Cyber insurers have quietly reached the same conclusion we’ve been arguing: the provider holding the most access is the biggest risk. Underwriters now classify managed service providers among the highest-risk categories they cover — not because MSPs are careless, but because of what they hold: privileged, standing access to dozens or hundreds of client environments at once. When the insurance market — an industry that exists to price risk accurately — puts a premium on provider proximity, it’s worth understanding why. The answer reshapes how every provider should think about access, and how every business should evaluate its providers.
Why do insurers treat MSPs differently?
One word: aggregation. A normal business, breached, is one claim. An MSP, breached, is potentially every client on its roster filing at once — one intrusion cascading through the remote-access tools and admin credentials the provider legitimately holds. Insurers call it aggregation risk, and it’s why MSP premiums sit above market averages and why MSP applications face harder questions than businesses of similar size.
The pattern insurers are pricing isn’t hypothetical. The 2021 Kaseya incident pushed ransomware through a trusted MSP tool to roughly 1,500 downstream organizations in a single stroke. Verizon’s 2025 Data Breach Investigations Report found third-party involvement in breaches doubled year over year, from 15% to 30% — the largest single-year jump in the report’s history. ConnectWise’s threat research describes attackers deliberately using MSPs as force multipliers: skip the well-defended enterprise, compromise its provider instead. Insurers read the same reports. Then they set the rates.
What are underwriters actually asking now?
The application changed. Industry guidance for 2026 renewals describes underwriting that has moved from checkbox self-attestation to verified evidence — exports, reports, and screenshots proving the controls exist, not a signature saying they do. The recurring focus areas:
- MFA on all remote access — especially the provider’s own technician and RMM accounts, which underwriters increasingly treat as the highest-risk surface an MSP operates.
- Standing access discipline — who holds admin, to what, and why it persists.
- EDR, tested backups, and privileged access management — with documentation, not assertions.
- Vendor inventory and responsibility language — proof the MSP knows its own blast radius, including MSA terms that spell out who owns which security duties.
And the stakes on honest answers went up. In one widely cited coverage dispute — Travelers v. International Control Services — the insurer moved to void the policy after a ransomware claim because MFA hadn’t been implemented the way the application claimed. Evidence, not attestation, is the currency now.
What does this mean for MSP economics?
The access model has acquired a carrying cost. Reports from MSP-focused insurance programs put the pricing spread at 20–35% between providers with strong, documented controls and otherwise identical peers without them — before counting the deals lost when a client’s own security review asks the hard questions the insurer already asked. Holding maximal standing access to client environments now costs real money annually, whether or not anything ever goes wrong. Proximity, as we’ve argued since RSP vs. MSP, is the liability — and the actuarial market has now attached a number to it.
What should providers do with this?
Treat the underwriting pressure as free consulting on your own blast radius. Every question on a 2026 cyber application is a question about the four dimensions in The Blast-Radius Principle — standing access, depth, spread, and detection. The providers who will pay least and win the most security reviews are the ones re-architecting toward holding less: agentless visibility where possible, per-environment separation, expiring access instead of permanent credentials, and evidence generated continuously rather than assembled at renewal.
That last point is the practical unlock. If your platform produces the proof as a byproduct of operating — monitoring logs, scan reports, posture documentation, client-ready evidence — then the insurance application, the client security review, and the sales conversation all draw from the same well. Proving security instead of claiming it is precisely the discipline Centry Secure is built around, and the market has never rewarded it more directly.
And for the businesses hiring providers?
Borrow the insurers’ homework. If underwriters — the people financially exposed to being wrong — now interrogate a provider’s standing access, MFA discipline, and breach-cascade plan, those are the questions to ask before signing an MSA. A provider who can answer them with documentation is managing their radius. A provider who can’t is asking you to carry it.
The insurance market has no ideology — it just prices what the claims data shows, and the claims data says provider access is where the catastrophic losses live. The MSPs that thrive under that scrutiny will be the ones who hold less, prove more, and treat a hard underwriting question as a preview of every client conversation to come. The framework for getting there: The Blast-Radius Principle, and the distinction that started this series — RSP vs. MSP.
Was this article helpful?
Thanks for your feedback.
Have a question about this topic?
