August 24, 2026

Cyber Liability vs Technology E&O in Malaysia

Written by
Michelle Chin

Entrepreneur & strategist - experienced in driving digital-first insurance innovation, with extensive experience in scaling successful businesses

Most Malaysian technology businesses assume cyber insurance and technology errors and omissions cover are two names for the same thing. They are not, and a client contract that names one while meaning the other is how a business ends up holding a policy that will not answer the claim it was bought for.

Cyber liability is about your data and systems being attacked. Technology errors and omissions is about your product or service failing a client. The claim decides which one pays, and some claims sit in both.

This is written for Malaysian software companies, IT services firms, agencies, SaaS businesses and any SME that handles customer data under a client contract.

Client contract asking for both, and you hold one?

Send the clause and your current schedule. You will get back which cover it actually names and where the two do not meet. This sits around cybersecurity insurance and technology professional indemnity.

WhatsApp Us Now

Key Facts: Cyber Liability vs Technology E&O in Malaysia

What is the core difference? Cyber liability responds when your systems or data are compromised, covering response costs and your liability to people whose data was involved. Technology errors and omissions responds when your product, code or service causes a client financial loss.

Who needs which? Any business holding customer personal data has a cyber exposure. Any business paid to build, host, integrate or support technology has an errors and omissions exposure. Most Malaysian software and IT services firms have both, in different sizes.

What drives the cost of each? Cyber is rated on the volume and sensitivity of the data you hold, your security controls and your sector. Technology errors and omissions is rated on fee income, what you build, who you build it for and the contracts you sign.

Is either required in Malaysia? No. The Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, imposes no insurance requirement, and neither does the Cyber Security Act 2024 (Act 854). Where you are required to carry cover, the instrument is your client contract.

What changed recently? Data breach notification became mandatory from 1 June 2025, as did the appointment of a data protection officer where the thresholds apply. Both create work and cost after an incident, which is what the cyber response side of a policy is built around.

Last verified: August 2026. Checked against the Personal Data Protection Act 2010 as amended in 2024, the Cyber Security Act 2024, and MyCERT incident reporting for 2025.

Two policies, two kinds of accident

The clearest way in is to look at what has to happen before each policy is relevant at all.

This table sets out what triggers each cover and what it is written to pay for.

Feature Cyber liability Technology errors and omissions
What has to have happened A breach, an attack, an outage caused by an incident, or unauthorised access to data A negligent act, error or omission in the technology service or product you delivered
Who is usually harmed You, plus the individuals whose data was involved Your client, financially
Typical first-party costs Incident response, forensics, notification, restoration, and business interruption where the wording provides it Generally none. This is a liability cover
Typical third-party costs Claims by affected individuals or clients arising from the incident Damages and defence costs on a client's claim about your work
Trigger Commonly claims made, with incident discovery conditions attached Claims made, with a retroactive date
Who asks you for it Enterprise clients, vendor security questionnaires, data processing agreements Clients buying delivery, in the services agreement itself

Where the two meet, and where they miss

Some incidents are obviously one or the other. The interesting ones are the incidents that could be described either way, because that is where cover is either doubled up or absent.

This table walks scenarios a Malaysian technology business could realistically meet, and names where each one lands.

Scenario Where it lands The trap
Ransomware locks your own systems and you cannot deliver for a week Cyber Your client's losses from the outage may be a separate claim on a different section
A misconfiguration your team made exposed a client's customer database Both are arguable If you hold only one, the insurer may reasonably say the loss belongs to the other
Your integration silently dropped transactions for two months Technology errors and omissions No security incident occurred, so a cyber-only policy has nothing to respond to
An employee was tricked by a phishing email and sent a payment to a fraudster Cyber, where the wording includes it Social engineering and funds transfer cover is frequently sub-limited or excluded. Read the schedule
You hosted a client's application and the hosting provider suffered an outage Depends on the contract and the wording Dependent business interruption is a named extension, not an assumption
A former staff member took client data with them Cyber, if the wording covers insider acts Deliberate acts by employees are treated very differently between wordings

The second row is the one worth sitting with. A single mistake by your own team that exposes a client's data is simultaneously a security incident and a professional error, and which policy answers depends on how each wording is drafted rather than on how you describe it afterwards.

Which one is your contract asking for?

