logo
Mitigating cyber-risks in outsourcing: Contract strategies for compliance and protection

Mitigating cyber-risks in outsourcing: Contract strategies for compliance and protection

Finextra5 hours ago

0
This content is contributed or sourced from third parties but has been subject to Finextra editorial review.
A clear and present danger
In recent years, several prominent UK businesses have faced significant technology and cybersecurity challenges and the consequences of data protection breaches.
For example, in October 2023, the Financial Conduct Authority (FCA) fined Equifax over £11 million for failing to manage and monitor the security of UK consumer data it had outsourced to its parent company based in the US. The breach allowed hackers to access the personal data of millions of people and exposed UK consumers to the risk of financial crime.
As reported by Finextra on 15 May, NatWest's head of cyber security has revealed that the Bank faces 100 million cyber-attacks every month.
That incident brought into sharp focus the risks and vulnerabilities which can arise where a customer outsources the handling of sensitive data, and the serious regulatory consequences faced by UK firms if they fail to ensure the safeguarding of sensitive information.
Rules are rules
Aside from principles of good business sense, obligations in relation to security and data protection are imposed on customers looking to outsource IT services to third parties via a range of regulatory and quasi-regulatory/industry measures.
Regulatory measures in the UK include the requirements in the UK GDPR relating to security and data processor contracts, as well as more financial services-specific rules such as the FCA Operational Resilience regime, the FCA and PRA rules on material outsourcing and use of cloud, and the incoming FCA rules on use of Critical Third Party suppliers.
Businesses operating in the EU (and by extension their relevant suppliers) must now also comply with the requirements of the EU Digital Operational Resilience Act (DORA) and its requirements in relation to critical IT services providers. Regulatory measures carry the added risk of sanctions and penalties from the relevant enforcement agencies if they are breached.
Non-regulatory, but nonetheless important, requirements which impact many financial services business include the Payment Card Industry Data Security Standard (PCIDSS) which impose requirements on the security of card data, and the information security requirements of ISO27001.
Get it in writing
The typical provisions which a customer can try to include into contracts to meet its regulatory obligations, and otherwise to guard against (or at least provide some form of recourse in the event of) cyber and data infringements, can be grouped into two main types: (1) contract standards; and (2) rights and remedies.
Contract standards
Set out the general standards to which a supplier must conduct its business and provide their service(s) - for example in compliance with all laws and regulations, with professional skill and care and in accordance with good industry practice.
standards to which a supplier must conduct its business and provide their service(s) - for example in compliance with all laws and regulations, with professional skill and care and in accordance with good industry practice. Set out any specific requirements which the supplier must meet which are intended to address particular cyber and data concerns, for example: Detailed security provisions, including compliance with the customer's own information and systems security policies Warranties of compliance with any information provided by the supplier pre-contract as part of the customer's due diligence process. Early warning requirements related to suspected cyber incidents or data breaches. Specific clauses designed to meet the requirements of the UK GDPR including: to exercise sufficient technical and organisational measures to protect data against unauthorised access, to notify data breaches in good time, and controls on the export of data outside of the UK/EEA. Compliance with specific industry standards including PCIDSS and ISO27001 Regular conduct of security testing and the provision of results to the customer (this can be a source of debate - a customer may want the right to conduct its own testing (including penetration tests) but suppliers can be reluctant to give this, especially over systems used for multiple customers, and so a right to see the results of the supplier's own internal or third party testing may be the best which can be achieved). An obligation to rectify any detected weaknesses after testing. Restrictions against use of sub-contractors and/or AI systems without the customer's consent. Requirement to use at least 'industry – standard' cybersecurity measures such as firewalls, malware blockers etc.
requirements which the supplier must meet which are intended to address particular cyber and data concerns, for example:
Rights and remedies
Making sure that the supplier's liability for losses which might be suffered due to a cyber or data breach are not excluded out of hand, or caught by a general exclusion of 'indirect or consequential' liability.
Potentially no or separate/higher liability caps for issues such as breach of confidentiality, security, or data protection requirements. It is now not uncommon to have 'supercaps' for data liability (although suppliers may not accept uncapped liability given the potentially large data protection regulatory fines).
Indemnities for issues such as security or data breach
Audit rights for the customer (and also its regulators) - which would extend to the supplier's sub-contractors.
Definite termination rights in the event of a cyber or data related breach
A right to remove supplier personnel or sub-contractors or the service if there are any concerns.
Prevention is always better than the cure, and the only sure-fire way to avoid cyber and data issues is to make sure that, practically, the appropriate measures and behaviours are put in place by suppliers.
However, a well-drafted contract will make it clear what a supplier is required to do, meet any regulatory requirements for terms which must be included, provide the customer with various rights and remedies (ideally to try and catch and avoid problems before they escalate), and otherwise provide the customer with a potential claim for damages for breach of contract, or indemnity rights should the supplier fail to comply with the relevant terms and the customer suffers loss or liability as a result.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

River Island eyes store closures following £33m losses
River Island eyes store closures following £33m losses

The Independent

time16 minutes ago

  • The Independent

River Island eyes store closures following £33m losses

Fashion retailer River Island is undergoing a restructuring process that could lead to the closure of 33 UK stores and put hundreds of jobs at risk. An additional 71 stores face uncertainty as the company seeks improved rental deals with landlords to combat a recent slump in trading. The family-owned chain, which employs around 5,500 people, has hired advisors from PwC to oversee the restructuring. The proposals, aimed at securing fresh funding and turning around the business, will be put to a vote by the firm's creditors in August. River Island reported a 33.2 million pound loss in 2023, with sales down 19 per cent, attributed to weaker consumer spending and competition from online rivals.

