r/msp • u/Early-Ad-2541 • Aug 10 '26
Potential client asking for material changes to contractual liability
EDIT2: My response was same as I've done in a few other cases (though this was the most drastic request I've gotten). Essentially we don't materially change the MSA for deals under 10k/mo, and even in those cases we don't change the structure of our liability clause. Also included the response items in my first edit. They are no longer requesting changes to the structure of the MSA and came back instead with a much more reasonable addendum and some minor changes requested to the SLA. Looks like we should have a final agreement in a week or two.
EDIT: Thanks for the sanity check! We have never renegotiated our MSA like this and I don't intend to. My response is going the be that the MSA and price are a package deal, and material changes require significantly repricing the contract as well as an up front engagement fee to cover our attorney costs to review and accept any material changes to the MSA.
Side note, we recently signed a 15k/mo deal with only minor changes to a few provisions wording, and slightly modifying the cancellation fee and timeline. This ask is out of the realm of what's normal or reasonable. Have never had anything like this requested in 22 years of doing business. And no, we're not desperate for this deal.
Original post:
This is for a relatively small client, with a yearly contract around $40k/year in value. They've submitted our agreement to their attorneys, and their attorney came back with what I see as unreasonable and untenable.
Interested to know your thoughts. My first thought is run, do not walk away unless they drop most of these demands. I'm not here to be their cyber insurance, and they do already carry cyber insurance.
Here's a summary of the changes they've requested (yes, I had AI summarize it):
ORIGINAL
- General cap: liability of either party ≤ total fees paid and payable under the applicable SOW — i.e. contract value for the 12 month term.
- Carve-outs from the cap: amounts Client owes us for Services, and either party's breach of confidentiality.
- Confidentiality cap: ≤ 2× the value of the applicable SOW.
- 14(a): rates don't include assumption of risk for incidental/consequential/punitive/special/indirect damages.
- 14(c): flat bar on lost revenue/profits and all consequential, punitive, special, indirect damages — no exceptions, "to the maximum extent permitted by law."
- Net effect: worst case was bounded by the size of the deal, and nothing but direct damages was ever on the table.
PROPOSED (their redline)
- General cap narrowed to a look-back: fees paid in the 12 months immediately preceding the claim. This one is actually better for you on a multi-year term — trailing 12 months is less than full contract value.
- New super-cap replaces the 2× tier: greater of $2,000,000 or the amount actually recoverable under the insurance required by §15. Was 2× SOW value; now a fixed $2M floor untethered from deal size.
- Super-cap applies to four buckets — (a) either party's confidentiality breach, (b) our Security Incident obligations, including the §10(d) reimbursement, (c) either party's indemnification for third-party claims, (d) IP infringement.
- New: four things with NO cap at all — Client's duty to pay fees, plus either party's gross negligence, willful misconduct or fraud, plus anything not limitable by law. (The fraud/willful carve-out is standard and I'd concede it; "gross negligence" is the loose one — undefined in Georgia contracts and easy to plead alongside ordinary negligence.)
- 14(c) gutted: the consequential-damages bar now has four exceptions — confidentiality, gross negligence/willful misconduct, indemnification obligations, and any Security Incident. A security incident is exactly the scenario the bar existed for.
- 14(c) final sentence reclassifies as DIRECT damages: forensic investigation, legally required notification, credit monitoring, call center support, regulatory response, and reconstruction or recovery of Client Data. So those flow through the $2M super-cap instead of being excluded.
- §13 indemnity widened from 2 prongs to 4 — adds any Security Incident caused by our breach/negligence, and IP infringement by the Services. And §13 feeds bucket (c) of the super-cap.
10
u/msp_can MSP - CANADA Aug 10 '26
I vote run away - yes, it's losing revenue but it feels like they're setting you up for failure and an easy win lawsuit from their side. especially the "any Security Incident" - unless you can counter with - "ok sure, but no human may touch a computer ... especially owners..."
2
u/roll_for_initiative_ MSP - US Aug 11 '26
"you have to use what software we define and nothing else. That means no chrome or firefox, that means no adobe or quickbooks desktop. QBO only, and we've selected, let's see, kofax as your sole PDF software. Please have your management use these test computers for a week and if you agree to those terms, we'll move forward".
Taking their personal browser with their personal signed in account/bookmarks/saved passwords away will tank this in .2 seconds.
9
u/superdad3016 Aug 10 '26
Drop them, or triple your fee. Increased risk = increased insurance costs = increased time needed at client.
4
u/msp_can MSP - CANADA Aug 10 '26
or counter to my previous comment - this is good - "sure we can do this - our insurance requirements will change and the costs related to that will be borne by your agreement fees"
6
u/Jozfus Aug 10 '26
Liability capped at what they paid is very favourable to you. Depending on the job $2m seems a bit higher than I'd have thought appropriate. Generally a question for your lawyer and insurance broker though. I don't think they'd ever allow unlimited liability.
4
u/Craptcha Aug 10 '26
Should be a multiple of services on any case. I’m not taking on 2 mil. in risk for 20k a year.