Contract drafting rarely uses the names insurers use. This table matches the phrases that turn up in Malaysian client agreements and vendor questionnaires to the cover being described.

Phrase in the clause Cover being described What to confirm before you agree
"cyber liability insurance" Cyber, usually including the response sections Which sections they actually need, because the label alone does not say
"technology errors and omissions" or "tech E&O" Technology professional indemnity That the trigger reads claims made, and what retroactive date is required
"privacy liability" or "network security liability" Sections inside a cyber policy rather than separate products That your schedule names those sections, not merely the policy
"professional liability including cyber risks" A combined ask, often meaning a tech PI policy with cyber extensions Whether your extensions survive your endorsement pages
"data protection insurance" Not a standard product name here Ask which loss they mean. It is nearly always the cyber response and liability sections

What Malaysian law requires, and what it does not

This gets overstated constantly, so it is worth being exact. No Malaysian statute currently requires a business to buy cyber insurance or technology errors and omissions cover.

What the law does require is conduct and process. The table below separates the obligations from the insurance question.

Instrument What it obliges Does it require insurance?
Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 Handling, security and accountability duties over personal data No
Data breach notification requirements, mandatory from 1 June 2025 Notifying the Commissioner, and affected individuals where the criteria are met No, but it generates the cost the cyber response section is designed for
Mandatory data protection officer appointment, effective 1 June 2025 Appointing and registering a DPO where the thresholds apply No
Cyber Security Act 2024 (Act 854) Duties on entities in designated national critical information infrastructure sectors No
Your client's services agreement or data processing agreement Whatever it says, at the limit it names Frequently yes. This is where nearly every real requirement comes from

One point admits no hedging. Whether any policy responds to a regulatory penalty is a question about your own wording and the law that applies to it, and it is not something to assume in either direction. Ask the question directly and get the answer in writing before you rely on it.

Filling in a vendor security questionnaire this month?

The insurance section is usually where it stalls, because the questionnaire asks for a cover by a name your schedule does not use. We can map your schedule to their wording. See data breach cover and the PDPA for the response side.

Get a Quote

Reading a Malaysian cyber schedule

Cyber policies are built from named sections, and the section names tell you what the policy will actually do. This is what to look for on your own schedule.

Section What it does What to check on yours
Incident response Funds forensics, legal advice and the notification work after a breach Whether you must use the insurer's panel, and how fast you can reach them
Data restoration Rebuilding data and systems after an incident Whether it covers your cloud environment as well as your own hardware
Business interruption Lost income while you cannot trade because of an incident The waiting period, and whether outages at your suppliers are included
Cyber extortion Response to a ransom demand The sub-limit, which is often well below the headline figure
Third-party liability Claims by clients or individuals affected by the incident Whether defence costs sit inside or on top of the limit
Social engineering or funds transfer Loss from a deceptive instruction rather than a technical intrusion Whether it is present at all, and at what sub-limit. This is the section most often missing

Compare that list against your contract clause rather than against a competitor's brochure. A client asking for cyber cover usually wants the response and third-party sections, and a policy strong on restoration but thin on liability satisfies the letter of the clause and not its purpose.

What the incident numbers actually show

Malaysian reporting data is useful here because it shows which exposures are common rather than which ones are dramatic.

The Cyber999 incident response centre received 1,657 incidents in the first quarter of 2025, up 7% from 1,550 in the previous quarter, according to MyCERT's Cyber Incident Quarterly Summary Report for Q1 2025. Fraud accounted for 1,126 of them. Data breach reports came to 195, up 29% on the previous quarter, and intrusions to 132, up 76%.

"phishing represented 68 percent of total fraud incidents reported in Q1 2025"

That is MyCERT, Cyber Incident Quarterly Summary Report Q1 2025, published by CyberSecurity Malaysia. The pattern matters for cover selection. The most frequently reported category is deception aimed at people, not a technical compromise of a system, and the sections of a cyber policy that answer deception are often the ones carrying the smallest sub-limits.

For scale, the Malaysian general insurance market wrote RM24.2 billion of gross premium in 2025, up 4.8% year on year, per the Persatuan Insurans Am Malaysia release dated 6 May 2026. Cyber remains a small and fast-moving part of that, which is why wordings differ between insurers far more than they do in older classes.

