Skip to main content
Right of Boom
January 30, 2025

April 5th, 2021

In this video, Wes Spencer and Eric Tilds discuss legal considerations for MSPs, focusing on managed service agreements and limitation of liability clauses. They explore the importance of establishing clear terms in contracts, such as customer responsibilities and cyber insurance requirements, to mitigate potential legal risks. Additionally, they emphasize the need for a strong security posture and governance to ensure both the MSP and their clients are protected.<ul><li>The importance of understanding and negotiating Managed Service Agreements (MSAs), focusing on limitation of liability, warranties, and indemnification.</li><li>The need for MSPs to clearly define customer responsibilities, including the requirement for cyber insurance and adherence to security protocols like MFA.</li><li>The value of maintaining open communication and documentation with clients, especially regarding security measures and risk management practices.</li></ul>

Guests

Andrew Morgan

Video Transcript

All right. Welcome everybody. Week 44. Good to have you back. Wes Spencer, um, on the lake last time or river. How you doing? How was vacation? Yeah, vacation was good. Uh, it didn't feel I was on calls all the time. It's a typical vacation for Wes, but it was nice. And we did get to do some swimming in some beautiful, uh, springs. Uh, had a good time. Yeah. Well, it's great to have you back, Ryan. Great to have you with us.

Um, I think we've got Paul bunion outside your door there, if I understand correctly. And, um, Mike Beard is filling in for Gary Pika. However, there are some audio challenges we're having right now with Mike. So, um, I may have to play Gary Pika and Mike regard, Wes, which will be an interesting, uh, kind of thing. I Have faith, full faith in you, Andrew. So our special guest today, Eric, til Eric, good to see you. Thanks for joining us. Thanks for having me, guys. Yeah, absolutely.

So, just a, let me kind of just a, a few quick announcements. There's really only one I have, and that is Wes. We started doing some, um, a, a security, um, uh, basically a, a, a security channel slash content with Gary Pika and true methods that we're gonna open up, um, for free, um, to, to anybody. Um, it's being sponsored in part by Cisco. Um, we're gonna, we're actually gonna dedicate a few of the cyber calls once the content's available, the security track's available.

We'll have more stay tuned on that. Um, so, um, it's gonna be based on, um, there's gonna be different sections. Everything from packaging and pricing resiliency. We're gonna have special guests on, like, Ryan will be on, and Phyllis will be on, on all these different things. So stay tuned for that when we know, uh, when we've got that up and running. That'll be congruent.

By the way, with Gary's new, um, they're build, they're about to release their new portal in the next four to six weeks, uh, as well. So that's the only announcement I have. So today, um, we are talking legal and, um, I couldn't think of a better person, Eric, to bring on than yourself. Um, for those of you that may have seen the video trailer, Eric, I've known you for 17 years, you have quite a, a background in MSP and legal, and I'm gonna have you tell people about that.

I will put a quick caveat out there. It's almost like this is not investment advice. You know, if you're thinking of making any type of investment, please seek, you know, your, your investment or your broker. So this is the same thing here. So, Eric, although is, uh, a lawyer, he, this is not considered legal advice, what we're talking about today. Please seek your own counsel before making any decision, uh, uh, for that. Eric, is that about a fair way to put that?

That was a very good disclaimer for my non lawyer. That Was really good, because We all know that, uh, you know, every good legal case begins with five guys on a Crowdcast. Were telling me, your honor, Well, we, what do, hey, we, it's almost like a joke. Ask, what are three CSOs and ACL O? Or, you know, blah, blah, blah, blah. Anyway. Yeah. Alright. So, Eric, um, quick intro. Can you tell folks a little about yourself, your background, and we'll jump right on into things today? Absolutely.

Thanks, Andrew. I have spent, uh, 22 of my 23 year legal career, um, working for technology service providers, MSPs, systems integrators, var, et cetera. Um, I started back in 1999, um, when a, a buddy of mine from college called me and said, Hey, I need some help. I'm starting this company. Um, and I, uh, I joined him at a time when the company was about six or seven people. Um, it was a, a tiny little break fix, uh, Cisco shop.

Um, and we, over the course of about 12 years, uh, built that company into about a 250 person organization. Um, we did it both organically and Acquisitively. Uh, and, uh, and, and it was a great run. Um, we were operating in, in seven or eight states when we finally sold the company. Uh, and we sold the company to Logis. Um, logus is a, a global provider of technology, products, and services. Um, it's, uh, publicly traded at its parent company level.

Um, you probably haven't heard of the parent company, but you've probably heard of Westcon. Uh, Westcon is the sister company to Logus, and they're both owned by a company called Data Tech. So I spent, um, about eight years as the, uh, the EVP, general counsel, corporate secretary, and Chief Risk Officer of Logis, um, after they acquired, um, my company, net arcs. Um, and, uh, and here we are today. Excellent.

So, you know, I, before this Eric, uh, Crowdcast this, this session, I, I, I spoke to a few MSPs and I'm, and I said, you know, what, what is it that you know, you want to know about? And, and managed service agreements was, you know, at the top of by, by far. And I'm looking at my notes at the top of the list.

And, um, what do you see as, you know, the most important things if you were to give us a high level and were there certain things that you would accept as red lines and be like hard line stance, you know? And yeah, so It's a good question. And, and every, every MA is different. Um, every service provider is different, so, so they need different terms and conditions in their MSAs, but there are some topics that, that do show up over and over again in, in everyone's MSA, right?

One of them is limitation liability clauses that, that we're gonna talk a lot about later on today. Um, another is warranties. You know, what, what kind of warranty are you providing for the services that you are are selling? Um, indemnification ISS a big one, and it's kind of one of my favorites because not many people understand what indemnification is. They all kind of just agree to it, 'cause that indemnification clauses are in every contract. So let's not talk about it.

But again, we'll talk a little bit later about why it's so important. So to look at clauses like that, um, and, and in our space, data security, um, you know, talking about the kind of data that as a service provider we're going to be exposed to. Um, is it PHI? Is it PII? Is it encrypted? Is it not encrypted? How do we get it? Who has it? Who, who keeps it? Who's responsible for it? Um, those are all important things.

