Actualizado en May 2026

Yes — sometimes. Insurers can deny or void claims when policy wording, proposal answers or contract warranties required insured suppliers or specific controls and those terms were breached. Check wording, what you declared to the broker and the MSP contract now.
Does subcontracting to an uninsured MSP void cover?
This section explains when cover fails and why. Read the three short rules below first.
Insurance outcomes depend on wording, disclosure and causation. An insurer will decline, repudiate or seek recovery based on those three things.
If the insurer can show an undisclosed MSP relationship or a breached warranty that mattered to underwriting, they can deny the claim.
How insurers decide
Insurers check whether the MSP relationship was declared on the proposal form. They also check whether any warranty or condition precedent was broken.
A breached warranty framed as a condition precedent may let an insurer treat the policy as never in force for that claim.
When a loss is blamed on a disclosure failure, insurers usually must show the omission mattered under applicable insurance disclosure laws. The materiality test does not always replace an express warranty or a well‑drafted condition precedent.
Always read the clause type first: misrepresentation, representation, warranty or condition precedent. That tells whether materiality or the wording governs the insurer's stance.
Vague answers on a proposal form increase repudiation risk. Give clear facts and back them with documents.
List the MSP name, services, remote access type and whether the MSP holds cyber insurance with policy details. Save the signed proposal and broker emails as proof of disclosure.
Causation and forensic proof
Insurers want proof that the MSP caused or materially helped cause the loss. Preserve logs and MSP access records immediately to prove or disprove causation.
If the MSP had no causal connection, insurers are less likely to deny cover. Quick forensics makes a difference.
Which policy clauses insurers use to void claims
This section lists the exact clause types to check in any cyber policy. Read these clause names and check your policy schedule.
Warranties, condition precedents and material change clauses most commonly decide whether a claim is paid or repudiated.
Warranties and condition precedent
A warranty can be absolute or a condition precedent. If framed as a condition precedent, an insurer may treat the policy as never effective for that claim.
Some warranty breaches can lead to claim refusal. The insurer's right to refuse still depends on the clause language and facts rather than a blanket rule.
Seek to convert absolute warranties into representations or to add carve outs for reasonable endeavours.
Example wording to avoid: "It is warranted that all third‑party providers maintain cyber insurance of not less than £1,000,000." Split obligations work better than absolute statements.
Exclusions for subcontracting and third
Some policies contain explicit exclusions for losses caused by subcontractors or for services by third parties. If your policy has such an exclusion, an insurer can refuse to pay for subcontractor‑caused losses.
Ask your broker to map any exclusion to the facts of an incident before accepting a denial.
Subrogation and waiver of recovery
Subrogation allows insurers to pursue the MSP after paying a claim for recovery. A waiver of subrogation stops insurer recovery but insurers accept waivers rarely and often for a fee or endorsement.
Contract terms that let insurers subrogate strengthen recovery chances. Low MSP insurance reduces recovery in practice.
A common clause that triggers denial reads: 'loss arising from acts of any subcontractor unless named in the schedule and maintaining cyber insurance with limits not less than the amount specified.' Check for this exact wording in your policy.
Sample policy wording helps spot trigger language. Below are three common samples used in claims.
Sample subcontractor exclusion:
'This policy does not cover loss or liability arising directly or indirectly from the acts or omissions of any subcontractor, third party supplier or managed service provider unless such subcontractor is named in the schedule and maintains cyber insurance with limits not less than the amount specified in the schedule.'
Sample condition precedent/warranty clause:
'It is a condition precedent to the liability of the Insurer that the Insured shall ensure that all third‑party IT suppliers engaged to provide remote administration or backup services shall at all times maintain in force cyber insurance with minimum limits of £1,000,000 and shall implement multi‑factor authentication and endpoint detection and response. Any breach of this condition shall entitle the Insurer to refuse cover in respect of any claim to which the breach contributed.'
Sample subrogation/waiver wording:
'The Insurer shall be subrogated to all rights of recovery against any third party responsible for a loss; no waiver of such rights shall be effective unless agreed in writing by the Insurer.'
Including these exact phrases makes it clear what to search for on a policy schedule and in supplier contracts.
Assessing your risk: due diligence checklist for MSPs
This section gives a ready checklist directors can use now to test vendor risk. Use it to prepare evidence for a broker meeting or an insurer query.
A documented evidence pack with MSP insurance schedule, contract clauses and access logs reduces the chance of denial and speeds subrogation.
Evidence pack items
Produce these items and keep copies in one folder.
- Signed MSP contract including insurance clause and indemnity.
- MSP insurance certificate with insurer, policy number, limits and retroactive date.
