Select how you’d like to proceed with your insurance needs.
Talk to a real insurance expert on your time.
15-minutes consultation with licensed advisors
Perfect if you’re unsure about coverage needs
Get personalised recommendations
Already have coverage? Let’s simplify your service
Keep your current carriers & policies
Simple digital authorisation process
Seamless transition to better service

Most businesses face cyber risk in one direction. Their own systems, their own data, their own downtime. A managed service provider, or MSP, faces it in every direction at once. You hold admin access to dozens or hundreds of client systems, which means a single compromise at your end does not produce one victim. It produces a queue.
That one feature reorders the entire insurance conversation. It changes which policies come first, what underwriters ask before they quote, and why two providers with identical revenue can get very different answers from the market.
Most Australian MSPs and IT services businesses assess two covers first and everything else afterwards. Technology professional indemnity, often shortened to technology PI or tech E&O, responds where a client says your error caused their loss. Cyber responds to a security incident and its results. Public and products liability, management liability or directors and officers cover, and workers compensation, layer around those two. Workers compensation is compulsory once you employ staff, and each state and territory runs its own scheme with different rules about when a contractor is treated as a worker.
The order matters. For most businesses cyber is a sensible addition. For an MSP it is close to the core of the risk, because your access to client systems is the product. upcover arranges managed service provider insurance for managed IT service providers and cover for IT and software development professionals across Australia as a Corporate Authorised Representative of an AFSL holder.
Your business model decides which cover comes first. An MSP with standing admin access starts with cyber and technology PI together. A project-based developer starts with technology PI and contract terms. A product company is a different placement again.
"IT services" covers business models with very different risk profiles. Underwriters treat them differently. It helps to know which description fits before you start answering questions.
Two of those deserve a flag. Cybersecurity providers carry an unusual exposure, because the allegation is often that you failed to stop a breach, which sits awkwardly across both policies. Staff augmentation raises a definitional question: are your contractors insured persons under your policy, or not?
Because one incident at your end can become many claims at once. Administrative access across client systems means a single compromise reaches every client on your management plane, and insurers price that clustering rather than your headcount.
Your remote monitoring and management platform, your service desk tool and your remote access stack are, by design, the most powerful systems you operate. They exist to let a small team administer many environments efficiently. That design makes them the highest-value target in your business. Compromise an MSP and an attacker does not get one set of credentials. They get a management plane that reaches every client on it.
Insurers have a word for this: aggregation risk. One incident at your level cascading across every client you manage, producing claims at once from many directions rather than a single loss.
Three results follow, and they explain most of what feels odd about MSP underwriting.
This is the one that surprises people. Underwriters ask what proportion of your managed clients have multi-factor authentication and endpoint detection enforced. Not what you recommend. What is actually turned on. Where a client refuses a control and you keep managing them anyway, that sits in your risk profile as well as theirs.
Say one incident generates claims from thirty clients. Does your limit apply per claim, or across the whole policy year? That distinction rarely matters for an ordinary business. For an MSP it can be the difference between covered and uninsured.
The Australian Information Commissioner has noted that third parties such as managed service providers can be a weak point in protecting personal information. Your clients' regulators are already thinking about you. See also what a managed service provider is in the insurance sense.
These two answer different halves of the same bad week, and buying one without the other leaves half the exposure open.
Technology professional indemnity, also called tech E&O, often responds where a client alleges your error or omission caused them a financial loss. A misconfigured firewall. A patch that took production down. A migration that lost data. Support that was unavailable when the contract said it would be.
Cyber often responds to the security incident itself and what follows. Forensic work, system restoration, business interruption, notification costs, extortion where the law permits it, and third-party privacy claims.
Here is what catches MSPs. Technology professional indemnity generally requires an error or omission by you as the cause of the client's loss. So picture two failures. In the first, your systems are compromised through no failure of yours and client data is exposed. A client's claim may not meet that test cleanly, and cyber insurance is built for exactly that scenario.
