Third-Party Cyber Risk: The Contract Controls That Actually Do Something
By the Legal Cyber Academy editorial team ·
What third-party cyber risk contract controls actually do
Third-party cyber risk contract controls change outcomes only when each provision carries a deadline, a named addressee, and a consequence. The clauses that do work are breach-notice provisions computed backward from the regulator's clock, audit rights exercisable without vendor consent, security addenda locked to a version-dated control set, security indemnities carved out of both the consequential-damages waiver and the aggregate liability cap, and deletion obligations backed by officer certification. The rest is decoration.
Start from the clock you are on, not the one the vendor offers
A vendor notice provision is not a standalone term. It is an input to a regulatory deadline that runs against you, and it fails whenever the vendor's outer limit equals or exceeds your own. Four clocks, all different:
SEC-regulated firms. Regulation S-P, as amended in 2024, requires a covered institution's response program to include written policies and procedures reasonably designed to require oversight of service providers — "including through due diligence and monitoring" — and to ensure that service providers "[p]rovide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider." 17 C.F.R. § 248.30(a)(5)(i). The institution must then notify affected individuals "as soon as practicable, but not later than 30 days." § 248.30(a)(4)(iii). Compliance ran 18 months (larger entities) and 24 months (smaller entities) from Federal Register publication on June 3, 2024 — December 3, 2025 and June 3, 2026. Both dates have passed.
One qualifier matters at the drafting table, and it is the opposite of what the rule is often said to require. The proposal would have mandated a written contract obligating service providers; the Commission dropped that at adoption, reasoning that smaller institutions "may not have sufficient negotiating power or leverage to demand specific contractual provisions from a large third-party service provider." Regulation S-P Adopting Release, Exchange Act Release No. 34-100155, at 71-75. So the rule does not order a 72-hour clause into your contract. It requires your program to be reasonably designed to produce that notice, through oversight, due diligence and monitoring. The clause is the ordinary way to evidence it — but the obligation, and the examination finding, sit with you rather than with the vendor.
NYDFS covered entities. 23 NYCRR 500.17(a)(1), as amended by the Second Amendment effective November 1, 2023 (compliance with the amended § 500.17 required from December 1, 2023 under § 500.22(d)(1)), requires notice to the superintendent "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred at the covered entity, its affiliates, or a third-party service provider." Your 72 hours can begin on someone else's network. A contract giving the vendor 72 hours to reach you leaves you none.
Non-bank financial institutions under FTC jurisdiction. The FTC Safeguards Rule requires notice to the Commission "as soon as possible, and no later than 30 days after discovery" of a notification event involving at least 500 consumers. 16 C.F.R. § 314.4(j). "Customer information" is defined to include records "handled or maintained by or on behalf of you or your affiliates." § 314.2(d). A vendor's incident is your notification event. Check the regime before you rely on that clock: banks and credit unions answer to the banking agencies' GLBA security guidelines, and SEC registrants to Regulation S-P above.
HIPAA covered entities. A business associate must notify "without unreasonable delay and in no case later than 60 calendar days after discovery." 45 C.F.R. § 164.410(b). The covered entity's own outer limit is also 60 days, measured from its own discovery. § 164.404(b). Whether those two periods run one after the other or on top of each other turns on agency. Knowledge is imputed to the covered entity where a breach is known, or would have been known through reasonable diligence, to "any person, other than the person committing the breach, who is a workforce member or agent of the covered entity (determined in accordance with the federal common law of agency)." § 164.404(a)(2). If your business associate is your agent, its discovery is your discovery, and a vendor clause set at the full 60 days can consume your entire period before anyone tells you anything. If it is not your agent, your clock starts when it notifies you. That makes the agency question a control question — decided by how much direction the contract gives you over the work — and it decides whether your clock started two months ago.
Two more. Florida requires a third-party agent to notify the covered entity "as expeditiously as practicable, but no later than 10 days following the determination of the breach of security or reason to believe the breach occurred." Fla. Stat. § 501.171(6)(a). And under the GDPR the controller has 72 hours (Art. 33(1)) while the processor owes notice only "without undue delay after becoming aware" (Art. 33(2)) — with no outer limit whatsoever. The GDPR does not fix processor timing. Your contract has to.
