Cyber Insurance
Last updated
Definition
Cyber insurance (also sold as cyber liability) covers the costs of a security incident – forensics, breach counsel, notification, business interruption, extortion payments, and third-party claims. For an MSP it exists in two forms: the policy you carry yourself, usually bundled with technology errors and omissions (E&O) coverage, and the policy each client carries, whose application questionnaire has become the de facto security standard for small business.
Why it matters to an MSP
Your own policy is the backstop for the worst day in the business: a client breached through your RMM, a technician's mistake wiping a server, a ransomware event that spreads across tenants. Tech E&O plus cyber at $1M–$2M limits typically costs a small MSP low-to-mid four figures a year as of 2026, and the premium is underwritten on your own controls – MFA everywhere, EDR on your systems, tested backups, no standing admin access. Serious MSA negotiations will ask for your certificate of coverage.
The client-side policy is where the sales and delivery mechanics live. Since the 2020–22 ransomware losses, the standard questionnaire demands MFA on email, remote access, and privileged accounts, EDR or MDR on every endpoint, offline or immutable backups with documented restore tests, email filtering, security awareness training, and patching cadence. Weak answers mean 40–100% premium increases, ransomware sublimits, co-insurance, or declination – so "your carrier requires this" closes upgrades ROI arguments cannot, and every renewal is a sales event. Never sign the attestation yourself: give the client written control status with evidence, have their officer sign, keep your copy, and require in your MSA that they carry their own policy. Post-incident, the carrier's hotline is the first call, because an unapproved responder can forfeit coverage. See cyber insurance readiness for the questionnaire-to-control mapping.
Related terms: MFA, EDR, Ransomware, BDR