A breach in a remote-management tool or cloud platform can prompt one commercial question from your client. Are you paying for the loss? Cyber insurance may help with your own incident costs, but it does not automatically settle a client claim against your MSP or reseller business.
An MSP or IT reseller can face a client claim after a breach. This can happen even when a criminal or supplier began the attack. Liability usually turns on the contract, promised security standards, data-protection roles, and reasonable care.
When an MSP can owe after a client breach
An MSP is not automatically liable when a client suffers a breach. The client normally needs to link its loss to your promise, error, or lack of reasonable care.
Claims based on service failure
A client may allege breach of contract if an MSP misses an SLA. This might include missed backup checks or slow response times. It may allege negligence if an engineer makes an avoidable configuration error.
Sales documents matter as much as the main agreement. Terms such as “fully managed security” can raise expectations. So can “guaranteed recovery” and “24/7 monitoring”.
A client may weaken its own claim by ignoring written MFA advice. The same applies if it refuses a patching budget or withholds needed access.
Written evidence often decides these disputes.
Shared blame is common
A supply-chain attack can involve the MSP, client, cloud supplier, software maker, and subcontractor. Shared responsibility does not stop a client from claiming against its direct supplier first. The contract should explain each party’s role.
A Managed Service Provider is often a data processor. This means it handles personal data under the client’s instructions. It remains a controller for its own staff, billing, and marketing data.
A Data Processing Agreement helps define tasks. It does not remove security duties or contractual duties. Think of it as a map, not a shield.
Managed service provider liability and IT reseller liability should be assessed service by service. Do not assume that the party nearest the incident is liable. The client agreement should name who controls each key task.
Check who configures the cloud tenant and applies patches. Check who controls remote monitoring, privileged access, and backup recovery tests. An SLA can set response and restoration commitments.
The Data Processing Agreement should state the provider’s data role and explain how both sides handle incidents. Unclear contracts are often where expensive arguments begin.
Evidence of rejected MFA can affect how loss is shared. The same applies to delayed fixes or client-made security errors.
The breach source changes the cover you need
The breach source helps identify the likely claim and policy response. Cyber insurance usually addresses the incident itself. Tech E&O may matter when clients say your professional service failed.
From breach to likely insurance response
RMM compromise
Privileged access abused
Client allegation
“Your controls failed”
Cyber cover
Forensics, response, privacy
Tech E&O
Service-error defence
One event can trigger more than one policy. Notify insurers early. Do not admit liability before receiving advice.
RMM, backups and privileged accounts
An RMM tool lets an MSP remotely monitor and manage client devices. A compromise can spread ransomware across several client environments. Cyber cover may fund the incident response.
Tech E&O may defend claims about poor access controls. It may also address backup configuration, monitoring, or recovery testing. These are service-failure allegations, not just breach costs.
A common case involves one compromised privileged account. Ransomware then reaches several client networks. The client may claim that the MSP failed to limit access.
Licence resale can still create exposure
A reseller that only sells packaged licences has lower technical exposure. This assumes it never accesses systems and gives no support. The position changes when it makes wider promises.
A reseller may promise that a product is suitable or secure. It may promise integration, compliance, or availability for a client’s business. Those words can create a claim after a failure.
A reseller may include “managed recovery support” in its offer. If licences lapse, configuration fails, or recovery is unavailable, a client may claim negligent advice. It may also claim contractual failure.
Cyber insurance and tech E&O answer different claims
Cyber insurance and Professional Indemnity cover different risks. Cyber cover can pay immediate breach costs. Tech E&O can address claims that technical services caused financial loss.
For an MSP, cyber cover and Tech E&O should usually work together. Cyber cover handles the fire after an incident. Tech E&O may handle the argument about who failed to prevent it. This does not apply where a reseller only sells products and has no system access, support role, or security promise. Compare your largest contract cap with both policy limits before renewal.
| Cover type | Usually relevant where | Check before relying on it |
|---|
| Cyber liability | Forensics, ransomware, notification, privacy claims, and business interruption | Extortion, restoration, and social-engineering sub-limits |
| Professional Indemnity / Tech E&O | Negligent configuration, missed monitoring, bad advice, or SLA failure | Definition of professional services and contractual-liability exclusion |
| Crime / Fidelity | Employee dishonesty or defined fraud losses | Whether social engineering and client funds are included |
| Public Liability | Injury or physical property damage | It rarely covers data, downtime, or poor IT advice |
| Directors’ and Officers’ | Claims against directors over management decisions | It does not replace operational cyber or Tech E&O cover |
First-party and third-party costs
First-party cyber cover concerns your own costs. These can include incident response, legal advice, restoration, extortion, and lost income. It is cover for damage to your own business.
Third-party liability concerns what another party says you owe. This may include privacy claims or costs after a confidentiality breach. Some cyber policies include defence costs for privacy claims.
