The SaaS insurance stack
The four covers that most SA SaaS companies carry:
- Cyber — POPIA breach response, ransomware, third-party claims.
- Tech E&O / Professional indemnity — product failures and missed SLAs.
- Business interruption — with an explicit cyber trigger.
- D&O — for the board, becomes required around Series A.
What investors expect
Series A+ investors typically require cyber + tech E&O in place, and D&O cover for the board. Getting the stack right ahead of due diligence removes friction from term-sheet negotiations.
Common gaps
Where SaaS founders under-insure:
- Cyber limits below 12 months' MRR
- No cyber extension on business interruption
- PI without a tech E&O endorsement
- No cover for cloud-provider outages