FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Managed service providers

Professional indemnity for managed service providers (MSPs)

A managed service provider holds the keys to every client it looks after — privileged, administrative access to networks, infrastructure and cloud that belong to someone else. Professional indemnity, known in technology as technology errors and omissions (tech E&O), responds when your service, configuration or advice fails and a client suffers a financial loss as a result. For an MSP the defining worry is aggregation: one mistake, made once through the shared tools you use to manage everyone, can land on your whole client base at the same time.

In short

Professional indemnity — known in technology as technology errors and omissions, or tech E&O — covers a managed service provider against third-party claims when a service, configuration or piece of advice you provide fails and causes a client a financial loss. It funds the defence of the allegation and meets damages or a settlement where you are liable. The product matters more for an MSP than for almost any other IT firm because of aggregation: you manage many clients through the same people, processes and remote tools, so a single error, a bad change pushed to every estate, or a misconfiguration replicated across the base can trigger claims from dozens of clients at once. PI is almost always written on a claims-made basis, so the policy in force when a claim is made — not when the work was done — is the one that has to respond.

Why an MSP carries a higher-stakes, aggregation-heavy risk

Most professional firms advise one client on one matter at a time. A managed service provider does the opposite: you hold administrative access to many clients’ networks, servers, identity systems and cloud tenancies at once, and you manage them through a shared stack of remote monitoring, automation, security and backup tools. That concentration is what makes the risk unusual. You are responsible for infrastructure you do not own — often the part a client depends on to trade — and a single mistake does not stay contained to one account.

The industry word for this is aggregation. A change pushed through automation to every managed device, a backup job that silently stops protecting a whole group of clients, or a patch withheld or applied wrongly across the base can each convert one human error into many simultaneous claims. Professional indemnity is the cover built to respond to those third-party allegations: that your service or advice fell below reasonable skill and care and caused a client a financial loss.

It helps to see which MSP exposures PI is designed to meet, and which belong to other covers:

MSP exposureWhat typically responds
A faulty configuration or change that brings down a client’s systemsProfessional indemnity / tech E&O — third-party loss caused by your work
Negligent advice on architecture, migration or security designProfessional indemnity / tech E&O
One error replicated across many clients through shared toolingProfessional indemnity, subject to how the wording treats linked or aggregated claims against a single limit
Your own network breached, ransomware, or data held to ransomCyber — first-party
Forensics, client notification and incident response after your breachCyber — first-party
Injury to a person, or damage to property, at a client sitePublic liability
Theft or dishonesty by an employeeCrime / fidelity cover
Investigation following a personal-data breachCyber breach response; note regulatory fines are frequently uninsurable

Underwriters look hard at how you limit aggregation: change-control discipline, tested backups, least-privilege access, and whether a bad change can be rolled back quickly. Those same controls are what keep one mistake from becoming a portfolio-wide loss.

The supply-chain exposure: when a tool you rely on is compromised

The sharpest version of aggregation is not an error you make at all — it is a weakness in something you depend on. MSPs run their clients through powerful third-party platforms: remote monitoring and management, scripting and automation, endpoint security, backup and identity tools. Those tools are trusted by design and reach deep into every client estate. If one of them is compromised at source, an attacker can ride the same trusted channel you use to manage clients straight down into all of them. The pattern is generic and well understood: the more privileged and widely connected a tool is, the more attractive it becomes as a route to everyone downstream.

This is where the line between your fault and someone else’s gets blurred, and where claims get complicated. A client that suffers a loss will often look first to the MSP it contracted with, regardless of where the failure originated. Professional indemnity responds to the allegation that you were negligent — for example in how you selected, configured, monitored or secured the tool — while the costs of your own compromised environment sit with cyber cover. Whether a supplier further up the chain ultimately bears responsibility is a separate, slower question that does not pay your defence costs in the meantime.

MSPs manage this exposure on two fronts at once:

Neither front removes the exposure; together they make it defensible — and a defensible risk is one an insurer can more readily support.

Contracts, client indemnities and flow-down

An MSP’s real liability is usually written long before any claim, in the managed services agreement. These contracts routinely commit you to service levels, uptime targets, security standards and response times, and they frequently ask you to indemnify the client against losses — sometimes including the client’s own downstream customers. What you agree to in writing directly shapes what a PI policy can stand behind.

