IT consultants and managed service providers are often told they need “tech E&O” or “cyber insurance,” sometimes interchangeably. The two are related, they are often sold together, and they respond to overlapping situations, but they are not the same coverage. An MSP that carries one and assumes it has the other can find out the difference at the worst possible time.
This article explains what each coverage is typically designed to do, where they overlap, where the gaps are, and how firms that manage other people’s systems should think about putting them together.
What Technology Errors and Omissions Covers
Technology E&O, sometimes called technology professional liability, is designed for claims by your clients alleging that your services or products failed to perform as promised and caused them financial loss. For an IT consultant or MSP, that includes scenarios such as a migration that corrupted a client’s data, a misconfigured firewall that let an intruder in, a backup system that was never actually backing up, a software implementation that missed the deadline and cost the client a contract, or advice that led the client to buy a system that did not work for them.
The trigger is your professional error, and the loss is the client’s financial damage. General liability does not respond to these claims, because they involve neither bodily injury nor physical property damage, and because most GL forms exclude professional services.
What Cyber Liability Covers
Cyber liability is designed for losses arising from a security or privacy event affecting your own systems and data. It typically has two parts. First-party coverage pays your own costs after an incident: forensic investigation, breach notification, credit monitoring, ransomware response and extortion payments where insurable, data restoration, and business interruption while your systems are down. Third-party coverage responds to claims by others, such as customers whose data was exposed, and to regulatory investigations and penalties where insurable.
The trigger is an event on your network or involving data you hold, and the coverage is designed around the response to that event.
Where They Overlap and Where They Do Not
Here is the scenario that shows why the distinction matters. An MSP manages a client’s network. An attacker gets in through a vulnerability the MSP should have patched and deploys ransomware across the client’s systems. The client is down for a week and loses revenue.
The client’s claim against the MSP for negligent patching is a tech E&O claim. The MSP’s own cyber policy generally does not respond to it, because the event happened on the client’s network, not the MSP’s, and the loss is the client’s, not the MSP’s.
Now change the facts. The attacker compromises the MSP’s remote management tool and uses it to push ransomware to every client at once. The MSP’s own systems are involved, the MSP’s own data may be exposed, and the MSP has first-party costs to investigate and recover. That part is a cyber claim. The claims from the clients for the damage done to them through the MSP’s tool are tech E&O claims. Both policies are needed, and both need to be written to recognize the other.
The Gaps to Look For
Several problems come up when the two coverages are purchased separately from different carriers without coordination.
A cyber policy may exclude claims arising from professional services, pushing everything toward E&O. An E&O policy may exclude claims arising from a security breach or unauthorized access, pushing everything toward cyber. If both exclusions exist and the claim involves both a professional error and a breach, each carrier may point at the other while you pay the defense costs.
Contractual liability is another issue. MSP service agreements often include indemnification provisions and service-level commitments. E&O policies typically cover negligence, not promises, and a claim framed as breach of contract may face an exclusion.
Coverage for third-party systems matters as well. Some cyber forms limit first-party coverage to the insured’s own network. An MSP whose business depends on cloud platforms it does not own should look for dependent business interruption coverage that extends to those providers.
Combined Policies and Why They Exist
Because these gaps are well known, many carriers offer a combined technology E&O and cyber policy under a single form. The advantage is that one carrier and one policy respond to the whole incident, without arguments about which coverage applies. The definitions are typically written to fit together, and the limits may be shared or separate depending on the form.
Combined policies are not automatically better. Shared limits can be exhausted by a large first-party event, leaving little for the client claims that follow. And some combined forms are stronger on one side than the other. But for most small and mid-sized IT firms, a well-written combined policy is simpler and more reliable than two separate policies that were never designed to meet.
What Clients and Contracts Increasingly Require
Larger clients and their insurers have become more specific about what they expect from IT vendors. It is common for a master services agreement to require both technology E&O and cyber liability with stated minimum limits, sometimes with the client named as an additional insured where available. Cyber underwriters for the client may also ask about the MSP’s own security controls, because a vendor with weak controls is a risk to the client’s coverage. Being able to produce a certificate showing both coverages, at limits the client considers adequate, is frequently a condition of winning or keeping the account.
Building the Right Program
For an IT consultant or MSP, the practical questions are whether your E&O covers claims arising from security failures on client systems, whether your cyber covers incidents that start on your systems and spread to clients, whether the two policies or the combined form work together without a gap in the middle, whether your contracts create obligations the policies will not cover, and whether your limits match what your clients require.
An independent agent who works with technology firms can compare combined and standalone options, review the exclusions on both sides, and check your service agreements against the policy language. When you are responsible for other people’s systems, the line between your error and their breach is thin. Your insurance should be built with that in mind.
Leave a Reply