Back Office / Source date:

Outsourcing Cybersecurity Requirements Get Teeth

Buyers began mandating controls testing, evidence, and incident SLAs instead of accepting attestations.

Illustration of a supplier engineer testing a phone notification path beside an incident contact tree and security schedule.

Four months into the year, the pattern is hard to miss. A network management vendor's build process was compromised and delivered signed malware to its customers. In March, organisations spent a weekend scrambling because their mail servers were being exploited faster than they could be patched. This month a code coverage tool used inside software pipelines was found to have been tampered with. None of those were failures of the victim's own security programme. All of them were failures inside somebody else's. Meanwhile, the security annexe in most outsourcing contracts still says that the supplier shall maintain appropriate technical and organisational measures in line with industry standards. That sentence has never prevented anything. This is the year to replace it with clauses that can actually be tested, and the difference is not legal sophistication — it is structure.

What "teeth" actually means

A security requirement has teeth when it has three parts. Almost every schedule I read has the first, occasionally has the second, and essentially never has the third. A defined obligation. Specific enough that two reasonable people would agree whether it had been met. An evidence obligation. The artefact that demonstrates compliance, who produces it, how often, and at whose cost. Without this, the obligation is an opinion. A consequence. What happens when the obligation is not met, short of the termination nobody will ever exercise. Apply that test to your current annexe. "Supplier shall maintain industry-standard security" has no standard named, no scope defined, no evidence attached and no consequence. It is decorative. "Supplier shall enforce multi-factor authentication on all remote and administrative access to systems processing Customer data, shall provide quarterly confirmation of enforcement coverage, and shall remediate any gap within ten business days, failing which Customer may suspend the affected access at Supplier's cost" is a clause.

Make a security requirement testableArticle-derived contract-design structure. Illustrative questions only, not legal drafting or universal notification deadlines.
PartQuestion to settle
ObligationWhich control, systems and access paths are covered?
EvidenceWho provides which artefact, on what cadence and at whose cost?
ConsequenceWhich proportionate action follows an unmet obligation?

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

The six obligations worth arguing about

Every buyer's annexe is too long, and most of the length is in the wrong places. Six obligations carry nearly all of the real value. Notification, with the clock starting at discovery. Name an individual and a deputy, with telephone numbers. Require initial notification within a stated number of hours of the supplier becoming aware — not of confirming, not of concluding an investigation. Specify minimum content: what happened, what data and systems are affected, what is still unknown, and what the supplier is doing. Then require updates on a fixed cadence until closure. The single most common failure in third-party incidents is not the breach; it is finding out late from somebody else. Subcontractor control. No onward subcontracting of in-scope work without prior notice, flow-down of equivalent terms, and a current list of subcontractors available on request. Add a right to object. The supplier chain beyond tier one is where the last two years of incidents originated. Identity and access. Named individual accounts only, no shared credentials, multi-factor authentication on remote and privileged access, and — the clause people forget — an obligation to notify you and remove access within twenty-four hours when any individual with access to your environment leaves the account or the company. Supplier-side leavers with live credentials are a standing exposure that no annual audit will catch. Vulnerability and patch obligations with timeframes by severity, applied explicitly to internet-facing systems, plus periodic reporting on patch currency. March demonstrated that the exposure window on an internet-facing service is measured in hours, and a clause that says "promptly" is not a timeframe. Data handling. A list of the locations where your data is processed and stored, encryption in transit and at rest, a retention period, and return or destruction on exit with a certificate. Exit is the obligation most frequently omitted and most frequently needed. Assurance you can use. The right to receive the actual report rather than a certificate — with the scope statement, because scope is where certifications hide — the right to receive a penetration test summary and remediation plan annually, the right to test yourself or appoint an assessor, and the right to require participation in one joint exercise a year. A certificate tells you a supplier passed an audit against a scope you have not read.

Remedies: the part buyers get wrong

Most security schedules have exactly one remedy, which is termination. Buyers will not use it, suppliers know that, and so the schedule prices at zero. A remedy ladder works better, because each rung is credible: A remediation plan with named dates. Increased reporting frequency while the gap is open. Service credits tied specifically to the security failure rather than to availability. The right to appoint an independent assessor at the supplier's cost when a material obligation has been missed. Step-in rights over the affected function. Suspension of processing for a defined data set. And only then termination for cause, with exit assistance obligations and no early termination charges. One more provision is worth more than all of the above combined: security and confidentiality breaches should sit outside the general liability cap, or under a separately negotiated higher cap. If your exposure from a supplier incident is capped at three months of fees, the commercial risk has already been allocated to you, whatever the annexe says.

Practical Guidance for Vendor Security Requirements Design

  • Rewrite every obligation into the three-part form: obligation, evidence, consequence. Delete anything you cannot express that way; it was never enforceable.
  • Put the notification clock on discovery, in hours, with a named human and a deputy. Then test it: call the number at seven in the evening and see what happens.
  • Require leaver notification and access removal within twenty-four hours for anyone at the supplier who held access to your systems.
  • Ask for the report and the scope statement, not the certificate. Read the scope first; it frequently excludes the service you bought.
  • Build a remedy ladder, and negotiate security out of the general liability cap. A single termination right is not leverage.
  • Tier your requirements by supplier size and criticality. One annexe for scaled providers, a short baseline for small suppliers who will otherwise sign promises that are untrue.
  • Require a current inventory of connections and accounts into your environment, refreshed quarterly. This costs the supplier nothing and is the most useful artefact you will hold.
  • Check who you actually contracted with, and whether that entity has the capital to stand behind the indemnity you negotiated.

