FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Managed service provider (MSP) insurance

In short: A managed service provider usually needs technology professional indemnity (for mistakes in your work or advice), cyber insurance (for breaches affecting the systems and data you touch), public liability, and employers' liability once you have staff. Tech PI and cyber are frequently bought together as a combined technology policy, and clients often require this cover in contract.

Managing clients' systems day in, day out? Let's build a policy around what you actually touch, not a boilerplate IT wording.

Get a tailored quote →
  • FCA directly authorised, FRN 724952
  • 17 years in business
  • a named broker reads every submission.

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06

If you run a managed service provider, you sit inside your clients' businesses in a way few suppliers ever do. You hold the admin credentials. You monitor the alerts at 2am. You push the patches, manage the firewalls, run the backups and decide when something needs escalating. That level of access is exactly why clients hire you — and exactly why your insurance needs to be built for the risk you actually carry, not a generic "IT company" template. This guide walks through the covers that matter for an MSP, why each one earns its place, and what your clients will typically insist on before they sign.

What does a managed service provider actually need insured?

An MSP's risk profile is different from a one-off project shop. You are not delivering a piece of software and walking away; you are running things on an ongoing basis, often across dozens of clients at once. That continuity is the whole value proposition, and it is also where the exposure concentrates. A single misconfigured backup policy, a patch that breaks a line-of-business app, or a monitoring gap that lets an intrusion sit undetected can turn into a financial loss for a client who then looks to you to make it good.

Broadly, most managed service providers should be looking at four covers as the core, plus one or two more depending on what you do: technology professional indemnity, cyber, public liability, and — the moment you employ anyone — employers' liability. Media and intellectual property liability comes into play if you produce content, host client material or resell software in your own name. We will take them in turn, because the why matters as much as the what.

Why is technology professional indemnity the backbone for an MSP?

Technology professional indemnity (tech PI) — the same cover US contracts call technology errors & omissions, or tech E&O — responds when a client alleges that a mistake, oversight or negligent piece of advice in your work caused them a financial loss. For an MSP that is the bread-and-butter claim: the migration that corrupted data, the firewall rule that took a system offline, the recommendation to skip a piece of redundancy that later mattered. It covers the cost of defending the allegation and any damages or settlement, which is what makes it the backbone of an MSP's programme.

It is worth being precise about one thing. Professional indemnity is not a statutory legal requirement for IT firms in the UK — there is no law obliging an MSP to hold it. In practice it is almost always a contractual requirement: clients, and particularly larger or regulated ones, write a minimum PI limit into the master services agreement and will not let you near their systems without it. So while the law does not force it, your pipeline effectively does. We go deeper on this cover on our technology professional indemnity insurance page.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Why do MSPs carry heightened cyber risk compared with other IT firms?

Here is the exposure that keeps MSP underwriters awake. Because you hold privileged access into many clients at once, a compromise of your environment — your remote monitoring and management platform, your credentials, your automation — can cascade outward to every client connected to it. This is often called contagion or a systemic event: one breach, many victims. It is a genuine, well-understood feature of the MSP model, not scaremongering. A vulnerability in a widely used management tool can, in the worst case, become a route into the businesses that tool manages.

Cyber insurance is what funds your response when that happens. A good policy pays for the incident-response specialists, forensics, legal advice, notification and credit-monitoring costs, and the business interruption you suffer while systems are down. It can also respond to third-party claims where affected clients pursue you. What cyber insurance should not be sold to you as is a guarantee that it will pay any regulatory fine. The insurability of UK GDPR and Data Protection Act 2018 penalties is legally uncertain and is commonly excluded or restricted — the Information Commissioner's Office (ICO) issues those fines, and you should treat any that arise as potentially uninsurable. Think of cyber as funding breach response, interruption and liability, not as a cheque for fines.

Because MSP cyber exposure is so concentrated, insurers increasingly expect strong controls before they will quote well: multi-factor authentication everywhere, tested backups, endpoint detection, and disciplined privileged-access management. Those are the same controls that keep your clients safe, so the underwriting conversation tends to be a useful one. Our cyber insurance explained page breaks the cover down further.

Should tech PI and cyber be bought together as a combined policy?

