Darren's company in Renton manages IT for about forty small businesses: dental offices, accounting firms, a few manufacturers. His team of eleven handles help desk tickets, patches servers, and runs backups, all through a remote monitoring and management platform that connects to every client network.
He had a cyber policy. He came to us because a new client, a medical group, asked for $5 million in coverage, and his policy was $1 million.
What he asked for
A higher cyber limit.
What the review found
His cyber policy was written for an office, not a service provider. It covered breach response for his own company's data and a modest amount of liability. It did not clearly cover liability to clients whose networks were compromised through his systems. For an MSP, that is the whole ballgame: if an attacker gets into the remote management tool, every client is exposed at once.
His errors and omissions coverage was thin. A missed patch, a backup that silently failed, or a misconfigured firewall causes client losses without any hacker involved. That is a technology professional liability claim, and his policy had a low limit and a vague definition of services.
One event, forty claims. Because the same tool touches every client, a single incident could produce claims from many clients at once. The aggregate limit matters as much as the per-claim limit.
His client contracts had no limitation of liability.
What we put in place
We replaced both policies with a combined technology E&O and cyber liability program from a carrier that specializes in managed service providers. It covers his own breach response, liability to clients for security failures, errors in services with no hack involved, and contingent business interruption. The primary limit is $3 million, with an excess tower above it to reach the $5 million his larger clients require.
The underwriting was serious. The carrier asked about privileged access management, multi-factor authentication on the remote management platform, offline backups, and incident response plans. Two gaps came up, and fixing them before binding got a better price.
We added a commercial umbrella over his general liability and the two service vans, which some client contracts also required. We noted clearly that the umbrella does not extend the cyber or E&O limits, which is why the cyber program has its own excess layer.
We gave Darren model contract language, reviewed by his attorney, that caps liability at fees paid over twelve months and requires clients to maintain their own cyber coverage.
Why it mattered
The medical group signed. And the MSP now has a program built for its real risk: that the trusted access it gives its technicians is the same access an attacker would want.
If you run an MSP or IT services firm
- Confirm your cyber policy covers liability to clients, not just your own data
- Buy tech E&O for failures that happen without an attacker
- Watch the aggregate limit; one incident can hit every client
- Put limitation of liability clauses in every client agreement
See how we work with technology companies, or get a free policy review.