The pivotal distinction is between reasonable skill and care and an absolute promise. Professional indemnity is built to respond when you have been negligent — when your work fell short of the standard a competent MSP would meet. It is not built to underwrite guarantees. A clause that promises a specific uptime outcome come what may, warrants a particular security result, or accepts liability regardless of fault creates an obligation that can exceed negligence — and a liability assumed purely by contract, beyond what the law would impose, may fall outside cover.

Practical points that protect both the contract and the cover:

The Insurance Act 2015 runs underneath all of this: you owe a duty to make a fair presentation of the risk when you buy and renew, which means telling the insurer about the contracts, clients and concentrations that actually drive your exposure. A specialist broker will usually read the liability and insurance clauses of a major client contract against your wording before you commit.

Tech E&O and cyber: two policies, one gap to close

An MSP needs both professional indemnity and cyber, because they answer different questions. The simplest way to hold the boundary in mind:

The trouble is that an MSP incident rarely respects that line. A compromise of your environment (a cyber event) can flow into clients and cause them loss (a PI allegation) in the same incident. When the two covers sit with different insurers, or the wordings are not aligned, each can point at the other — and the claim risks falling into the gap between them.

That is why how the policies interlock matters as much as either one alone. Two things to check: first, whether a single event that is both a breach and a service failure is clearly allocated rather than disputed; second, whether definitions, retroactive dates and notification rules line up, since PI is written on a claims-made basis and a late or misdirected notification can prejudice cover. Many MSPs resolve this by placing combined technology cover — tech E&O and cyber in one wording with one insurer — so there is no argument about whose claim it is. On data, be clear-eyed: these policies fund breach response and defend third-party claims under the UK GDPR and the Data Protection Act 2018, but regulatory fines are frequently uninsurable, so cover is never a substitute for compliance.

How Apex places professional indemnity for managed service providers

Why managed service providers move their PI to Apex

When it is worth getting a second quote

It is worth asking us to re-market your cover when:

When we are not the right broker

We would rather say so than waste your time. We are probably not for you if:

Related guides

Frequently asked

Is technology E&O the same as professional indemnity for an MSP?

Yes — technology errors and omissions (tech E&O) is the term used in technology; professional indemnity is the UK term for the same product. For an MSP it covers third-party claims that your service, configuration or advice failed and caused a client a financial loss. It is contractual cover, driven by your client agreements, not a statutory requirement.

Does an MSP need cyber insurance as well as PI?

Almost always. PI responds to a client’s loss caused by your work; cyber responds to your own breach and the first-party costs that follow — ransomware, business interruption, forensics and notification. A single incident can trigger both, so the two should be placed to interlock, ideally under one combined technology wording.

What is aggregation, and why do underwriters focus on it?

Aggregation is the risk that one mistake affects many clients at once, because you manage them through the same people and tools. It is the defining MSP exposure. Insurers look closely at how you contain it — change control, tested backups, least-privilege access, and the ability to roll a bad change back quickly.

A client wants us to guarantee uptime and security. Is that a problem for cover?

It can be. PI responds to negligence — work that fell below reasonable skill and care — not to absolute guarantees. A clause that warrants a specific outcome or accepts liability regardless of fault can create an obligation that sits outside cover. Have the liability and insurance clauses checked before you sign.

If a tool we rely on is compromised and our clients are affected, are we covered?

It depends on the allegation and your wording. A claim that you were negligent in how you selected, configured, monitored or secured the tool typically engages PI; the cost of your own compromised systems sits with cyber. Because these incidents blur the line, aligned PI and cyber cover matters.

What does ‘claims-made’ mean, and what happens if I switch insurer or close the firm?

Claims-made cover is triggered by when a claim is made against you, not when the work was done. You need a live policy when the claim arrives, and the retroactive date must reach back over your past work. If you stop trading or leave an insurer, run-off cover keeps you protected for services already delivered.

How much cover does an MSP need?

There is no statutory minimum — your client contracts set it. Size the limit to the agreements you actually sign, and tell your broker before you commit to a contract that demands more cover, a different basis or named-insured status than you currently hold. Resolving it early is routine; discovering a gap at claim time is not.

Get MSP cover sized to your client base, not a generic IT policy

Tell us how many clients you manage, the tools you manage them through, and the contracts you sign. A specialist broker can place technology E&O and cyber so that your service failures and your own breaches are both covered — with no gap between them — and check your client agreements against the wording before you commit. Or call 0117 325 0027.

Get a quote Request a callback

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.