And if you're providing a managed service and your, your customers are accessing your systems, uh, then acceptable use policies, um, are, are also really, really important. Um, and are really one of the few reasons that a, uh, a service provider would ever really wanna terminate a contract before it's it's natural end. Um, and to answer your question about what's negotiable, what's not, um, I hate to give you the lawyer answer, but it depends.

Um, it depends on the risk profile of, of you as a service provider. I can share with you that in my logical days, there were very few things that we wouldn't negotiate. Um, and we got into some very complex and very protracted negotiations that would take months and months and months. Um, but really there were just a couple of things that, that, that were just deal killers for us, that we wouldn't, if, if we couldn't get past, we just would, would kill it right then and there.

Um, and that was really around the limitation of liability clauses as, uh, as our parent company, you know, CEO used to used to remind us why would we bet the company on one deal? Mm-Hmm. And the answer is you wouldn't. And, and that's why you need to have a, a solid, well negotiated limitation of liability clause. Very cool.

So when I was talking to Gary Pika offline this weekend, you know, he was saying from his perspective, you know, it's almost like, um, keeping Things In, in our world, SMB are kind of straightforward in that there was three things that he was really focused in on, and those were, you know, what's included and what's not, um, term termination. And, you know, the, you mentioned before the liability clause. What are your thoughts on these components?

You know, you, you mentioned some others there, and, and so I just want to get a sense of the importance of those three. Where do they rank and, and how do we bring those other ones in? And by the way, before you answer, put up a poll and, and again, you know, I wess appreciate you, man, in the chat. I'd love to get your guys' thoughts too out there. You know, like, Hey, yeah, I, this is a big deal for me. You know, I, I agree, I disagree, you know, so please chime in. Go ahead, Eric.

Yeah, so, so all three of those things are important. You know, Gary's been around a long time in this industry, and, and, and he gets it. Um, I'll just preface this by, at the, at the enterprise level of, of MSPs, like Logis is we would typically truncate, um, the, the legal terms and conditions from the business terms and conditions.

So we'd have an MSA, we called it a, a, a master services agreement that has all the legal stuff in it that we would spend some time negotiating, and then what's included, what's not included would end up in the statement of work. Um, but, you know, it's, it's not the only way to do it. You can do it a hundred different ways and, and including them all together is, is certainly acceptable. Um, but, but what's included and what's not included is really important.

And, and, and one thing that, that I've developed over my career is it's not only what's included and what's not included from the service provider standpoint, that that's certainly important, but what's included from the customer standpoint, what are they going to do to make sure that this engagement is successful? What is their role? What is their responsibilities in in all of this?

Um, they have no problem asking us to, to tell us what we're gonna do for them, but we've gotta make sure that, uh, at least they're on the same page as us and, and they know what we're going to expect, uh, to, um, term and termination. So, so term is of course, important. Termination's probably even more important. Um, you know, how long does something last? What happens at the end? Uh, what happens at a natural end?

What happens if it happens to end before it's natural end by because of some breach from one party or the other party? Um, and what happens after? Um, so, so what kind of termination assistance is the, the customer looking for? If they're going to transition away from you, what, for whatever reason, whether they want to or you want them to, or, or are requiring them to, um, and then yeah, limitation of liability. That's, uh, that's, that's the biggie. Yeah.

Well, it's interesting you brought up what, I'm glad you brought this up as we transition, and hopefully we can get Mike to connect, and if not, I'm gonna be playing Mike slash Gary Peak a momentarily, but Eric, you know, what's the customer's responsibility? Maybe I'll even lean in on Wes a little bit for this, Wes to, to give some thoughts on this because, you know, we're so often, you know, it's about, you know, all are risk as an MSP.

And I think, you know, because majority, I'm not saying all, and probably not, you know, this group is the exception. If you're showing up here to the cyber call, a lot of these people are focused, they have sales engines, they're not solely reliant on referrals only. So there's a concern, I think, but holistically in our space, Wes, of pushing back, like, Hey, that's your responsibility. You know, you're, you know, and, and, you know, so Wes, can you just give a little color to that, please?

Yeah. Point. Well, let's start here. Um, Eric, can you kind of, so you mentioned those words, risk profile and I, I put into chat. We, we talk about that, that term a lot on cyber call. Uh, do you mind kind of defining how you view and look at risk profile and, um, maybe even giving some advice on how an MSP should define that? Is that a working definition? Is that a per client def definition?

Is that sort of almost like a risk appetite statement that is set by the board level and we never go outside of it? And how is it defined? Just talk to us more about that, those, those words, risk profile and what that means. Yeah, so, so it generally is set at the corporate level, not at the client level. Um, now would you bend a little bit for certain clients maybe, right?

But, but in order to do that, you've gotta go to the folks who set that risk profile and, and get their permission to do it. Uh, you know, back in my logic days, um, we had certain things we could do and certain things we couldn't do. And we had this authority matrix that, that said, all right, here's where you can operate, and if you wanna operate anywhere outside of that, then you've gotta go talk to your boss or your boss's boss, or your boss's boss's boss, um, to, uh, to make that happen.

And, you know, I've, I've seen everything. I started really, really small and, and, and sort of ended really, really big on the spectrum of, of size of, of it service providers. And, you know, we did a lot of very, very risky things when we were smaller. And why did we do it? Because we had to, um, because we were, we were sort of the, the mouse running around the feet of the elephant trying to close deals.

And, uh, and without taking on that additional risk, we wouldn't have been able to grow the company. Well, why does that make sense? Well, it's because we had not much to lose. Uh, you know, if, if a 10 person company goes belly up, well, it's very, very sad. But at the end of the day, it's a 10 person company going belly up. If Logicalis goes belly up, now you're talking about a company of 3000 people and investors and, and all sorts of other things.

So, so the, the risk profile of the company is a lot tighter and more narrow than at a smaller service provider. And, you know, we get into it when we talk more about limitations of liability and, and why it's important, because when we're negotiating things like that, I, I used to hear all the time, well, the guy down the street, he'll, he'll, he'll agree to uncapped liability, why won't you? And, and it goes back to the risk profile because we have a lot to lose.