Six mistakes that show up repeatedly

These are the recurring errors when a business buys one of these covers against a contract requirement.

Mistake Consequence How to avoid it
Assuming a technology professional indemnity policy with cyber extensions equals a standalone cyber policy The extensions may be narrower, sub-limited, or removed by endorsement Read the endorsement pages, not the schedule summary
Buying to the contract limit without checking the sub-limits inside it The headline limit satisfies the client, the section you need is capped far lower Ask for the sub-limit schedule before you bind
Ignoring the retroactive date when switching insurer Work delivered before the new date falls outside cover Carry the earlier retroactive date across, and confirm it in writing
Treating notification conditions as paperwork Late notice of a circumstance can prejudice the claim Put the notification route in your incident plan, next to the regulator's
Answering a proposal form loosely about controls you do not actually have A disclosure problem at the worst possible moment Answer against reality. The duty of disclosure for a business buyer sits in Schedule 9, paragraph 4(1) of the Financial Services Act 2013
Letting the policy lapse between contracts Both covers are claims made. A lapse removes cover for everything already delivered Keep continuous cover even in a quiet quarter

FAQ

Do I need both cyber and technology E&O?

If you hold client or customer personal data and you are paid to build or run technology, you have both exposures. Whether you buy both depends on which is larger for your business and what your contracts demand. Buying one and assuming it stretches to the other is where businesses get caught.

Is cyber insurance mandatory in Malaysia?

No. The Personal Data Protection Act 2010 as amended in 2024 and the Cyber Security Act 2024 both impose duties on how you handle data and systems, and neither requires insurance. Where you are obliged to carry cover, that obligation comes from a client contract or a data processing agreement.

My tech PI policy already includes cyber extensions. Is that enough?

Sometimes, and it depends entirely on what those extensions say and whether any endorsement has amended them. Extensions are often narrower than a standalone wording and carry their own sub-limits. Read the endorsement pages of your own policy before deciding.

What does a data breach actually cost a Malaysian SME?

The costs that arrive first are investigation, containment, legal advice, notification and restoring systems, before any claim by an affected person. Since 1 June 2025 breach notification has been mandatory, which makes part of that work non-optional. The size varies too much by incident for a single figure to be meaningful.

Does either policy pay a regulatory fine?

That depends on your specific wording and on the law applying to the penalty, and it is not safe to assume either way. Ask your insurer the question directly and get the answer in writing before you rely on it in a board paper or a client response.

My client's questionnaire asks for "cyber liability including technology E&O". What is that?

It is usually a request for both covers, written by someone consolidating two requirements into one line. Ask which losses they want covered. The answer tells you whether you need one policy with the right sections or two policies sitting alongside each other.

Contingent Conclusion

Cyber liability and technology errors and omissions are bought by the same businesses for opposite reasons. One assumes something was done to you, the other assumes something was done by you. Most technology firms in Malaysia can construct a plausible claim of each kind, which is why the contract clause naming both is often the honest one.

The practical work is smaller than the theory. Find the loss you are most afraid of, name it in a sentence, and check which of your policies is written to answer that sentence. If neither is, that is the gap, and it is easier to fix before a client asks than after an incident.

Contingent helps Malaysian businesses get the cover their contracts and landlords require. Whether you're comparing options or checking whether your existing policy actually does what the contract asks, we can help.

Get a quote · or WhatsApp us directly

Related reading: our guide to cyber insurance in Malaysia, PI for IT consultants and software companies, PI for SaaS startups, ransomware cover for Malaysian SMEs, the PDPA compliance checklist for SMEs, and insurance for tech and SaaS startups.

Primary sources: the Personal Data Protection Commissioner for data breach notification, the MyCERT quarterly incident report published by CyberSecurity Malaysia, and the Laws of Malaysia portal of the Attorney General's Chambers for the Personal Data Protection Act 2010, the Cyber Security Act 2024 and the Financial Services Act 2013.

Published by Contingent, the commercial insurance brand of Emerge Insurtech (Malaysia) Sdn. Bhd.

Disclaimer: This article describes how these policy terms commonly operate in the Malaysian market as of August 2026. Wordings differ between insurers and between policy years, and endorsements can delete or amend any cover described here. Always read your own schedule and endorsement pages, and consult a qualified insurance professional before relying on any of it.

Protect your revenue, people and systems today