Click to toggle navigation menu.

Co-Managed IT: Where Liability Falls When You Share a Client Stack

< BACK

By Ryan Windt | Head of Growth Marketing | Updated June 2026


Co-managed IT is one of the fastest-growing service models for MSPs, and one of the murkiest from a liability standpoint. In a fully managed relationship, the lines are reasonably clear: the MSP runs the environment, and the MSP’s contracts and insurance are built around that. Co-managed is different. An internal IT team and the MSP both have hands on the same systems, often with overlapping access, undocumented division of duties, and no clear answer to the question that matters most after an incident: who was responsible for the control that failed.

That ambiguity is not just an operational headache. It is a liability exposure, and it shows up in how your cyber and Technology E&O policies respond when a breach traces back to a shared environment. This post breaks down where the exposure sits, how coverage responds, and what an MSP should do contractually and operationally to avoid being the last party standing when the finger-pointing starts.


What Co-Managed IT Actually Means for Liability

Co-managed IT is any arrangement where an MSP and a client’s internal staff share responsibility for the same IT environment. The split varies widely. Sometimes the internal team handles day-to-day support and the MSP handles security, backups, and infrastructure. Sometimes it is the reverse. Often it is neither cleanly defined nor written down.

The liability problem is structural. When a breach happens in a singly-managed environment, responsibility points in one direction. In a co-managed environment, a plaintiff’s attorney, a forensic investigator, and two insurers all start asking the same question: whose duty was it to patch that server, enforce that MFA policy, or monitor that endpoint? If the contract does not answer that question, the answer gets decided after the fact, which is the worst possible time for the MSP.

In a co-managed relationship, an undocumented division of duties is not a neutral gap. It defaults to a dispute, and the MSP is usually the party with the deepest pockets and the most explicit professional duty of care.


The Two Coverages in Play

A co-managed incident can implicate both of an MSP’s primary insurance lines, and understanding which responds to what is the foundation for managing the exposure.

CoverageResponds ToCo-Managed Trigger
Cyber (first-party)The MSP’s own breach costs, downtime, extortion, breach responseAn attack that compromises the MSP’s own systems or tooling
Cyber (third-party)Claims from others alleging the MSP’s failure caused their lossA client alleging the MSP’s negligence led to the client’s breach
Technology E&OClaims alleging the MSP’s professional services were negligent or deficientA client alleging the MSP failed to perform a service it was contracted to perform

The distinction between cyber third-party liability and Technology E&O matters enormously in co-managed disputes, because the allegation usually sounds in professional negligence: you were supposed to do X, you did not, and our breach is the result. That is squarely Tech E&O territory, though many claims plead both. Our post on where Tech E&O and cyber each respond walks through how these lines divide in practice, and what Technology E&O insurance is covers the fundamentals.


Where the Exposure Concentrates

Overlapping access without ownership

When both teams have administrative access to the same systems, every unmanaged change is a potential claim. If the internal team disables a control the MSP installed, or the MSP pushes a change that conflicts with internal configuration, the resulting incident has two plausible owners. Without logging that establishes who did what, the dispute is unwinnable by documentation, which favors the party with the lighter contractual duty.

The “we assumed they had it” gap

The single most common co-managed failure pattern: a control nobody owned because each side assumed the other had it. MFA on a specific application, patching of a particular server class, monitoring of a specific log source. In a co-managed environment, the controls that fall between the two teams are exactly the ones underwriters and plaintiffs scrutinize after a breach.

Scope creep beyond the contract

Co-managed relationships drift. The MSP starts handling things outside the original statement of work because it is easier than escalating. Over time, the de facto scope diverges from the contracted scope. After an incident, the client argues the MSP was responsible for the drifted-in duty; the MSP argues it was never contracted. Tech E&O responds to the defense of that dispute, but the exposure is real and the outcome uncertain.


How Underwriters View Co-Managed Books

Carriers underwriting an MSP’s cyber and Tech E&O coverage increasingly ask about the service-delivery model, because co-managed relationships change the risk profile. An MSP whose book is heavily co-managed presents a more complex liability picture than one running fully managed environments with clear control.