Very often, yes. For technology businesses the two covers overlap at the edges — a single incident can look like a professional failing and a security breach at the same time — and buying them under one combined technology wording removes the risk of a claim falling into the gap between two separate policies. A combined technology policy typically bundles tech PI and cyber, and can sit alongside your liability covers so the whole programme reads as one coherent package rather than a stack of disconnected certificates.

The practical benefit for an MSP is clean claims handling: one insurer, one notification, one view of an incident that could otherwise be argued between a PI insurer and a cyber insurer while your client waits. It is not automatically the right structure for everyone, but for most managed service providers it is worth pricing. We explain the trade-offs on our combined technology insurance page, and it is a good thing to talk through with an Apex specialist rather than guess at.

Do MSPs need public liability and employers' liability too?

These two are easy to overlook when your work is mostly remote, but they still matter. Public liability responds if your business causes injury to someone or damage to their property — and MSPs do end up on client sites: racking hardware, installing kit, attending a comms room, running cabling. If an engineer trips a client's staff member with a stray cable or knocks over equipment, public liability is the cover that answers. Many client contracts and site-access agreements also require you to hold it before they let your people through the door.

Employers' liability is different because it is not optional. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are legally required to hold employers' liability insurance, subject to some narrow exceptions. It covers claims from employees who are injured or fall ill because of their work. This is a genuine statutory duty rather than a contractual nicety, so if your MSP has grown beyond just you, it needs to be in place. If you are still a solo operator, the picture is different again — our IT contractor insurance guide covers the sole-trader and contractor angle.

Where do media and intellectual property liability come in?

Not every MSP needs this, but some do without realising it. Media and IP liability responds to allegations such as infringing someone's copyright or intellectual property, or defamation, arising from material you produce or publish. For an MSP it becomes relevant if you host client content, build or brand software, resell or white-label third-party products under your own name, or produce marketing and documentation at any scale. If a rights-holder claims your work infringed theirs, this is the cover in the frame. It is often available as an extension within a technology policy rather than a standalone purchase, so it is worth flagging what you do when we scope your cover.

What will your clients actually demand in the contract?

This is usually what triggers the whole conversation. When you win a new managed-services contract, the client's procurement or legal team typically specifies insurance you must hold and evidence before go-live. For an MSP that commonly means:

  • A minimum technology professional indemnity limit — illustrative figures often sit at £1m, £5m or £10m depending on the client's size and how critical your service is.
  • Cyber insurance to an agreed limit, increasingly named explicitly given how much access an MSP holds.
  • Public liability, especially where your engineers attend client premises.
  • Employers' liability if you have staff — often requested as evidence even though it is already a legal requirement.

The important point is that the required limits are set by your clients, not by any regulator, and they can move as you win larger accounts. Getting the structure right early saves you scrambling to increase cover mid-tender. If you want a wider view of the whole programme, our what insurance does an IT company need guide is a good companion read.

What drives the cost of MSP insurance?

We won't quote a price on a web page, because a realistic figure depends entirely on your business — and an honest broker's job is to explain the levers rather than pluck a number from the air. The main factors underwriters weigh for an MSP include your annual revenue and client mix, the limits your contracts require, the nature of the systems you manage and how critical they are, and — heavily for cyber — the security controls you have in place. Strong MFA, tested backups, endpoint detection and tight privileged-access management genuinely help both your risk and your terms. Your claims history and the geographies your clients operate in also feed in.

One thing that does not belong in this conversation is IR35. Off-payroll working rules are a tax matter about employment status for tax purposes, and holding insurance neither changes nor determines your IR35 position. If you contract through a limited company and need to understand your status, that is a question for a qualified accountant or tax adviser, not an insurer.

Apex specialises in insurance for IT and technology firms. Tell us how your MSP is set up and we'll match the cover to the contracts you're winning.

Get a tailored quote →

Getting it right for your MSP

The through-line for every managed service provider is access. You hold the keys to your clients' systems, which is why tech PI and cyber sit at the centre of your programme, why contagion risk deserves real attention, and why your clients care so much about what you carry. Build the cover around the work you actually do — the platforms you manage, the sites you attend, the staff you employ, the content you publish — and it stops being a box-ticking exercise and starts being something that protects the business you've built. If you'd like a second pair of eyes on your contracts and cover, that's exactly the kind of conversation we're here for.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →