Ransomware

Ransomware Loss Allocation: Insurers, MSPs, and the Coverage Gap

When a ransomware attack crosses an MSP's network into a client's environment, three parties reach for the same loss — and the contracts, policies, and indemnification chains rarely agree on who absorbs it.

Daniel B. Garrie, Esq.August 11, 20269 min read

Three Parties, One Loss, No Consensus

Ransomware loss allocation disputes have become one of the most structurally complex problems in commercial litigation precisely because the harm is simultaneous but the legal relationships are sequential. An insured suffers encrypted systems; its managed service provider (MSP) held the keys to the network perimeter; the carrier wrote a policy that describes the covered event in terms that predate the MSP delivery model. Each party has a colorable claim that someone else should bear the primary economic weight, and none of the governing instruments were drafted with the other two in mind.

The insured occupies the most sympathetic position but not necessarily the strongest legal one. Its cyber extortion coverage may respond to the ransom demand and the restoration costs, but the policy's vendor-exclusion language — drafted to avoid moral hazard — may carve out losses traceable to a service provider's negligence. The carrier, reading that exclusion, points at the MSP. The MSP's master services agreement points back at the insured's own security-hygiene obligations. The circle closes without resolving who pays.

What breaks the circle, in practice, is a structured dispute process that sequences the coverage questions before the indemnification questions, and appoints a neutral with technical competence to evaluate the forensic record. Without that sequencing, the parties litigate all fronts simultaneously, burn through privilege protections inadvertently, and settle for amounts that satisfy no one. The analysis that follows traces each relationship in turn, identifies the pressure points where disputes concentrate, and explains what a well-prepared party needs to have documented before the first demand letter goes out.

In plain terms

Three parties — the victim company, its IT vendor, and its insurer — each believe one of the others should pay for a ransomware attack. Their contracts and the insurance policy were not written to work together, so disputes are almost inevitable.

The policy, the master services agreement, and the vendor's sub-limit of liability were each drafted without the others on the table. Reconciling them requires sequencing, not simultaneous litigation.

The MSP Liability Exposure: What the Contract Actually Says

MSP liability in ransomware scenarios turns almost entirely on the indemnification clause and the limitation-of-liability cap embedded in the master services agreement. Most standard MSP contracts cap liability at some multiple of the trailing monthly fee — a figure that bears no rational relationship to the client's potential downside. Courts enforcing these caps do so routinely when the language is unambiguous, because sophisticated commercial parties are presumed to have allocated risk deliberately. The insured that never negotiated that cap — or that accepted a template without legal review — finds itself arguing unconscionability in a context where unconscionability rarely prevails.

Vendor indemnification clauses in the MSP context are equally treacherous. A well-drafted clause obliges the MSP to defend and indemnify the client for losses arising from the MSP's own acts or omissions. But 'acts or omissions' language litigates badly when the attack vector was a zero-day exploit neither party anticipated, or when the attacker pivoted through the client's own unpatched endpoint before reaching the MSP-managed segment. Causation attribution — which systems, under whose administrative control, provided the initial foothold — becomes a forensic question that the indemnification clause does not answer and that the parties must resolve through expert testimony.

The competence obligation deserves attention here. ABA Model Rule of Professional Conduct 1.1 requires counsel to understand the technology sufficiently to advise on these clauses. An attorney who reviews an MSP agreement without understanding how a remote monitoring and management platform operates — and how an attacker who compromises that platform gains lateral movement across every client the MSP serves — cannot adequately evaluate whether the indemnification clause covers the actual loss vector. The drafting gap between the contract's language and the technical reality of the attack is where MSP liability disputes are won and lost.

One underappreciated complication: the MSP's own cyber insurance. Many MSPs carry technology errors-and-omissions coverage that may respond to a client's claim. That policy, however, will have its own notice requirements, consent-to-settle provisions, and cooperation obligations. If the insured and the MSP litigate rather than coordinate, the MSP's carrier may disclaim on late-notice grounds, eliminating a recovery source the insured assumed was available. Coordination between the insured's coverage counsel and the MSP's coverage counsel — early, and preferably before suit — is the structural move that preserves this asset.

In plain terms

The IT vendor's contract almost always limits how much it must pay, often to a small fraction of the actual loss. Whether that cap applies depends on the contract's exact language and who the forensic evidence shows was actually responsible for the attack's entry point.

