I often see growing companies change faster than their insurance programs.

At Seed and Series A, the focus is usually on putting the first protections in place. By Series B, the company may have a product in the market, a larger workforce, enterprise customers, a more experienced board, and operations across multiple states or countries.

As the company grows, more people are making decisions on the company’s behalf and contracts carry greater obligations. A missed milestone, employment dispute, or security event can cost more to resolve.

Yet the risk program may still look much as it did when the company was smaller, carrying the same limits, retentions, and assumptions into each renewal.

That makes Series B a good time to pause and ask whether your coverage and controls still fit the business. Governance, people, and security are three good places to start.

Governance Risk: More Scrutiny and More Personal Exposure

At earlier stages, founders and a small group of executives may make most decisions quickly. By Series B and beyond, decision-making is spread across more leaders, and the board may include outside directors with deeper operating experience.

As leadership broadens, clear ownership, reliable documentation, and defined escalation paths become more important. Without those practices, operating problems can become governance problems.

Consider a Series B software company that’s signing larger enterprise customers. The engineering team is falling behind on implementation commitments, but the issue isn’t consistently reported to the board.

The company later misses its revenue forecast, making additional financing harder to secure. Investors then allege that leadership failed to provide enough visibility into known operating problems.

The original problem was operational, but the reporting gap made it a governance issue

To prevent a situation like this, leadership teams should ask:

  • Who owns each major category of risk?
  • Which issues should reach the board, and when?
  • How are major decisions documented?
  • What events require escalation?
  • Where is the company still relying on informal processes?

Those governance practices should be paired with Directors and Officers (D&O) liability insurance, which helps protect executives and board members when decisions made on the company’s behalf come under scrutiny.

For private companies, D&O coverage may protect individuals when the company can’t indemnify them, reimburse the company when it does, and cover certain claims against the company itself.

A $1 million limit selected at Seed or Series A shouldn’t carry forward automatically. Whether that limit still fits depends on factors such as the company’s valuation, financing, industry, board composition, and exposure to investors, employees, customers, and regulators.

Other management liability coverages deserve the same attention. For example, as employee benefit plans grow, companies should review fiduciary liability and confirm they carry any fidelity bond required under the Employee Retirement Income Security Act (ERISA).

While good governance won’t prevent every disagreement or allegation, it gives the company a clearer record of who made the decision, what information they considered, and how the issue was addressed.

People Risk: Coverage Needs to Follow the Growth of Your Workforce

By Series B, founders are no longer involved in every hire, performance discussion, promotion, or termination. Managers often make these decisions before they’ve been fully trained for the responsibility.

Suppose a company doubles its headcount in less than a year. Managers have wide autonomy, and performance concerns are documented unevenly. After a termination, a former employee alleges discrimination and retaliation.

The company may believe it made a fair and defensible decision. But without records of coaching, expectations, prior discussions, and the reasons behind the termination, it may have a harder time showing how that decision was reached. Defense costs can grow well before the merits of the claim are resolved.

That’s why Employment Practices Liability (EPL) coverage should be reviewed alongside management practices. A limit selected when the company had 30 employees may not make sense at 150.

EPL is only one part of the review. Workforce growth also affects workers’ compensation, benefits administration, payroll, and local insurance requirements.

Common triggers for coverage review include:

Hiring in new states: A new hire in a new state should prompt a review of workers’ compensation, payroll reporting, and state-specific requirements. It shouldn’t be treated as an onboarding matter alone.

Leaving a PEO: Before moving away from a professional employer organization (PEO), companies should map everything the PEO previously provided. Workers’ compensation, employment support, benefits administration, and claims handling may all need to be replaced or coordinated independently.

Expanding internationally: Employees may be traveling abroad, relocating, or being hired directly in other countries. Local insurance and employment requirements vary, and some companies may need locally issued policies coordinated with a global master program.

Adding new pay and equity arrangements: More employees, job levels, locations, and compensation structures create more opportunities for payroll mistakes, inconsistent treatment, equity record errors, and missed notices.

These issues may start as administrative problems but later contribute to wage-and-hour disputes, discrimination allegations, or other employment claims.

Security Risk: More Access, More Accountability

Security exposure grows as more teams make decisions about data. Sales may accept demanding security obligations in customer contracts while product teams introduce new uses of data and vendors take on a larger role in storing or processing it.

These decisions often happen in different parts of the business, but together they can change the company’s obligations and the way its insurance program needs to respond.

Consider a SaaS company that has reviewed its internal security controls but conducts limited oversight of a third-party vendor. The vendor is later compromised, exposing customer data stored on the company’s behalf.

Because the incident began with the vendor, the company may expect the vendor to handle the response. Customers are likely to see it differently and look to the SaaS company for answers, notification, remediation, and, in some cases, reimbursement.

That’s why a security review should connect three parts of the risk:

  1. What the company has promised customers in its contracts
  2. How it manages data, system access, vendors, and incident response
  3. How its insurance and vendor agreements would respond after an incident

Cyber insurance may help pay for forensic work, legal support, notification, business interruption, and third-party claims. Technology Errors and Omissions (Tech E&O) coverage may respond when a technology failure, outage, or security event causes a customer financial loss.

These policies should be reviewed together because a single incident can involve customer contracts, cyber coverage, Tech E&O, privacy obligations, and a vendor’s indemnification responsibilities.

A useful review starts with a realistic scenario and follows it through the company’s controls, contracts, vendors, and insurance program. That approach makes it easier to see where responsibilities overlap and where gaps may remain.

Don’t Let Last Year’s Program Renew by Default

At least once a year, and after any major business change, leadership should revisit the assumptions behind the program, including:

  • The company and its capital: valuation, financing, investors, board composition, acquisitions, restructurings, and leadership changes
  • The workforce: headcount, new states, international hiring, business travel, PEO transitions, and layoffs
  • Products and customers: new products, services, revenue streams, enterprise customers, and contractual obligations
  • Technology and security: data use, vendors, AI adoption, security commitments, incidents, and near misses
  • The insurance program: limits, retentions, exclusions, sublimits, shared aggregates, claims, and coverage gaps

If the company has no in-house risk manager, a chief legal officer, CFO, treasurer, COO, or other executive should own the process. That person should bring legal, finance, HR, security, operations, and other relevant teams into the discussion.

The broker has a responsibility, too. A good broker should ask what has changed, where the company is headed, and whether the current policies still fit the organization’s operations and obligations.

If no one is challenging last year’s assumptions, the company may be buying coverage for a business it no longer runs.

Build for the Company You’ve Become

By Series B and beyond, governance practices, people processes, security controls, customer contracts, vendor agreements, and insurance need to support one another

Your company’s insurance program must reflect the company it has become and the exposures it’s likely to face next.

If you’re reviewing whether your risk program still fits the business, connect with a Sequoia advisor to talk through your current coverage and the changes ahead.

Kristen Peed — is the Chief Risk Officer at Sequoia and has over two decades of experience in the risk industry. She leads the placement of Sequoia’s corporate insurance programs, including captive operations, enterprise risk management, and the Risk team. Kristen also serves as the 2025 President of the Risk Management and Insurance Society (RIMS) and was named one of Captive Review’s Top 20 Captive Owners for 2025. She earned her B.A. in Industrial Relations from the University of North Carolina at Chapel Hill. Outside of work, Kristen enjoys training for half-marathons with her dog, golfing with her husband, and going to the beaches of South Carolina.