- Security proofs: MFA policy, EDR logs, segmentation diagrams, backup test records.
Security controls to verify
Ask the MSP for proof of these minimum controls. Require MFA for all remote access, central EDR, encrypted backups and no exposed RDP to the public internet.
If any control is missing, document a remediation plan and timeline.
Due diligence questions for the MSP
Use these exact questions in emails or meetings.
- Who has admin access and how is it logged?
- What insurer and limits cover your cyber policy?
- What is your retroactive date and claims history?
Request written answers and keep them with the proposal form.
A broker/client evaluation checklist that gives a clear coverage outcome avoids ambiguity at renewal or incident. Use these items as a scored checklist.
- Is the MSP named on the proposal form? (Yes = 0; No = 3)
- Does the MSP have a current cyber insurance certificate with insurer, policy number, limit and retroactive date? (Yes = 0; No = 3)
- Does the MSP have persistent admin or RDP access to production systems or backups? (Yes = 3; No = 0)
- Are required controls evidenced: MFA, centralised EDR, encrypted backups, segmentation? (All present = 0; any missing = 2 each)
- Does the contract contain an indemnity and requirement for insurer consent to subcontracting? (Yes = 0; No = 2)
Tally score: 0–2 green (low risk), 3–6 amber (review and remediate before renewal), 7+ red (high risk, restrict access and obtain insurer sign‑off).
Keep documentary proof for each item and present the score to the broker when seeking insurer confirmation.
Real UK cases: claims denied after third‑party outsourcing
This section summarises how real claims played out in England and Wales. These are anonymised patterns drawn from claims managed in the London market.
In multiple cases I handled, insurers declined claims where the insured had not disclosed persistent MSP remote access and had signed warranties requiring specific controls.
Case example 1: undisclosed remote access
Situation: an SME used an MSP with persistent RDP access and did not list the MSP on the proposal form.
Outcome: the insurer declined the ransom and forensic costs after proving nondisclosure mattered to underwriting.
Lesson: put MSP access on the form and supply logs proving control.
Case example 2: MSP with no insurance
Situation: a supplier introduced malware while patching and had no cyber policy or adequate controls.
Outcome: insurer paid the claim and then pursued the MSP by subrogation. Recovery was limited because the MSP had no insurance.
Practical hit: insist on MSP insurance to improve recovery odds and to signal seriousness.
Field data and sources
Regulatory context dates to note: UK GDPR and Data Protection Act 2018 (2018), Insurance Act 2015 (2015) and NIS Regulations 2018 (2018).
NCSC guidance on incident response remains a key resource for technical standards. For ICO reporting see ICO breach reporting.
Across London market placements, denial or heavy payment reduction is a non‑trivial outcome where disclosure, warranties or subcontractor exclusions are implicated. Reported ranges for contested losses involving undisclosed third‑party access or material warranty breaches commonly sit between 10 and 30 percent, varying by insurer and clause strength.
Where subrogation is attempted, recovery rates vary widely. Recoveries can be less than 50 percent of the insured loss if the MSP is insolvent or uninsured.
Cost trade‑offs: uninsured subcontractors versus insured vendors
A cheap uninsured MSP can cut costs now but raise the chance of claim denial or poor recovery later. The modest annual premium for an MSP often costs far less than the uninsured recovery shortfall after a major incident.
Direct costs and hidden costs
Direct savings come from lower invoicing by an uninsured MSP. Hidden costs include claim denial, regulatory fines, business interruption and reputational damage.
Estimate timelines for losses and litigation when choosing cost priorities.
Comparison table
| Market |
Common insurer stance |
Vendor requirements |
| United Kingdom |
Insurers enforce disclosure, use warranties and expect MSP controls. |
Proof of MSP cyber cover often requested; contractual security clauses expected. |
| United States |
Insurers focus on system configurations and may face broader litigation exposure. |
Higher limits requested for critical vendors; broad indemnities common. |
| European Union |
NIS2 and local rules increase vendor obligations for cross‑border providers. |
Insurance plus demonstrable security controls required for critical services. |
When uninsured vendors make sense
A small local freelancer with no access to sensitive systems may be low risk. Document the limited access and keep a short contract that restricts privileges.
If the vendor needs admin access later, upgrade their obligations and insurance first.
Deciding: keep, insure or contractually oblige your MSP
This section gives a decision flow and a practical 30‑day plan. Follow the flow and then apply the 30‑day checklist to fix gaps.
If an MSP has admin access and no insurance, the safest immediate action is to restrict access and require certification of controls within 30 days.
Decision flow
Is the MSP listed on your proposal form? If no, add them and prove disclosure.