An attorney who cannot explain how a remote monitoring and management platform enables lateral movement cannot adequately evaluate the indemnification clause that governs it.

Cyber Extortion Coverage: Reading the Policy Against the Attack Narrative

Cyber extortion coverage is a policy endorsement or standalone insuring agreement that responds to the demand itself — the payment to unlock systems or prevent publication of exfiltrated data. Most modern cyber policies include it, but the coverage trigger language varies in ways that matter enormously in an MSP-sourced incident. Policies that tie coverage to 'unauthorized access to the insured's computer systems' face an interpretive question when the entry point was the MSP's own administrative console, which the insured had contractually authorized the MSP to operate. The insured argues the attacker was unauthorized; the carrier argues the pathway was authorized, at least initially.

The second pressure point is the waiting period embedded in business interruption coverage, which typically works alongside the extortion coverage in a ransomware claim. A waiting period of several hours before coverage attaches means that a fast-moving encryption event — the kind that propagates across a network in minutes — may be substantially complete before the clock even starts. The insured that understood this before the attack would have structured its incident response retainer and its forensic timeline documentation with that waiting period in mind. The insured that learns about it during the claim finds itself arguing about when 'interruption' began, a factual dispute that the forensic record must resolve.

Carrier coverage defenses in MSP-sourced ransomware claims tend to cluster around three theories: the voluntary payment defense (the insured paid the ransom before the carrier approved it); the failure-to-maintain-security defense (the policy required specific controls that the MSP was supposed to implement but did not); and the known-loss or prior-knowledge defense (the MSP had detected anomalous activity before the policy inception date). Each of these defenses converts a coverage dispute into a forensic dispute — and each one requires that the insured have preserved the relevant technical evidence and kept it outside the scope of a carrier's discovery requests through appropriate privilege and work-product doctrine protections established at the outset of the response.

In plain terms

The ransomware insurance policy may not cover an attack that entered through the IT vendor's systems rather than directly through the victim's own network. Three specific defenses — early payment, missing security controls, and pre-policy warning signs — are where carriers most often push back.

Every carrier coverage defense in the MSP-sourced ransomware context eventually becomes a forensic question. The party that controlled the forensic narrative from day one is the party best positioned to answer it.

Privilege, Work Product, and the Forensic Record

The relationship between the insured's breach-response investigation and the subsequent coverage and indemnification litigation is the most delicate structural problem in the entire tripartite dispute. Forensic reports prepared at counsel's direction, in anticipation of litigation, are candidates for protection under the work-product doctrine as articulated in Hickman v. Taylor. But that protection is neither absolute nor automatic, and it dissolves quickly if the report is shared with the carrier during the claims process without a non-waiver agreement that satisfies Federal Rule of Evidence 502.

The attorney-client privilege, recognized in Upjohn Co. v. United States as extending to corporate internal investigations, protects the communications between counsel and the forensic vendor when counsel has retained that vendor to assist in providing legal advice. It does not protect the underlying facts — the log files, the network topology, the timeline of the encryption event — that exist independently of counsel's engagement. Carriers and MSPs seeking discovery will frame their requests to reach those underlying facts, and the insured must be prepared to distinguish between protected communications and discoverable data from the first day of the investigation.

Federal Rule of Civil Procedure 26 governs expert disclosure in the litigation that frequently follows a coverage denial or an indemnification dispute. The forensic expert who authored the breach investigation report faces a disclosure dilemma: if that expert is designated as a testifying expert, the report and all materials considered in forming opinions become discoverable. If retained as a consulting expert only, the report is shielded but the expert cannot testify. Sophisticated parties resolve this by retaining separate forensic teams — one for the privileged investigation, one for the anticipated litigation — a practice that is expensive but preserves the strategic optionality that a single-team approach forecloses.

Federal Rule of Evidence 702 and the Daubert standard will govern the admissibility of the forensic expert's attribution opinion: whether the MSP's misconfiguration, or a specific threat actor's tools, or the insured's own security failures caused the attack to succeed. Attribution opinions in ransomware cases are probabilistic by nature, and courts applying Daubert scrutinize whether the methodology is testable, peer-reviewed, and generally accepted in the forensic community. An attribution opinion that relies on threat-intelligence feeds without explaining the analytical steps that connect observed indicators to a conclusion about causation is vulnerable to exclusion — and an excluded causation opinion collapses either the coverage claim or the indemnification claim that depends on it.

