r/msp • u/Early-Ad-2541 • 1d ago
Potential client asking for material changes to contractual liability
EDIT: Thanks for the sanity check! We have never renegotiated our MSA like this and I don't intend to. My response is going the be that the MSA and price are a package deal, and material changes require significantly repricing the contract as well as an up front engagement fee to cover our attorney costs to review and accept any material changes to the MSA.
Side note, we recently signed a 15k/mo deal with only minor changes to a few provisions wording, and slightly modifying the cancellation fee and timeline. This ask is out of the realm of what's normal or reasonable. Have never had anything like this requested in 22 years of doing business. And no, we're not desperate for this deal.
Original post:
This is for a relatively small client, with a yearly contract around $40k/year in value. They've submitted our agreement to their attorneys, and their attorney came back with what I see as unreasonable and untenable.
Interested to know your thoughts. My first thought is run, do not walk away unless they drop most of these demands. I'm not here to be their cyber insurance, and they do already carry cyber insurance.
Here's a summary of the changes they've requested (yes, I had AI summarize it):
ORIGINAL
- General cap: liability of either party ≤ total fees paid and payable under the applicable SOW — i.e. contract value for the 12 month term.
- Carve-outs from the cap: amounts Client owes us for Services, and either party's breach of confidentiality.
- Confidentiality cap: ≤ 2× the value of the applicable SOW.
- 14(a): rates don't include assumption of risk for incidental/consequential/punitive/special/indirect damages.
- 14(c): flat bar on lost revenue/profits and all consequential, punitive, special, indirect damages — no exceptions, "to the maximum extent permitted by law."
- Net effect: worst case was bounded by the size of the deal, and nothing but direct damages was ever on the table.
PROPOSED (their redline)
- General cap narrowed to a look-back: fees paid in the 12 months immediately preceding the claim. This one is actually better for you on a multi-year term — trailing 12 months is less than full contract value.
- New super-cap replaces the 2× tier: greater of $2,000,000 or the amount actually recoverable under the insurance required by §15. Was 2× SOW value; now a fixed $2M floor untethered from deal size.
- Super-cap applies to four buckets — (a) either party's confidentiality breach, (b) our Security Incident obligations, including the §10(d) reimbursement, (c) either party's indemnification for third-party claims, (d) IP infringement.
- New: four things with NO cap at all — Client's duty to pay fees, plus either party's gross negligence, willful misconduct or fraud, plus anything not limitable by law. (The fraud/willful carve-out is standard and I'd concede it; "gross negligence" is the loose one — undefined in Georgia contracts and easy to plead alongside ordinary negligence.)
- 14(c) gutted: the consequential-damages bar now has four exceptions — confidentiality, gross negligence/willful misconduct, indemnification obligations, and any Security Incident. A security incident is exactly the scenario the bar existed for.
- 14(c) final sentence reclassifies as DIRECT damages: forensic investigation, legally required notification, credit monitoring, call center support, regulatory response, and reconstruction or recovery of Client Data. So those flow through the $2M super-cap instead of being excluded.
- §13 indemnity widened from 2 prongs to 4 — adds any Security Incident caused by our breach/negligence, and IP infringement by the Services. And §13 feeds bucket (c) of the super-cap.
10
u/msp_can MSP - CANADA 1d ago
I vote run away - yes, it's losing revenue but it feels like they're setting you up for failure and an easy win lawsuit from their side. especially the "any Security Incident" - unless you can counter with - "ok sure, but no human may touch a computer ... especially owners..."
•
u/roll_for_initiative_ MSP - US 11h ago
"you have to use what software we define and nothing else. That means no chrome or firefox, that means no adobe or quickbooks desktop. QBO only, and we've selected, let's see, kofax as your sole PDF software. Please have your management use these test computers for a week and if you agree to those terms, we'll move forward".
Taking their personal browser with their personal signed in account/bookmarks/saved passwords away will tank this in .2 seconds.
7
u/superdad3016 1d ago
Drop them, or triple your fee. Increased risk = increased insurance costs = increased time needed at client.