"Without undue delay" fails for three separate reasons
First, it has no number, so there is nothing to breach until the delay is provably undue — a standard you litigate after the harm. Second, it usually attaches to the wrong trigger. Clauses conditioned on a "confirmed breach of Vendor's systems resulting in unauthorized acquisition of Customer Data" let counsel argue for weeks that confirmation has not occurred. Third, it is addressed to nobody. A notice provision routing to a support portal or a generic legal@ inbox will not reach the person who has to decide about a 72-hour filing.
Draft the clause with four elements: a trigger set that includes reasonable suspicion, not just confirmation, and reaches incidents at the vendor's subprocessors; an hour count that leaves you working room inside your own deadline (24 hours is the common landing point when your outer limit is 72); a delivery method naming individuals and phone numbers, with email as backup rather than the primary channel; and a content minimum — data categories, affected record counts or best estimate, systems involved, containment status. Then add a continuing-update duty. NYDFS supplies the model language: covered entities "shall have a continuing obligation to update the superintendent with material changes or new information previously unavailable." 23 NYCRR 500.17(a)(2). Put the same duty on your vendor, because the first report is always wrong.
A security addendum is a control list until you make it an obligation
"Vendor maintains an information security program consistent with industry standards" creates no obligation capable of breach. Neither does an addendum the vendor may "update from time to time in its sole discretion," which converts the entire schedule into a unilateral option.
Three fixes. Attach the control set as a version-dated exhibit and prohibit amendment that materially reduces protection without consent. Strike "commercially reasonable efforts" from control obligations — efforts language is for outcomes outside a party's control, and configuration of the vendor's own systems is not one of them. And add an affirmative duty to notify you of any material degradation in the program, which gives you a fact to act on before an incident.
Two statutory hooks are free. Where a business sells personal information to, or shares it with, a third party, or discloses it to a service provider or contractor for a business purpose, California requires the agreement to obligate the recipient to "provide the same level of privacy protection as is required by this title" and to notify the business "if it makes a determination that it can no longer meet its obligations under this title." Cal. Civ. Code § 1798.100(d)(2), (4). HIPAA requires the business associate contract to provide that the associate will "[r]eport to the covered entity any security incident of which it becomes aware." 45 C.F.R. § 164.314(a)(2)(i)(C). Security incident is materially broader than breach; drafted well, that clause gives you visibility into failed intrusions and anomalies months before anything becomes reportable.
Note what NYDFS actually requires: 23 NYCRR 500.11(b) obligates covered entities to maintain policies including "relevant guidelines for due diligence and/or contractual protections." The regulator mandates the policy, not the clause. Examiners therefore test your executed contracts against your own written standard — which means a policy more ambitious than your contract portfolio is an exam finding you wrote yourself.
Audit rights that can actually be exercised
Most audit clauses are unexercisable by design: annual cap, sixty days' notice, at your sole cost, only during business hours, only on a showing of material breach, and satisfiable by the vendor's completion of a security questionnaire. Every one of those is a veto.
The GDPR sets the benchmark for what an assessment right looks like when it means something. Article 28(3)(h) requires the processor to make available all information necessary to demonstrate compliance and to "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." Two features matter: inspections are named separately from paper audits, and a third-party auditor you designate counts. California is thinner but points the same way, granting the business rights to "take reasonable and appropriate steps to help ensure" the recipient's use is consistent with the business's obligations. Cal. Civ. Code § 1798.100(d)(3).
In a negotiated agreement, ask for the artifacts rather than the ritual: the complete SOC 2 Type II report including management responses and the full exceptions table, not the summary or the certificate; a bridge letter covering the gap between the report period and today; a written remediation plan with dates for each exception; and the executive summary of the most recent penetration test. Then add an incident-triggered right that suspends the annual cap, shifts cost to the vendor, and permits interviews with the named security officer. And exercise the right once in the first year on a routine basis. Unexercised audit rights atrophy — the vendor learns you do not use them, and by the time you need one you are asking for a favor. Where the audit turns up evidence you may need later, sequence it against the questions covered in privilege over incident response reports.