The Regional Angle

Three regional features change how these clauses should be drafted here. The first concerns remedies, and it is the reason to prefer rights over money. In several Gulf jurisdictions, agreed compensation and penalty provisions are not applied mechanically: a court can examine whether the amount reflects the loss actually suffered and adjust it accordingly, and enforcement takes time even when the clause is upheld. A service credit regime that reads impressively may therefore deliver far less than its face value, and considerably later. Operational remedies behave differently, because they are self-executing. Suspending a data feed, revoking an access path, appointing an assessor whose invoice you offset against the next payment, or exercising a step-in right does not require a judgment — it requires the contract to say you may. Draft the ladder around rights you can exercise on a Thursday afternoon, and treat monetary remedies as secondary. The second is the thinness of the supplier market, which makes uniform requirements self-defeating. A great deal of critical work in this region is performed by small local firms: the twenty-person support company that administers your servers, the single authorised partner who can commission the equipment, the regional integrator whose entire security function is one capable engineer. Sending that firm a forty-page annexe produces a signature and no change, because compliance is impossible and the alternative supplier does not exist. Tier the requirements honestly. A baseline that small suppliers can genuinely meet — named accounts, multi-factor authentication on remote access, leaver notification, device encryption, no onward subcontracting, an annual external vulnerability scan, and a notification obligation with a real telephone number — delivers more actual security than an unenforceable full set. Reserve the complete annexe for providers with the scale to satisfy it. The third is recourse, and it is frequently overlooked in a market built on free zones and special purpose entities. The entity on your contract may be a lightly capitalised vehicle whose assets consist of a licence, a lease and some laptops, while the work is performed by a group operating company in another jurisdiction. An uncapped indemnity from that entity is an uncapped claim against nothing. Before negotiating liability at all, establish which legal person is signing, what stands behind it, and whether you need a parent guarantee or a direct contract with the operating company. This is a five-minute question at the outset and an unanswerable one after an incident. A related practical note: access in this market is often granted informally and quickly, through a messaging app, to whoever the supplier has sent this week. The leaver and inventory clauses exist precisely to counteract that culture, and they only work if somebody on your side reviews the quarterly list rather than filing it.

The objection worth taking seriously

The strongest objection is that none of this prevents a breach. The customers of the network management vendor had sophisticated contracts and world-class security teams, and they were compromised anyway by signed software they had every reason to trust. The organisations exploited through their mail servers in March mostly had patch obligations in writing. Adding teeth to an annexe does not add a control; it allocates consequences after the fact, increases legal cost on both sides, lengthens procurement, and — at the small end of the market — raises prices or drives capable suppliers away. There is a real argument that the entire third-party assurance industry has produced enormous documentary output and very little measurable risk reduction. Most of that is correct, and anyone who claims a contract would have stopped a compromised build pipeline is selling something. What contracts change is narrower and still valuable: time to know, time to act, and who pays. The notification clause determines whether you learn about an incident from your supplier in hours or from a journalist in weeks. The leaver and access clauses reduce a live, boring, entirely preventable exposure. The subcontractor list tells you whether your work has quietly moved to a fourth party. The exit clause determines whether your data comes back. And the liability position determines whether a supplier's failure becomes your loss. Those outcomes are worth the drafting effort, and none of them depend on the fiction that paperwork prevents intrusions.

Common Questions

Is a certification enough?

No, but it is a useful filter. Read the scope statement and the date, ask which of your services were in scope, and treat an unread certificate as evidence of nothing more than a supplier's willingness to be audited.

How short can a workable annexe be?

Two pages, if it covers notification, access and leavers, subcontracting, patching, data location and exit, each in the three-part form. Two good pages beat forty unenforceable ones.

What if the supplier refuses the notification timeframe?

That is informative. A provider with a functioning incident process finds a discovery-based clock uncomfortable but acceptable; a provider without one resists it absolutely.

What should we expect over the next twelve months?

Expect public-sector and large corporate buyers to start writing software supply chain requirements into contracts this year — provenance of components, build integrity, vulnerability disclosure — and expect those requirements to cascade down to anyone selling into them. Expect insurers to begin asking for evidence of specific supplier controls rather than accepting a general assurance, which will change procurement behaviour faster than any regulation. Expect at least one more compromise of a widely used development or management tool, because the economics of that attack are now proven. And expect regulators in this region to formalise third-party risk expectations for regulated sectors, which will turn today's good practice into next year's minimum.


Vendor Security Requirements Design — we rewrite your supplier security schedule into obligations with evidence and consequences, tier it for the suppliers you actually use, and pressure-test the notification path before you need it.

Continue reading

Talk to OPS

Start with the operating problem.