer locations.
General liability can address certain bodily-injury and property-damage claims, but the actual operations and exclusions matter. Have the insurer confirm how guarding, installation and monitoring are classified.[1][7]
Which guarding, installation, monitoring and customer-site activities are declared, and what exclusions, limits or conditions apply?
Clients rely on assessments, monitoring, penetration testing, incident response or security recommendations.
Ask the insurer whether each stated security service falls within the professional-services definition and which exclusions apply.[1][2]
Are assessment, testing, monitoring and response services listed as insured professional work, and which loss types are excluded?
The company sells managed detection, security software or technology-enabled monitoring.
Chubb describes technology E&O for third-party financial injury from insured products and services in its named DigiTech ERM summary. Treat that as a product example only; ask the insurer to define services and claims under your proposed form.[6][5]
Which products and services, third-party financial-loss claims, response commitments and customer configurations are within the quoted form?
The provider holds customer credentials, logs, incident records or privileged system access.
Assess supplier and vendor-held data risks, then ask how your own policy treats them. Customer vendor-review guidance does not establish your policy’s response.[3][4]
Does the proposed form address your own access, customer systems, vendor incidents, response, defense and interruption? Ask for definitions and exclusions.
Cameras, sensors, test devices or tools move between storage, customer sites and installation jobs.
Ask whether movable devices should be scheduled under inland-marine wording, including each custodian, transit leg and installation stage.[7]
Which devices, values, sites, handlers and installation or transit stages are scheduled?
List physical guarding, patrols, alarm monitoring, equipment installation, penetration testing, managed detection and incident response as distinct operations. Ask the insurer which activities are included in the application and which definitions or exclusions apply.[1][7]
For each contract, flag promises about response time, detection, containment, uptime or loss prevention. These commitments shape the scenario to discuss with the broker; they do not establish that a policy covers a service failure or customer loss.[5]
Inventory administrator accounts, customer credentials, logs, endpoints, incident records, subprocessors and who can access each environment. FTC advises businesses to assess supplier and vendor data risks; use that as an operational checklist and ask separately how your own policy treats each scenario.[3]
Ask how the proposed forms address vendor incidents and errors in technology services, including response obligations, exclusions and sublimits. Chubb’s examples describe exposures; they do not establish your policy’s response.[5]
Identify devices and tools that leave storage, who transports them and which customer sites receive installation or maintenance work. Ask whether the quoted property or inland-marine wording schedules the items, movement and installation stages you use.[7]
If another firm performs monitoring, installation or response work, describe its role and access to the customer environment. Ask how the contract and insurance application treat subcontracted work instead of assuming your policy automatically extends to the other firm.[1][3]
Not enough ratings
Not enough ratings
Not enough ratings
Not enough ratings
Not enough ratings
Do not assume one policy includes every operation; ask which forms and declared activities apply.[1]
Read the Full AnswerNo. A customer’s vendor-risk review assesses supplier security; it does not interpret the security provider’s policy.[3]
Read the Full AnswerFTC cybersecurity guidance on supplier risk and policy questions.
Chubb risk scenarios for technology-service and vendor exposure.
California-focused reference for commercial liability, property and inland-marine topics; confirm terms and requirements where the business operates.
Spot, a product of Tools for Enlightenment, publishes this guide and works in the commercial insurance market. This is general buyer education; policy terms and state-specific obligations determine coverage and requirements.
Updated 2026-09-28. Editorial Policy
Get help buying coverage and managing renewals, with less paperwork for your team. Start with a free consultation.