The limitation of liability that eats the indemnity
The security indemnity you negotiated for three weeks is worth whatever survives the liability section, and courts read the carve-out list as the operative text.
In Copart, Inc. v. Sparta Consulting, Inc., 339 F. Supp. 3d 959 (E.D. Cal. 2018), the IT services agreement's limitation clause opened: "EXCEPT FOR A BREACH OF A PARTY'S OBLIGATIONS UNDER SECTION 11 OR SECTION 12, INDEMNIFICATION OBLIGATIONS UNDER SECTION 17, OR LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT (INCLUDING WILLFUL BREACH OF THIS AGREEMENT)," and then barred indirect, incidental, special and consequential damages and capped cumulative liability at the greater of $5,000,000 or amounts actually paid or payable. Post-verdict, the court accepted the vendor's reading that the clause excluded only gross negligence and willful misconduct from the negligence family — "[d]efendants contend ISA § 18 covers all negligence except for gross negligence. Defendants' interpretation is correct" — and rejected Copart's attempt to place its professional negligence award outside a clause reaching conduct "arising out of or relating to" performance under the agreement.
Which limb did the work matters, and it is the drafting lesson. The court held the consequential-damages bar did not reduce the award: "either because the 'indirect, incidental, special, or consequential damages' limitations do not apply to tort claims, or because Copart has shown general damages ..., the only portion of the limitation of liability clause applicable to Copart's professional negligence award is therefore ISA § 18(B)." It was the aggregate cap that bit, reducing the jury's award to $9,091,568.70 — fees actually paid, less Copart's 20 percent share of responsibility. Id. at 976-80. The list decided which limb applied; the cap decided the number.
Three drafting consequences follow. First, breach-response costs — forensics, notification, call center, credit monitoring, regulator response — are routinely characterized as indirect or consequential. Define them as direct damages in the definitions section rather than arguing about it later. Second, carve the security and privacy indemnity out of both limbs: as Copart shows, a carve-out from the consequential-damages waiver alone still leaves the aggregate cap standing over it. Third, if uncapped liability is unavailable, negotiate a supercap keyed to something other than fees paid — a multiple, or a figure tied to the insurance tower — because fee-based caps on a $40,000 SaaS subscription are not a remedy for a seven-figure notification event.
One more structural point. An indemnity limited to third-party claims does nothing for your own regulator interactions, your own forensics, or your own notification costs, and those are the bulk of vendor-breach spend. If the clause says "claims brought by third parties," it does not reach the invoice from your incident response firm.
Insurance requirements and the additional-insured question
Certificates of insurance are collected and filed and almost never read. Two realities are worth knowing before you draft.
Additional-insured status does not port cleanly from general liability practice to cyber. Cyber towers are typically written on manuscript forms without the endorsement architecture that makes additional-insured status routine in CGL, and where a vendor's carrier will accommodate it, you are sharing the vendor's limits with the vendor and every other customer — the tower erodes, and you are behind the vendor's own defense costs.
More useful requirements: stated per-claim and aggregate limits with a retention ceiling; confirmation the policy responds to the vendor's contractual indemnity obligations rather than excluding assumed liability; regulatory defense and, where insurable, fines and penalties; notice to you of cancellation, non-renewal, or material reduction; waiver of subrogation against you; and evidence in the form of declarations pages and the endorsement schedule, not only a broker certificate. And keep the sequence straight — insurance does not defeat a cap. If the contractual cap is $500,000 and the vendor carries $10 million, you recover $500,000. Coverage fights over exactly these gaps are the subject of cyber insurance coverage disputes.
Subprocessor flow-down that survives more than one hop
Three regimes give you the language. GDPR Article 28(2) bars the processor from engaging another processor "without prior specific or general written authorisation of the controller"; Article 28(4) requires the same data protection obligations to flow down and provides that "[w]here that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations." HIPAA applies the business associate contract requirements to the contract between a business associate and a subcontractor "in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate." 45 C.F.R. § 164.314(a)(2)(iii). And DFARS 252.204-7012(m)(1) requires the clause to be included in covered subcontracts "without alteration, except to identify the parties" — the strictest of the three, and a useful drafting model even outside defense work.