Having a $5 million liability cap from Logic callus is a lot more meaningful than an an uncapped liability from the guy down the street whose business is, may be worth half a million dollars. And, and trying to educate our customers to, uh, to that was, uh, where we spent a lot of time. Yeah, that's really good.

And I, and I can make some correlations here from my, my banking days, and I'm still recovering from, uh, and, uh, you know, we ran into this a lot of times as well, understanding like, what does, when we build our risk profile, that would sort of culminate multiple different ways. For example, I worked, um, at a community bank about a billion dollars in assets. And so there was a certain loan threshold that could be made, um, both for commercial and residential.

So if it's residential, there are certain limits of the height of what you could, you could loan out. So if, you know, Elon Musk came to us and said, Hey, I want to buy, you know, a $150 million home, our bank is gonna say no every time. There's too much concentration risk there, and it's simply above our risk profile. Same with business style lending. Um, even in like the vendor selection process that we would go through.

You know, my bank was very, um, uh, we, we loved taking on some, some risk combined with innovation. We would love to do the, we'd love the ability to do some innovative things. We'd take on some risk and work with younger companies. But, uh, just as another example, I remember we brought on, um, to kind of pitch to us a, a brand new like core banking provider. And long story short, those are the guys that do everything for a bank.

Everything from holding the accounts to, you know, transactions to wires, a CH on and on and on and on. And they're a brand new company and had literally one bank in their portfolio. And I remember they pitched to us, I'm like, I love what you guys are doing. I love how how open this ecosystem is and how it can build on top, but the answer's a hard pass. And he's like, well, why not? You just said everything good. I said, risk profile simply won't allow it.

There's no way I can go to my board and advocate moving this significant, like 90% of what our bank does and what all our revenue's tied to, um, and move over to that, move over to you guys and, and suffer the, you know, the, the potential risk of this thing going south. It would destroy our bank. Um, that was difficult, right? But understanding what our risk profile is, um, is important for all that.

And I also love what you said too, Eric, about when you're a younger company, if you're a younger MSP, you do have the ability to take on some things that are a little bit more risky that someone else wouldn't, and you should use that to your advantage wisely, right? Not do things that are gonna sink you. But this is something I think a lot of larger orgs, and if I can be honest, even a lot of legal counsel I've talked to don't always understand it.

'cause they've never come from a startup mentality. And that startup mentality is, I've got to survive and put bread on the table for this company. And so that does mean that sometimes I just have to take a little bit more risk and do something, um, that I might, might otherwise not do as a, as a more mature established company. And so I love that comment that you made there, because I think those are things that are very important to us when we're thinking about risk profile.

Yeah, and Wess, that's a good point about, uh, going to outside counsel and them not understanding that. And, and, you know, my experience has been largely that outside counsel doesn't really care about that because they don't know about that.

And, and that's why, you know, my role as inside counsel, uh, in-house counsel for a corporation lets me understand the business profile, the risk profile, the customer profile, uh, and, and frankly enables to get more business done than if you're just outsourcing it to the, the law firm down the street. Yeah. So let's tie this back to cybersecurity then. If we could for a minute.

Can you get real practical, Eric, on how, if I'm an MSP and I'm on this call today, and I'm thinking, okay, I think I understand what a risk profile is, but when it comes to cybersecurity, how do I actually define that?

Is that, um, in terms of like certain, you know, Gandalf style, you shall not pass, you know, that I, I I mark, um, in the agreement is that KPIs and thresholds, is that solution deliveries of like, everyone's gotta have a firewall and EDR and SOC as a service, or like, how does that actually manifest Eric?

And can I just throw one thing in there, Wes, to your, to your point, and I, it may be brought up later, but since you're bringing this up now, Eric, can you also, maybe as you think about this, talk about cyber insurance, and let me just give you a context on that. You know, we've asked the MSPs, you know, do you know if all your customers have cyber insurance and the majority don't? And we had, you know, cyber experts on, you know, that sell, sorry, cyber insurance experts on.

And their point is, you know, you are now all of a sudden gonna be the back if you don't backstop, you're the, you're the one that they're gonna go after, you know, as an MSP. So as Wes' question, I just wanted to, if I could just toss that in there Yeah. With, I think it's part of the overall, you know, how do you look At it? Yeah. So cyber insurance is, is of utmost importance, right? And, and it goes back to the customer responsibilities.

Um, does it make sense for you to require that of your customers? I think the answer is absolutely yes. And, and it's important from a, a, a, a security standpoint that what you're doing for one customer from a, a security, from from your own internal security standpoint has to necessarily be identical for what you're doing for every other customer. So for us, those terms, were always non-negotiable.

We wouldn't negotiate any of our internal security policies, our, uh, any sort of disaster recovery, business continuity. Um, we, we just don't negotiate it. And we don't negotiate it. Because if we start negotiating it for one customer and we tweak it, then all of a sudden it doesn't apply to the rest of our customers. We know what our policies are, um, we know how they work. We've gone through all the tabletops, we're, we're, we're, we're okay with everything.

Um, and our customers to a certain extent that, that there has to be a certain level of, of trust there, right? We're, we're audited, um, and we're, we're audited AD naum. Um, I'll tell you how Wes, we, I shared this with Andrew a couple weeks back. We were actually under constant audit by the FDIC. Well, what does the FDIC want with, uh, an IT company?

Well, we had a lot of banking customers and we kept showing up over and over again when the FDIC would do the review of, of their, their insured banks. Um, and finally we came up enough such that they came knocking on our door one day, shortly after I became general counsel and said, Hey, we're here to audit you. We Talked about this on the call before. Yeah, Yeah. And I was like, no, you're not gonna audit us. Get out of here. I I love this part, Eric. Well, what happens if I say no? Yeah.

Well, what happens if I say no? Right? And well, what happens if you say no? Is that when those contracts come up for renewal, guess who's not getting the business? Mm-Hmm mm-Hmm. You're not getting the business. So, you know, for, for six or seven years, we were under constant audit by the FDC. Now that's, that's sort of the, the, the, the shield of it. The sort of, it is we got to tell everyone, Hey, we're under constant audit by the FDIC.