Now flip it. You misconfigure something, a client loses money, and no security incident is involved. Cyber insurance may have nothing to respond to. Two policies, two halves. What matters is that they coordinate rather than leave a seam. For the general distinction, see tech PI vs cyber insurance.
The honest framing is that MSP underwriting often looks like a security assessment with an insurance product attached. Requirements vary between insurers and there is no universal checklist, but for a provider holding client access, controls often affect whether cover is available and not only what it costs.
In Australia, the reference point most underwriters and clients use is the Essential Eight. It is a set of eight priority mitigation strategies from the Australian Signals Directorate, published through the Australian Cyber Security Centre. The eight strategies are:
On maturity levels. The model runs from level zero to level three. The right target is risk-based, not universal. Maturity Level 2 is mandatory for certain Commonwealth entities under the Protective Security Policy Framework. A private business picks a level based on the threats it actually faces.
One caveat worth knowing. ASD notes the framework was built mainly for Windows networks connected to the internet. Cloud-first environments may need other mitigations, which matters if that is where your clients live.
Six of the eight map closely onto what cyber underwriters ask about: the two patching strategies, MFA, backups, restricting admin rights, and application control. Alignment with the framework does not mean cover will be offered, and rules vary between insurers. For what Australian cyber insurers commonly ask, see cyber insurance requirements in Australia.
For a provider holding client access, these five often receive extra attention.
The Australian Signals Directorate recorded more than 84,700 cybercrime reports in its 2024 to 2025 annual reporting. That is roughly one every six minutes. Average self-reported losses ran about $56,600 for small businesses and $202,700 for large ones. Underwriters are not pricing a theoretical risk.
Indirectly, and it is worth knowing why. There is no rule that an MSP must hold a set Essential Eight maturity level to get cover. But the framework describes controls that many Australian cyber underwriters ask about, so alignment often makes an application easier to answer well.
What ASD has published. On 15 June 2026 the Australian Signals Directorate announced national consultation on the evolution of the Essential Eight. Consultation ran until 12 July 2026.
The proposed evolution introduces a new Essentials series, grounded in the Information Security Manual. Current guidance becomes the first chapter, Essentials for enterprise IT, with more chapters to follow. ASD has said businesses already using the Essential Eight can expect strong alignment with their existing controls and investments. Note the language. ASD calls this an evolution. Some market commentary frames it as a retirement with dates attached. Those dates are not part of what ASD published. Treat them as commentary, not guidance, and check current ASD and ACSC pages, because this is still moving.
What it means practically. Keep implementing. The Essential Eight remains current published guidance and is still what tenders, contracts and insurance questionnaires reference. If you deliver Essential Eight uplift as a service, expect client questions. Having a considered view is a commercial advantage as much as a technical one.
Your master services agreement is an underwriting document. Most MSPs do not think of it that way, and it is one of the more consequential blind spots in this sector.
Five things in a typical MSA affect both eligibility and price.
A cap set at one month of fees looks protective until you read the carve-outs. Caps that do not apply to data breach, confidentiality or gross negligence may leave open the risk you thought you had capped.
An indemnity is a promise to cover someone else's loss. It can reach well past what the law would have made you liable for. Insurance generally responds to legal liability. Where you have contracted for more, the policy may not follow you there.
Vague scope is a liability problem. If the contract says you provide "IT services" without defining boundaries, a client can argue that something you never priced was in scope. Underwriters read undefined scope as undefined risk.
Uptime promises and response-time service level agreements create contract duties. Those may sit outside ordinary legal liability, and service credits are often excluded from cover.
The OAIC recommends that entities engaging third parties address data breach responsibilities in the contract, including who assesses a suspected breach, who notifies, and within what timeframe. For an MSP this cuts both ways: your clients' contracts may push assessment and notification obligations onto you, and your own contracts should say who does what. Silence here creates a dispute at the worst possible moment.