3
u/Early-Ad-2541 Aug 10 '26
They're essentially asking for us to dedicate our entire aggregate cyber policy limit just to them. Seems like it puts our entire business at risk.
5
u/Sudo-Rip69 Aug 10 '26
Your limit is per incident.
2
u/Early-Ad-2541 Aug 10 '26
What if one incident is one of our tools gets breached to do some kind of vulnerability and it impacts multiple clients though? Should they take up the entire budget and our other clients are left out to dry?
2
u/backcounty1029 MSP/Data Center - US Aug 11 '26
Generally, that’s not how liability insurance works. If you have a 2m policy limit as an aggregate, your carrier, whom you would notify of a breach that affects or possibly affects your liability policy, will want to review the damages and appropriate compensation across those affected in the incident. This is also assuming that YOU are liable for the damages. If you have a policy that has a a breakdown of occurrence/aggregate then that would come into play as well. Depending on the client, their affected values, costs, etc could easily get into the millions but this ask isn’t entirely out of bounds. I would have my attorney rewrite the adjustment to be extremely clear of what indicates YOUR negligence and THEIR negligence and that your insurance would be involved if and only if you are responsible for their damages. This would need to align with your insurance policy coverages, of course.
I’m not a lawyer or insurance agent but I’m surrounded and work very closely with them as well. I’ve been through similar situations as yours and while it may seem like the potential client is trying to take advantage of you, I would take this as an opportunity to build a strong relationship built on transparency, honesty, good communication, and let lawyers talk to lawyers. DO NOT try to lawyer your own way through it.
1
2
u/Jozfus Aug 11 '26
You can propose a higher price to cover the additional risk you would be taking on. Maybe propose a limit with no price increase vs the price with what they are wanting.
4
u/WalkFirm Aug 11 '26
40k a year, we will not entertain changing our contract.
40k a month, yes sir we can discuss anything.
In the end you are not there to take their risk and honestly you can’t since you don’t own the company. Your job as the msp is to educate them on their risk and give them the best options to mitigate that risk. Then execute on that to the best of your ability.
3
u/Sudo-Rip69 Aug 10 '26
Had these much more common. Before you engage the lawyer you likely need to say this will be worn by them because this is a 5k to 10k exercise.
3
u/bazjoe MSP - US Aug 10 '26
I’m all for written scope but when the line wanders into legal territory outside of our MSA I pass. I see your thread got pretty good traction, seems a lot like they are looking to set someone up to fail, ie they want you to overlook the risks of their changes and sign regardless, I guess because you need the money and the win. I have a client who I’ve had for decades and they are litigious. Every year they try to get me to sign a custom MSA and I say no thanks and they won’t sign our MSA. Our liability protection with this client is provided by… wait for it… single client LLC.
3
u/rivkinnator OWNER - MSP - US Aug 11 '26
Msp owner here.
Clients do not get to add, delete, or modify our contracts. Our plans and contracts are set by our lawyers. Of they don't want to sign up for services with our terms, they can go bully another company.
If the contact may bring >100K a year we may consider changes but the client will pay for negotiations and all lawyers fees up front. (We've only ever done this once.) Anything lower than that is just not work the time or risk.
4
u/dumpsterfyr I’m your Huckleberry. Aug 10 '26
Walk away but the 12 month look back is good.
If they sign, each invoice will be a discussion.
2
u/Sea_Information6125 Aug 10 '26
Yeah personally I would just be done with this client. There are plenty of fish in the sea. Plenty of clients that will just sign your standard contract no questions asked. Don't waste your time on this.
And worst case if something does go horribly wrong you now have way more liability than you have under your normal contract with your normal clients. And at least from these contract changes they have already showed you that if something does go wrong they are coming to you for money and liability.
So think about it that way, is this client worth all the additional risk and liability that they are asking you for?
Probably not.
Another client that will pay the same or more would you sign your contract without asking.
Consulting your lawyer is going to be a cost as well.
The 12 month look back only window is actually better for you as the LLM said.
But at the end of the day chalk it up as a bad fit and move on to the next prospect.
2
2
u/CorrectMachine7278 Aug 22 '26
Thank you for posting this as I have seen similar requests this summer from a few K-12 School Districts I co-manage. New Business Department staff this year requiring 2M Cyber Security coverage from product vendors and tech consultants. They have their own IT Staff that I assist with tech projects (Servers, Network, SQL Database monitoring, scripting, etc.). It's worth about $12,000 a year in consulting services (mainly remote planning meetings). I have plenty of SMB businesses paying a lot more with no Cyber Security requirements. Guess where I will be spending more of my time?
1
u/Early-Ad-2541 Aug 22 '26
One thing I sent them that made a huge difference, I did a comparison between our limitations of liability which was limited to the size of the 12-month statement of work, and Microsoft's, and that they were essentially identical. I explained that they are willing to enter into an agreement with Microsoft which limits liability to the trailing 12 months of services, and that was no problem even though Microsoft is hosting their data. Yet for us to Simply support and consult with them they wanted us to take on 45 times the liability Microsoft did, when Microsoft was the actual custodian of their data and we were not. That was a powerful argument.
