FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
MSPs & IT Support

Managed service provider insurance UK: the full cover stack

In short: An MSP sits inside its clients’ infrastructure — remote access, admin credentials, backups, email, security. That position makes the firm commercially valuable and, from an insurer’s point of view, unusually exposed: one mistake or one compromise can affect many clients at once. A properly built MSP programme stacks professional indemnity (the tech E&O piece), the MSP’s own cyber cover, employers’ and public liability, and usually directors’ and officers’ cover — arranged so the policies meet, rather than gap, where client claims and security incidents overlap.

Why MSPs are a supply-chain target

Attackers follow leverage. Compromising one business yields one victim; compromising the firm that remotely manages fifty businesses yields fifty. Remote monitoring and management (RMM) platforms, privileged credentials and centralised patching make MSPs exactly that kind of leverage point, and supply-chain incidents over recent years have made both attackers and underwriters very aware of it. The consequence for MSPs is twofold: your own security posture is now an underwriting subject in its own right, and your clients’ insurers and procurement teams increasingly want to know who has keys to the estate they are covering.

None of this means MSPs are uninsurable — far from it. It means the risk needs describing properly, by someone who understands what the firm actually does, before it goes to market.

The cover stack, piece by piece

Professional indemnity (tech PI / tech E&O). The core professional cover: it responds when a client alleges that your work caused them financial loss — a migration that corrupted data, backups that were not running when they were needed, a security configuration that failed. For an MSP this is the policy that stands behind the promises in your master services agreement. We cover it in depth on our MSP professional indemnity page.

Cyber insurance — your own. This is first-party protection for the MSP itself: incident response, forensics, system restoration, business interruption while your own platform is down, and cover for extortion demands. Given that an MSP’s own compromise is the nightmare scenario for its whole client base, underwriters look hard at controls here. See our dedicated MSP cyber insurance page.

Employers’ liability and public liability. EL is compulsory once you employ staff. PL covers injury or property damage to third parties — less dramatic for a desk-based business, but engineers on client sites carrying kit and lifting floor tiles generate real PL exposure, and client contracts routinely require both.

Directors’ and officers’ cover. When something goes seriously wrong at a technology business — a major outage, an incident with regulatory involvement — questions can be directed at the people who ran it, not just the company. D&O protects directors personally for claims arising from their management decisions.

PI and cyber answer different questions

The most common confusion we see in MSP programmes is the assumption that one policy covers the whole cyber landscape. It does not, and the distinction is worth being precise about. Your cyber policy responds when your systems are breached: it funds your response, your recovery and your lost income. Your PI responds when a client alleges that your professional failure caused their loss — which may follow from your breach, from their breach, or from no breach at all, just a botched piece of work. Neither policy automatically covers your clients’ own losses; whether you are liable for those at all depends on your contract, your liability caps and the facts. We walk through that scenario on MSP liability when a client is breached.

Client contracts now ask for evidence

A visible shift in the market: insurance has moved from a back-office matter to a sales document. Enterprise clients, public-sector frameworks and increasingly ordinary SME customers ask MSPs to evidence PI and cyber cover at specified limits before contracts are signed or renewed — sometimes because their own insurers ask them who manages their IT. An MSP that can produce clean certificates at sensible limits removes friction from its own sales process. One that cannot may not find out what it cost them.

Limits: when one incident touches many clients

Limit selection for an MSP is not a per-client calculation. The defining feature of the risk is aggregation: a single failure — one bad patch, one compromised credential, one backup platform misconfiguration — can generate claims from many clients arising out of the same event. That makes the difference between aggregate and any-one-claim limits, and the policy’s treatment of related claims, genuinely important rather than small print. It is exactly the kind of wording detail a broker should be arguing about before the policy is bound.

How Apex approaches MSP programmes

We start with what the firm actually does — the services in the MSA, the tooling, the client concentration, the contractual promises already made — and build the programme around that, rather than forcing an MSP into a generic IT wording. Bristol-based and FCA-regulated, we place cover with insurers who understand technology risk, and we read the wordings so that the PI, the cyber and the contract sit together coherently. If you run an IT business that has grown past its current arrangements, our IT support companies page covers the earlier stages of the same journey.

Frequently asked questions

Is tech E&O the same as professional indemnity?

Effectively, yes. Errors and omissions (E&O) is the American name for what the UK market calls professional indemnity, and technology wordings often blend the two labels. Whatever the label on the schedule, what matters is that the wording responds to claims arising from the technology services you actually provide, including managed services, security work and cloud administration.

Do MSPs legally have to carry professional indemnity insurance?

No. PI is not a statutory requirement for IT businesses — the pressure is contractual. Client agreements, framework tenders and partner programmes increasingly require PI and often cyber cover at specified limits, so in practice most MSPs of any size cannot trade without it. Employers’ liability, by contrast, is compulsory once you have employees.

Will cyber insurance pay an ICO fine?

You should not count on it. Whether regulatory fines under UK GDPR and the Data Protection Act 2018 can be insured at all is legally uncertain, and wordings differ on the point. Treat cyber insurance as paying for breach response, legal costs, notification and business interruption — and treat avoiding ICO enforcement as a matter of governance, not insurance.

Do we really need both PI and cyber?

For most MSPs, yes, because they answer different questions. Cyber responds when your own systems are compromised and you need help responding and recovering. PI responds when a client alleges that your work — a missed backup, a misconfiguration, a security failure — caused them loss. One policy does not do the other’s job.

Get your MSP cover stack reviewed
PI, cyber, liability and D&O arranged to work together — by a broker who reads the wordings. Bristol-based, FCA-regulated.
Get a quote  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Get a quote →