Skip to Main Content
Publications

Securing Your Interests in Your Cybersecurity Architecture: Litigation Risks Posed by Outsourcing the Protection of Your Networks, Systems, and Data

Part 3 of a Series on Technology-Provider Litigation Risk

Managing Cybersecurity Risk is a Non-Negotiable for Organizations – But Can Be Expensive

Cybersecurity is no longer a "nice to have" for organizations; it is a must. And the resources required to build, maintain, and monitor a layered cybersecurity architecture around the clock are costly. Now more than ever, organizations are outsourcing their cybersecurity needs to third-party vendors to the tune of more than $200 billion globally in 2025.

Not only is outsourcing cybersecurity needs often a more cost-efficient strategy, but it is also a means for organizations to transfer some of their cybersecurity risk. Organizations often rely on the belief, and provide assurances of the same to customers and regulators, that their networks, systems, and data are safe with their cybersecurity vendors on guard to detect and respond to suspected threats. However, it is only when something goes wrong that the effectiveness of the risk transfer is fully understood.

When cybersecurity service agreements fail to capture and transfer the intended risks, the resulting legal consequences can be costly, leaving organizations managing regulatory scrutiny and litigation on multiple fronts, including with their own cybersecurity vendors. To avoid these costly battles, organizations should scrutinize the cybersecurity vendor agreements from both a legal and technical point of view. How these agreements define the scope of the services and obligations of the parties or otherwise limit liability can be the difference of millions of dollars when something goes wrong.

Scope of Services

The starting point for any cybersecurity services agreement is a clear understanding of exactly what the vendor is responsible for doing – and just as importantly, what it is not responsible for doing.

The broad umbrella of "managed security services" can sound all-encompassing, but agreements often differ in terms of the functions and duties the vendor is obligated to perform. While an organization may believe a vendor's associated threat monitoring service is reviewing security alerts and responding to identified threats, the agreement may limit the vendor's duties to determining whether the security alert should be escalated to the organization for further action or simply marked as a false positive based on available information. These gaps in understanding lead to no response, allowing threats and their impacts to spread across an organization's IT enterprise.

Further limitations may be imposed by the agreement within the defined "in-scope" environments and assets. This is a critical aspect of cybersecurity service agreements and for an organization's cybersecurity posture given the layered IT architectures common to developed industries. When segregated networks or unaccounted-for systems are excluded from a vendor's area of responsibility, an organization can face serious risks of the initial compromise going undetected in an unmonitored environment or system, and the threat is discovered after an attack infrastructure is built and lateral movement is detected.

Before negotiating these agreements, organizations should also take a full accounting of their networks, systems, and data, so a full picture of an organization's threat vector is understood to scope the areas of responsibility for the vendor. Once the applicable environments are clear, organizations should seek to incorporate the specified duties for the vendor within each line of service. These are often effectively incorporated in agreements through detailed Responsible, Accountable, Consulted, and Informed (RACI) matrices, where the parties agree to specified roles.

Standards for Delivery

Cybersecurity agreements frequently rely on aspirational language such as "industry-standard security," "commercially reasonable efforts," or "best practices." While familiar, these terms can become battlegrounds in litigation because they often lack objective benchmarks. The truth is that cybersecurity is hard, so when an organization seeks expert testimony to address the perceived failings of a vendor, most consultants find it difficult to take a justifiable position when the sophistication or complexity of the industry is taken into account.

Organizations should consider whether service levels, response times, escalation obligations, and reporting requirements can be measured against specific criteria rather than generalized standards whose meaning may be contested after an incident. Moreover, what steps are required of the vendor in its response, escalation, and notification procedures should be clear. And organizations should think through how those procedures work outside of regular business hours, as threat actors rarely make themselves known when it is most obvious or convenient for the target and its vendor to coordinate.

Control of Information

When a ransomware event, unauthorized access incident, or major service disruption occurs, disputes often arise not just because the provider failed to prevent the event, but because the parties disagree about who controls the relevant evidence necessary for investigation. In some cases, disputes focus less on the cause of the underlying security incident than on whether the vendor provided all of the relevant information, preserved evidence, or communicated material findings that would have allowed for a more timely or effective response.

If the vendor controls monitoring systems, endpoint detection tools, forensic repositories, or cloud-based logging environments, an organization's most important evidence may reside outside its direct control. While organizations often assume that logs, detection data, and forensic artifacts will be available when needed, in practice, those materials may be retained for only a limited time or subject to the vendor's consent for access. Therefore, it is critical that organizations understand preservation obligations and access rights before an incident occurs. Without the proper information, an organization faces serious risk as a security incident spreads across its enterprise, regulatory scrutiny begins, or discovery obligations apply.

The Fine Print of General Terms and Conditions

At this point, it is generally understood that a cybersecurity incident is likely to generate contract disputes as operations are disrupted, regulatory scrutiny over the sensitive data managed by an organization is heightened, and litigation is initiated on the improper assumption that the organization had to be negligent for the incident to occur. While vendors will acknowledge these risks in marketing materials, the fine print in the general terms and conditions of cybersecurity service agreements will govern whether these consequences are foreseeable for the purposes of addressing the failure to uphold an obligation.

As a general matter, limitation-of-liability clauses often exclude recovery for special, indirect, or consequential damages, leaving only those damages that are foreseeable and flow naturally from the alleged wrongful act. Often, standard limitation-of-liability clauses seek to define what is considered indirect or consequential damages, and those definitions often include loss of data and loss of revenue from operational disruption – the exact consequences they are being hired to prevent. And this is not the only inconsistent limitation that may be imposed by the fine print of the agreement.

Disclaimers on warranties are often broad and all-encompassing, and cybersecurity service agreements often seek to redefine the nature of the services being delivered. It is not unusual for organizations to receive standard disclaimers that reframe services as tools for visibility and awareness only. Some clauses will explicitly say the vendor's services are not designed to prevent an intrusion into the organization's systems or networks.

These inconsistencies lead to further disputes when things go wrong. Organizations should scrutinize the standard terms and conditions of these agreements, particularly where limitations on liability are imposed and broad warranties are disclaimed. While some vendors will refuse to amend this language, often organizations can find compromise through exceptions for heightened negligence standards.

Looking Ahead

The final article in this series will examine what happens when technology failures escalate into formal disputes. We will focus on the practical realities of evidence preservation, logging, data mapping, forensic collection, and litigation strategy in the critical days and weeks after a significant technology or cybersecurity event.

***

For more information about managing litigation risks in cybersecurity vendor agreements, please reach out to Scott M. DouglassJohn David "J.D." KoestersClinton P. Sanko, or any member of Baker Donelson's Data Privacy and Cybersecurity Team.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept