Insurance for IT Consultants and Managed Service Providers

IT consultants and managed service providers need technology errors and omissions combined with cyber, because one incident can be both: your own systems are breached, and a client claims your service failed. Clients, especially those under the FTC Safeguards Rule, must oversee service providers and require safeguards by contract, so MSPs see strict insurance and security requirements. Washington and Idaho do not license IT providers.

By Trella Commercial · Updated October 5, 2026

The short version

  • Tech E&O and cyber, usually combined: tech E&O covers claims that your service or product failed a client; cyber covers breaches of your own systems. MSP incidents often trigger both.
  • Clients push their obligations onto you. The FTC Safeguards Rule requires financial institutions, including tax preparers and many lenders, to oversee service providers and require safeguards by contract (16 CFR 314.4(f)).
  • Remote access tools are the exposure. An attacker who compromises an MSP can reach every client.
  • Contracts set limits and terms: commonly $1 million to $5 million of tech E&O and cyber. See contract requirements for cyber.
  • No state license for IT consultants or MSPs in Washington or Idaho.

Coverage for an IT business

CoverageWhat it handles
Technology errors and omissionsA client's losses from your failed implementation, missed patch, or outage
CyberBreaches of your systems, ransomware, notification, and liability for client data
Social engineeringFake invoices and payment redirection, on your side and your clients'
General liabilityInjuries and property damage at client sites
Business owners policyOffice and equipment
Employment practicesStaff claims

What clients expect from MSPs

RequirementWhy
Tech E&O and cyber at stated limitsThe client's own contracts and regulators expect it
Multifactor authentication on all client accessThe most common entry point for attackers
Security controls written into the contractThe FTC Safeguards Rule requires covered clients to do this
Incident notice within a set timeClients need time to meet their own breach deadlines
Additional insured or certificateProof of coverage, though additional insured is often unavailable on E&O

See cyber vs tech E&O vs crime and the managed IT provider story.

Common questions

What insurance does an MSP need?

Technology errors and omissions combined with cyber, plus general liability and a business owners policy. Many insurers write tech E&O and cyber on one form, which avoids disputes over which policy responds.

Why do clients require MSPs to carry cyber insurance?

Because an attack through an MSP's tools can reach every client, and clients covered by rules like the FTC Safeguards Rule must require service providers to maintain safeguards by contract.

Do IT consultants need a license in Washington or Idaho?

No state license applies to IT consulting or managed services in either state. General business registration applies.

Sources

This page is general information. Coverage depends on the policies actually issued. Reviewed October 2026.

More technology & startups we insure

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.