A software company has no kitchen fires or forklift accidents, so it's tempting to conclude insurance is someone else's problem. In practice, three forces pull a startup into the insurance market whether it plans to or not: enterprise clients whose contracts demand professional indemnity and cyber cover before signing, investors whose term sheets expect D&O once they take a board seat, and employment law — because WICA obligations don't care that your product is SaaS.
At a glance: what you need, and why
| Cover | Status | Why it matters here |
|---|---|---|
| WICA work injury insurance | Compulsory | Compulsory once you hire anyone earning S$2,600 a month or less, interns included. |
| Professional indemnity / tech E&O | Usually required | Enterprise customers set a limit in the contract before they will sign with you. |
| Cyber insurance | Usually required | Customers who hand you their data increasingly make cyber cover a contract term. |
| Directors and officers | Worth considering | Becomes a condition of the round once outside investors take board seats. |
| Public liability | Worth considering | Your landlord or co-working operator may still ask for a modest limit. |
| Office contents and equipment | Worth considering | Laptops, screens and fit-out, if the company owns anything worth replacing. |
| Group employee benefits | Worth considering | Medical cover is how small teams compete for engineers against bigger payers. |
What your client contracts will demand: PI / tech E&O
The first insurance most startups buy is professional indemnity (in tech, usually written as technology errors & omissions), and the trigger is almost always a client contract. Enterprise customers and government tenders routinely require vendors to hold PI at S$1 million or more before a deal signs.
Tech E&O covers claims that your product or service failed and cost the client money — a bug that corrupted their data, an outage that broke an SLA, a missed delivery that sank their launch, negligent advice in an implementation. It typically pays defence costs as well as damages, which matters because defending even a weak claim burns cash a startup doesn't have.
Two things to get right: buy a policy that matches your actual contracts (limits, jurisdictions if you serve overseas clients, and cover for contractual liabilities where possible), and keep it continuous — PI is claims-made, so the policy in force when a claim arrives is the one that responds. See our professional indemnity guide.
Cyber insurance: for your systems and their data
If you hold customer data or run production systems, cyber insurance covers the costs of a breach or attack: incident response and forensics, legal and notification costs, data restoration, business interruption from downtime, and third-party claims from affected customers. Ransomware and business email compromise are the claims actually happening to small companies — this isn't cover for a hypothetical.
Increasingly, enterprise clients ask about cyber cover in vendor security reviews alongside PI, and insurers ask about your controls (MFA, backups, endpoint protection) before quoting — weak controls mean higher premiums or declined cover. Indicatively, cyber for a small firm runs from around S$500–1,500 a year. Whether it's worth it at your stage is a real question — our guide Is cyber insurance worth it? works through it, and the cyber insurance page covers what policies include.
Once investors are in: D&O
Directors' and officers' liability insurance protects the personal assets of directors and officers against claims arising from their decisions — from shareholders, regulators, creditors or employees. Pre-funding, few startups buy it. Post-funding, it becomes standard fast: VCs taking board seats commonly require D&O as a condition of investment, because board members are personally exposed and won't serve unprotected.
D&O also matters in the scenarios founders least want to think about — a down round dispute, insolvency where creditors examine directors' conduct, or an employment claim naming directors personally. If a term sheet is on the table, price D&O into the round. See D&O insurance.
The employer layer: WICA and group benefits
The moment you hire, employer obligations start:
- WICA insurance is compulsory for all employees doing manual work at any salary, and all non-manual employees earning S$2,600 a month or less — which in a startup often means interns, junior support staff and early ops hires. Many startups simply insure the whole team; the premium for office staff is small, indicatively S$50–100 per person per year. Employees above the threshold can still claim WICA compensation from you if injured — without a policy, the company pays. Details in the WICA guide.
- Foreign Worker Medical Insurance applies if you employ S Pass holders — at least a S$60,000 annual claim limit per worker. (Employment Pass holders are outside FWMI, but many startups extend group medical to them anyway.)
- Group employee benefits — medical, hospitalisation, sometimes dental — are a hiring tool in a market where candidates compare offers on benefits, not just salary. Indicatively S$300–800 per employee per year depending on plan design. See group employee benefits.
Actual premiums depend on your team and cover choices — get quotes rather than budgeting off ranges.
Frequently asked questions
Does a tech startup legally need insurance in Singapore?
Only in one respect for a typical software startup: WICA work injury insurance, which is compulsory for any employee earning S$2,600 a month or less and anyone doing manual work — so a startup with interns or junior staff usually has a legal obligation from its first hires. Everything else (PI, cyber, D&O) is driven by client contracts and investors rather than statute.
What is tech E&O insurance and do I need it?
Tech E&O (errors and omissions) is professional indemnity for technology companies — it covers claims that your software or service failed and caused a client financial loss, including defence costs. You need it when your client contracts require it, which for enterprise and government customers is the norm, typically at S$1 million or more. Most startups buy it the first time a big contract demands it.
When should a startup buy D&O insurance?
The common trigger is institutional funding — VCs taking board seats usually require D&O so directors aren't personally exposed for board decisions. Before that, it's a judgement call; after a priced round with outside directors, it's effectively standard. If you're negotiating a term sheet, assume D&O will be a closing condition and price it in.
Do I need WICA insurance if all my staff are engineers on good salaries?
You're not legally required to insure non-manual employees earning above S$2,600 a month — but any employee earning at or below that (interns, junior hires) must be insured, and injured employees above the threshold can still claim WICA compensation that your company would pay out of pocket without a policy. Insuring the whole team costs little for office staff and closes the gap.
Is cyber insurance worth it for an early-stage startup?
If you hold customer data or run production systems for paying clients, usually yes — a single ransomware or breach incident carries response, legal and downtime costs that would be existential for most seed-stage companies, and cover starts from around S$500–1,500 a year for small firms. If you're pre-product with no customer data, it can reasonably wait. Enterprise clients' security reviews often settle the question for you.
Related cover & guides
Professional Indemnity Insurance
Covers negligence, errors and omissions in professional work. Required by some professional bodies and many B2B contracts.
Read more →Cyber Insurance
Covers ransomware, data breaches, email fraud and PDPA fallout — response costs, lost income and third-party claims.
Read more →Directors & Officers (D&O) Liability Insurance
Protects directors' personal assets against claims from their decisions. Key for companies with investors or regulated activities.
Read more →Is Cyber Insurance Worth It for Singapore SMEs?
Honest cost-benefit on cyber cover for SMEs: PDPA exposure, email-compromise risk, and when a small firm can reasonably skip it.
Read more →