FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

Insurance for established MSPs and IT service firms

An established MSP should evaluate cyber and Tech E&O together because one compromise, service error, or tool outage can affect many clients at once. The review must test the insured-services definition, shared limits, subcontractor treatment, client contracts, and response obligations rather than relying on a headline limit. Higher limits are individually evaluated and subject to actual placement availability.

Who this page is for

An established managed service provider can hold administrative access to many customer environments while depending on a common set of remote-management, security, backup, and ticketing tools. An MSP insurance review should connect that concentration to Tech E&O, cyber, contracts, subcontractors, incident response, and the limits customers require.

OnePark Risk can discuss an individually evaluated higher-limit review with the business. That process is distinct from the site's standardized $1M/$2M cyber and Tech E&O program and remains subject to actual placement availability.

Discuss your MSP program with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

Why does privileged access change an MSP insurance review?

An MSP may hold administrator credentials, remote access, security alerts, backups, or configuration authority for many unrelated clients. That access is operationally useful, but it can create a common path through which stolen credentials, a mistaken deployment, or a compromised tool affects several customers. The review should map which employees and subcontractors have privileged access, how it is approved and removed, where credentials are stored, and whether customer environments are segmented.

Aggregation means that one originating event can produce costs or allegations across a client base. A compromised remote-monitoring tool could trigger the MSP's own forensic and restoration expense while customers allege privacy, security, or service failures. Policies may count related claims as one claim, apply one retention, or aggregate them under one annual limit; the wording, not the number of customer complaints, determines that treatment.

The submission should explain controls without converting them into a coverage promise. Multi-factor authentication, privileged-access management, logging, tested backups, patch governance, and an incident plan help describe risk. They do not establish that every event is covered, and a control representation must remain accurate throughout the application and policy process.

Do the Tech E&O definitions match the services delivered?

Tech E&O generally addresses allegations that defined technology services failed to perform as promised, subject to the policy's exclusions and conditions. The insured-services definition should therefore match the actual work: managed security, help desk, cloud administration, migrations, backup management, procurement, consulting, implementation, and any software supplied to clients. More limit does not broaden a definition that omits a material service.

Service descriptions should also identify where responsibility stops. A contract may describe the MSP as monitoring an environment while the client retains patching, backup testing, or approval authority. Another agreement may make the MSP responsible for implementation and ongoing administration. The broker should compare these obligations with exclusions for warranties, contractual liability, unauthorized collection, or performance guarantees and refer legal interpretation to counsel.

Subcontractors create two questions. First, does the insured-services definition include work performed on the MSP's behalf, and are subcontractors insureds or merely service providers? Second, what indemnity, insurance, security, notice, and audit obligations run back to that vendor? The MSP remains exposed to its client even when a subcontractor or offshore help desk performs the work, while the policy response and contractual recourse remain separate issues.

Should cyber and Tech E&O share one limit?

Cyber coverage commonly addresses defined security, privacy, incident-response, restoration, and interruption events. Tech E&O addresses allegations about defined technology products or services. One ransomware event at an MSP can implicate both: the MSP may incur response expense and lost income while customers allege that monitoring, backup, or security services failed. The review should identify how the form allocates that event and which retention and limit apply.

A combined form may apply one annual aggregate across cyber and Tech E&O. If a covered cyber matter consumes part of that aggregate, less may remain for a later service claim. Separate policies or separate limits can preserve capacity, but they introduce questions about overlapping definitions, other-insurance clauses, notice, defense, and which carrier controls a matter. Neither structure is automatically preferable.

Defense costs may reduce a per-claim limit or sit outside it, and multi-client allegations may be deemed related. The review should compare per-claim limits, annual aggregates, incident-response or dependent-system sublimits, and any excess layer. A casualty umbrella should not be assumed to extend cyber or Tech E&O; higher limits for these coverages require their own evaluated structure.

Translate master service agreements into policy questions

Master service agreements can request $3M, $5M, or $10M per-claim or annual-aggregate limits for a specified coverage, together with technology-services wording, cyber incident notice, indemnity, additional insured status, or evidence of subcontractor insurance. The broker should record exactly what each number measures. A $5M Tech E&O annual aggregate is not a $5M cyber per-event limit, and unrelated policy limits cannot be added to satisfy one requirement.

