Technology · Renton, WA

When a Managed IT Provider Gets Breached, Every Client Gets Breached

An MSP supporting forty small businesses had a cyber policy sized for its own office. The review found that its real exposure was a single compromised tool that touches every client at once.

An illustrative story. The business is a composite drawn from situations common to technology businesses, not a specific client, and names and details are invented. What any policy pays depends on underwriting and its actual wording.

Darren's company in Renton manages IT for about forty small businesses: dental offices, accounting firms, a few manufacturers. His team of eleven handles help desk tickets, patches servers, and runs backups, all through a remote monitoring and management platform that connects to every client network.

He had a cyber policy. He came to us because a new client, a medical group, asked for $5 million in coverage, and his policy was $1 million.

What he asked for

A higher cyber limit.

What the review found

His cyber policy was written for an office, not a service provider. It covered breach response for his own company's data and a modest amount of liability. It did not clearly cover liability to clients whose networks were compromised through his systems. For an MSP, that is the whole ballgame: if an attacker gets into the remote management tool, every client is exposed at once.

His errors and omissions coverage was thin. A missed patch, a backup that silently failed, or a misconfigured firewall causes client losses without any hacker involved. That is a technology professional liability claim, and his policy had a low limit and a vague definition of services.

One event, forty claims. Because the same tool touches every client, a single incident could produce claims from many clients at once. The aggregate limit matters as much as the per-claim limit.

His client contracts had no limitation of liability.

What we put in place

We replaced both policies with a combined technology E&O and cyber liability program from a carrier that specializes in managed service providers. It covers his own breach response, liability to clients for security failures, errors in services with no hack involved, and contingent business interruption. The primary limit is $3 million, with an excess tower above it to reach the $5 million his larger clients require.

The underwriting was serious. The carrier asked about privileged access management, multi-factor authentication on the remote management platform, offline backups, and incident response plans. Two gaps came up, and fixing them before binding got a better price.

We added a commercial umbrella over his general liability and the two service vans, which some client contracts also required. We noted clearly that the umbrella does not extend the cyber or E&O limits, which is why the cyber program has its own excess layer.

We gave Darren model contract language, reviewed by his attorney, that caps liability at fees paid over twelve months and requires clients to maintain their own cyber coverage.

Why it mattered

The medical group signed. And the MSP now has a program built for its real risk: that the trusted access it gives its technicians is the same access an attacker would want.

If you run an MSP or IT services firm

  • Confirm your cyber policy covers liability to clients, not just your own data
  • Buy tech E&O for failures that happen without an attacker
  • Watch the aggregate limit; one incident can hit every client
  • Put limitation of liability clauses in every client agreement

See how we work with technology companies, or get a free policy review.

Run a technology business? See what your policies miss.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.