Cyber cover may not pay lost profits from an alleged service failure. That is often where Tech E&O becomes relevant. Read the policy wording rather than relying on its title.
Limits, retentions and sub-limits
A policy limit is the most an insurer pays for covered claims. A retention is the amount your business pays first. Think of the retention as the excess on a motor policy.
MSPs commonly consider limits between £1 million and £5 million. Retentions often sit between £1,000 and £10,000. Suitable amounts depend on client contracts and plausible loss.
Check sub-limits beside the headline limit. Focus on extortion, social engineering, reputational costs, and dependent business interruption. A £5 million headline limit may not mean £5 million for each cost.
The most frequent mistake is comparing only the policy limit. A restricted sub-limit can leave a major part of the incident unpaid.
A claims review should start with the event. Then test each policy wording against the facts. This avoids assuming that one policy covers every cost.
Ransomware may spread through an RMM platform. Cyber liability may fund forensics, restoration, extortion response, and privacy notices. Tech E&O may defend claims about poor monitoring or access controls.
A backup configuration error may stop recovery. This may mainly create a Tech E&O claim for the client’s financial loss. Cyber cover may be limited unless it includes restoration costs.
A finance employee may be tricked into changing bank details. This may need Crime, Fidelity, or social-engineering cover. Public Liability rarely responds unless injury or physical damage occurs.
D&O may matter only when directors face personal management claims. It does not replace cyber or Tech E&O cover. Each policy has a separate job.
UK MSP cyber liability insurance pricing depends heavily on the risk presented. There is no single dependable market rate. A small reseller may pay a low four-figure annual premium.
That reseller would have no system access or managed backups. It would also have modest turnover. An MSP with persistent privileged access may face five-figure premiums or more.
Remote tools, regulated clients, and high contract limits can raise costs. So can large amounts of client data. Insurers assess the exposure, not just turnover.
Underwriters often ask for revenue split by service. They may ask about the largest client and contract cap. They also ask about claims history and cloud suppliers.
They commonly request MFA evidence and patching records. Expect questions about endpoint controls, tested backups, and response plans. Past ransomware events and security errors also matter.
Match client terms to your real insurance protection
A client contract can create uninsured exposure despite sensible policies. Compare liability caps, indemnities, SLA credits, and incident deadlines with the policy wording. Also compare all security promises.
Contract clauses worth checking
Review these clauses with a solicitor and insurance adviser before accepting them. They can decide whether a client claim is insured.
- Liability cap: Check whether it applies to data protection, confidentiality, and subcontractor claims.
- Indirect loss exclusion: Exclude lost profit, lost revenue, and consequential loss where appropriate.
- Indemnities: Avoid paying every client loss regardless of fault, especially after privacy or security events.
- Incident notice: Align client notice duties with insurer notice rules and the UK GDPR process.
- Subcontractors: Require equivalent security, insurance, and cooperation from outsourced providers.
- Audit rights: Limit scope, timing, and cost. Keep evidence of Cyber Essentials and your security controls.
A cap can fail if it excludes confidentiality or data claims. An indemnity can also bypass a cap. These clauses need to work together.
Policy conditions that can block a claim
Cyber and Tech E&O policies often exclude known circumstances and prior incidents. They may also exclude deliberate acts. They can exclude liability accepted only under a contract.
Policies may require MFA for remote access. They may also require tested backups, patching, endpoint protection, or prompt notice. Give insurers an accurate account of your services.
Describe managed security, hosting, and backup administration clearly. Include cloud access and privileged credentials. Incorrect answers can create problems when you claim.
This approach matters less where a reseller only sells packaged products and has no client system or data access. The reseller must give no support or promise on security, performance, or suitability. This does not replace a solicitor’s review of a live contract or claim. Notify your insurer or broker immediately after a suspected breach.
Common questions
Do MSPs need cyber liability insurance in the UK?
Usually yes, if you hold client data or have remote access. The same applies to RMM tools, backups, or managed security duties. Cyber cover should sit beside Tech E&O where clients could allege poor service.
Does cyber insurance cover a client suing my MSP?
Sometimes, but only for claims within the policy wording. This can include privacy liability or confidentiality breaches. Negligent configuration, downtime, or missed SLA claims may need Professional Indemnity or Tech E&O.
Is my MSP liable if Microsoft or AWS is breached?
Not automatically. Exposure depends on the client contract, your security promises, and your configuration work. It also depends on whether you could reasonably reduce the loss.
What is the right cyber insurance limit for an MSP?
Many small and medium MSPs consider limits between £1 million and £5 million. The right amount should reflect your largest client contract. It should also allow for a multi-client RMM event.
Can a Data Processing Agreement protect my MSP?
No. A Data Processing Agreement sets data-handling duties. It does not remove contractual liability or your own UK GDPR duties.
What can make an MSP cyber claim uninsured?
Common problems include a known issue before policy inception and late notice. An undeclared managed service can also block cover. Failure to meet stated MFA conditions can create the same result.