Cipher Insurance
Running a business · Guide

Why a Managed Service Provider's Cyber Cover Often Costs More Than a Developer's

Both can still be sued for work years after it's finished. What actually drives an MSP's higher premium is the ongoing, continuous access an engagement like website hosting or IT support involves.

Jack O'Hagan

By Jack O'Hagan, Co-Founder & Insurance Broker

Published 11 September 2026 · 4 min read

In this guide
  1. Can a software developer still be sued for a system after handover?
  2. Why are MSPs often rated at a higher premium than project-based developers?
  3. What actually counts as an “ongoing engagement” here?
  4. Does that mean a finished project carries no risk at all?
  5. Why does website hosting specifically carry this kind of ongoing exposure?
  6. Key Takeaways

Both a managed service provider and a project-based developer can still face a claim years after the work was actually done. That’s not what tells them apart. What often drives an MSP’s higher cyber liability premium is the ongoing, continuous access and responsibility an engagement like website hosting or IT support involves, not a difference in whether a claim can happen at all.

A claim can still land later

a defect can surface well after handover, for developer and MSP work alike

Bounded vs continuous

a delivered project is set at handover, ongoing access keeps generating fresh exposure

Priced by engagement, not label

website hosting and ongoing support rate differently to a one-off build

Can a software developer still be sued for a system after handover?

Yes, and it’s worth being clear about this upfront. A defect that wasn’t apparent when a system was delivered, a bug that corrupts data or a feature that doesn’t meet specification, can surface well after the engagement ends and still generate a professional indemnity claim. Professional indemnity is typically arranged on a claims-made basis. The policy in place when the claim is actually made and notified is the one that responds, not the policy that was current when the work was done.

The work can be finished. The risk from that work isn't necessarily finished with it.

Why are MSPs often rated at a higher premium than project-based developers?

Insurers commonly price a managed service engagement higher because of the ongoing, continuous access and responsibility it involves, not because a completed project carries no risk at all. Every day an MSP holds live access into a client’s systems is another day that access could become the point an incident actually starts. Insurers generally see more claims activity come out of that kind of continuous exposure than out of a bounded, already-delivered piece of work. Pricing tends to reflect that difference.

What actually counts as an “ongoing engagement” here?

Website hosting, an ongoing IT support or helpdesk arrangement, managed security monitoring or holding standing administrative access to a client’s systems are all examples. What they have in common is that the engagement doesn’t end at a delivery point. It continues day after day for as long as the contract runs. A one-off build is different in kind, not just in size or duration, because the engagement itself has a clear end.

Does that mean a finished project carries no risk at all?

No. This is an important distinction. The work is finished at one point in time. A claim about that work can still be made much later, though. The real difference isn’t whether risk exists after the fact, it’s whether new exposure keeps accumulating. A developer’s exposure is effectively set at the point the work is delivered, even though a claim about it can still surface afterwards. An MSP’s exposure keeps building fresh, day by day, for as long as the access or service continues.

Why does website hosting specifically carry this kind of ongoing exposure?

Hosting a client’s website involves holding standing access and responsibility for as long as the hosting relationship runs: server credentials, DNS, ongoing patching and monitoring. Every day of that responsibility is a fresh point where an outage, a compromised account or a missed update could cause a real problem. A developer who delivers a finished system and hands it over doesn’t carry that same daily operational responsibility once the engagement ends.

Key Takeaways

  • A developer can still face a professional indemnity claim well after a project is delivered. Being handed over doesn't end the risk from the work itself.
  • What often drives an MSP's higher premium is the ongoing, continuous access involved in services like hosting and support, not a difference in whether a claim can occur.
  • A developer's exposure is set at the point the work is delivered. An MSP's exposure keeps accumulating fresh for as long as the access or service continues.
  • Insurers rate the nature of the engagement, not the label. A developer who also provides ongoing hosting or support is priced on that basis for that part of the work.

The information in this article is general in nature and does not constitute legal, financial or insurance advice. Please speak with a qualified adviser about your specific circumstances.

Not sure how this applies to your situation?

Frequently asked questions

Can a software developer still be sued for a system after it's handed over?

Yes. It's a genuine risk, not an edge case. A defect that wasn't apparent at handover, a bug that corrupts data or a feature that doesn't meet specification, can surface well after the work is finished and still generate a professional indemnity claim. Professional indemnity is typically arranged on a claims-made basis. The policy in place when the claim is actually made is the one that responds, not the policy that was current when the work was done.

Why are managed service providers often rated at a higher premium than project-based developers?

Insurers commonly price managed service engagements higher because of the ongoing, continuous access and responsibility involved, not because a completed project carries no risk. Every day an MSP holds live access to a client's systems is another day that access could become the point an incident starts. Insurers generally see more claims come out of that kind of continuous exposure than out of a bounded, already-delivered project.

What counts as an 'ongoing engagement' for this kind of pricing?

Services that continue day after day for the life of the contract: website hosting, ongoing IT support or a helpdesk, managed security monitoring or holding standing administrative access to a client's systems. A one-off build is different in kind, not just in size, since the engagement itself ends once the system is delivered.

Does this mean a one-off project carries no risk once it's delivered?

No. That's an important distinction. The work itself is finished at one point in time. A claim about that work can still be made much later, though. What differs isn't whether risk exists after the fact, it's whether new exposure keeps accumulating. A developer's exposure is set at the point the work is delivered, even if a claim about it surfaces afterwards. An MSP's exposure keeps building fresh, day by day, for as long as the access or service continues.

Why does website hosting specifically carry this kind of ongoing exposure?

Hosting a client's website means holding standing access and responsibility, server credentials, DNS, ongoing patching, for as long as the hosting relationship runs. Every day of that responsibility is a fresh point where an outage, a compromised account or a missed update could cause a problem. A developer who delivers a finished system and hands it over doesn't retain that same daily operational responsibility.

What actually drives how insurers rate this kind of risk?

The number of clients under active management, how critical those systems are and the claims pattern insurers see across the managed services category generally, more than the label MSP or developer. Insurers rate the nature of the engagement. An ongoing, continuous-access arrangement is treated differently to a defined, completed piece of work.

If a developer also provides ongoing hosting or support, are they rated like an MSP for that part of the work?

Generally yes. Pricing follows the nature of the engagement rather than how the business describes itself. A developer who also manages ongoing hosting or support for a client takes on that same continuous exposure for that part of the work, alongside the more bounded exposure from the systems they've built.

Keep reading

Where this guide fits

Business Insurance

This guide sits alongside our Business Insurance cover pages.

Browse Business Insurance

Written by

Jack O'Hagan

Jack O'Hagan

Co-Founder & Insurance Broker

Jack spent 6+ years across law, finance and insurance, seeing the impact insurance can have on the growth of a business. With a strong focus on advocacy, he firmly believes insurance broking does not stop after the policy has been placed. It continues when a claim is lodged. He co-founded Cipher Insurance to help Australian businesses get the right broker experience.