The questions underwriters tend to probe: what portion of the book is co-managed, whether responsibilities are documented per client, whether the MSP controls or merely advises on security controls, and how access is segregated between MSP and internal staff. An MSP that can demonstrate documented division of duties and clean access controls presents far better than one that cannot. Our post on how underwriters evaluate an MSP client base covers the broader evaluation, and the same documentation discipline applies here.

The MSP that can hand a carrier a clear responsibility matrix for each co-managed client is underwriting a fundamentally different risk than the MSP that says “it depends on the client.”


What MSPs Should Do

The exposure is manageable, but only with deliberate contractual and operational discipline. The goal is to make the division of duties explicit before an incident, so it is not litigated after one.

Document the responsibility split per client. A responsibility matrix that names, for each major control area, which party owns it, is the single most valuable artifact in a co-managed dispute. It defines the duty of care, which is the thing Tech E&O claims turn on.

Write the division into the contract, not just an email. The statement of work and the master services agreement should reflect the actual split, including security controls, patching, monitoring, and backups. Where the client retains a duty, say so explicitly. Our post on embedding cyber insurance into MSP services covers how this fits the broader service structure.

Segregate and log access. Separate credentials for MSP and internal staff, with logging that establishes who made which change, converts an unwinnable he-said-she-said into a documentable record. This also strengthens your underwriting position.

Address scope drift periodically. Review the actual division of duties against the contracted one on a schedule, and update the agreement when they diverge. Drift is the enemy; periodic reconciliation is the fix.

Confirm both coverages are in force and aligned. An MSP in co-managed relationships needs both cyber and Technology E&O, with limits that reflect the liability concentration in its largest clients. Our post on Technology E&O for MSPs covers what adequate coverage looks like.


A Co-Managed Scenario

An MSP handles infrastructure, backups, and perimeter security for a mid-sized client. The client’s two-person internal IT team handles endpoints and user support. A phishing email compromises an internal user’s credentials; the account had local admin rights the internal team had granted without telling the MSP. Ransomware spreads from that endpoint. The MSP’s backups work, but the client suffers a week of downtime and sues, alleging the MSP should have detected the lateral movement.

Who is liable? The internal team granted the over-privileged access. But the MSP was contracted for “perimeter security,” and the client argues monitoring for lateral movement fell within that. If the contract does not define the boundary, this goes to a contested Tech E&O claim where the outcome depends on documents that may not exist. Had the MSP held a signed responsibility matrix assigning endpoint privilege management to the internal team, the defense would be straightforward. Without it, the MSP is defending its professional reputation on ambiguity.

This is why the documentation discipline is not bureaucratic overhead. It is the difference between a defensible position and an expensive settlement.


Frequently Asked Questions

Does cyber or Tech E&O respond to a co-managed dispute?
Usually Tech E&O, because the allegation is typically professional negligence: the MSP failed to perform a contracted service. Many claims plead both cyber third-party liability and Tech E&O, which is one reason MSPs in co-managed relationships should carry both.

Can a contract fully eliminate co-managed liability?
No, but a clear contract with a documented responsibility split dramatically narrows it. The contract defines the duty of care, which is what negligence claims turn on. It will not stop a client from suing, but it makes the defense far stronger.

Do underwriters charge more for co-managed books?
Not necessarily more, but they scrutinize them more. An MSP that documents responsibilities and segregates access can present a co-managed book favorably. One that cannot may face tougher terms or more questions at renewal.

What is the single most important thing to have in place?
A per-client responsibility matrix, written into the contract, that names which party owns each control area. It is the artifact that resolves the question every co-managed dispute comes down to.

Who is liable if the client’s internal team disables a control we installed?
If logging establishes the internal team made the change and the contract assigned that control to them, the MSP’s position is strong. Without documentation, it becomes a contested question, which is the exposure this whole discipline is designed to prevent.



Co-managed IT is a strong growth model, but it concentrates liability in the gaps between two teams. The MSPs that thrive in it are the ones that make the division of duties explicit before an incident forces the question. Talk to our team about structuring cyber and Tech E&O coverage around your co-managed book.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.