MSP liability when a client is breached: who pays?
The scenario, played out
Ransomware lands at a client. Systems are encrypted, trading stops, and the client’s own cyber insurer — if they have one — steps in to fund the response. Then the accounting starts. The client has suffered real losses; their insurer has paid real money; and both look at the managed service provider who held responsibility for the environment. What follows is rarely a dramatic courtroom moment. It is a letter: an allegation that patching was behind, that monitoring missed the intrusion, that a recommended control was never implemented, that backups the MSP managed failed to restore. The MSP’s handling of the next ninety days — and the paperwork from the previous three years — decides most of what happens after.
Who is actually liable?
Not automatically the MSP. Liability requires a failure: something the MSP was engaged to do and did not do with reasonable skill and care, which caused the loss. An MSP contracted to manage backups and patching is not thereby the guarantor of the client’s entire security posture — attackers get through well-run environments too, and a breach is not, by itself, proof of negligence. The dispute is nearly always about scope: what exactly was the MSP responsible for, and does the route the attacker took run through it? That is why the single most valuable document in these cases is the service agreement, and why vague scopes are dangerous for both sides.
What the client’s insurer may do
When a client’s cyber insurer pays out, it generally acquires the client’s rights of recovery — and if there is a plausible case that a service provider’s failure contributed to the loss, the MSP is an obvious candidate for recovery action. This is worth understanding in advance: the claim against the MSP may arrive not from an unhappy client trying to preserve a relationship, but from an insurer with no relationship to preserve and a paid loss to recoup. It changes the tone, and it is one of the reasons MSPs should never assume goodwill will keep a security incident out of the legal arena.
Where the MSP’s PI comes in
Allegations of negligent professional work are what professional indemnity exists for. The policy funds the defence — the causation and scope arguments that decide these cases — and pays damages or settlements where liability is established. Notify early: PI policies require prompt notification of claims and of circumstances that might give rise to one, and a ransomware event at a major client is usually a notifiable circumstance long before any letter arrives. If the attacker’s route ran through the MSP’s own systems, the firm’s own cyber policy handles that side — two policies, one incident, working from opposite ends.
Documentation is the defence
Almost every strong MSP defence is built from contemporaneous paper. The scope of service, precisely drawn. Change records and patch logs. Monitoring reports actually sent. And above all, recommendations with responses: the proposal to roll out MFA, the quote for the backup upgrade, the email flagging the end-of-life server — and the client’s decision, recorded at the time. “We recommended MFA and they declined” is a strong position in writing and a weak one from memory; after a six-figure loss, recollections of verbal conversations diverge sharply. The discipline is simple and cheap: recommend in writing, record the decision, keep the records. It is the highest-return risk management an MSP can do.
Before the bad day: what to have in place
Three things, arranged in calm conditions. A contract with a clear scope and a liability cap that reflects the work. A PI limit chosen with the aggregation question in mind — one incident can touch several clients at once. And the habit of written recommendations. The wider programme around this — the full stack of PI, cyber and liability covers — is set out on our MSP insurance page. Apex is a Bristol-based, FCA-regulated broker; helping technology firms get this structure right before it is tested is a large part of what we do.
Frequently asked questions
Can a client sue us just because they were breached on our watch?
They can allege it; whether it succeeds depends on what you were engaged to do and whether you did it with reasonable skill and care. Being the IT provider at the time of a breach is not liability by itself. The claim has to connect a failure in your actual scope of service to the loss — which is why the written scope matters so much.
Does our cyber insurance pay the client’s losses?
No — your cyber policy is for your own breach response and your own losses. A client’s claim that your negligence caused their loss is a professional indemnity matter. If your systems were the attacker’s way in, both policies may be working at once: cyber on your incident, PI on their allegations.
The client declined the security measures we recommended. Are we off the hook?
You are in a far stronger position — if the recommendation and the refusal are in writing. A documented recommendation, a clear statement of the risk, and the client’s decision recorded at the time is powerful evidence. The same conversation held verbally and remembered differently by each side is close to worthless. Put it in writing, every time.
Will the liability cap in our contract protect us?
It is your first line of defence and often holds, but it is not absolute: caps can be challenged as unreasonable, may not cover every head of claim, and only bind the party that agreed them. Treat the cap as risk management and your PI limit as what stands behind it — and make sure the two figures were chosen with each other in mind.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
