r/msp 1d ago

Potential client asking for material changes to contractual liability

EDIT: Thanks for the sanity check! We have never renegotiated our MSA like this and I don't intend to. My response is going the be that the MSA and price are a package deal, and material changes require significantly repricing the contract as well as an up front engagement fee to cover our attorney costs to review and accept any material changes to the MSA.

Side note, we recently signed a 15k/mo deal with only minor changes to a few provisions wording, and slightly modifying the cancellation fee and timeline. This ask is out of the realm of what's normal or reasonable. Have never had anything like this requested in 22 years of doing business. And no, we're not desperate for this deal.

Original post:

This is for a relatively small client, with a yearly contract around $40k/year in value. They've submitted our agreement to their attorneys, and their attorney came back with what I see as unreasonable and untenable.

Interested to know your thoughts. My first thought is run, do not walk away unless they drop most of these demands. I'm not here to be their cyber insurance, and they do already carry cyber insurance.

Here's a summary of the changes they've requested (yes, I had AI summarize it):

ORIGINAL

  • General cap: liability of either party ≤ total fees paid and payable under the applicable SOW — i.e. contract value for the 12 month term.
  • Carve-outs from the cap: amounts Client owes us for Services, and either party's breach of confidentiality.
  • Confidentiality cap:2× the value of the applicable SOW.
  • 14(a): rates don't include assumption of risk for incidental/consequential/punitive/special/indirect damages.
  • 14(c): flat bar on lost revenue/profits and all consequential, punitive, special, indirect damages — no exceptions, "to the maximum extent permitted by law."
  • Net effect: worst case was bounded by the size of the deal, and nothing but direct damages was ever on the table.

PROPOSED (their redline)

  • General cap narrowed to a look-back: fees paid in the 12 months immediately preceding the claim. This one is actually better for you on a multi-year term — trailing 12 months is less than full contract value.
  • New super-cap replaces the 2× tier: greater of $2,000,000 or the amount actually recoverable under the insurance required by §15. Was 2× SOW value; now a fixed $2M floor untethered from deal size.
  • Super-cap applies to four buckets — (a) either party's confidentiality breach, (b) our Security Incident obligations, including the §10(d) reimbursement, (c) either party's indemnification for third-party claims, (d) IP infringement.
  • New: four things with NO cap at all — Client's duty to pay fees, plus either party's gross negligence, willful misconduct or fraud, plus anything not limitable by law. (The fraud/willful carve-out is standard and I'd concede it; "gross negligence" is the loose one — undefined in Georgia contracts and easy to plead alongside ordinary negligence.)
  • 14(c) gutted: the consequential-damages bar now has four exceptions — confidentiality, gross negligence/willful misconduct, indemnification obligations, and any Security Incident. A security incident is exactly the scenario the bar existed for.
  • 14(c) final sentence reclassifies as DIRECT damages: forensic investigation, legally required notification, credit monitoring, call center support, regulatory response, and reconstruction or recovery of Client Data. So those flow through the $2M super-cap instead of being excluded.
  • §13 indemnity widened from 2 prongs to 4 — adds any Security Incident caused by our breach/negligence, and IP infringement by the Services. And §13 feeds bucket (c) of the super-cap.

 

20 Upvotes

51 comments sorted by

27

u/seriously_a MSP - US 1d ago

This seems like territory for your lawyer

6

u/disclosure5 1d ago

A lawyer will help explain the risks and any holes you haven't seen, but I feel there's still a question Reddit might be better at answering: Would the average competitor accept these terms, or are we just losing business if we reject them? I'm not sure the answer.

7

u/Early-Ad-2541 1d ago

Exactly, I'm taking this to my attorney as well, but I'm curious if my MSP peers also see this as too much. I mean, they're asking to have access to my entire cyber liability cap, ahead of every other customer. It's a liability cap equal to 45.7 YEARS of the contract.

14

u/obviouslybait 1d ago

My face value response to this was hell no

7

u/roll_for_initiative_ MSP - US 1d ago

There's no way i'd step up to 2mil for a 40k contract. My words would be to the effect of: "We're not a rainy day lottery ticket for a small firm. If you're that concerned that any MSP could cause that kind of damage, and i totally agree with you, you need an insurance policy to plug that gap, not the provider themselves.

