By Ryan Windt | Head of Growth Marketing | Updated July 2026
Most MSPs think about cyber insurance as protection for their own business. Fewer think about the scenario that has quietly become one of the most common ways an MSP ends up in a coverage fight. A client suffers a breach, the client’s cyber insurer pays the claim, and then that insurer turns around and tries to recover the money from the MSP whose systems or service failure let the attacker in. That recovery action is called subrogation, and MSPs are increasingly the target of it.
This post explains how subrogation against an MSP works, what triggers it, which of your policies responds, and how your client contracts change the outcome.
What Subrogation Actually Is
When an insurer pays its policyholder for a covered loss, it acquires the policyholder’s right to pursue whoever caused that loss. The insurer steps into the shoes of the client and can go after the responsible third party to recover what it paid out. For an MSP, that responsible third party is often you.
This is the mirror image of the subrogation provision in your own policy, where your carrier reserves the right to recover from a vendor who caused your loss. We cover that side in our guide to reading a cyber insurance policy. Here the arrow points at you.
Subrogation does not require your client to sue you. The client is already made whole by their insurer. It is the insurer, with far more resources and patience than the client would have brought, that pursues you, often a year or more after the incident.
Why MSPs Are the Target Insurers Look For
Two things make MSPs attractive subrogation targets. The first is the short causal line. An MSP holds privileged access to client systems and takes on explicit responsibility for security, patching, backups, and monitoring. When a breach traces back to something inside the MSP’s control, the path from failure to loss is easy for a claims investigator to document.
The second is aggregation. A single failure at the MSP level can cause losses across many clients at once, which means several different client insurers may each pursue the same MSP for the same underlying event. One misconfiguration becomes a stack of simultaneous demands. We break down that concentration risk in our analysis of the aggregation exposure MSPs carry and in how underwriters evaluate an MSP’s client base.
What Triggers a Subrogation Claim Against an MSP
Subrogation follows fault. The demands that succeed are the ones where a claims investigation can tie a duty the MSP owed to a failure that caused the client’s loss. The common triggers:
- An unpatched or known-vulnerable system that the MSP was responsible for maintaining
- A compromise of the RMM or management plane that cascaded into client environments
- A misconfiguration such as open remote access or disabled multi-factor authentication that the MSP set up or was maintaining
- Backups that failed or were never tested, when the MSP had guaranteed recovery
- A security control the managed services agreement said the MSP would provide but did not
- Delayed detection or response on services the MSP was contracted to deliver
The thread running through all of these is a documented obligation and a documented failure. When you share a client stack with internal IT, causation gets more contested, which we cover in co-managed IT liability.
Which of Your Policies Actually Responds
A subrogation demand is routed by the nature of the underlying claim, not by the fact that it arrived as a recovery action. That means the type of failure decides which policy is on the hook.
| Underlying client loss | Likely responding policy | Why |
|---|---|---|
| An MSP service failure or error caused the client’s downtime or data loss | Tech E&O | It is a professional services failure claim |
| Client data or personal information was exposed through the MSP’s environment | Cyber liability | It is a privacy and data breach claim |
| Both a service failure and a data exposure occurred | Both may be triggered | The claim spans professional services and privacy |
There is a catch worth understanding. If your contract had you assume liability beyond what you would have owed at common law, the contractual liability exclusion in your own policy may limit what responds to that assumed portion. This is one reason MSP policies should be read with the managed services agreement in hand. Start with the basics in our guide to Technology E&O insurance and the MSP-specific version in Tech E&O for MSPs.
The dangerous gap is the MSP that carries cyber liability but no Tech E&O. A subrogation claim built on a service failure is a professional services claim, and a cyber-only policy may not respond to it at all.
How Your Client Contracts Change the Math
Two clauses in your managed services agreement do more to shape a subrogation outcome than almost anything in the policy itself.
Limitation of liability. A well-drafted cap limits your exposure, but whether that cap binds the client’s subrogating insurer depends on the wording and on how enforceable it is in the relevant jurisdiction. A cap that protects you against the client directly does not automatically protect you against their insurer.
Waiver of subrogation. If your agreement includes a mutual waiver of subrogation, the client’s insurer may be contractually barred from coming after you at all. It is often the single most protective term you can negotiate. The complication is that this cuts both ways. Clients increasingly ask you to waive your rights against them, and your own carrier may restrict your ability to waive rights in a way that prejudices its recovery. These clauses have to be reviewed together, not in isolation.
We walk through tightening these terms in embedding cyber insurance into your MSP services and fortifying your MSA.
A Realistic Scenario
An MSP manages 40 small and mid-size clients. A firmware update on a shared network appliance gets missed, and ransomware reaches three of those clients through the gap. Each client files a claim, and each client’s cyber insurer pays. The incident feels resolved.
Eighteen months later, two of those insurers file subrogation demands against the MSP. Together the demands exceed the MSP’s annual revenue. Whether the business survives comes down to three questions decided long before the incident: were the aggregate limits sized for a multi-client event rather than a single claim, was Tech E&O in force alongside cyber, and did the managed services agreements cap liability or waive subrogation. Nothing about the response to the ransomware itself changes those answers.
What MSPs Should Do
- Carry both Tech E&O and cyber liability, not one or the other
- Size aggregate limits for a multi-client event, not for a single client’s claim
- Have counsel review every managed services agreement for limitation of liability and waiver of subrogation, and review those two clauses together
- Understand the contractual liability exclusion in your own policy before you sign contracts that expand your duties
- Document change management, patching, and backup testing, because subrogation fights are won and lost on proof of what you actually did
- Do not sign a client release or waiver without checking how it interacts with your own coverage
- Work with a provider that underwrites MSPs specifically and prices aggregation honestly
For the full picture of coverage built for how MSPs operate, see our guide to cyber insurance for MSPs.
Frequently Asked Questions
Can a client’s insurer really pursue my MSP after paying their claim?
Yes. Once the insurer pays its policyholder, it acquires the client’s right to recover from whoever caused the loss. If the loss traces to your systems or service, you can become the recovery target.
Does my client have to be involved for subrogation to happen?
No. The client has already been paid and made whole. The insurer stands in the client’s place and pursues the claim on its own.
Will my cyber policy cover a subrogation claim against me?
It depends on the nature of the underlying loss and on what coverage you carry. A service failure is a professional services claim that points to Tech E&O, while a data exposure points to cyber liability. An MSP with only one of the two can have a real gap.
Does a waiver of subrogation in my MSA protect me?
It can bar the client’s insurer from pursuing you, which makes it one of the most valuable terms to negotiate. Enforceability varies by wording and jurisdiction, and your own carrier may limit how you waive rights, so it should be reviewed alongside your policy.
How long after an incident can a subrogation claim arrive?
Often months to years later. That delay is why your policy timing matters, including claims-made triggers and your retroactive date.
Related Resources
- Tech E&O for MSPs: How It Coordinates with Cyber
- Co-Managed IT: Where Liability Falls When You Share a Client Stack
- How Underwriters Evaluate an MSP’s Client Base
- Embed Cyber Insurance in Your MSP Services and Fortify Your MSA
- Cyber Insurance Built for How MSPs Actually Operate
SeedPod Cyber is a specialized provider of cyber and Tech E&O coverage built for how MSPs actually operate, including the aggregation and subrogation exposure that most policies underprice. Talk to our team about coverage sized for your book, or learn more about our coverage for businesses.