In plain terms

The reports and communications created during the breach investigation may be legally protected from discovery — but only if counsel structured the investigation properly from the start. If those protections are lost, the insurer and the MSP both get access to the most damaging internal analysis the victim produced.

Structuring the Tripartite Dispute for Resolution

When three parties with adverse interests are connected by interlocking but inconsistent obligations, sequential dispute resolution almost always outperforms simultaneous litigation. The coverage question — does the policy respond to this loss at all — is properly resolved first, because its answer determines how much of the loss the insured must recover from the MSP through indemnification, and what leverage each side holds in any subsequent negotiation. Litigating coverage and indemnification simultaneously invites the carrier to use MSP discovery to build its own coverage defenses, and invites the MSP to use coverage litigation to argue that the carrier, not the MSP, should bear the loss.

Federal Rule of Evidence 408 is an important tool in the resolution architecture. Settlement negotiations and offers made in the context of disputed claims are inadmissible to prove liability. Parties who understand this can structure mediated negotiations among all three parties simultaneously, using a neutral with technical competence, without fear that a concession in the mediation room becomes an admission in the courtroom. The mediator's role is to maintain confidentiality across the sessions — including between the carrier's private sessions and the MSP's private sessions — while helping each party understand the forensic narrative that will govern if the matter proceeds to an evidentiary hearing.

Federal Rule of Civil Procedure 53 authorizes the appointment of a special master for complex pretrial matters, including technical evidentiary disputes. In tripartite ransomware disputes, a special master with forensic competence can evaluate competing expert reports on the attack timeline, make findings on causation and attribution, and provide a neutral record that the parties can use either to settle or to streamline the issues for trial. The special master structure is underused in this context but is particularly well-suited to disputes where the technical record is voluminous, the experts disagree on methodology, and the judge lacks the technical background to resolve the methodological dispute at a Daubert hearing without assistance.

Indemnification negotiations between the insured and the MSP benefit from a clear understanding of what the MSP's own insurance will and will not cover. If the MSP's technology errors-and-omissions policy excludes the specific attack vector — for example, a social-engineering attack on the MSP's own credentials rather than a technical exploit of the MSP's platform — the MSP's available assets may be limited to whatever its contractual cap permits. The insured's realistic recovery from the MSP may then be far smaller than the indemnification clause suggests on its face. Knowing that before filing a demand puts the insured in a position to negotiate a global resolution rather than litigate toward a judgment it cannot collect.

In plain terms

The smartest approach is to resolve the insurance coverage question first, then the vendor indemnification question, using a neutral mediator who understands the technology. A court-appointed special master can also help untangle the competing technical evidence if the case reaches litigation.

Sequential dispute resolution — coverage first, indemnification second — is not merely strategic preference; it is the structural choice that keeps all recovery options open longest.

Practical Preparation: What Each Party Should Have in Place Before the Attack

For the insured, the most valuable pre-incident work is a careful read of the cyber policy's vendor-exclusion and authorized-access provisions alongside the MSP master services agreement, conducted by counsel who can identify the gap between what the policy promises and what the MSP contract delivers. That gap analysis should inform a negotiated amendment to one or both instruments — either broadening the policy's vendor-incident coverage or narrowing the MSP's liability cap to a figure that at least approximates the insured's realistic exposure. The organization that performs this analysis after the attack is reading contracts under duress and has no leverage to amend them.

For the MSP, the preparation obligation runs in two directions: toward its own insurance program and toward its clients' reasonable expectations. An MSP that carries cyber extortion coverage and technology errors-and-omissions coverage with limits that reflect its clients' actual risk profiles is a better dispute partner and a better acquisition target than one that carries nominal limits. The MSP that has documented its security configurations, its patch management records, and its incident response procedures has a defensible evidentiary record if a client later claims the MSP's negligence caused the attack. That documentation is the MSP's primary defense against an indemnification demand.

For carriers, the underwriting moment is the last opportunity to align policy language with the actual architecture of the risk. A carrier that issues a cyber extortion coverage endorsement to an insured heavily dependent on MSP infrastructure without asking about the MSP's own security posture, its contractual liability cap, and its insurance limits has underwritten the risk incompletely. The coverage disputes that arise from that gap are foreseeable and expensive. Carriers that invest in underwriting questionnaires sophisticated enough to surface the MSP relationship — and that price or condition coverage accordingly — face fewer coverage litigation disputes on the back end.