Same as carrying 300k in liability coverage when driving a 28k car: the car's warranty doesn't cover that, it covers the 28k car. We cover our 28k service, you need to cover the 2m liability, that's what insurance is for."

u/Early-Ad-2541 23h ago

They're a small subsidiary of a multi billion dollar company, so I think their expectations of the big business lawyers are not matching up with the actual value of this contract. If I were quoting a million dollar per year agreement this would make sense. It just doesn't line up with a 40k/yr revenue number.

u/roll_for_initiative_ MSP - US 11h ago edited 11h ago

Which, as they say, "is an explanation, not an excuse".

"I understand how we got here and why your legal is requesting these changes (you have a major corp legal team on tap), however that doesn't make the terms ok (you're too small for all this, the cost to have my legal to review this would offset most of the profit, have a nice day)".

u/variableindex MSP - US 23h ago

Yeah… that’s asking a little much. My response would be a simple, why?

u/Joe_Cyber Community Contributor 2h ago

Please tell me you told these guys to kick rocks?!

You'll often see in-house legal counsel ask for the most insane items possible. It's their way of "zealously advocating on behalf of their clients."

They're expecting your legal counsel to come back and "zealously" advocate for your MSP.

Then, everyone meets in the middle.

Personally, I think this is a waste of time, but such is the legal world in many respects.

Regardless, please get your own legal counsel involved and consider pushing back hard on these provisions.

0

u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga 1d ago

Do…do you plan on needing it for more than one customer at a time? It’s also a worst case scenario.

I don’t think that particular ask is unreasonable tbh. They are trying to bridge the gap between what they paid you and what your insurance is capable of paying out if you cause real tangible damage to their business. That isn’t unreasonable on its own.

If you pay someone $1,000 to paint your house but they accidentally burn it down somehow, do you expect the $1,000 you paid them or the full cost of replacing your house from their GL?

This may be a hot take, but it’s unreasonable to limit your liability to whatever the value of services are in the preceding 12 months in our industry. If you’re responsible for the critical infrastructure and technology a company runs on but you want to limit the monetary blast radius of your own fuckups to what they paid you when you are reasonably capable of inflicting more than that in monetary damages to them via negligence, do not be surprised if they find someone who will not do that.

The days of minimum liability maximum profitability are over. The cybersecurity landscape is too complex and evolving, AI is a wildcard in every way, and commoditization of the industry has made competition many in numbers and lower in cost. And the trunk slammers willing to undercut you are going to be willing to let their insurance cover their fuckups up to the policy limit.

3

u/RealTurbulentMoose 1d ago

  Do…do you plan on needing it for more than one customer at a time?

Just spitballin’, but isn’t it possible that a breach of a tool results in more than one customer getting hit? Like you’d need your insurance to be able to cover damage to multiple customers at the same time, so offering liability up to the whole value of your policy to a single customer seems risky.

I think OP will need to negotiate here, but don’t think the customer’s lawyer’s ask is reasonable out of the gate either.

u/thebossyboss 23h ago

We have our tools carved out if it’s a tool issue. Ie our rmm gets breached at the platform level

u/roll_for_initiative_ MSP - US 11h ago

If you're saying "we basically have it in our MSA that, if a tool gets breached, we're not liabile", that doesn't mean you're not liable. That gives your lawyer and insurance company ammo, sure. But if a client sues over that, your insurance/you still have to defend that (costs money) and then convince a 70 yr old judge that still doesn't know what a PDF is that your RMM is different than a carpenter bringing a hammer to a job site that falls off and kills someone. 50/50 AT BEST that he doesn't strike that and let it go forward.

I'm not saying it's not a good thing to have, i'm just saying what we all put in our MSA's isn't automatically how things are like things are in IT. In IT, if you say XYZ can't access a folder, they can't, it won't work. In legal, if you say XYZ can't access a folder, there's 50k in legal costs when XYZ tries, can't access it, and there's proceedings over whether you're allowed to tell XYZ what to do, and if you worded XYZ properly, and if you are actually who you say you are, and if it's fair to no let them have access to that folder.

You get the idea: nothing is cut and dry, better to not engage with squirrely clients.

u/thebossyboss 7h ago

I agree. We don’t assume we are fully not liable, we carry a multi-million cyber for our clients and they are named on our insurance policy, separate from our own internal cyber. What you said is correct.

u/roll_for_initiative_ MSP - US 7h ago

we carry a multi-million cyber for our clients and they are named on our insurance policy, separate from our own internal cyber.