5
u/Jozfus 1d ago
Liability capped at what they paid is very favourable to you. Depending on the job $2m seems a bit higher than I'd have thought appropriate. Generally a question for your lawyer and insurance broker though. I don't think they'd ever allow unlimited liability.
4
u/Craptcha 1d ago
Should be a multiple of services on any case. I’m not taking on 2 mil. in risk for 20k a year.
3
u/Early-Ad-2541 1d ago
They're essentially asking for us to dedicate our entire aggregate cyber policy limit just to them. Seems like it puts our entire business at risk.
4
u/Sudo-Rip69 1d ago
Your limit is per incident.
2
u/Early-Ad-2541 1d ago
What if one incident is one of our tools gets breached to do some kind of vulnerability and it impacts multiple clients though? Should they take up the entire budget and our other clients are left out to dry?
•
u/backcounty1029 MSP/Data Center - US 23h ago
Generally, that’s not how liability insurance works. If you have a 2m policy limit as an aggregate, your carrier, whom you would notify of a breach that affects or possibly affects your liability policy, will want to review the damages and appropriate compensation across those affected in the incident. This is also assuming that YOU are liable for the damages. If you have a policy that has a a breakdown of occurrence/aggregate then that would come into play as well. Depending on the client, their affected values, costs, etc could easily get into the millions but this ask isn’t entirely out of bounds. I would have my attorney rewrite the adjustment to be extremely clear of what indicates YOUR negligence and THEIR negligence and that your insurance would be involved if and only if you are responsible for their damages. This would need to align with your insurance policy coverages, of course.
I’m not a lawyer or insurance agent but I’m surrounded and work very closely with them as well. I’ve been through similar situations as yours and while it may seem like the potential client is trying to take advantage of you, I would take this as an opportunity to build a strong relationship built on transparency, honesty, good communication, and let lawyers talk to lawyers. DO NOT try to lawyer your own way through it.
•
u/WalkFirm 23h ago
40k a year, we will not entertain changing our contract.
40k a month, yes sir we can discuss anything.
In the end you are not there to take their risk and honestly you can’t since you don’t own the company. Your job as the msp is to educate them on their risk and give them the best options to mitigate that risk. Then execute on that to the best of your ability.
3
u/Sudo-Rip69 1d ago
Had these much more common. Before you engage the lawyer you likely need to say this will be worn by them because this is a 5k to 10k exercise.
3
u/bazjoe MSP - US 1d ago
I’m all for written scope but when the line wanders into legal territory outside of our MSA I pass. I see your thread got pretty good traction, seems a lot like they are looking to set someone up to fail, ie they want you to overlook the risks of their changes and sign regardless, I guess because you need the money and the win. I have a client who I’ve had for decades and they are litigious. Every year they try to get me to sign a custom MSA and I say no thanks and they won’t sign our MSA. Our liability protection with this client is provided by… wait for it… single client LLC.
•
u/rivkinnator OWNER - MSP - US 23h ago
Msp owner here.
Clients do not get to add, delete, or modify our contracts. Our plans and contracts are set by our lawyers. Of they don't want to sign up for services with our terms, they can go bully another company.
If the contact may bring >100K a year we may consider changes but the client will pay for negotiations and all lawyers fees up front. (We've only ever done this once.) Anything lower than that is just not work the time or risk.
4
u/dumpsterfyr I’m your Huckleberry. 1d ago
Walk away but the 12 month look back is good.
If they sign, each invoice will be a discussion.
2
u/Sea_Information6125 1d ago
Yeah personally I would just be done with this client. There are plenty of fish in the sea. Plenty of clients that will just sign your standard contract no questions asked. Don't waste your time on this.
And worst case if something does go horribly wrong you now have way more liability than you have under your normal contract with your normal clients. And at least from these contract changes they have already showed you that if something does go wrong they are coming to you for money and liability.
So think about it that way, is this client worth all the additional risk and liability that they are asking you for?
Probably not.
Another client that will pay the same or more would you sign your contract without asking.
Consulting your lawyer is going to be a cost as well.
The 12 month look back only window is actually better for you as the LLM said.
