Cyber insurance for MSP clients is usually worth buying for UK SMEs. Cover depends on who controls systems, contract terms and MSP security. Prepare evidence and clear contracts to avoid declines.
Cyber insurance for clients of managed service providers
This section explains what cover looks like and why MSP relationships change underwriting. Insurers split first‑party costs from third‑party liability and check how responsibilities divide. Underwriters want evidence, not vague statements.
What typical cover includes
Most SME cyber policies pay for forensic costs, breach notification, legal fees and public relations. They also often include business interruption cover and ransom or extortion cover. Ransom cover may need specific wording.
When professional indemnity is different
Professional indemnity covers professional mistakes, not always first‑party ransomware losses. The most common error at this point is assuming PI covers client cyber losses. That error leaves a gap when an MSP toolchain causes a breach.
That gap leads to denied claims and surprise bills.
Quick citable fact
Small UK SME premiums commonly start around £3,500 pa with typical limits between £250,000 and £5,000,000 (2024). This figure helps set expectations before submission.
How insurers assess MSP clients
Underwriters focus on controls, exposure and contract liability. The application is evidence driven and underwriters expect clear proof of the claimed controls. Poor evidence raises price and rejection risk.
Controls underwriters expect
Underwriters usually require MFA for all admin and remote access. They also expect EDR on endpoints, immutable or offline backups and a documented incident response plan. Backups need test records that show restores worked.
Typical underwriting questionnaire items
Insurers ask for revenue, employee count, cloud providers and previous incidents. They also ask for Cyber Essentials or ISO27001 status and restoration testing. Provide screenshots, backup logs and MFA enforcement records when possible.
Price drivers and thresholds
Premiums depend on revenue, sector and controls. Typical small‑client premiums range £3,500–£35,000 pa, with excesses commonly £1,000–£25,000 (2024). Critical patching within 7 days and RTO under 72 hours reduce premium pressure.
Get the core controls in place before you quote.
Preparing clients for cover
This section gives a practical checklist MSPs must deliver to turn an application into an accepted risk. Present the evidence in a clear folder, with dates and contact points. Underwriters want testable items.
Technical underwriting checklist
Require these minimums before application: MFA for all admins, EDR on all endpoints and immutable or offline backups. Backups must have weekly restore tests and segmentation between user and server networks. Document patch cadence and vulnerability scans.
Supply a one‑page index, then screenshots, backup logs and pentest summaries. Label each item with a date and contact for underwriter validation. Keep the evidence pack to ten documents or fewer.
Client communication and contract
Tell the client what is needed in plain language and why. Use a short email to request logs and a one‑page SLA amendment that limits indemnities to insured limits. Ask the client not to accept unlimited hold‑harmless clauses.
Estimated cost ranges in the UK market (2024): typical SME premiums £3,500–£35,000 pa; standard policy limits £250k–£5m; excess commonly £1k–£25k. Use these ranges to set client expectations before approaching insurers.
- Underwriting teams rarely accept vague statements of control.
- They want measurable thresholds for key controls.
- For MSP clients this means MFA enabled for 100% of privileged and remote access.
- Include service accounts and RDP in the MFA scope.
- Use single sign‑on with conditional access where possible and document enforcement dates.
- Deploy endpoint detection and response (EDR) to 100% of managed endpoints.
- Retain telemetry data searchable for at least 90 days.
- Maintain immutable, air‑gapped backups with at least one off‑site copy.
- Align retention windows to sector risk, commonly 30 to 90 days.
- Provide documented restore tests: full restores quarterly and spot tests monthly.
- Record RTO and RPO metrics for each backup set.
- Enforce network segmentation between user, server and management networks.
- Run monthly authenticated vulnerability scans and record results.
- Patch critical CVEs within 7 days and high risks within 14 days.
- Keep a written incident response plan with roles, contacts and tabletop evidence.
- Providing these metrics in the evidence pack improves placement and pricing materially.
Policy wording, exclusions and traps
Policy wording often determines payment more than premium. Read exclusions and sublimits closely because small clauses can defeat a claim. Wording choices affect ransom, forensic and BI recovery.
Common exclusions to check
Watch for nation state or act of war exclusions, silent cyber language and retroactive prior acts exclusions. Check for social engineering carve outs and other narrow loss definitions. These exclusions often sit inside definitions.
Example clause differences
A ransom clause that covers payments to a third party to prevent a cyber incident is broader. A restrictive clause limits payments to approved providers only. Ask for affirmative ransomware wording where possible.
Contractual indemnities and insurability
Unlimited indemnities or broad hold harmless language can make a risk unacceptable to insurers. A common case: a small firm agreed to unlimited liability in an MSP contract. The insurer then applied a sublimit and raised premium substantially.
Policy wording differences turn on a few lines of text and who must approve payments. Read retroactive dates, approved providers and aggregation clauses carefully. Understanding these lines decides whether a claim pays.
Contract wording between MSP and client can make or break insurability. Practical clauses reduce ambiguity while keeping commercial protection. Useful examples include insurance aligned indemnities and cooperative claims clauses.
A narrow waiver of subrogation might prevent recovery but keep cover active. Draft testable clauses, caps tied to policy limits and clear cooperation duties. This alignment eases placement with insurers.
Claims handling and realistic timelines
This section shows the claim lifecycle and what insurers expect from an MSP during a claim. Timing of actions affects whether costs are recoverable. Quick, documented steps improve outcomes.
