Cyber insurance for MSPs is two separate problems wearing one name, and the dangerous one isn't your renewal. Picture the other one. Your client gets encrypted on a Thursday night, and inside a week their carrier is asking for evidence of the multi-factor rollout somebody attested to on the application. That somebody was you, working from a screenshot and a good memory. MSP Pentesting sits on the evidence side of this, channel-only, because the fastest way to make an attestation defensible is to have an independent party test it.
Two policies. Two completely different failure modes.
Your policy fails when a claim lands outside the coverage you thought you bought. Your client's policy fails when an answer on the application turns out to be wrong.
Your own policy, and what the standard form misses
Start with vocabulary, because brokers use it and MSPs nod along without agreeing on meaning.
First party cyber insurance pays for your losses. Forensics, data restoration, your own business interruption, the extortion payment if the policy permits one, notification costs. It's the money that gets you back online.
Third party cyber insurance pays when someone else sues you over a security failure. Your client, their customers, a regulator.
Technology errors and omissions is also third party, but it responds to performance failures rather than security failures. You promised patching and didn't deliver it. You misconfigured a tenant. You gave advice that turned out to be wrong.
Here's why the distinction matters for you specifically. A lot of MSP claims live in the seam. A client is ransomed through your RMM, they sue you, and the argument is partly about your security and partly about whether you performed the service you sold. Carriers that write for the channel usually combine cyber and tech E and O on one form for exactly that reason. Two policies from two carriers means two adjusters pointing at each other while your client's lawyer waits.
| Coverage | Who suffers the loss | Typical MSP trigger |
|---|---|---|
| First party cyber | You | Your own tooling is ransomed and you stop billing |
| Third party cyber | Your client, or their customers | Data exposed in an environment you administer |
| Tech errors and omissions | Your client | You did not deliver a service the contract promised |
| Contingent business interruption | You | A vendor you depend on goes dark and takes you with it |
Three more things to press your broker on.
Aggregation. One compromised RMM instance is not one claim, it's every client at once. Ask how the carrier treats a single event affecting forty customers, because the limit that looks generous against one incident looks thin against forty.
Vicarious liability from your MSA. Read your own contracts. If you've accepted indemnity obligations to clients, check whether the policy actually responds to liability you assumed by contract or excludes it as an assumed obligation.
Contingent business interruption. Often sublimited, sometimes absent without an endorsement. Your dependency chain runs through a handful of platform vendors, and when one of them has a bad week you don't get to bill for the week either.

Your clients' policies, where the questionnaire becomes the product
The cyber insurance questionnaire stopped being paperwork a few years ago. Now it's the underwriting.
Carriers ask for six things, in roughly this order.
- Phishing resistant multi-factor on email, VPN, remote access and admin consoles.
- Endpoint detection on servers, not just laptops.
- Immutable backups with a documented restore test and a date.
- A written incident response plan.
- Privileged access separated from daily use.
- And increasingly, whether an independent third party performs annual penetration testing.
Guess who answers all of that. You do, because you're the only one who knows.
That's the exposure. Every answer you supply is a representation the carrier relies on to price and issue a policy, and if it turns out to be materially wrong the carrier can go after the policy itself. In 2022 Travelers filed suit in the Central District of Illinois to rescind a cyber policy issued to International Control Services, alleging the application misstated the company's use of multi-factor authentication. The parties stipulated to an order rescinding the policy and declaring it void from inception. Not a coverage dispute. The policy simply stopped existing.
Now imagine that claim, and the client's next call is to the MSP who filled the form in.
So build a rule and never break it. You don't answer a client's questionnaire from memory. You answer it from evidence, you show the client the evidence, and the client signs. Where the honest answer is no, write no and attach the remediation plan. A rated up premium is survivable. A rescinded policy after a loss is not.