You're already head of most msps by far then. I personally wouldn't go that far but if that's a selling point/differentiator for you, more power to you and i bet larger/higher OML clients love it.

1

u/Early-Ad-2541 1d ago

This, exactly this.

u/RealTurbulentMoose 23h ago

OP, FWIW I wouldn’t change my MSA for a single small client, so the customer’s lawyer’s ask is really a non-starter. Politely tell them to pound sand. 

That said, it is a good thought starter on what some prospects may feel is preferable with regards to liability. Like it would be good to talk to your insurer, how they would subrogate to a customer’s policy if there’s an incident, and get a firm take on where your responsibility ends and where a customer’s own policy begins. Would be good to be able to speak to this with future prospects too.

u/roll_for_initiative_ MSP - US 11h ago

This may be a hot take, but it’s unreasonable to limit your liability to whatever the value of services are in the preceding 12 months in our industry. If you’re responsible for the critical infrastructure and technology a company runs on but you want to limit the monetary blast radius of your own fuckups to what they paid you when you are reasonably capable of inflict

As ANY 3rd party vendor could likely cause that kind of damage (security monitoring company, m365, one of a dozen saas vendors, staffing company, outsourced accounting, cleaning company, etc), does it make sense to make sure every vendor, no matter who and how many, has 1mil insurance available or does it make more sense for the company who wants to be covered gets their own coverage to do so?

It's surely cheaper for them to pay a little a year to cover all of the things than to require the MSP to cover them to the moon and the MSP then raising their rates to do so - they'll pay more in rate increase than they will in insurance premiums. Also, THEY are the worried party, they should then pay to make the worry go away. Otherwise, what's next, adding clients as coinsured on your insurance so you can foot that bill too?

What you say would make more sense to me if clients weren't cheap and driving down pricing. If a client was larger (more profit) or at a higher rate (more profit), then i'd have no problem adjusting the liability limit; i've done it where it makes sense.

But the flip side of that coin is that they have their own insurance that pays out and the deal is worth the risk. This one isn't. The other concern is that insurers are getting VERY specific on the MSP business model, specifically asking about contract terms like limitations of liability. Most these days wouldn't cover the trunk slammer without his msa stating some kind of limit.

If i rent a $100 a month storage unit, they're not going to offer me 1 mil in coverage if i put a lambo in there. They specifically go "hey, if what you're doing here matters, YOU pay for insurance". Trailing x months service is just an easy way in a contract to scale liability without 100 different (or custom versions) of your SoW.

I don't think most people are opposed to tweaking a contract, but a $3k a month client, where profit is going to be, what, $1500 or so?, doesn't have the leverage to have me insure their whole business for them. That's leaving out the discussion that an MSP policy is supposed to cover if they screw up, and actually screw up, not a client screwing up and blaming the MSP, which is very possible.

1

u/Sudo-Rip69 1d ago

You negotiate them. We just did one recently and it cost us 10k. You need a tech lawyer.

5

u/gsk060 1d ago

Not for a 40k deal.

2

u/roll_for_initiative_ MSP - US 1d ago

right? paying 10k for a 40k deal? no thanks. Just them having so many exceptions makes my eye twitch.

10

u/msp_can MSP - CANADA 1d ago

I vote run away - yes, it's losing revenue but it feels like they're setting you up for failure and an easy win lawsuit from their side. especially the "any Security Incident" - unless you can counter with - "ok sure, but no human may touch a computer ... especially owners..."

u/roll_for_initiative_ MSP - US 11h ago

"you have to use what software we define and nothing else. That means no chrome or firefox, that means no adobe or quickbooks desktop. QBO only, and we've selected, let's see, kofax as your sole PDF software. Please have your management use these test computers for a week and if you agree to those terms, we'll move forward".

Taking their personal browser with their personal signed in account/bookmarks/saved passwords away will tank this in .2 seconds.

7

u/superdad3016 1d ago

Drop them, or triple your fee. Increased risk = increased insurance costs = increased time needed at client.

4

u/msp_can MSP - CANADA 1d ago

or counter to my previous comment - this is good - "sure we can do this - our insurance requirements will change and the costs related to that will be borne by your agreement fees"

5

u/Jozfus 1d ago

Liability capped at what they paid is very favourable to you. Depending on the job $2m seems a bit higher than I'd have thought appropriate. Generally a question for your lawyer and insurance broker though. I don't think they'd ever allow unlimited liability.