Commercially, the objection right is where these clauses die. A notice-and-objection mechanic with no consequence is theater. Attach one: if you object to a new subprocessor and the vendor proceeds, you terminate the affected services without penalty and receive a pro-rata refund of prepaid fees. Then ask, once, for evidence that the flow-down was actually executed — the vendor's template, or the counterparty's signature page — rather than the representation that it exists.
The deletion obligation nobody enforces
Article 28(3)(g) requires the processor, "at the choice of the controller," to delete or return all personal data at the end of the services and delete existing copies unless law requires retention. HIPAA is weaker by design: return or destruction is required only "if feasible," and where infeasible the associate must "extend the protections of the contract to the information and limit further uses and disclosures to those purposes that make the return or destruction of the information infeasible." 45 C.F.R. § 164.504(e)(2)(ii)(J). "Not feasible" is the clause vendors live in.
At termination the data is rarely in one place. It is in backups on their own retention cycle, log and telemetry stores, support ticket attachments, derived aggregates, sandbox copies, and sometimes model training sets. A clause that says "Vendor shall delete Customer Data" addresses the production database and nothing else. Specify scope by category; permit backup deletion on the documented expiry cycle but fix a hard outer date; require a deletion certificate signed by an officer; enumerate every retention exception and place the retained data under continuing confidentiality and security obligations; and make the whole clause survive termination expressly.
Then put the certificate on the offboarding checklist with an owner, because the reason this obligation goes unenforced is not drafting — it is that termination is handled by procurement after legal has moved on. One carve-out is mandatory: the deletion duty must yield to any preservation obligation, or a routine offboarding becomes a spoliation problem. The trigger analysis is set out in legal hold: what triggers the duty, and the volume-side consequences of vendor-held data show up again in data subject access requests at scale.
Learn more
- David Shonka — Partner and General Counsel, Redgrave LLP; three-time Acting General Counsel of the Federal Trade Commission
- Aaron Tantleff — Partner, Foley & Lardner LLP
- Tamara Snowdon — Head of Cyber Risk Wordings, Beazley
- Michael Kleinman — Special Counsel, Fried Frank LLP
- Roland Cloutier — Former Global Chief Security Officer, TikTok; former Chief Security Officer, ADP
- Sean Zadig — Senior Vice President and Chief Information Security Officer, Yahoo
- Gail Gottehrer — Vice President, Global Litigation, Labor & Employment, and Government Relations, Fresh Del Monte Produce, Inc.
- Gregory M. Sleet — Hon. Gregory M. Sleet (Ret.), neutral at JAMS; twenty years on the U.S. District Court for the District of Delaware, seven as chief judge
Related reading: mediating a data breach dispute and navigating ransomware response and legal obligations.
This article is general information about contracting practice and regulatory requirements; it is not legal advice, and it does not create an attorney-client relationship.
Go deeper — courses on this
FreeRansomwareBest Practices to Limit an Organization's Ransomware Risk from a Legal Perspective
This seminar covers the ransomware threat landscape alongside both technical and legal risk-management…
Daniel B. Garrie
Cyber IncidentsData Disputes: Navigating Data Breach Mediation
This seminar walks legal, security, and business professionals through the data breach mediation process…
Daniel B. Garrie · 1h 5m
Cyber IncidentsCounsel's How To: Advising the Board on Cyber Incident Response Planning
Panelists explain the board's role in cybersecurity oversight and what that looks like in practice…
Daniel B. Garrie
Keep reading
- Legal Hold: What Triggers the Duty to Preserve, and What Actually Satisfies ItWhen the duty to preserve attaches, how far a legal hold must reach, and what FRCP 37(e) requires before a court can sanction a party for lo…
- Cyber Insurance Coverage Disputes: Where Claims Actually Get DeniedWhere cyber insurance claims actually get denied: war exclusions, late notice, application warranties, control conditions, sublimits and con…
- Regulation S-P: The Incident Response Obligations Advisers Keep MissingHow amended Regulation S-P works in practice: when the 30-day clock starts, what the notice must say, the 72-hour vendor rule, and the recor…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.