If, if our security policies and practices and procedures are good enough for the FDIC, well they ought to be good enough for you as well. Yes, indeed. We talked about this and, and, uh, if any of you find folks listening today have enough banks under your control, congratulations. Um, the, uh, whoever it happens to be, FDIC, federal Reserve, OCC, one of those guys will determine that they now regulate you, uh, because they said so, uh, what a fun world we live in. Interesting.

And, and Eric, if you could just cap this, Kevin asks any thoughts on requiring clients to carry cyber liability insurance? And I think your answer was in fact, Absolutely. Yeah. Why, why wouldn't you? And, and you know, it, it kind of goes to, you know, again, back to customer responsibilities and, and you know, what's good business versus what's not good business. And, and it's something that took me a really long time to learn.

And because in the early days, like we talked about, you take any business you can get, right? You, you, you basically morph into the customer's risk profile. And if they want you to do something, well, if you need to hit payroll, you're gonna do it. Um, but as you mature, um, you can start to distinguish what's good business from bad business.

And if a, if one of your customers isn't going to carry insurance, or if you're one of your customers isn't going to use MFA, or if they aren't going to, you know, fill in the blank, um, then that might not be good business for you to take. Yeah, yeah. We're hearing that more and more, Eric. Um, you become the back, in essence, you become the whipping post, for lack of a better word, in a defensible po you, you're not gonna be defensible and correct. They don't have cyber insurance.

You are the biggest pockets. Correct. Um, one other quick question 'cause and then we'll move on to some more questions here. Um, Rob asked a great question, thoughts on contract length, Eric, some MSPs do multi-year, others touting month to month thoughts on that? It, it's what works for you? I mean, it's, you have to look at your upfront investment. You have to look at your incremental cost to onboard another customer. Um, you know, we used to be very, very flexible in contract terms.

Of course you wanna lock up a customer for, for as long as you can. Uh, but if they push back and they want to go month to month, well guess what? The proof will be in the pudding if you're delivering for them. If you're doing what you say you're going to do for them, then, then that should be okay. And you can have a really long term customer on a month to month basis.

Now, if you have to invest 50,000, a hundred thousand, a million dollars, um, in, in some cost to onboard this customer, well, you can still go month to month, but there's some penalty or, or some fee associated with, uh, not going a certain number of months. Got it. Okay. So we don't have Mike, we don't have Gary, so I'm gonna do my best here. Eric, talk to us back again about the liability statement or liability clause. I'm gonna, I, I don't wanna always take the assumption.

Everybody knows what that is. Yeah. Could you give us a brief, your, you know, quick reader's diagram, digest A 200 year history of it? Yeah, thank you. That'd be awesome. And then which Case well cited, I hope. And then maybe what should a, you know, what are the muscular Yeah.

So, uh, so, but, but really if you go back a couple hundred years in contract law, um, the, the courts decided that it was okay for a customer to limit its liability or for a vendor to limit its liabilities to their customers, that was okay to put in a contract. Um, and, and, and if you think about it, you, you, you go back to that time and you got the guy selling apples on the corner.

Well, if you sell the apples for a penny a piece, and someone gets sick from eating one of his apples, that could in theory lead to an awful lot of liability associated with that, right? All because of a 1 cent apple. So the judges realize, well, what does that do? All it's gonna do is drive up the cost of everything, unless you can allow a vendor to limit their liability to their customers. So if you, you know, fast forward 150 years, there are two ways to do that.

Um, one is to limit the types of damages that are recoverable in a contract case. The other is to limit the amount of damages that are recoverable in a contract case. Hmm. So, types of damages, what does that mean? That means that generally speaking, the service provider wants to limit the damages recoverable to direct damages. What are direct damages? They're damages that are generally foreseeable, right?

So if you sell something to someone and it doesn't work and they have to replace it, the cost of replacing it is a direct damage. It doesn't include indirect damages, consequential damages, lost profits, a whole laundry list of other things that you see in the big bold type of these limitations of liability clauses. And why doesn't it include those? Well, because they're not predictable. You don't know what you're signing up for necessarily.

Now, the other piece of it is limiting the amount of damages that are recoverable. And that's a, a bit of a more simple thing to understand. It's all right in my relationship with you, if things go bad and you end up suing me, and you end up winning, no matter what the judge says, you're not recovering more than X dollars. That, that, that's generally speaking what it is. So in its simplest terms, limiting the types of damages recoverable and limiting the amount of damage.

Now there's, I'm sorry, go ahead. I was gonna say, just little fun thought exercise for everyone listening. If you, if you go pull up a lot of probably a hundred percent of the contracts you've signed with the vendors you're using, you will see limitations. And probably like what you just said, Eric, like limits of, you know, the annual contract value, something like that. Just go, look, if you've never looked at what you've signed, you will see that exist in probably everything you've signed.

It, it just, it's, it's prevalent for sure. Absolutely. And, and it's prevalent because it has to be, actually one of the, the, the, the part of the law around limitation of liability is that it has to be conspicuous. That's why you see it in all caps. That's why you see it in bold print. Because if it's not conspicuous, then the argument is you don't know exactly what you're signing up for. So, And it's gotta be wing dings. Now if you really want to show up. Exactly.

We were joking chat about all that. Exactly. So, so here's where the lawyers earn their keep, right? It's, it's really easy to pick a number to say, all right, I'm gonna limit my liability to, like Wes said, the, the annual contract value, three times a monthly contract value, a million dollars, pick a number. That's easy, right? Where the lawyers earn their keep is all of the complexities around the limitation of liability, because there's things in there that we call carve outs, right?

Where we will limit your liability to the annual cost of the contract, except if it is for a breach of confidentiality or for indemnification obligations or personal injury or death, which you can't limit anyway. Um, it's those carve outs where it gets really complex, and I'd like to separate it. I like to separate the clause into the types of damages and amounts of damages and have separate carve outs for each.

Because while you might be willing to, to carve out a breach of confidentiality from the types of damages, maybe you don't wanna do it from the amount of damages. So you can allow, uh, for example, payments of lost profits due to a breach of confidentiality, but only up to the amount of the, the, the, the damages kept. Um, so that's, that's possible.