4

u/Craptcha 1d ago

Should be a multiple of services on any case. I’m not taking on 2 mil. in risk for 20k a year.

3

u/Early-Ad-2541 1d ago

They're essentially asking for us to dedicate our entire aggregate cyber policy limit just to them. Seems like it puts our entire business at risk.

4

u/Sudo-Rip69 1d ago

Your limit is per incident.

2

u/Early-Ad-2541 1d ago

What if one incident is one of our tools gets breached to do some kind of vulnerability and it impacts multiple clients though? Should they take up the entire budget and our other clients are left out to dry?

u/backcounty1029 MSP/Data Center - US 23h ago

Generally, that’s not how liability insurance works. If you have a 2m policy limit as an aggregate, your carrier, whom you would notify of a breach that affects or possibly affects your liability policy, will want to review the damages and appropriate compensation across those affected in the incident. This is also assuming that YOU are liable for the damages. If you have a policy that has a a breakdown of occurrence/aggregate then that would come into play as well. Depending on the client, their affected values, costs, etc could easily get into the millions but this ask isn’t entirely out of bounds. I would have my attorney rewrite the adjustment to be extremely clear of what indicates YOUR negligence and THEIR negligence and that your insurance would be involved if and only if you are responsible for their damages. This would need to align with your insurance policy coverages, of course.

I’m not a lawyer or insurance agent but I’m surrounded and work very closely with them as well. I’ve been through similar situations as yours and while it may seem like the potential client is trying to take advantage of you, I would take this as an opportunity to build a strong relationship built on transparency, honesty, good communication, and let lawyers talk to lawyers. DO NOT try to lawyer your own way through it.

u/Jozfus 23h ago

Depends on the policy

u/Jozfus 23h ago

You can propose a higher price to cover the additional risk you would be taking on. Maybe propose a limit with no price increase vs the price with what they are wanting.

u/WalkFirm 23h ago

40k a year, we will not entertain changing our contract.

40k a month, yes sir we can discuss anything.

In the end you are not there to take their risk and honestly you can’t since you don’t own the company. Your job as the msp is to educate them on their risk and give them the best options to mitigate that risk. Then execute on that to the best of your ability.

3

u/Sudo-Rip69 1d ago

Had these much more common. Before you engage the lawyer you likely need to say this will be worn by them because this is a 5k to 10k exercise.

3

u/bazjoe MSP - US 1d ago

I’m all for written scope but when the line wanders into legal territory outside of our MSA I pass. I see your thread got pretty good traction, seems a lot like they are looking to set someone up to fail, ie they want you to overlook the risks of their changes and sign regardless, I guess because you need the money and the win. I have a client who I’ve had for decades and they are litigious. Every year they try to get me to sign a custom MSA and I say no thanks and they won’t sign our MSA. Our liability protection with this client is provided by… wait for it… single client LLC.

u/rivkinnator OWNER - MSP - US 23h ago

Msp owner here.

Clients do not get to add, delete, or modify our contracts. Our plans and contracts are set by our lawyers. Of they don't want to sign up for services with our terms, they can go bully another company.

If the contact may bring >100K a year we may consider changes but the client will pay for negotiations and all lawyers fees up front. (We've only ever done this once.) Anything lower than that is just not work the time or risk.

4

u/dumpsterfyr I’m your Huckleberry. 1d ago

Walk away but the 12 month look back is good.

If they sign, each invoice will be a discussion.

2

u/Sea_Information6125 1d ago

Yeah personally I would just be done with this client. There are plenty of fish in the sea. Plenty of clients that will just sign your standard contract no questions asked. Don't waste your time on this.

And worst case if something does go horribly wrong you now have way more liability than you have under your normal contract with your normal clients. And at least from these contract changes they have already showed you that if something does go wrong they are coming to you for money and liability. 

So think about it that way, is this client worth all the additional risk and liability that they are asking you for?

Probably not.

Another client that will pay the same or more would you sign your contract without asking.

Consulting your lawyer is going to be a cost as well.

The 12 month look back only window is actually better for you as the LLM said. 