Does the MSP have admin access or backups? If yes, require insurance and stronger controls.
If the MSP caused the incident, preserve evidence and notify insurer immediately.
Day 0–7: collect MSP insurance schedule, contract and access logs.
Day 8–21: negotiate contract clauses and require proof of controls and penetration test results.
Day 22–30: obtain signed endorsement or addendum and record insurer or broker confirmation.
Sample insurer notification email (copy/paste):
"Subject: Potential cyber incident involving MSP [name]
We have identified a potential security incident involving MSP [name]. We are preserving evidence and appointing forensics. Please confirm the claims contact and the insurer's preferred forensic provider. Attached: signed contract and MSP insurance schedule."
This short template helps record your notification time and content.
Opinion and practical perspective
Many recommend insisting on an MSP carry cyber insurance, but after analysing claims for UK SMEs, the common error was failing to record the MSP's retroactive date and policy number. That gap made recovery harder in several cases I handled.
This works in theory, but in practice in England, replacing an absolute warranty with a written insurer endorsement takes negotiation and can add 7 to 21 days. If the MSP refuses cover, restrict access and insist on auditable controls backed by contract.
Errors and warnings when relying on an MSP
Read these common mistakes and fix any you recognise this week.
The most common error is failing to get written proof of MSP insurance and security controls before a loss.
Mistake 1: verbal assurances only
Verbal promises about insurance do not prove cover. Get a certificate of insurance and the policy schedule with retroactive date.
Keep the document in your evidence pack.
Mistake 2: editing proposal answers
Altering proposal answers after a loss destroys credibility and often triggers repudiation. If an error exists, inform the broker in writing immediately and request insurer confirmation of any correction.
Keep originals and timestamps.
Mistake 3: ignoring warranty wording
Signing a warranty can be risky if it is absolute and not limited to reasonable steps. Ask your broker to reword warranties into representations or to limit them to sensible controls.
Document any exceptions the insurer accepts in writing.
This advice does not apply where the MSP already holds appropriate cyber insurance with the required limits and retroactive date, where the policy explicitly covers subcontractors, or where the MSP had no causal connection to the incident. If an insurer has already accepted a claim and paid, the policyholder's main risk is subrogation rather than repudiation.
One practical CTA before the FAQ
Contact your broker today with the evidence pack: signed MSP contract, MSP insurance schedule and proposal form PDF to get an immediate cover check and written guidance from the insurer.
Frequently asked questions
Can an insurer void my policy if an MSP caused a breach?
Yes. If you failed to disclose the MSP relationship or breached a warranty that influenced underwriting, an insurer can repudiate that claim. Provide proof of disclosure and MSP controls to defend the claim.
What wording should I use when the proposal asks about third parties?
Answer clearly with name, services, access type and MSP insurance details. Example: "Yes: [MSP name], manages network and backups, remote admin via VPN, MFA enabled. MSP insurer: [insurer], policy no: [X], limit: £[Y], retro date: [dd/mm/yyyy]."
How quickly must I notify my insurer after discovering MSP involvement?
Notify your broker and insurer as soon as you suspect MSP involvement, ideally within 24 to 72 hours. Preserve logs immediately and appoint forensics to maintain cover.
Will insurers always pursue the MSP after paying a claim?
Not always. Insurers commonly pursue subrogation when the MSP is negligent and has assets or insurance. If the MSP lacks insurance, recovery is often limited.
Can I force an MSP to carry insurance after I have a contract?
Yes, you can require it by contract. If the MSP refuses, restrict their access and renegotiate the agreement. Implement a 30‑day remedy plan and document compliance.
Insurance law requires disclosure of facts that would influence underwriting under the Insurance Act 2015. Listing MSPs and their roles helps meet that duty.
What happens if the MSP is outside the UK?
You must still disclose cross‑border suppliers and confirm their insurance and controls. NIS2 and local laws may add obligations for EU or international MSPs.
What to do next
This final section gives the exact first three actions to take in the next 48 hours.
1) Assemble your evidence pack: proposal form, signed MSP contract, MSP insurance certificate and security proofs.
2) Notify your broker with the short template email above and ask for insurer confirmation of coverage position.
3) If an incident exists, preserve logs, appoint a forensics lead and avoid altering any proposal answers until advised.
Additional resources: refer to NCSC guidance and the ICO breach reporting page when planning incident response.
Many recommend insisting on a million‑pound limit for MSPs; however, after analysing claims for UK SMEs the most frequent error is failing to record the MSP's retroactive date and policy number. That gap made recovery harder in several cases I handled.
This works in theory, but in practice in England replacing an absolute warranty with a written insurer endorsement takes negotiation and can add 7 to 21 days.