And then we're to add another layer of complexity on top of that, if you get into a, a shouting match with the other side about what's carved out and what's not carved out, well, now you can have super caps. You can say, all right, here's my liability cap. It's a year of services. But if it's for a, an indemnification obligation or confidentiality, maybe it's three times the annual contract value. So you can have those super caps in there as well.

Um, and that's where we, as in-house technology services attorneys spend a lot of time negotiating it because it's really important. And it's important because as soon as you start carving out things from those liability caps, you, you start to neuter it and take indemnification, for example. It's very common to remove indemnification from liability caps or indemnification obligations. Well, most people when they do that, they say, okay, everyone does it.

Well, you have to look at your indemnification obligations now, and if you get a savvy lawyer on the other side, what they're gonna do is they're gonna make indemnification as absolutely broad as they can to have everything fall as an indemnification obligation. Why? Because that's carved out of the limitation liability. And now you're betting your company on an indemnification obligation.

Eric, can you kind of define a little bit more about indemnification and, uh, what that, the classic term, what that really means? Yeah, so, so from a classic perspective, it is, I mean, real world example, uh, your customer, you do something wrong. You, you commit some sort of negligence, your customer is affected. But not only is your customer affected, because then they'd have a breach of contract claim against you, maybe their customer is affected and their customer then sues your customer.

And that is a, it's called a third party claim. Um, and now your customer is having to defend itself from a lawsuit from its own customer, and then they would invoke the indemnification clause. The indemnification clause says, well, if someone brings a third party claim against me, you are going to indemnify me, hold me harmless, cover my legal fees, which is a big one. Um, because as we all know, we live in a litigious society, legal fees get super expensive.

Um, but here's where it gets interesting. So, classically, as you said, Wes, it's for third party claims. A lot of lawyers I see try to make it apply to first party claims. Well, as soon as you have it apply to a first party claim, then you have a simple breach of contract claim could fall under indemnification.

And if that falls under indemnification and you carved that out of a limitation of liability, now all of a sudden a simple breach of contract claim between you and your customer leads to uncapped liability. And oh, by the way, you're also paying your customer's legal fees. And the reason I ask that you, you already intuited where I was going at with this, is, this is part of the me that many MSPs find themselves in, in what we call it perch, a buffalo jump attack, where the MSP is attacked.

Um, they use the bad, the threat actor uses the RMM to deploy ransomware to all of their customers. Now, all of a sudden, this rockets up into the, you know, the stratosphere and importance, especially within indemnification, because you have all of these clients that they're serving, who they themselves have clients.

And so if they're out of work and they are, there's nothing that they can do, uh, and now their contracts are at risk, um, guess who they're gonna go point their finger at is the MSB. Right? Every time. Every time. So what, oh, sorry, go ahead. Please. I was, that's why it's so important to have someone who understands this, negotiate these for you. Um, I, I can't stress, and, and, and yes, I'm biased. I'm, I'm the, the, the technology lawyer.

But, um, but if you're just signing these willy-nilly, if you're just accepting the customer's red lines because they look okay, um, then I think you're doing yourself a disservice. Awesome. Ryan, I'm gonna bring you in here. We, there was a few more things around, you know, liability, but I think we beat that up pretty good liability clauses. But just real quick, um, in terms of the poll, interesting here, guys, that as the, the MSPs out there, you know, we've got a few hundred here, um, live.

They've said, um, you know, poll one, I have legal concerns around my MSAs. Uh, 78% said yes. So that's, that's, that's pretty significant that, uh, Tony, uh, asked us to put up a question. Has an MSP ever had legal action taken by client so far? No, no one has. Oh, there's one. Um, and then I also put up a poll per Dustin, kind of, I thought it was a good one, and Dustin, I'm kind of paraphrasing it here. Um, which is kind of like, have we had to use our MSA to in a dispute with our client?

And, uh, um, that one keeps, that one's kind of dancing back and forth here, but, uh, appreciate, uh, the, uh, again, the, uh, insights and thoughts from the audience. So, Ryan, let me let you take over. You, you know, as a CSO of a public company, probably this is fairly, I don't wanna say near and dear to your heart, but something probably you deal with quite a bit, um, in your role. Yeah, for sure.

We, I, I read way more legal contracts than I would ever have thought that I would, being a security practitioner. Um, I do wanna, I do wanna dig into the limitation of liability, just real quick. Sure. Take a good detail. Right? So, you know, west out outline the buffalo jump, which is an MSP being attacked in order to compromise their customers. And we have this limitation of liability, uh, clause that has carve outs. There's certain situations in which they apply and they don't apply.

Um, and then we have a bunch of MSPs that are kind of sitting here and being like, okay, well, like I'm, I am working on improving my security posture, or I have achieved some level of security posture that I think is acceptable. How, how does that limitation of liability work for an MSP who might be the proximate cause of, of a breach that affects a customer when they do or do not have kind of an effective security program in place?

Does, does one lead to like a, a claim of negligence and lack of due care, whereas the other one, there's a harder, there's a harder claim there. Like, how does that impact the liability clause depending on where you are in your, So, so the, the legal term is what's the duty of care, right? What, what duty does the managed services provider owe to their customer?

Um, and that is, you know, yet another thing that we negotiate all the time in our contracts, if, if you are an MSP and you are accepting your customer's contracts as, as the, the governing body for your relationship, I can nearly guarantee you that you are also accepting liability for anything that might ever possibly kind of, sort of maybe happen during the course of your relationship.

Um, if you're looking at a well crafted, well negotiated warranty, it's going to talk about a standard of care. And the standard of care can mean a whole bunch of different things, right? It could mean that you agree to provide the services according to industry standards. You know, what does that mean? I don't know. You can let a judge figure it out. Now, you can also agree to, well, maybe you can, you can agree to provide the services to the highest degree of industry standards.

Well, that's even more nebulous, you know, what does that mean? So, I hate to give you another, it depends answer. I hear you were gonna say it depends, But it, but it really depends. It depends. What is the standard of care that you, as the MSP have negotiated with your customer? And how does that standard of care apply to limitation of liability? Because I didn't mention it before, but another one of the classic carve outs for a limitation of liability is a breach of warranty.