Across all three parties, ABA Model Rule of Professional Conduct 1.6 reminds counsel that confidentiality obligations shape what can be shared in multi-party settlement discussions and what representations can be made to the neutral. Counsel representing the insured in a tripartite mediation must be thoughtful about disclosures made in joint session — particularly disclosures about the forensic findings that could benefit the carrier's coverage defense while advancing the indemnification claim against the MSP. Sequencing the disclosures, and using confidential sessions strategically, is not gamesmanship; it is the competent representation that the rule requires.

In plain terms

The best time to fix the gap between a cyber insurance policy and an MSP vendor contract is before an attack, not during one. Each party — the insured, the vendor, and the insurer — has specific things it should document and negotiate in advance to avoid the worst outcomes in a tripartite dispute.

The organization that reads its policy and its MSP contract together — before the ransom demand arrives — is the one that controls its own recovery narrative.

Frequently asked

Does cyber extortion coverage automatically respond when an MSP's network is the attack vector?
Not automatically. Most cyber extortion coverage triggers require unauthorized access to the insured's own computer systems. When the entry point is the MSP's administrative platform — which the insured contractually authorized the MSP to operate — carriers may argue the initial access was not unauthorized in the policy sense. Whether that defense succeeds depends on the specific policy language, the forensic timeline, and how courts in the governing jurisdiction have construed 'authorized access' in vendor-delivered environments. The insured that negotiated a vendor-incident endorsement before the attack faces a much shorter argument.
Can the MSP's liability cap be challenged successfully after the attack?
Rarely, in commercial contexts. Courts enforce negotiated liability caps between sophisticated parties as written, unless the insured can demonstrate that the cap was unconscionable, that the MSP fraudulently concealed a known vulnerability, or that the cap fails of its essential purpose — a doctrine available in some jurisdictions when the capped remedy leaves the injured party with essentially no recovery at all. These arguments are available but difficult. The more productive approach is to redirect the claim toward the MSP's own insurance or to frame the loss in ways the cap language may not reach, such as consequential damages excluded from the cap's definition.
How does the work-product doctrine protect the breach investigation when the carrier is also a party?
The work-product doctrine, rooted in Hickman v. Taylor, protects materials prepared in anticipation of litigation. If counsel retained the forensic vendor to assist in providing legal advice and the investigation was structured with litigation in mind, the resulting reports are candidates for protection. But sharing those reports with the carrier during the claims process can waive that protection unless a non-waiver agreement compliant with Federal Rule of Evidence 502 is in place before disclosure. Obtaining a 502(d) order from the court — or a binding 502(e) agreement with all parties — before any forensic materials are shared with any party is the standard of care.
What role can a special master play in a tripartite ransomware dispute?
Under Federal Rule of Civil Procedure 53, a court can appoint a special master to assist with complex pretrial matters. In a tripartite ransomware dispute, the special master's most useful function is evaluating competing forensic expert reports on the attack timeline, causation, and attribution. The special master can hold evidentiary hearings, review technical evidence, and produce findings and recommendations that either the parties use to settle or the court adopts to narrow the issues for trial. Because the special master has dedicated time and, ideally, technical background, the process is far more efficient than asking a generalist judge to resolve methodology disputes at a Daubert hearing.
How does Federal Rule of Evidence 408 protect ransomware settlement negotiations among all three parties?
Rule 408 renders inadmissible any offer of compromise or conduct during compromise negotiations offered to prove liability for the disputed claim. In a tripartite mediation among the insured, the carrier, and the MSP, each party's concessions, hypothetical frameworks, and settlement offers are protected from use as admissions in later proceedings. This protection enables frank negotiation that the parties would not risk in ordinary communications. The mediator reinforces this protection by maintaining separate confidential sessions and by ensuring that no party's private disclosure is transmitted to another without permission — a structural feature that makes mediation meaningfully safer than informal negotiation among adverse parties.

Analysis reflects the author's independent assessment of legal frameworks and dispute-resolution practice; no client matters or confidential information informed this commentary. This commentary is informational only and not legal advice.

Bring the dispute before the scales.

A confidential scoping call and conflicts check follow — without obligation.

The Breach Docket

Keep reading the docket

The Breach Docket collects recent data-breach decisions and notable settlements, read the way a neutral reads them. Free, every other week.

No advertising. Unsubscribe in one click.