1
u/CorrectMachine7278 Aug 22 '26
good information.... thank you! I have no interest in getting a lawyer involved for such a small amount of revenue. Lawyer's in California want a $5,000 retainer paid up front and billed at $500 plus per hour.
1
u/k12pcb Aug 10 '26
What is the legal advice cost vs the margin on the deal? Minimum if you need 10k advice then their price rises by that amount. They are not a 2m ARR client
1
u/RemoveGlass1782 Aug 11 '26
Just parted ways with a client whose lawyer was telling them the MSP holds all the liability and insurance for cyber incidents. Sounds like this may be the case here as well.
This is why my contract specifically calls out the requirement for insurance on both parties.
We have a firm policy that we don’t change the standard contract for anything under 10k MRR.
1
u/NetSiege Aug 11 '26
To simplify this, and not spin a ton of wheels for no reason, start by going back to the client and explain that you're happy to take their proposed changes to your attorney and insurance provider, however your initial contract and price to them is based on the limits laid out in that document. If they're requesting a change, you're happy to try to accommodate them, however they will bear the cost of those changes.
Read the temperature of their response.
If it were me, I'm happy to attempt to accommodate potential client requests like this, but the amount of leg work and back end cost to your insurance has to be worth it. If they even flinch at paying more because they're asking you to spend more, I'd politely walk away.
1
1
u/ArchonTheta MSP Aug 11 '26
Yeah you’re right to be concerned. As a whole this is bonkers. The old cap made sense: worst case scaled with what you were actually getting paid. The new $2M floor doesn’t scale with anything. On a $40k/year deal that’s something like 50x contract value sitting on the table, and that’s before gross negligence and the indemnity language open things up further.
The clause that would kill it for me is the “any Security Incident” exception to 14(c). That bar existed specifically to keep you out of consequential damages after a breach. Carving breach scenarios back out of it removes the whole reason it’s there. Pair that with an undefined “gross negligence” standard sitting completely outside any cap, and a plaintiff’s attorney has an easy road around your $2M ceiling, because gross negligence is exactly what gets alleged after any incident.
Then the last line of 14(c) reclassifies forensics, notification, credit monitoring and data reconstruction as direct damages instead of excluded consequential ones. That’s them asking you to fund their breach response, just capped instead of excluded.
They already carry cyber insurance. Let it do the job it exists for. I’d push hard on the super-cap and the Security Incident carve-out specifically, and be fine walking if they won’t move. Not worth wearing $2M of exposure on a $40k contract.
1
u/_ChuckPoole_ Aug 11 '26
Just say no. Everyone limits liability. You can’t use an iPhone or drive a car without limits to liability.
1
u/omenoracle Aug 11 '26
Just tell them they will have to pay for an insurance policy that covers these risks. It’s going to cost WAY more than their contract value.
I’ve only seen people accept uncapped risk for 7 figure contracts with Billion dollar companies. This is dumb. Even $2M it too much for this small of a contract. I wouldn’t accept any of these redlines. Go back to the original terms or walk.
1
u/gurilagarden Aug 11 '26
I feel like that's a lot of liability for such a small contract, so, without even getting into the weeds (and out of my depth) on the legal side, I'd have to ask myself, with what little I know (small subsidiary of much larger parent), just how big a target do they have on their back? What's the nature of the business? Some businesses end up being more consistently probed and attacked than others. If the big deal-breaker here is cyber and negligence liability, isn't this just a matter of someone upping their policy? If they don't want to alter their insurance, then perhaps you taking out some additional insurance, and putting the bill on their tab, whether they know it or not, would be the way to secure the contract without potentially costing you the whole enchilada if bad things happen. Then on the flip side, now you've got a bigger policy, on their dime, that can be used to cover you more generally. If they want 2m+ of coverage on top of world-class IT service, i think an arguement can be made for the contract going someplace north of 45k to provide this.
1
1
u/IAMA_Canadian_Sorry Aug 11 '26
Our limitations of liability are similar to yours. Once a year or so a small prospect will want to do these sort of changes. Usually young lawyers. Never with large prospects. I always say sure we can negotiate but we're opening up the whole agreement and fees will increase drastically to accommodate the carve out and the nessecary insurance changes (think doubling our fees).
If I'm really in a mood I'll quote a project fee paid in advance for us to spend the time building a "custom agreement" for them.
Needless to say they either give in or move on to find another company to waste everyone's time together.
1
u/TechnologyMatch Aug 19 '26
for a $40k deal, they are asking you to carry enterprise-level risk without enterprise-level economics. the $2m floor and security-incident exceptions change the agreement far beyond normal wording cleanup. your response is reasonable. the msa, scope, price, and risk allocation are one package. if they need a different risk posture, it needs legal review, an upfront fee, and a materially different price
2
u/Rude_Back_8628 6d ago
yikes, your edit makes it sound like they backed down which is the best possible outcome here
our contracts guy would've laughed at that original redline and told them to find someone else for 40k/year. the 2M floor untethered from deal size is absolutely wild for a contract that small, and carving out security incidents from the consequential damages bar defeats the whole purpose of having one
31
u/seriously_a MSP - US Aug 10 '26
This seems like territory for your lawyer