And a breach of warranty. All that is, is the standard of care. So if you are, if you agree to carve out from your limitation of liability, a breach of warranty, and in your warranty you've agreed to, to give them everything under the sun, then you're in trouble. Because now not only do you have a breach of warranty, but you've got uncapped damages, Right? Yeah. So the takeaways there are, you know, in your MSAs, make sure you're defining your, your warranty or your duty of care, right?

And then two, you didn't really say this, but I'll say it, if you have actually begun building a security program and it's documented and you can prove that you're doing it, that actually can be quite, uh, def, that can put you in a more defensible position when a claim comes up, because you can show, and you can demonstrate, um, that you have been attempting to implement a standard of care that is industry standard or above industry standard, which would probably be very easy to prove right now in our, our current landscape.

Uh, and, and when the judge figures it out, um, that can actually be to your favor. So do, building that security program can actually put you in a bit more of a defensible posture when there is a claim, even if there is a requirement for some interpretation. Would you say that's fair? Absolutely fair. Yep. So then let's, let's talk about, okay, I've built this great security program for me and I'm pushing it out to my customers, and we've defined duty of care.

We've, we've agreed the limitations of liability, and we say, okay, now we need to roll out a new capability. We need to turn MFA on for email. Mm-Hmm. And for VPN, and the customer says, no way. I'm not doing that. Mm-Hmm. Um, how, how big of a risk is that? Is, is that, is that the customer's risk? Is that the MSP's risk? Is it shared? Like, how does that work?

How, how should the Ms P think about, you know, that there's the practical side, which is if they say no, and I force it on 'em, they might leave. I might lose their business. Yeah. But, But is that really all their risk, or am I retaining some risk too?

So you would be retaining some risk if that were to happen, but, but that's why it's good to have these conversations in the contracting phase when you're drafting the MSA, when you're drafting your statements of work, who is responsible for what if the customer's responsible for MFA, then the customer's responsible for MFA, but it's gotta say that in the contract, right? And, and, and, and that's why this is all so important to, to have the conversation upfront.

You know, the, going back to the poll question, you know, have you ever gotten involved in litigation? You know, I, if, if it's done right? If you negotiate properly, you negotiate these documents and you put 'em in a drawer and you forget about 'em for forever, right? And you ne when it comes time to pull out a contract and look to see what it actually says, it's too late.

You know, you, you've already jumped the shark and, and you're already involved in a situation that no one wants to be involved in. Because when you get, when you get to that point, it's, uh, it's, it's just too late. So let me curve ball this, right? I've already, I've already, I have an MSA in place with the customer. It's been in place for a year and a half. I get another year and a half term on it. Yep.

There's no incentive for either party to renegotiate at this point, but they're telling me no, what do I do knowing that I haven't explicitly said that it's the customer's responsibility. How do I document that in a way that protects me legally, even though it might not be part of the MSA? Um, so, so a couple things. One, even though the, the other party, and you might not be incented to, to change the, the MSA, it never hurts to ask.

Um, we have had, in, in, in my career, we have had some wholesale changes to our risk profile, and they necessarily come up in the middle of statements of working in the middle of MSAs. And we've had to go to our customers and say, Hey, Mr. Customer, look, I know this is what the contract says, but here's what we'd like it to say. Here's why we'd like it to say this. And we've actually had really good success having reasonable conversations with our customers around that.

Now, if they won't do that, then you document, document, document, and, and that's part of your, your governance structure, um, and part of your risk management structure. Um, so to, to note that and talk to your insurers about that, and to see if a thing like that would be covered under insurance if, if that situation occurred. Okay, well, we're playing word bingo and you just hit another bingo word, Dilla, uh, governance. D describe for us what you mean when you say governance.

So governance means a lot of different things to a lot of people. And you know, as as lawyers, we sort of concentrate on one narrow portion of governance, and that's, that's risk management. But, but if you look at governance in general, it's, it's making decisions that are repeatable and structured, um, that, that allow it to achieve their goals, right? And it's a combination of, like I said, risk management, which is, you know, my, my portion of it, but also performance management strategy.

You know, what value does, does it bring? And it's, it's melding all of these things together. So in a relationship where I'm providing the IT for the company, is governance my responsibilities, the MSP, or is it the responsibility of the customer? And what's my role in helping them exercise that governance? I think it's shared. Um, and it depends to the, on the extent to which you're delivering it for that customer.

You know, are you doing it really from afar or, or on one end of the spectrum or on the other end of the spectrum? Are you there 100% outsourced IT solution? If it's toward that end of the spectrum, I'd say that you've got a big role to play in governance. If you're at the, the former end of the spectrum, I'd say maybe it's not so much. Okay. Um, I have a bunch of more questions, but I'll, I'll yield to Wes, let him, uh, ask you. I feel like I'm on the stand. You are, You are.

And this is 2,700 MSPs right now. And, and this is recorded, I'm just saying, but again, we go back to, uh, you know, your honor, this guy that I saw on Crowdcast told me this thing. Exactly. Hey, Wes, as you're kicking off, I just wanna let everybody know we put a poll up. This will be interesting, Wes, in the next few 10 minutes about, Hey, now that you heard what Eric said, um, are you considering adding verbiage to your agreements that your clients need to have cyber insurance?

Let's see if people change their mind, if, if, if, you know, if they're adding it, et cetera. So that's up there as well. So, great job, by the way, uh, Ryan and Eric, that was fantastic. Good. Wes? Yeah. So, uh, one question I saw coming in on chat, I want to zoom in on this a little bit too. I think Mylan is the one that asked this question.

So MSPs are very famous for talking about, you know, if the, the client doesn't agree to whatever I'm pitching, you know, they're gonna sign up, you know, we, we accept the responsibility clause, whatever you want to call that. Um, what do those look like in, in, uh, when the medal hits the meet, so to speak, and, uh, a breach occurs and they wanna pull that waiver, uh, out? Like, is that enforceable? What does it look like? Give us some thoughts. Well, you probably know my answer already.

It, it depends, right? It's, uh, it depends on what it says. Um, you know, and again, it goes back to good business versus bad business. If it's something that's, you know, somewhat minor, you're willing to look past, you know, then, then maybe you take the business and you assume the risk.

