Skip to content
cyber insurance Technology E&O

Cyber Insurance for MSPs: Who Pays After Client Ransomware?

Kody Houk
Kody Houk

Managed service provider security operations center protecting connected client networks while one endpoint shows a contained ransomware incident.

Quick answer: Most managed service providers need both cyber liability insurance and Technology Errors & Omissions (Tech E&O). Cyber insurance responds to the MSP's own breach, incident-response costs, and certain network-security or privacy claims. Tech E&O responds when a client alleges the MSP's service, configuration, monitoring, backup, or response work failed and caused financial harm. The client still needs its own cyber policy. One ransomware event can trigger all three policies.

Picture an attacker stealing an administrator credential for a remote monitoring and management platform on Friday night. By Saturday morning, ransomware has reached six client networks. The MSP hires forensics and breach counsel, clients begin restoration, and two customers claim the provider failed to enforce multifactor authentication. This is not a single-loss question. It is an allocation problem involving incident costs, client losses, professional-service allegations, and contract language.

Why can one MSP ransomware event trigger several policies?

MSPs are unusual because they hold privileged access to many unrelated organizations. A compromise inside the provider can create first-party loss for the MSP and downstream loss for every affected client. A configuration error can create the same downstream damage without the MSP's own network ever being breached.

The joint CISA, NSA, FBI, and international advisory for MSPs warns that attackers target the trust relationship between providers and customer networks. Its recommendations include hardening remote access, enforcing multifactor authentication, preserving important logs, exercising incident-response plans, and putting shared security responsibilities into contracts.

Insurance follows the facts, not the label placed on the incident. The key questions are: whose systems were compromised, what service was allegedly performed incorrectly, who suffered the financial loss, and what did the contract require?

Cyber insurance vs. Tech E&O for MSPs

Coverage What usually triggers it Possible MSP ransomware costs
MSP cyber liability A security or privacy event involving the MSP's network, data, credentials, or technology environment Forensics, breach counsel, notification, data restoration, cyber extortion, business interruption, and network-security or privacy liability, subject to the policy
MSP Tech E&O An allegation that the MSP's technology service was negligent, defective, late, or failed to meet a professional obligation Defense and covered damages arising from failed monitoring, misconfiguration, poor migration, unusable backups, missed alerts, or other service failures
Client cyber liability A security event affecting the client's systems, operations, or data The client's forensics, restoration, interruption, notification, extortion, and liability costs, with possible recovery efforts against the MSP

The boundaries are not automatic. Policy definitions, exclusions, retentions, sublimits, retroactive dates, causation, and the services described in the application can change the result. An integrated cyber and Tech E&O form can reduce arguments between insurers, but it still must describe the MSP's actual work.

Which policy responds in common MSP claim scenarios?

Scenario 1: A stolen RMM credential spreads ransomware to clients

The MSP's cyber policy may respond to its own forensic investigation, credential compromise, restoration, business interruption, and third-party network-security allegations. Each client turns first to its own cyber policy for its response and downtime. If clients allege the MSP failed to secure privileged access, monitor the tool, or follow its security commitments, the MSP's Tech E&O coverage may also be implicated.

CISA's Remote Monitoring and Management Cyber Defense Plan highlights the risk that an RMM compromise can give an attacker a foothold in numerous customer networks. That concentration risk is exactly why an MSP should not size insurance around an average client.

Scenario 2: Backups reported success but cannot restore

Assume ransomware reaches one client, but the MSP's own systems are not compromised. The client's cyber policy may fund incident response and business interruption. If the provider had contracted to manage backups and the recovery images are corrupted or untested, the allegation against the MSP is primarily a professional-service failure. That points toward Tech E&O, even though ransomware exposed the problem.

The distinction matters: a cyberattack does not automatically make every resulting claim a cyber-insurance claim. The MSP can face E&O liability because the promised service did not work.

Scenario 3: A firewall rule exposes client data

An engineer applies a rule to the wrong tenant, leaving a storage environment publicly accessible. The affected client's cyber policy may fund its response. The MSP could face a network-security or privacy claim under its cyber policy and a Tech E&O claim alleging negligent configuration. This overlap resembles the coverage problem described in our guide to cyber liability vs. Technology E&O for SaaS companies: one technical failure can create both an incident and a service-performance claim.

What should an MSP review in its insurance policy?

A certificate showing “cyber” and “professional liability” is not enough. Review the wording against the services listed in your proposals, master service agreements, and statements of work.

