A managed IT provider can hold administrative access across many customer environments. Its cyber and technology-liability enquiries should reflect the concentration of risk created by remote management tools and shared operational processes.
Incident response and cyber cover
Cyber policies can address different combinations of response services, the insured business’s own losses and third-party allegations. Check each section rather than relying on the product name. Security obligations and consent before spending can be important parts of the comparison.
Premiums, excesses and usable cover
Request quotations using the same business description, required limits and relevant dates. Put the annual premium, any instalment charges, excesses and important sublimits in one comparison. A cheaper premium can represent a different transfer of risk rather than the same cover at a better price.
| Comparison item | Question to resolve |
|---|---|
| Number and type of managed clients | How are multiple affected clients counted? |
| Privileged access and platform concentration | Are remote-management services expressly accepted? |
| Contractual liability and incident aggregation | Which access safeguards must remain in place? |
Request the proposed wording and schedule, not just a price or certificate. Mark any difference that affects a real activity before deciding whether the premium saving is worthwhile.
The decision that deserves the closest review
Identify which clients can be reached through each privileged platform. Compare protection for the provider’s own incident costs with allegations by clients. Ask how aggregation, subcontractors and contractual service commitments affect limits and underwriting requirements.
Prepare an accurate insurance enquiry
Give each adviser a consistent description of the activities being insured. Include important contracts, changes since the previous enquiry and matters the insurer asks you to disclose. Do not guess answers merely to obtain a faster or cheaper quote; ask for clarification when the proposal wording is unclear.
Show the provider’s access and retained client duties
Document the systems the managed provider can administer and the clients affected by a shared tool. Explain account separation, subcontracting and the duties that remain with each customer. This gives the underwriter a clearer basis for assessing aggregation than a simple count of employees or computers.
Test a quotation against a compromised administrative account affecting several customers. Ask how the provider’s own recovery and client allegations interact with professional-liability sections. Compare the proposed insurance with service agreements so broad promises in those agreements are visible during the review.
Include overseas work or sales in the UK business’s enquiry and confirm the accepted territories and jurisdictions.
A hypothetical example
One management account can administer multiple customer networks. The provider tests whether an incident affecting several clients is treated as one event or several claims, and how that affects the available limit.
A mistake to avoid
Comparing insurance as though the provider only manages its own internal computers.
Check what happens after the policy starts
Ask who to contact when activities change or a potential claim arises. Understand the notification and consent process before arranging repairs, appointing specialists or settling a complaint. At renewal, compare the new documents with the accepted business description; continuity of a familiar brand does not prove continuity of every term.
Questions before choosing
Is client-system damage always covered?
Ask about the exact technology-liability and cyber sections; neither a package title nor a client contract proves the response.
Does a client’s own cyber policy protect the provider?
Establish the provider’s responsibilities and insurance separately. A customer’s policy should not be assumed to pay the provider’s expenses or defend every allegation against it.
Sources and further reading
- NCSC: choosing a managed service provider
- NCSC: cyber insurance guidance
- ABI: professional indemnity insurance
Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.