Blog Details

The latest news, updates and insights from our technology specialist lawyers at Law 365.

News & Press Releases Employment

Third-Party Harassment and the Heightened Preventative Duty: What MSPs and Tech Employers Need to Know

Third Party Harassment Heightened Preventative Duty
Contents

    As we know, employment law in the UK is undergoing significant changes over the next year or so. There is going to be a decisive shift regarding workplace culture and harassment protections.

    What MSPs and Tech Employers Need to Know 

    Legislation regarding harassment changed a few years ago but now further amendments are coming down the line as a result of the Employment Rights Act 2025 which raises the bar even further for UK employers. For Managed Service Providers (MSPs) and technology companies, two impending reforms demand immediate attention: the re-introduction of direct employer liability for third-party harassment, and the strengthening of the statutory defence from taking "reasonable steps" to taking "all reasonable steps". These changes are coming into effect soon, at the end of October 2026.

    The Legal Shift: Third-Party Harassment and the Higher Legal Threshold

    Under the previous statutory framework, employers were tasked with taking "reasonable steps" to prevent sexual harassment. The Employment Rights Act 2025 significantly broadens and toughens this standard in two distinct ways.

    First, it reinstates full statutory liability for third-party harassment across all protected characteristics, including sex, race, disability, and sexual orientation. Employers will no longer be insulated when staff face discriminatory harassment from external individuals such as clients, contractors, suppliers, or end-users.

    Second, the threshold for avoiding liability for acts of harassment has been elevated. Employers will now be required to demonstrate that they took "all reasonable steps" to prevent such conduct. In legal terms, this is a markedly higher hurdle; an employer can no longer point to off-the-shelf policies or historic training sessions to discharge their duty if further practical, preventative interventions could have been implemented.

    Specific Risk Exposures for MSPs and the Tech Sector

    While all employers face heightened accountability, MSPs and technology firms operate in delivery environments that inherently generate elevated risk:

    • Engineers Deployed on Client Sites:

    MSP field engineers, infrastructure consultants, and deskside technicians frequently work on customer premises or have regular client interactions where client culture, behaviours, and supervision are outside your direct day-to-day oversight.

    • Remote Support and Helpdesk Interactions:

    Helpdesk agents and tier-one support technicians are on the frontline of customer frustration. High-pressure ticketing systems, outage resolutions, and remote desktop access can expose staff to abusive, derogatory, or discriminatory commentary from client personnel.

    • Informal Digital Communications:

    Tech sector collaboration frequently relies on informal platforms such as client Slack channels, Microsoft Teams instances, and shared ticketing systems. These environments can quickly blur professional boundaries, leading to inappropriate conduct that often goes unmonitored until an issue escalates.

    • Power Asymmetries in Commercial Contracts:

    Small-to-mid-sized MSPs may fear challenging or alienating high-value enterprise accounts, leading to internal reluctance when junior engineers report inappropriate treatment by key client stakeholders.


    When examining whether an employer has taken “all reasonable steps”, tribunals will look specifically at whether the provider actively anticipated these operational dynamics rather than merely reacting once an incident occurred.

     

    Mitigating Exposure: Practical Steps for Tech Leadership

    To satisfy the "all reasonable steps" standard, tech employers must adopt an active, documented risk-management approach that bridges internal HR policies with external commercial agreements.

    1. Conduct a Formal Harassment Risk Assessment:

      Assess where your technical staff interact with third parties. Map out vulnerabilities across on-site visits, remote helpdesk triage, vendor events, and collaborative messaging tools. Maintain this risk assessment by conducting regular reviews of the way you operate as a business and update the risk assessment appropriately.

    2. Embed Protections in Client Contracts (MSAs) and supply chain agreements:

      Commercial contracts and Service Level Agreements should explicitly include mutual zero-tolerance commitments regarding harassment and discrimination. MSPs should reserve the right to rotate or withdraw staff from a customer environment without commercial penalty if a client fails to uphold professional standards. Think more generally about your supply chain and acceptable use policies to ensure all risks of actions of harassment are mitigated.
    3. Establish Clear Protocols for Escalation:

      Frontline technical teams need accessible, safe reporting pathways for incidents involving clients. Empower your engineers to disengage respectfully from abusive client calls or remote sessions without fear of disciplinary pushback or missed SLA metrics. Operate and maintain a culture where staff can protect themselves and speak up to management without fear of sanction.
    4. Deploy Sector-Specific Anti-Harassment Training:

      Standard, generic harassment training is rarely sufficient to meet the "all reasonable steps" test. Deliver tailored training scenarios addressing remote ticketing abuse, cross-company communications, and client-site boundaries.
    5. Implement Regular Check-ins for On-Site Staff:

      Ensure team leads conduct structured check-ins with engineers embedded in client teams, explicitly inquiring about working relationships, site culture, and team safety.

     

    By treating the "all reasonable steps" requirement as an operational imperative rather than a mere compliance checklist, MSPs and tech businesses can insulate themselves from tribunal liability while creating a genuinely safe working culture for their technical talent.

    In preparation for these changes Law 365 have created a risk assessment to ensure 'all reasonable steps' have been considered. To request a copy of this contact our team.