  • Professional services definition: Does it expressly include remote monitoring, managed security, cloud administration, backup and disaster recovery, patching, migration, help desk, procurement, and incident response?
  • Network-security and privacy liability: Does the cyber form contemplate unauthorized access that moves through the MSP to a customer's environment?
  • Contractual liability: Are ordinary client indemnity obligations covered, carved back, or excluded? Insurance should support reasonable contracts, not replace contract review.
  • Dependent-system and vendor loss: How does the policy treat a compromise or outage at an RMM, backup, cloud, or security-tool vendor?
  • Subcontractors and tools: Are losses arising from outsourced technicians, SOC providers, and third-party platforms within the covered service?
  • Defense costs and limits: Do legal expenses erode the same limit available for settlement? A multi-client event can exhaust a limit quickly.
  • Incident notice: Can the MSP notify one carrier for both cyber and E&O allegations, or must separate notices be filed immediately?
  • Retroactive date: Does it reach back far enough to cover services performed before the current policy term?

If your work includes client data migration, review the related failure points in Tech E&O for consultants migrating client data. If staff or contractors have broad client-system permissions, compare your process with our article on cyber liability for consultants handling client access.

What should the MSP-client contract say about cyber incidents?

Insurance disputes often begin as contract disputes. The agreement should identify who owns each security task, who can make urgent containment decisions, how quickly incidents must be reported, which logs must be preserved, and who pays for work outside the regular scope.

The NIST Cybersecurity Framework 2.0 supply-chain guide encourages organizations to define and communicate supplier security requirements. For MSPs, that means converting broad promises like “industry-standard security” into workable responsibilities for MFA, endpoint coverage, backup testing, vulnerability remediation, privileged accounts, and incident cooperation.

Regulated customers may impose additional duties. For example, the FTC Safeguards Rule guidance tells covered financial institutions to select capable service providers, put security expectations in contracts, monitor their work, and reassess them periodically. An MSP serving auto dealers, lenders, tax preparers, or other covered financial institutions should expect those customers to push these requirements downstream.

Which security controls matter to underwriters and clients?

The strongest insurance program cannot compensate for uncontrolled privileged access. An MSP should be prepared to document:

  • phishing-resistant MFA for remote, administrative, and RMM access;
  • separate named administrator accounts, least privilege, and privileged-access management;
  • endpoint detection and response across the MSP and covered client endpoints;
  • central logging with retention that supports investigation and customer obligations;
  • network segmentation and restrictions on tool-to-tool access;
  • immutable or offline backups with documented restore testing;
  • employee and contractor offboarding that immediately removes access;
  • an incident-response plan exercised with key clients and technology vendors; and
  • an inventory of subcontractors and platforms that can reach customer systems.

Do not overstate these controls on an insurance application or client security questionnaire. A gap between the written answer and actual practice can create both a client claim and a coverage dispute.

How should an MSP choose cyber and Tech E&O limits?

Start with a realistic aggregation scenario, not annual revenue alone. Ask how many clients could be affected through one identity provider, RMM tenant, backup console, or security tool. Estimate the MSP's own response expenses, defense costs, the largest clients' downtime, contractual indemnity exposure, and the possibility of several claims sharing one aggregate limit.

Then compare those amounts with policy sublimits, retentions, defense-cost treatment, and the liability caps in your client agreements. The correct limit is specific to the MSP's access, services, customer mix, and contracts; there is no universal number that fits every provider.

Frequently asked questions

Does an MSP need both cyber insurance and Tech E&O?

Usually, yes. Cyber insurance is built around security and privacy events. Tech E&O is built around allegations that technology services failed and caused financial harm. MSP ransomware claims commonly contain both allegations.

Does the client's cyber policy protect the MSP?

Not automatically. The client's policy primarily protects the client. Its insurer may seek recovery from the MSP after paying the loss. The MSP needs its own cyber and Tech E&O program.

If ransomware caused the loss, is it always a cyber claim?

No. Ransomware may be the initiating event, but a claim that backups failed, patches were missed, or access was misconfigured can be a Tech E&O claim against the MSP.

Should cyber and Tech E&O be placed with the same insurer?

A combined form can reduce gaps, duplicate retentions, and carrier disputes. Separate policies can work when definitions, exclusions, notice requirements, and retroactive dates are coordinated deliberately.

Can an MSP's contract cap its ransomware liability?

A negotiated limitation of liability may reduce exposure, but carve-outs for confidentiality, data security, gross negligence, or indemnity can remove the cap. Contract enforceability also depends on the facts and applicable law. Have qualified counsel review the agreement.

Review coverage before the next client incident

An MSP should be able to answer one question before a claim: if our access or service failure contributes to ransomware at several clients, which policy responds to each layer of loss? PrimeRisk Insurance Solutions reviews cyber, Tech E&O, and client contract requirements together so the coverage reflects how the MSP actually operates.

Request a cyber and Tech E&O coverage review or call 480-613-8387 to discuss your managed services program.

Share this post