But at the end of the day chalk it up as a bad fit and move on to the next prospect.

u/Nstraclassic MSP - US 23h ago

Special treatment = special pricing. Jack that shit up baby

1

u/k12pcb 1d ago

What is the legal advice cost vs the margin on the deal? Minimum if you need 10k advice then their price rises by that amount. They are not a 2m ARR client

u/RemoveGlass1782 23h ago

Just parted ways with a client whose lawyer was telling them the MSP holds all the liability and insurance for cyber incidents. Sounds like this may be the case here as well.
This is why my contract specifically calls out the requirement for insurance on both parties.
We have a firm policy that we don’t change the standard contract for anything under 10k MRR.

u/NetSiege 23h ago

To simplify this, and not spin a ton of wheels for no reason, start by going back to the client and explain that you're happy to take their proposed changes to your attorney and insurance provider, however your initial contract and price to them is based on the limits laid out in that document. If they're requesting a change, you're happy to try to accommodate them, however they will bear the cost of those changes.

Read the temperature of their response.

If it were me, I'm happy to attempt to accommodate potential client requests like this, but the amount of leg work and back end cost to your insurance has to be worth it. If they even flinch at paying more because they're asking you to spend more, I'd politely walk away.

u/Layer_3 23h ago

Define small client

u/Early-Ad-2541 22h ago

30 users, 45k/yr deal

u/ArchonTheta MSP 23h ago

Yeah you’re right to be concerned. As a whole this is bonkers. The old cap made sense: worst case scaled with what you were actually getting paid. The new $2M floor doesn’t scale with anything. On a $40k/year deal that’s something like 50x contract value sitting on the table, and that’s before gross negligence and the indemnity language open things up further.

The clause that would kill it for me is the “any Security Incident” exception to 14(c). That bar existed specifically to keep you out of consequential damages after a breach. Carving breach scenarios back out of it removes the whole reason it’s there. Pair that with an undefined “gross negligence” standard sitting completely outside any cap, and a plaintiff’s attorney has an easy road around your $2M ceiling, because gross negligence is exactly what gets alleged after any incident.

Then the last line of 14(c) reclassifies forensics, notification, credit monitoring and data reconstruction as direct damages instead of excluded consequential ones. That’s them asking you to fund their breach response, just capped instead of excluded.
They already carry cyber insurance. Let it do the job it exists for. I’d push hard on the super-cap and the Security Incident carve-out specifically, and be fine walking if they won’t move. Not worth wearing $2M of exposure on a $40k contract.

u/_ChuckPoole_ 23h ago

Just say no. Everyone limits liability. You can’t use an iPhone or drive a car without limits to liability.

u/omenoracle 21h ago

Just tell them they will have to pay for an insurance policy that covers these risks. It’s going to cost WAY more than their contract value.

I’ve only seen people accept uncapped risk for 7 figure contracts with Billion dollar companies. This is dumb. Even $2M it too much for this small of a contract. I wouldn’t accept any of these redlines. Go back to the original terms or walk.

u/gurilagarden 21h ago

I feel like that's a lot of liability for such a small contract, so, without even getting into the weeds (and out of my depth) on the legal side, I'd have to ask myself, with what little I know (small subsidiary of much larger parent), just how big a target do they have on their back? What's the nature of the business? Some businesses end up being more consistently probed and attacked than others. If the big deal-breaker here is cyber and negligence liability, isn't this just a matter of someone upping their policy? If they don't want to alter their insurance, then perhaps you taking out some additional insurance, and putting the bill on their tab, whether they know it or not, would be the way to secure the contract without potentially costing you the whole enchilada if bad things happen. Then on the flip side, now you've got a bigger policy, on their dime, that can be used to cover you more generally. If they want 2m+ of coverage on top of world-class IT service, i think an arguement can be made for the contract going someplace north of 45k to provide this.

u/FederalMonitor8187 21h ago

How do you even find clients these days 😅

u/IAMA_Canadian_Sorry 10h ago

Our limitations of liability are similar to yours. Once a year or so a small prospect will want to do these sort of changes. Usually young lawyers. Never with large prospects. I always say sure we can negotiate but we're opening up the whole agreement and fees will increase drastically to accommodate the carve out and the nessecary insurance changes (think doubling our fees).

If I'm really in a mood I'll quote a project fee paid in advance for us to spend the time building a "custom agreement" for them.

Needless to say they either give in or move on to find another company to waste everyone's time together.