Play It Smart

A client wires half a million dollars to a criminal. Their cyber policy covers a hundred thousand, maybe two hundred fifty. The plaintiff's attorney does the math and knows exactly who to go after next: the managed service provider (MSP). Joe Brunsman has watched this from every side. He runs the Brunsman Advisory Group, an insurance brokerage in Annapolis built around MSPs, spent fifteen years with the United States (US) Navy, holds a master's in cybersecurity law, and has dealt with close to a thousand cyber claims. His starting point: before 2020, lawsuits against MSPs effectively did not exist. He went looking and found two, one of them an employment claim. Then the plaintiff's bar noticed an industry with no licensing regime, no statutory protections, and clients who lose real money when something breaks. Breach litigation has gone parabolic since, and MSPs are being named as co-defendants. The myth he wants dead is claim denial. In 11 years he has never had a cyber claim denied, across close to a thousand claims. Cyber insurance is dirt cheap, the policies are broader than most people fathom, and they pay. What actually sinks MSPs is everything around the policy: an indemnification clause pointing the wrong way, a client who skipped their own cyber policy and plans to sue you instead, a definition of technology services narrower than what you actually do. So the episode builds his defense in depth for the business itself: the master services agreement (MSA) first, hold harmless and indemnification done right, contractually requiring clients to carry their own cyber insurance, then your own technology errors and omissions (tech E&O) policy on top. Plus the phrase that matters when artificial intelligence (AI) shows up in a claim: "including but not limited to." And his mutual insurance framing, which turns the client risk conversation into a reason to trust you. What we cover: Why MSP lawsuits barely existed before 2020, and what changed How a plaintiff's attorney builds a case against an MSP, played out through a half million dollar wire fraud The 2019 research that said you needed a billion dollar company and 200,000 lost records to get sued, and why it no longer holds Whether your client's cyber policy protects you (it protects them) Hold harmless and indemnification, one way versus two way Defense in depth applied to the business, not the network The claim denial myth: 11 years, close to a thousand claims, zero denied Subrogation, explained with a car crash The big client versus small client risk math Tech E&O decoded: the four buckets and the one definition to read Contra proferentem, the rule from the year 462 buried in every argument about vague policy language What happens when the claim involves AI, a rogue large language model (LLM), or an outsourced security operations center (SOC) that missed the alert How many MSPs actually carry tech E&O (his estimate: under half) Where liability lands next, and clients running AI over your MSA The mutual insurance framing that wins the client conversation Find Joe on YouTube (Joseph Brunsman), where everything is free and nothing is monetized, on LinkedIn, or at thebrunsgroup.com. His books include Damage Control: Cyber Insurance and Compliance.

What is Play It Smart?

Play It Smart is the show where Alexej Pikovsky sits down with MSP operators and business owners and takes apart how they actually do it: winning clients, pricing, staying lean, using AI, and building toward an exit worth having. Season 2 is dedicated to MSP operators. Past guests include Rand Fishkin of Moz and SparkToro and the founders of Chili Piper, Flowchat and 3DLOOK.