Managed service provider insurance UK: the full cover stack
Why MSPs are a supply-chain target
Attackers follow leverage. Compromising one business yields one victim; compromising the firm that remotely manages fifty businesses yields fifty. Remote monitoring and management (RMM) platforms, privileged credentials and centralised patching make MSPs exactly that kind of leverage point, and supply-chain incidents over recent years have made both attackers and underwriters very aware of it. The consequence for MSPs is twofold: your own security posture is now an underwriting subject in its own right, and your clients’ insurers and procurement teams increasingly want to know who has keys to the estate they are covering.
None of this means MSPs are uninsurable — far from it. It means the risk needs describing properly, by someone who understands what the firm actually does, before it goes to market.
The cover stack, piece by piece
Professional indemnity (tech PI / tech E&O). The core professional cover: it responds when a client alleges that your work caused them financial loss — a migration that corrupted data, backups that were not running when they were needed, a security configuration that failed. For an MSP this is the policy that stands behind the promises in your master services agreement. We cover it in depth on our MSP professional indemnity page.
Cyber insurance — your own. This is first-party protection for the MSP itself: incident response, forensics, system restoration, business interruption while your own platform is down, and cover for extortion demands. Given that an MSP’s own compromise is the nightmare scenario for its whole client base, underwriters look hard at controls here. See our dedicated MSP cyber insurance page.
Employers’ liability and public liability. EL is compulsory once you employ staff. PL covers injury or property damage to third parties — less dramatic for a desk-based business, but engineers on client sites carrying kit and lifting floor tiles generate real PL exposure, and client contracts routinely require both.
Directors’ and officers’ cover. When something goes seriously wrong at a technology business — a major outage, an incident with regulatory involvement — questions can be directed at the people who ran it, not just the company. D&O protects directors personally for claims arising from their management decisions.
PI and cyber answer different questions
The most common confusion we see in MSP programmes is the assumption that one policy covers the whole cyber landscape. It does not, and the distinction is worth being precise about. Your cyber policy responds when your systems are breached: it funds your response, your recovery and your lost income. Your PI responds when a client alleges that your professional failure caused their loss — which may follow from your breach, from their breach, or from no breach at all, just a botched piece of work. Neither policy automatically covers your clients’ own losses; whether you are liable for those at all depends on your contract, your liability caps and the facts. We walk through that scenario on MSP liability when a client is breached.
Client contracts now ask for evidence
A visible shift in the market: insurance has moved from a back-office matter to a sales document. Enterprise clients, public-sector frameworks and increasingly ordinary SME customers ask MSPs to evidence PI and cyber cover at specified limits before contracts are signed or renewed — sometimes because their own insurers ask them who manages their IT. An MSP that can produce clean certificates at sensible limits removes friction from its own sales process. One that cannot may not find out what it cost them.
Limits: when one incident touches many clients
Limit selection for an MSP is not a per-client calculation. The defining feature of the risk is aggregation: a single failure — one bad patch, one compromised credential, one backup platform misconfiguration — can generate claims from many clients arising out of the same event. That makes the difference between aggregate and any-one-claim limits, and the policy’s treatment of related claims, genuinely important rather than small print. It is exactly the kind of wording detail a broker should be arguing about before the policy is bound.
How Apex approaches MSP programmes
We start with what the firm actually does — the services in the MSA, the tooling, the client concentration, the contractual promises already made — and build the programme around that, rather than forcing an MSP into a generic IT wording. Bristol-based and FCA-regulated, we place cover with insurers who understand technology risk, and we read the wordings so that the PI, the cyber and the contract sit together coherently. If you run an IT business that has grown past its current arrangements, our IT support companies page covers the earlier stages of the same journey.
Frequently asked questions
Is tech E&O the same as professional indemnity?
Effectively, yes. Errors and omissions (E&O) is the American name for what the UK market calls professional indemnity, and technology wordings often blend the two labels. Whatever the label on the schedule, what matters is that the wording responds to claims arising from the technology services you actually provide, including managed services, security work and cloud administration.
Do MSPs legally have to carry professional indemnity insurance?
No. PI is not a statutory requirement for IT businesses — the pressure is contractual. Client agreements, framework tenders and partner programmes increasingly require PI and often cyber cover at specified limits, so in practice most MSPs of any size cannot trade without it. Employers’ liability, by contrast, is compulsory once you have employees.
Will cyber insurance pay an ICO fine?
You should not count on it. Whether regulatory fines under UK GDPR and the Data Protection Act 2018 can be insured at all is legally uncertain, and wordings differ on the point. Treat cyber insurance as paying for breach response, legal costs, notification and business interruption — and treat avoiding ICO enforcement as a matter of governance, not insurance.
Do we really need both PI and cyber?
For most MSPs, yes, because they answer different questions. Cyber responds when your own systems are compromised and you need help responding and recovering. PI responds when a client alleges that your work — a missed backup, a misconfiguration, a security failure — caused them loss. One policy does not do the other’s job.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