The practical step: read your standard MSA next to your policy and look for places where the contract promises more than the insurance answers. Where a large client insisted on their paper rather than yours, read that separately. That is usually where the uncapped indemnity lives. Contract terms are a legal question, so a qualified adviser should review them.
Reviewing cover before a renewal? Talk to upcover about managed service provider insurance with your liability caps and indemnities to hand, so the insurance conversation reflects what you have actually agreed.
Not a stage question. These are the moments where the answer changes.
Neither binds an MSP directly. Both change what appears in your contracts.
Your first cloud service resold under your name. You now carry a dependency you do not control and cannot patch.
Your first fixed-price development project. Overrun risk concentrates on you rather than the client.
When your client count passes the point where one incident reaches all of them. There is no fixed number. The test is whether a single compromise of your management plane would produce one claim or thirty.
For the general startup picture, see when does a startup need insurance.
Fixed-price work puts overrun risk on you rather than the client. Code ownership decides whether an infringement claim arrives from a third party rather than a customer. Both shift what the policy needs to answer. Development work carries a different shape of risk from managed services, even inside the same business.
Fixed price concentrates overrun on you. Time and materials passes scope change to the client. Fixed price does not, so a badly estimated project becomes your loss and, if the client disputes the outcome, potentially your claim. Underwriters ask about the mix.
Acceptance testing decides when risk transfers. A defined acceptance process with documented sign-off gives you a defensible line. Its absence means a client can raise a defect months later and argue delivery was never complete.
Code ownership and reuse. Who owns the delivered code, what you reused from previous projects, and whether open-source components carry licence duties that flow to your client. An infringement claim can arrive from a third party rather than your customer.
Security defects in delivered applications. If an application you built is later breached through a coding flaw, the claim is a professional failure rather than a security incident at your end. That is technology PI territory, and it can surface long after the invoice was paid, which is why the retroactive date on a claims-made policy matters. See claims-made vs occurrence insurance.
Running project work rather than managed services? Start at IT and software development insurance.
Exclusions differ between insurers, so treat each of these as a question for your policy rather than a rule.
The policy wording, schedule and any endorsements determine cover, not the product name.
There is no useful average, and the reason is specific to this sector rather than a general disclaimer.
Two MSPs with the same revenue and headcount can receive very different answers. One enforces MFA across every admin account, runs EDR everywhere, tests its restores, and has hardened its RMM console. The other has most of that in progress. The first is a straightforward risk. The second may struggle to find terms at all.
That is the thing to understand about MSP pricing: control maturity is often an eligibility conversation before it is a price conversation. Some insurers may decline rather than load, and appetite varies across the market. What moves it, heaviest first:
Your own control maturity. RMM console security, MFA coverage on admin accounts, EDR deployment, tested immutable backups, and privileged access management. This is the dominant factor.
Administrative access footprint. How many client systems you can reach, and through what tooling.
Client base composition. Number of managed clients, their industries, and revenue clustering among the largest few.
Client-side control enforcement. What proportion of managed clients actually have MFA and EDR turned on.
MSA terms. Liability caps, indemnities, scope definitions and availability commitments.
Services mix and resale. Whether you resell cloud services, and whether you provide security services where the allegation could be failure to prevent.
Then the ordinary drivers: revenue, incident and claims history, cover level, excess and limits.
On limits. Client contracts frequently set the floor, so check what your largest agreements require before choosing a number. Cyber limits for smaller Australian businesses usually range from $250,000 to $5 million. Public liability options usually run from $5 million to $20 million, and contracts often set the number. For an MSP the aggregation question matters more than the headline figure: a limit that comfortably covers one client incident may not cover thirty.
For cover-specific pricing, see how much does cyber insurance cost.
Run your current schedule against these. They are ordered by how often they turn out to matter for a provider with client access.
Having this ready turns a long back-and-forth into a real quote.