Typical ransomware claim timeline
Detection should lead to containment within 24 hours. Forensic investigation normally starts in 48 to 72 hours. Notification and ransom decisions should occur within 72 hours.
Case study: manufacturing client
A 30 employee manufacturer had backups but never tested them. Ransomware encrypted systems and business interruption lasted 18 days. The insurer reduced the claim because restores were unproven. The final outlay included £345,000 in recovery and lost profit (2023).
Case study: professional services client
A 12 employee firm used an MSP with full EDR, tested restores and a playbook. After the intrusion the MSP isolated systems and followed the playbook. The insurer funded forensics and legal costs. Downtime was three days and insurer payments reached £328,000 (2022).
How MSPs should act in a claim
Preserve logs and avoid altering evidence. Contact the insurer and broker immediately and give full access to forensic investigators. Do not pay a ransom without insurer or legal advice.
Keep logs in a secure, read only location.
Costs, limits and structuring options
This section helps pick sensible limits and excesses for SME clients. Make choices based on revenue, data sensitivity and contract exposure. The aim is affordable, realistic cover.
Choosing limits and excesses
A simple rule: set first party limits to cover at least six months of revenue. Higher limits suit regulated sectors and clients with sensitive personal data. Revisit limits after material client changes.
Aggregation and supply chain exposure
Insurers assess concentration risk when many clients use the same MSP or third party provider. Declare large exposures and ask for aggregation wording that matches real risk. Non‑disclosure can lead to mid‑term issues.
Add-ons and overlaps with PI/E&O
Buy social engineering, regulatory fines and cyber extortion as add ons when needed. Use PI/E&O for professional liability and buy first party cyber for direct losses and BI. Align PI wording with cyber cover to avoid gaps.
| Insurer |
Typical small‑client limit |
Speciality |
Typical excess |
| Hiscox |
£250k–£2m |
SME focus, fast quotes |
£1k–£10k |
| Beazley |
£500k–£5m |
Ransomware specialist |
£2k–£25k |
| AXA XL |
£250k–£3m |
Broader liability wording |
£1k–£15k |
| Chubb |
£500k–£5m |
Large loss handling |
£5k–£25k |
Choosing broker, insurer and service levels
Select a broker and insurer that match the SME's needs and the MSP relationship. Claims handling, wording and panel forensics matter more than headline premium. Insurer service beats a slightly cheaper premium.
When to use a specialist broker
A specialist cyber broker negotiates wording, sources Lloyd's capacity and advises on subrogation and aggregation. Use a specialist for clients with complex supply chain exposure. A specialist also tests evidence packs before placement.
Service level checklist
Compare 24/7 claims hotlines, panel forensic investigators and ransom negotiation support. Check crisis PR and legal defence resources and ask for recent claim examples. Ask the broker for a pre placement wording review.
The evidence points to one clear choice: pick a broker who will read policy wording and negotiate sublimits.
Not relevant for very large organisations or enterprise MSPs (>250 employees) that need bespoke treaty level cover. Also not applicable when seeking cover for an active incident or when a client's sector requires statutory bespoke policies such as certain healthcare or critical infrastructure cases.
If a broker review is needed, instruct the client's broker to request a policy wording review. Send the insurer the evidence pack before binding cover.
Frequently asked questions
What does cyber insurance usually pay for?
Cyber policies usually pay for forensic investigation, legal costs and notification. Policies also often pay for business interruption and PR costs. Check wording for ransom and third party liability cover.
How much does cyber cover cost for small MSP?
A typical range for small UK clients is £3,500 to £35,000 pa. Actual premiums depend on revenue, controls and sector risk. Regulated businesses usually pay higher premiums.
What evidence do insurers require for backups?
Insurers require proof of immutable or offline backups and restore tests. Provide dated logs and restore test reports that show successful recovery within the stated RTO. Attach screenshots and test timestamps.
Can a contract clause make a client uninsurable?
A clause imposing unlimited indemnity or forcing insurers to waive subrogation can make a risk uninsurable. Amend contract clauses to match insured limits and keep subrogation waivers narrow. Consult a specialist broker for redrafting.
How long do insurers take to respond to a claim?
Insurers normally appoint a claims handler within 24 to 72 hours of notification. They usually appoint a forensic investigator within 48 hours. Timing affects recoverability and business interruption run rates.
How should an MSP help during a claim?
The MSP should preserve logs and provide secure forensic access. Avoid altering evidence and coordinate with the insurer and client. Prompt cooperation speeds forensic work and claim resolution.
What to do next
Gather the client evidence pack with screenshots, backup logs and MFA records. Use the technical checklist above and ask a specialist cyber broker to review policy wording before binding. Prepare the evidence pack before any insurer meeting.
Useful sources and guidance
Refer to the NCSC for practical guidance on resilience and incident response. See the NCSC guidance for clear steps and templates. Consult the ICO for data breach notification rules and timing.
NCSC guidance
ICO guidance
MSP client cover: 6‑step checklist
1
MFA for admins
2
EDR on endpoints
3
Immutable backups
4
Restore tests
5
IR playbook
6
Policy wording review
Will PI or E&O cover a ransomware loss?
PI/E&O may cover professional mistakes but often excludes first party ransomware losses. Where gaps exist, buy first party cyber and align PI wording with cyber cover. Match limits and notify both insurers where overlap occurs.