Revamped Kirkstone Pass Inn will 'not be aimed' at hens and stags
Revamped Kirkstone Pass Inn will 'not be aimed' at hens and stags

BBC News

time21 minutes ago

  • BBC News

Revamped Kirkstone Pass Inn will 'not be aimed' at hens and stags

The newest owners of a historical pub have dismissed rumours its rooms may be marketed at stag and hen highest pub, the Kirkstone Pass Inn, had provided respite for travellers for centuries and was bought by Supreme Escapes in firm is renovating the already existing rooms and turning the old keeper's house into holiday accommodation, but said the bar area would not change and operate for the public, whether there was a booking or Lake District National Park Authority (LDNPA) said it recognised concerns about "potential loss of historic character" and had opened an investigation to monitor the use of the building. The centuries-old former pub stands at 1,481ft (451m) above sea level, on an exposed hillside above was frequented by visitors who made it up the Kirkstone Pass - known locally as "the struggle" - before it was put on the market in 2021, sitting empty for works sparked concerns online about the future use of the site and whether the changes were kept within the building's character and location. 'Almost derelict' Jerry Huppert, a partner in Supreme Escapes, told BBC Radio Cumbria the building was being renovated sympathetically and they had already spend about £3m on the building."The pub was very, very tired - almost derelict beyond repair," he added while located four miles (6.4km) away from the nearest neighbours, the accommodation was not being marketed to hen and stag parties - as had been speculated added: "Although our company generally specialises in holiday lets, we have recently moved into a new business model of boutique hotels and this is our first one."The building would also continue to operate as a pub, Mr Huppert said, and he was hoping it would reopen in the summer. Car park plans Planning manager for LDNPA Julie Birkett said the building was not listed and therefore internal works did not require planning permission, "regardless of their impact on internal historic features or character".She added a previous investigation concluded the building's new and renewed roughcast render was not an act of development as defined by law, and therefore did not need planning had also been raised online about preserving public access to the pub's car park, which is used by Huppert said there was a long lease on the carpark to the LDNPA."We have approached [the LDNPA] to see what their plan is at the end of the lease and they said they will touch base to us about a year or two before the end of the lease," he LDNPA confirmed the lease was due to expire in 2029 and renewal options would be considered closer to that date. Follow BBC Cumbria on X, Facebook, Nextdoor and Instagram.

Mulberry in talks over £20m cash-call as losses widen
Mulberry in talks over £20m cash-call as losses widen

The Independent

time21 minutes ago

  • The Independent

Mulberry in talks over £20m cash-call as losses widen

Struggling luxury handbag maker Mulberry has revealed talks to raise more than £20 million as the group warned over widening annual losses and worsening trading conditions. The Somerset-based firm said it was launching the cash-call after a 'post-2024-25 year-end review by the executive management, and in light of an even more challenging trading environment'. It added: 'The board has concluded that the company will require additional capital to fund its growth strategy and achieve its desired financial targets.' Mulberry said it was in discussions with majority shareholder Challice – a group controlled by Singaporean entrepreneur Christina Ong and husband Ong Beng Seng – and major stakeholder Mike Ashley's Frasers Group over the fundraising. It comes as Mulberry expects to slump to an underlying pre-tax loss of around £23 million for the year to March 29 against losses of £22.6 million the previous year. The group is set to report annual revenues tumbling 21% to around £120 million, adding that it does expect 'material overall revenue growth' in the new financial year. Andrea Baldo, chief executive of Mulberry, said the group had taken action to overhaul the business and cut costs as part of plans laid out in January, including shutting some stores. It already axed around 85 jobs in the run-up to Christmas – around a quarter of its workforce – largely impacting head office workers. Mr Baldo said: 'In the near term, we are firmly in turnaround mode, focused on rebuilding profitability and gross margin, while strategically investing in brand building initiatives.' He added: 'We've taken action to reduce costs – restructuring head office and exiting unprofitable stores, delivering a lower run-rate cost base into 2025-26. 'Following our year-end review, the board and I are confident that, with additional funding, we can accelerate momentum and deliver against our targets at pace.' The firm said shareholder Challice was willing to underwrite the fundraising in full, but Mulberry said it hoped Frasers would also take part. 'Whilst these discussions are ongoing, the board notes that it may not be possible for all parties to agree fully on the structure of the fundraising, in which case the board… will conclude on the most appropriate structure for the company,' Mulberry said. It expects to complete the fundraising in July, to coincide with the publication of its annual results.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store