Ready to compare? Explore MSP and IT services insurance through upcover with those details to hand. Availability and terms depend on insurer acceptance.
MSP placements tend to split into two paths.
Straightforward technology risk. Say you provide project work or support without standing admin access to client systems. Technology professional indemnity and cyber can often be arranged through a standard process for eligible businesses.
Aggregation risk. Where you hold admin access across a client base, the placement needs an underwriter who understands what an RMM console is and why it matters. That is a broker conversation, and your control evidence does the heavy lifting.
Either way, gather your control evidence before you start. An MSP that answers the security questions precisely gets a better result than one that answers them loosely. It is the same work either way.
upcover is a digital-first insurance broker helping Australian small businesses get the right insurance without the paperwork or phone queues. upcover arranges cover for managed IT service providers and IT and software development professionals with access to 80+ insurance partners, including technology professional indemnity, cyber, public and products liability and directors and officers cover.
For the broader picture, see the startup insurance guide and technology, media and digital insurance. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.
Most Australian MSPs assess technology professional indemnity and cyber together as the base. Public and products liability, management liability or directors and officers cover, and workers compensation follow from there. The two core covers answer different halves of the same failure, which is why they are usually arranged as a pair.
Usually yes. Technology PI generally requires an error or omission by you as the cause of a client's loss. Cyber responds to a security incident and its results. A breach at your end with no professional failure may not engage technology PI. A misconfiguration with no security incident may leave cyber nothing to answer. Together they cover both halves.
It is the risk created by holding admin access across many client systems. One incident at your level can cascade to every client on your management plane. Insurers care about it because a single event can generate claims at once from many clients and exhaust a limit that would comfortably cover one.
Requirements vary by insurer and there is no universal checklist. Underwriters often ask about multi-factor authentication on all remote and admin access, endpoint detection and response, tested backups, patching, privileged access management and incident response planning. For an MSP, RMM console security usually receives the closest attention.
It is the framework most Australian underwriters and clients reference, and six of the eight strategies map closely onto standard cyber underwriting questions. Alignment does not mean cover will be offered. ASD has announced consultation on an evolution to a new Essentials series. The Essential Eight remains current guidance, so check current ASD and ACSC pages.
It can affect both price and whether cover is available. Broad indemnities, undefined scope, uncapped liability and availability guarantees all create exposure that underwriters assess. Insurance generally responds to legal liability, so where a contract promises more than the law would require, the policy may not follow.
Often yes, and this surprises most providers. Underwriters ask what proportion of your managed clients actually have MFA and EDR enforced, not what you recommend. Managing clients who refuse controls keeps their weakness inside your risk profile.
Software development company insurance usually centres on technology professional indemnity, since the exposure is a delivered application or project causing a client financial loss. Cyber matters where you hold client data or access. Contract structure drives a lot of it: fixed-price work, acceptance testing and any warranty you gave about performance all shape the exposure.
Third-party liability for client loss is commonly addressed under cyber, subject to the wording and limit. Technology PI generally requires an error or omission by you as the cause, so a compromise with no professional failure may not engage it. The questions to ask are whether third-party privacy liability is included, what limit applies, and whether that limit is per claim or an annual aggregate that many simultaneous client claims could exhaust.
This article is general information only. It does not take into account your objectives, financial situation or needs, and is not personal advice. It is not legal, contractual or cyber security advice. Australian Signals Directorate and Australian Cyber Security Centre guidance, including the Essential Eight and the proposed Essentials series, is published by those agencies; the position here reflects what had been published at the time of writing, so check current ASD and ACSC pages. Alignment with any security framework does not mean cover will be offered. APRA prudential standards and the Security of Critical Infrastructure framework apply to regulated entities, not to service providers directly. Cover, limits, inclusions and exclusions vary between insurers, so read the relevant policy wording, schedule and any Product Disclosure Statement before deciding whether a product suits you. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078, and arranges insurance with selected insurers and underwriters rather than the whole market.
We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.