Insurance clauses do not erase broader contractual promises. An indemnity may be wider than the policy, a liability cap may contain security or confidentiality carve-outs, and service credits may not be insured damages. Counsel should interpret the agreement; the broker should explain whether the proposed form recognizes the services, entities, territory, and allegations and whether defense reduces the requested limit.

Incident-response obligations deserve their own matrix. A client may require prompt notice, cooperation, forensic evidence, preservation of logs, regulator support, or payment of specified response costs. The MSP's policy may require carrier consent or use of approved response providers. The company needs an incident workflow that addresses both duties without assuming that meeting a contract deadline guarantees reimbursement.

What happens when a common MSP tool fails?

Remote monitoring and management, endpoint security, identity, cloud hosting, backup, professional-services automation, and ticketing tools can concentrate operations. The review should identify each critical provider, clients reached through it, alternative access methods, contractual recourse, and the time required to replace or restore the service. A vendor outage can stop the MSP's work even without compromising client data.

Dependent business interruption is coverage for the insured's lost income and extra expense after a qualifying event at a specified or qualifying provider. Its definition, waiting period, measurement period, and sublimit can differ from the policy's own-system interruption coverage. A customer allegation arising from the same outage may instead implicate Tech E&O, so the business should model its own loss and client-facing liability separately.

Vendor contracts should be read alongside the insurance. Liability caps, disclaimers, service credits, incident notice, data-return obligations, and the vendor's insurance can affect recourse but do not determine the MSP's policy response. Concentration is especially important where one tool reaches much of the client base or where several services rely on the same identity or cloud provider.

How does an individually evaluated review differ from the $1M/$2M program?

The site's homepage cyber and Tech E&O program offers stated $1M and $2M options for businesses that fit that standardized path. It is not a source of $3M, $5M, or $10M limits. An established MSP seeking a higher amount needs an individually evaluated brokerage review, subject to actual placement availability, that examines contracts, revenue by service, client concentration, privileged access, controls, claims, subcontractors, and tooling dependencies.

The higher-limit discussion must identify whether the requested amount is per claim, an annual aggregate, a sublimit, an excess layer, or a total aligned program limit for one coverage. Primary and excess forms may differ in service definitions, exclusions, defense treatment, attachment, and exhaustion. More capacity does not cure a definition that excludes managed security or an unreported acquisition.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.

Hypothetical scenario: Hypothetical multi-client MSP incident review

Consider a hypothetical MSP with $45M in annual revenue, privileged access to hundreds of client environments, and a master service agreement requiring a $5M per-claim Tech E&O limit and separate $5M cyber annual aggregate. A compromised remote-management credential produces alerts at several clients. The review would examine whether those matters are related, how cyber and Tech E&O parts allocate the event, whether limits are shared, how defense is treated, and which client notice and forensic obligations apply. It would also examine the tool vendor's contract, subcontractor access, and any dependent-interruption sublimit. This illustration identifies policy and contract questions; it does not assume coverage or a claim outcome.

What your senior broker should examine

  • Which services, software, and security responsibilities appear in client contracts, and do policy definitions match them?
  • How many clients could one privileged credential, remote-management tool, backup provider, or identity platform affect?
  • Are cyber and Tech E&O limits separate or shared, and how are related multi-client claims counted?
  • What $3M, $5M, or $10M per-claim or aggregate requirements appear in master service agreements?
  • What incident notice, forensic, cooperation, and cost obligations are owed to clients?
  • How are subcontractors insured, supervised, and required to indemnify or notify the MSP?

Questions businesses ask

Does Tech E&O cover every service listed in an MSP contract?

Not automatically. The policy's insured-services definition and exclusions control, while the contract may describe a broader scope. The broker should compare them service by service and flag legal interpretation for counsel.

Can one cyber event use both the cyber and Tech E&O limits?

That depends on the form. One event may implicate both coverage parts, but a shared aggregate, allocation clause, related-claims provision, or other-insurance wording can affect the amount available. Two headline limits should not be assumed to stack.

Will an umbrella satisfy a client's higher Tech E&O requirement?

A casualty umbrella ordinarily follows scheduled casualty policies, not cyber or Tech E&O. The client requirement and underlying schedule must be read, and any higher Tech E&O capacity requires its own evaluated structure.

Why do MSP tooling vendors matter to insurance?

A common tool can create both operational dependency and a path to many client systems. The review should examine dependent-interruption terms, client allegations, vendor recourse, waiting periods, and sublimits rather than treating the vendor's policy as the MSP's protection.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.