If, if what you're talking about is, well, we don't have a lock on the door of our data center, and you want them to sign a waiver that says, you know, you're not responsible 'cause they don't have a lock on the door of the data center. I'd think twice about doing business with that customer. Hmm. Yeah. I mean, and this, this goes into, um, what we've been talking about a lot on the cyber call of what, what, what is a good customer and which ones do you walk away from and do not take.

And, uh, I do know that we often talk in this space that, you know, boy, we've got, um, uh, we've got all of these, these, you know, no barrier to entry. Anyone can now call themselves an MSP, but the reality is, you know, the reward that you get for growing your, um, client base and becoming mature in your practices is that there are some that you just say no to, and you let someone else go take that risk.

Uh, and maybe that's a current client that you have now, and it's gonna hurt a little bit to get rid of that client from a revenue perspective, but it needs to happen because they're just going to cause more problems to you, um, than the revenue they provide at the end of the day. Right. And those are hard decisions, but the reality is those are, those are calls we have to make, right, Eric? Yeah, they definitely are. And, and, and I've had a lot of those, those conversations in my career.

You know, one that sticks out to me, it was a a nine figure deal. We were working on where the, the customer wanted some concessions that were pretty far outside of our risk profile. And, uh, we went back and forth and back and forth for a really, really long time before deciding what to do. Yeah. We, uh, I can't talk about them, but we've, we've had some similar ones as well at Perch when, um, we have a few Fortune five hundreds that use perch.

And, um, I, I was in the middle of those negotiations and sometimes they ask for some wild, wild things that are in there. Yeah. Um, that are very scary. Um, and sometimes it's not even like the liability, but it's like the expectations and requirements or like the ability to audit books. And it's not just books, but audit, like any practice at all. And you just, your eyes pop open and be like, wait a second. You realize what they're asking us. Yeah.

Um, and speaking of that, can you talk to us a little bit about like right to audit and what that should look like? 'cause I see Ryan nodding his head, the CISOs on the call right now. We understand that gets us, that scares us every single time, doesn't it, Ryan? So, Eric, Aaron. Well, It's funny, right? We want it in every contract that we're asking a vendor to sign, but, but we're nervous of it when it comes our way. So Yeah, exactly. And, and, and we talk about that a lot actually.

Not, not a whole lot, but, but it gets discussed and, um, you know, it it, it started with, you know, right, to audit your books, right? To audit your audit, your, the financials associated with the, um, with the deal. Um, that in our mind is always okay, provided that you put the parameters around it, you know, the time, place notice, things like that.

Um, when you get customers that want to audit your internal audits, um, that, that want to audit, you know, your your sock compliance and, and ISO and, and all of the other stuff, that's when it gets, uh, a lot more touchy. Um, we say no more than yes, usually. Um, and, um, and, and usually that's okay.

What we, what we've ended up doing, um, oftentimes to, to make our customers feel better, um, is that we would put them on the phone with our VP of information security and compliance, and he would have a conversation with the, the, the C-I-O-C-C-T-O CSO from our, our, our potential customer organization. And they talk for an hour or two hours or three days or whatever it took to, to get them comfortable. Um, but in terms of auditing documents, we were usually pretty averse to it.

Yeah, that's well said. And, and that's largely purchase stance as well, the way that we, because I just don't wanna sign myself into these kinds of things and, you know, imagine a systemic event happens and I've got 15, 20 different, uh, clients all determining right now is when they want to go through an audit with us and, and, you know, even come on site or whatever, stuck a nightmare. You just don't wanna ever have happen.

And that's where I think due diligence packages are very, very helpful that give insight into the risk management process that you have in place. And this is something I think MSPs should really be thinking more about in 2021, is like, how do I give my clients insight into the things I'm doing? For sure. You know, a SOC two is helpful in that regard, but it should be more than a SOC two, right?

Like what, what kinds of things should an MSS p be producing to their clients that show evidence of, uh, proper risk management involved in in their own practices? Yeah. And, and Eric with, uh, Ryan, I was gonna say with that, like if you're doing this as an MSP, what a differentiator, right? Hey, we're gonna proactively show you what our security programs like, Ryan, you are gonna say something, please. Yeah. I was gonna go into the right to audit, right?

The other area of Right to audit comes in a lot is if there is a breach, right? Correct. If there is a, uh, you know, uh, what we would consider a security breach, not a, not a legal breach necessarily, right? Sure. There's a, there's a clause that says, you know, you know, we get this all the time from, from big companies like West Side, fortune five hundreds.

If there is a breach, then we have the right to call in whatever auditor we want to come in and look in every cabinet and every drawer in your house. And, And, and you as the MSSP might have to pay for that. Yeah. Um, talk to, talk to folks about how to think about, you know, negotiating out of that too. Because that can be, that can be really tricky because you're like, alright, well now we're talking about a situation where we've determined that I'm clearly at fault. Mm-Hmm.

And now you want to audit, but say I have a hundred customers and they all want a different auditor. Yeah. Right? How, how can you manage that to a good outcome that you can live with for your own risk profile? So, so let me put another layer on top of that is that a lot of times in these, these right to audit situations, they not only wanna audit you, but they wanna audit your vendors as well. So, so now you have to look at, all right, well, what do my agreements with my vendors say?

And am I signing up for more for my customers than I get with my vendors? Um, and if, if the answer is yes, then you're in trouble, right? If, if you agreed to your customer that they can audit your vendors, but you haven't agreed with your vendors, that your customers can audit them, then now you're in a, a breach situation that, that no one wants to be in.

But we are, and, and historically had been more flexible with audits, associated with breaches, um, you know, knock on wood, it, it didn't happen during my tenure there. Um, we never had that situation, whether it was by, by skill or by luck, I won't comment. Um, but, um, but, but it, but it happens and, and you have to position it in such a way such that, you know, number one, to the extent possible, it's covered by your insurer.

Um, and I know we talked about insurance so that, you know, so we're blue in the face here, but, but that's really, really, uh, a, a big thing there. Um, and, and no, we won't, we we would never allow, you know, a hundred different auditors from a hundred different customers in there. We would negotiate that away and, and to a, to a point that makes the, the customer comfortable. Um, but also makes it feasible for us because putting the, the cost aside, it's gotta be practical. Yeah.

