Article

Your supplier had a cyber incident: what do your contracts allow?

21 September 2026

Make an enquiry
Young programmer and female IT professional reviewing documents together

Businesses across Herefordshire, Shropshire and the Wye Valley are increasingly reliant on third-party providers to keep operations running. As a result, a cyber incident affecting one of your suppliers can quickly become your problem too.

A breach involving an IT provider, payroll bureau, hosted software platform, marketing agency or outsourced service partner can have immediate commercial consequences, from downtime and delayed orders to missed service levels and urgent questions about whether sensitive information has been compromised.

For organisations that depend on connected supply chains and outsourced services, the impact can extend far beyond the affected provider. A cyber incident may disrupt production, delay customer deliveries or prevent access to business-critical systems.

In that moment, your contract is either a practical toolkit or a document that offers reassurance but little leverage. A targeted review of supplier and customer contracts can help ensure you have the right protections in place, including prompt notification, meaningful support, appropriate liability provisions and the ability to exit arrangements if risk becomes unacceptable.

Key areas to review

Practical areas to check include:

  • Security obligations: are there clear minimum security standards, and do they reflect the sensitivity of your data and reliance on the service?
  • Incident notification: how quickly must a supplier notify you, and what information must they provide about the incident, its impact and mitigation measures?
  • Cooperation and remediation: are suppliers required to support investigations, recovery efforts and customer communications?
  • Audit and assurance: can you request evidence of security controls or independent assurance without renegotiating terms under pressure?
  • Business continuity: are there commitments around resilience, backups, disaster recovery testing and restoration times?
  • Liability and caps: do liability caps adequately address cyber incidents and data breaches where exposure may be highest?
  • Termination and step-in rights: can you exit or transition services quickly if confidence is lost, and can you recover your data in a usable format?
  • Back-to-back protections: do your customer contracts reflect the protections and commitments you can enforce against suppliers?

A practical contract review

If your business depends on software providers, IT partners, outsourced operations or managed services, reviewing key supplier contracts can highlight where you currently have leverage and where protections may be lacking.

A focused review can identify priority amendments and strengthen future procurement and renewal negotiations, helping you prepare before the next incident occurs. It can also help you respond confidently when customers, insurers or regulators ask how cyber risks are being managed.

How can we help you?

Related articles

View All