The written security program you tell clients to have — for yourself
MSPs write the security story for everyone else’s business. Your own cyber and tech E&O insurer, and increasingly your own clients’ contracts, now want to see that story written down for yours too.
Usually one of three moments: your tech E&O or cyber renewal asks for a written program you’ve never had to produce for yourself, a client’s procurement team names you by name as a subcontractor in their own security review, or a client’s cyber insurer asks who has access to their systems and what secures that access.
What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.
What tends to be true of firms like yours.
Your own insurer is starting to ask, not just tell your clients to
Cyber and tech E&O underwriters increasingly expect MSPs to carry a documented, enforced security program of their own — MFA on every RMM and technician account, named rather than shared logins, and contract language that states plainly where your responsibility for a client’s environment ends and theirs begins. A policy you sell the idea of to clients but never wrote for yourself is the gap an underwriter now asks about directly.
You may be a HIPAA business associate yourself
If any client is a healthcare practice and you have access to clinical systems, hosting, or anything touching patient records, you can be a business associate under HIPAA regardless of what your own business does — a role, not a certification. Where that isn’t confirmed, your documents say so and name what to check, rather than guessing either way.
You’re the vendor in someone else’s questionnaire
You build the vendor responsibility matrix that answers a client’s “who manages X?” row for every tool they use. When a client’s bigger customer or insurer pushes a security review down to them, you are frequently the row — named as the outside IT provider — with no matching document of your own to hand back.
The access you hold is the whole business, honestly stated
Privileged access to every client’s environment is the asset and the liability at once — it is what an incident at one client can turn into an incident at all of them. The documents state what’s actually in place (technician account MFA, access reviews, logging) and flag what isn’t with a remediation commitment, the same honesty rule that applies to every business this product generates for.
Whether you’re a HIPAA business associate for a given client, or what your MSA should say about splitting responsibility, is a determination for you, your counsel, and that contract — not something a generated document decides for you. Coverwright produces the documentation an insurer or client asks an MSP to hold; holding it is not the same as being compliant, certified, or covered.