Build the evidence pack once
The same eight or nine controls come up on nearly every application, so stop rebuilding the answers per client.
Keep a folder per client. Six things live in it.
- The MFA enforcement export.
- The EDR coverage report, with a count of covered endpoints against the asset list.
- The last restore test, with its date and its result.
- The incident response plan, with a revision date.
- The privileged account list.
- The most recent independent test report.
Refresh it quarterly. When renewal lands you're pulling files rather than reconstructing history, and when a claim lands you're producing evidence that predates it.
Why carriers look at MSPs the way they do
None of this scrutiny is arbitrary. In May 2022 the cybersecurity authorities of the US, UK, Australia, Canada and New Zealand published joint advisory AA22-131A on cyber threats to managed service providers and their customers, warning that actors were targeting providers to exploit the trust relationship with downstream clients.
Underwriters read those. When an application asks whether your client uses an MSP and what access that MSP holds, it's asking about a concentration risk the carrier already has opinions about.
Which cuts both ways. An MSP that can produce evidence, a current independent test and a clean remediation history makes a client easier to underwrite. That's a commercial advantage you can actually name in a renewal conversation.
Verticals where the questions get sharper
Cyber security insurance for law firms is the clearest example. Firms hold privileged material, they wire money, and business email compromise against a real estate closing is a well understood loss pattern. Applications reflect that: expect specific questions about wire verification procedure, out of band callback on payment instructions, and who can change bank details in the practice management system.
Healthcare applications ask about protected health information volume and business associate agreements. Financial services applications ask about funds transfer controls. If you serve one of those verticals, get the sector specific questionnaire in advance and work the gaps before renewal season, not during it.
A structured risk assessment is a reasonable way to find those gaps on your own schedule instead of an underwriter's.
Where testing actually fits
Testing does two jobs here and they're both commercial.
It substantiates the answers. "We require MFA" is a policy statement. A test report showing every remote path enforced it, and naming the one legacy protocol that didn't, is evidence. That's the difference between an attestation you'd defend and one you'd rather not discuss.
And it satisfies the question directly, when the application asks for an independent annual test. You can't be independent for a network you administer, which is the whole reason white-labeled pentesting exists. The tester stays separate, the report carries your brand, and the remediation work stays yours.
What MSPs ask at renewal time
Does having cyber insurance mean we don't need tech E and O?
No, and that assumption is how MSPs end up uninsured for their largest exposure. Cyber generally responds to security failures. Tech E and O responds to service failures. Most client disputes involve both, so look for a combined form or make sure the two policies dovetail rather than overlap awkwardly.
Should we fill out client questionnaires at all?
You'll be asked, so yes, but change how. Provide factual answers about systems you administer, attach the evidence, and let the client sign the application. Don't sign it yourself, don't answer for systems outside your contract, and put in writing that answers reflect the environment as configured on a stated date.
Will a penetration test lower a client's premium?
Sometimes, and nobody should promise it. What testing reliably does is let a client answer control questions accurately and evidence them, which affects whether they're offered coverage and on what terms. Underwriting is a whole picture, not one line item.
Our client says their carrier accepts a vulnerability scan. Is that enough?
If the question asks for a scan, a scan is the answer. Read the actual wording, because "vulnerability scanning" and "penetration testing" appear as separate questions on plenty of applications, and answering yes to the second when you performed the first is exactly the kind of mismatch that surfaces after a loss.
What limits should an MSP carry?
That's a broker conversation driven by client count, contract terms and the data your clients hold. What we'd push you on is the structure rather than the number: aggregation treatment, whether contractually assumed liability is covered, and whether contingent business interruption is real or a token sublimit.
Do the evidence work before renewal season
Cyber insurance for MSPs comes down to a single discipline. Never state a control you can't evidence, on your application or on a client's.
Everything else follows. If you can evidence it, the questionnaire gets easier, the renewal gets calmer, and a claim doesn't turn into an argument about what you said in March.
Pick your three largest clients and read their most recent applications against what's actually deployed today. You'll find at least one answer that's drifted. Then fix it, test it, and go into renewal with proof. Get a pentest quote, attach the client's last application, and we'll test the answers they already gave.



.avif)
.png)
.png)
.png)