Um, and, and allowing the, each one of your customers, the choice of auditors just isn't practical. The practicality, the pragmatic, the reasonable thing there. Right? Exactly. So, so when I think about those clauses, I think, well, what's reasonable, it's reasonable for them to want some sort of third party audit post breach to tell 'em the reality of the situation. So one of the tactics I use is, here are three firms that I might choose to use.

You either agree that one, that any one of these three is fine. Or if you want a separate one, you must pay everything. Mm-Hmm. Relating to that audit, including time and materials on das side. Right. And generally they're like, yeah, I'm okay with one of those three. Yeah. Hey, before we go, Wes, can we rewind to your question? 'cause I thought it was really important. Um, 'cause it's really applicable. Oh yeah. I think what that question was. Yeah.

So, um, and this may be the final one and we can answer any other questions that may have come in from the audience, but, um, yeah, just from a due diligence perspective, how, what should MSPs be thinking about that they need to provide, uh, to their clients to prove that they have adequate risk management in place? Obviously a SOC two is very, very helpful because it's third party attested, all that kind of stuff. Yeah. But, but what else should they be providing?

You know, one of the most successful things that I mentioned a few minutes ago that, that we would routinely provide is access to our people. Um, and, and we would provide as much access to our people as, as it took to, to get them comfortable. Um, I mean, you know, look, we've all seen SOC two audits and they aren't that specific. They're not that good. They don't really tell you that much. Right.

You can glean a lot more from a 15 minute conversation with the MSP's personnel than you can by thumbing through a 30 or 40 page SOC two audit. And I don't know if you guys would agree with me or not. I I agree. And honestly, the, the hesitance that we get of people getting on phone calls, like I say all the time, you wanna do vendor due diligence, start with a half hour phone call with your vendor. Absolutely.

You need to send 'em a, a questionnaire or get their SOC two document, just spend 30 minutes with 'em. You're gonna find out if they're full of crap or if they're walking the walk. Yeah. And, and frankly, we, as, as a service provider, we would get these, in some cases, 200 page diligence questionnaires, particularly from our financial services clients. Um, It questionnaires And, and oftentimes we wouldn't do it if, if, if they wanted us to do it, they could pay us to do it.

Um, but we wouldn't go through that expense, uh, that pre-sales expense, um, on the, the if come that they might maybe do some business with us at some point in time. Hey, so we got a few minutes here, Eric. Well, I look at a few final questions. What's next in your chapter? I'd love to hear what you're doing and then let me just pull up a question or two in closing here. Yeah, thanks. This is Fantastic. So I am, uh, going down the path of, as, as lawyers like to say, hanging out a shingle.

Um, and, um, opening my own practice during, at, at which I will provide fractional general counsel services to IT services providers, MSPs, MSPs, um, and as we talked about a little bit earlier, that's very much different than outside counsel services. Right? The, my goal is to, to a certain extent become embedded in the organization, understand who they are, understand what their risk profile is, and allow me to manage that risk for them.

Whether that means, you know, 15 hours a month or 90 hours a month or, or more. Um, that is, uh, that is my goal to provide those fractional general counsel the same types of, of general counsel services I was providing to, you know, logis for so long do for companies that don't need a full-time general counsel, but could certainly use the assistance of a a, of general counsel. Very cool. I'm excited for you, my friend. Thank you.

So, so, so a a closing comment here, Ryan will be reaching out to you shortly. No, um, it's, uh, will, will letters of under will, letters of understandings with clients, um, work like for minimum standards with backup or security limits. The MSA liabilities, this comes from Eric. Um, I'm not exactly sure what that means, but it sounds like sort of a, a step down from a contract. Um, if it's binding, um, then it might work. If it's not binding, then it won't work.

Um, I'm not a big believer on starting projects based on a letter of intent. Um, I think that's sort of a, a, a lazier way to go about things. Um, I would rather, uh, the, the, there, to me, there's not a good reason to not document the relationship upfront before you expend any effort from either side. Got it. And then closing, Julian asked, you know, he's like, when we were going back and forth with changes to contract language or maybe in mid, mid-contract.

Eric, is there any best practice or thoughts, and I think you may have said just have an open conversation, but to change clauses in the current MSA? Uh, yeah, it's, it's have the open conversation and, and, and don't just talk lawyer to lawyer. Um, have, have your business folks involved as well. Have your sales folks involved, your account management people, um, who can maybe translate a little bit better for the lawyers. Lawyers deal in contracts all day long. Right.

And it's not a big deal to ask a lawyer to amend a contract. Um, however, if it's, if other folks are involved and they don't quite understand what's going on, then it might be a more difficult conversation to have. Um, so my advice is to have open and honest conversations across all levels of the organization. Probably save you a boatload of money too, Eric, right. Having that conversation first. Absolutely. Absolutely. I mean, lawyers are expensive, right? Especially outside counsel.

Um, and to, to get as much done upfront as you can is always in your best interest. Fantastic. Well, it's fantastic. Uh, really, really appreciate you coming on, Eric, Russ closing comments. We're right at two. I know you love to go on and on at two o'clock, so give us some closing thoughts There. Uh, no, this has been helpful, right? And the, the reason we have these recorded is so you can hold Eric accountable. No, I'm, I'm teasing.

Uh, the reason we have it recorded is because, um, if absolutely, please take this and share it with coworkers. Share it with, you know, your CEO business partners. Share it with others in your peer groups, um, because these are things that definitely I think everyone needs to hear to give it a better understanding of, um, you know, what, what, what kind of risks do I take from a, a contractual point of view. So it's really good.

And there are a bunch of questions coming in over, Eric, what's your, uh, what's your email? I don't know if you can pop in your, uh, email here in the chat as well. Yeah, I, yeah, put that in there, Eric. I also put in, uh, your LinkedIn and the call to action in the bottom. And please yeah, put in your email for anybody that would wanna reach out to you as well. Um, it's typically a slight delay. There it is, eric@tils.com to make Ryan clo. Yeah.

Closing thought from you and we'll let everybody go. Let's just let everyone go. I mean, was a great conversation. Thanks. Alright everybody, have a fantastic week. We'll look forward to seeing you next week and make it a great day. Take care. I dunno if this will show.

Related Videos