Skip to content
Coverwright
← Notes
August 25, 2026 · 6 min read

MSP E&O insurance and cyber insurance aren’t the same policy

An MSP that has one and not the other usually finds out which one it’s missing during a claim. What errors and omissions insurance actually covers, what it doesn’t, and where cyber insurance picks up.

Search “MSP E&O” and most of what comes back either explains cyber insurance instead, or treats the two as interchangeable line items on the same renewal email. They aren’t. Errors and omissions insurance and cyber insurance answer two different questions about the same bad day, and an MSP that only has one of them usually finds out which question it needed answered while a claim is already open — the worst possible time to learn the difference.

What E&O actually covers

Errors and omissions — “professional liability,” “tech E&O” — responds to a claim that you did the job badly: negligence, a missed deliverable, advice that turned out wrong, a service level the contract promised and the MSP didn’t meet. The trigger isn’t a security incident. It’s a client saying, in effect, we paid you to do this and you didn’t, and it cost us money.

  • A patch or update the MSA committed to, that didn’t happen, and something broke because of it.
  • A backup that was supposed to be running and wasn’t, discovered only when a restore was needed.
  • A migration or configuration change that took a client’s systems down longer than the contract’s own commitments allowed.
  • Advice or a recommendation a client relied on that turned out to be wrong, where the client can point to a real financial loss that followed from it.

None of that requires an attacker. An MSP can face an E&O claim without any security incident ever occurring — the claim is about the contract and the service, not about a breach.

Where cyber insurance picks up instead

Cyber insurance is built around the incident itself — the costs that follow from a security event, whoever’s systems it started on. Forensics to find out what happened, the cost of notifying affected people, credit monitoring where it’s owed, business interruption while systems are down, and — where an attacker is actually involved — extortion payments and legal defense if someone sues over the breach. The trigger is the event, not whether anyone can show the MSP failed to deliver something it promised.

The two overlap in exactly the scenario that makes MSPs nervous: a missed patch leads to a ransomware event in a client’s environment. The client’s breach costs are a cyber claim. The client’s argument that the MSP was contractually on the hook for patching and didn’t do it is an E&O claim — a separate cause, against a separate policy, that can run at the same time as the first. An MSP holding only one of the two is covered for half of that conversation.

Why underwriters for both are asking the same new questions

This is the part that connects back to an MSP’s own written security program, not just its insurance line items: renewal applications for both E&O and cyber coverage have converged on largely the same underwriting questions — MFA on every account that reaches a client environment, named rather than shared technician logins, a documented boundary in the MSA for where the MSP’s responsibility ends and the client’s begins, and a written security policy an underwriter can actually read rather than take on faith. An MSP that has never had to produce one for its own business, rather than for a client’s, is the exact gap both renewals now find at the same time.

What it doesn’t do

Buying either policy, or both, doesn’t retroactively create the documentation an underwriter is asking about, and it isn’t a substitute for the MSA language that actually decides where an MSP’s contractual responsibility stops. Which policy responds to a given claim, whether a specific incident is covered, and what a specific carrier’s application requires are all questions for that carrier and the MSP’s own broker — this is a description of what the two products generally do, not advice about either coverage.

What a written security program does is give both renewals the same honest answer instead of two different guesses: the access controls actually in place, the ones still outstanding with an owner and a date, and the responsibility split the MSA already states — the document underwriters for both policies are increasingly asking to see before they’ll quote at all.