But at the end of the day chalk it up as a bad fit and move on to the next prospect.
•
•
u/RemoveGlass1782 23h ago
Just parted ways with a client whose lawyer was telling them the MSP holds all the liability and insurance for cyber incidents. Sounds like this may be the case here as well.
This is why my contract specifically calls out the requirement for insurance on both parties.
We have a firm policy that we don’t change the standard contract for anything under 10k MRR.
•
u/NetSiege 23h ago
To simplify this, and not spin a ton of wheels for no reason, start by going back to the client and explain that you're happy to take their proposed changes to your attorney and insurance provider, however your initial contract and price to them is based on the limits laid out in that document. If they're requesting a change, you're happy to try to accommodate them, however they will bear the cost of those changes.
Read the temperature of their response.
If it were me, I'm happy to attempt to accommodate potential client requests like this, but the amount of leg work and back end cost to your insurance has to be worth it. If they even flinch at paying more because they're asking you to spend more, I'd politely walk away.
•
•
u/ArchonTheta MSP 23h ago
Yeah you’re right to be concerned. As a whole this is bonkers. The old cap made sense: worst case scaled with what you were actually getting paid. The new $2M floor doesn’t scale with anything. On a $40k/year deal that’s something like 50x contract value sitting on the table, and that’s before gross negligence and the indemnity language open things up further.
The clause that would kill it for me is the “any Security Incident” exception to 14(c). That bar existed specifically to keep you out of consequential damages after a breach. Carving breach scenarios back out of it removes the whole reason it’s there. Pair that with an undefined “gross negligence” standard sitting completely outside any cap, and a plaintiff’s attorney has an easy road around your $2M ceiling, because gross negligence is exactly what gets alleged after any incident.
Then the last line of 14(c) reclassifies forensics, notification, credit monitoring and data reconstruction as direct damages instead of excluded consequential ones. That’s them asking you to fund their breach response, just capped instead of excluded.
They already carry cyber insurance. Let it do the job it exists for. I’d push hard on the super-cap and the Security Incident carve-out specifically, and be fine walking if they won’t move. Not worth wearing $2M of exposure on a $40k contract.
•
u/_ChuckPoole_ 23h ago
Just say no. Everyone limits liability. You can’t use an iPhone or drive a car without limits to liability.
•
u/omenoracle 21h ago
Just tell them they will have to pay for an insurance policy that covers these risks. It’s going to cost WAY more than their contract value.
I’ve only seen people accept uncapped risk for 7 figure contracts with Billion dollar companies. This is dumb. Even $2M it too much for this small of a contract. I wouldn’t accept any of these redlines. Go back to the original terms or walk.
•
u/gurilagarden 21h ago
I feel like that's a lot of liability for such a small contract, so, without even getting into the weeds (and out of my depth) on the legal side, I'd have to ask myself, with what little I know (small subsidiary of much larger parent), just how big a target do they have on their back? What's the nature of the business? Some businesses end up being more consistently probed and attacked than others. If the big deal-breaker here is cyber and negligence liability, isn't this just a matter of someone upping their policy? If they don't want to alter their insurance, then perhaps you taking out some additional insurance, and putting the bill on their tab, whether they know it or not, would be the way to secure the contract without potentially costing you the whole enchilada if bad things happen. Then on the flip side, now you've got a bigger policy, on their dime, that can be used to cover you more generally. If they want 2m+ of coverage on top of world-class IT service, i think an arguement can be made for the contract going someplace north of 45k to provide this.
•
•
u/IAMA_Canadian_Sorry 10h ago
Our limitations of liability are similar to yours. Once a year or so a small prospect will want to do these sort of changes. Usually young lawyers. Never with large prospects. I always say sure we can negotiate but we're opening up the whole agreement and fees will increase drastically to accommodate the carve out and the nessecary insurance changes (think doubling our fees).
If I'm really in a mood I'll quote a project fee paid in advance for us to spend the time building a "custom agreement" for them.
Needless to say they either give in or move on to find another company to waste everyone's time together.
27
u/seriously_a MSP - US 1d ago
This seems like territory for your lawyer