Is it unclear who pays the bill after a supplier is compromised? For many UK SMEs reliant on third-party vendors, the first reaction is uncertainty: who covers IT forensics, customer notification, regulatory fines or lost income? This guide gives a practical, UK-specific answer to "Supply chain dependence: Who pays when a supplier is breached?" and lays out decision steps, likely cost-allocations, and contractual traps to avoid.
Key takeaways: what matters in 60 seconds
- Responsibility depends on contract, insurance cover and law. Typically costs fall to the party whose contract or insurance covers the risk, not automatically the supplier or the SME.
- Insurers can pay for contingent losses, but cover depends on explicit contingent business interruption (CBI) or supply-chain extensions in the policy.
- Supplier indemnities are useful but limited. Indemnities may be capped, time-limited or practically worthless if the supplier is insolvent.
- GDPR fines and regulatory costs usually follow the data controller/processor rules. The Information Commissioner's Office (ICO) focus and liability depend on roles under the GDPR.
- Contractual errors often leave SMEs footing the bill. Missing minimum insurance clauses, weak security requirements and broad liability caps expose SMEs.
Who picks up the bill after a vendor breach?
Determination of who pays after a supplier breach is a three-step practical test: contract, insurance, and insolvency/ability to pay.
-
Contract: The supplier contract (service agreement, SLA, data processing agreement) is the first point of reference. Clauses on indemnity, liability caps, security obligations and insurance requirements define contractual responsibility. If a supplier contractually accepts liability for losses caused by its breach, the supplier may be obliged to fund remediation.
-
Insurance: Where the supplier or the SME holds appropriate cyber or liability insurance, insurers may pay subject to policy terms, limits, excesses and exclusions. Many commercial cyber policies include contingent business interruption and third-party liability extensions that can respond to vendor-related incidents. Claim coordination and subrogation can make insurers the practical payers.
-
Practical ability to pay: If a supplier lacks funds or becomes insolvent, contractual liability may be legally established but practically unenforceable. In that case, the SME’s own insurance (if bought) or its internal funds will likely meet the immediate cost of recovery and continuity.
The final allocation often ends up split: immediate incident response and business continuity costs are commonly borne by the affected SME (or its insurer); long-term liability and compensatory claims may be pursued against the supplier or its insurer.
Insurer vs supplier liability: who pays for breaches?
How insurers typically respond to supplier-origin breaches
Insurers evaluate claims against the policy wording. Relevant covers include:
- Contingent business interruption (CBI), pays for lost income caused by supplier disruption when the insured did not have the direct physical damage. Cover is often subject to sub-limits and waiting periods.
- Cyber incident response, covers forensic costs, legal advice, public relations and notification when data held by the SME is affected by a vendor compromise.
- Third-party liability, pays claims from customers if the SME is legally liable for a breach caused by a supplier.
Policies differ: some will treat a supplier breach as an insured cyber event, others will exclude losses that arise from a third party where the insured has limited control. Always check definitions for “service provider”, “supplier”, and “dependent third party.”
When a supplier's insurer pays
If the supplier is contractually liable and has insurance that covers the incident, the supplier's insurer may pay under the supplier’s policy. Common complications include:
- Policy limits, supplier limits may be far lower than the SME’s loss.
- Exclusions, many policies exclude failure to patch, negligence, or acts by nation-state actors.
- Subrogation and coordination, the SME’s insurer may pay initially and then subrogate against the supplier’s insurer.
When the SME's insurer pays
If the SME has appropriate cyber or business-interruption extensions, its insurer may pay regardless of the supplier’s liability. That is often the fastest route to recovery but can involve:
- Higher premiums or increased future excesses if claims are made.
- Disputes over causation, insurers assess whether the loss is a direct consequence of the supplier breach, or a separate insured peril.
Short practical decision flow
- Check the contract for supplier liability and insurance obligations.
- Notify both insurers (SME’s and supplier’s) and preserve evidence.
- Use SME’s insurer for cashflow/response if supplier cannot meet immediate costs.
- Consider subrogation against supplier or supplier’s insurer later.
Should SMEs rely on supplier indemnities or insurance?
Contracts often offer both indemnities and an insurance requirement. Neither is a perfect substitute for the other.
Advantages of supplier indemnities
- Indemnities create a direct contractual obligation for the supplier to cover losses caused by their breach.
- They may include defence and settlement obligations, which can give the SME control over claims handling.
Limitations of indemnities
- Indemnities can be capped or qualified (e.g. excluding indirect losses), limiting practical recovery.
- If the supplier is a small or undercapitalised business, indemnities may be of little value in practice.
- Enforcing indemnities may require time-consuming litigation.
Advantages of supplier insurance requirements
- Requiring a minimum level of cyber and professional indemnity insurance gives the SME a practical recovery route.
- Insurance can provide faster cashflow for incident response if the supplier’s insurer accepts the claim.
Limitations of insurance requirements
- Policy terms, limits and exclusions vary; a clause stating a minimum limit (e.g. £1m) does not guarantee full recovery.
- Insurers may dispute causation or apply exclusions (e.g. exclusions for inadequate security measures).
Practical recommendation (neutral framing)
- Treat indemnities and insurance as complementary risk-transfer tools.
- Prefer explicit, uncapped indemnities for direct losses where commercially feasible, and insist on minimum insurance levels and specific cover types (cyber, CBI, PI).
- Include named insurers and certificate-of-insurance obligations, plus periodic evidence checks.
Is contingent business interruption cover worth the cost?
CBI is often the decisive factor in who ultimately pays for lost revenue after a supplier breach.
What CBI typically covers
- Loss of gross profit arising from interruption due to a supplier’s computer failure or data breach.
- Extra costs reasonably incurred to mitigate the loss (e.g. temporary suppliers, emergency IT)
Typical exclusions and limits
- Waiting periods (e.g. 24–72 hours or several days) before cover begins.
- Sub-limits specifically for supplier-related interruption, often much lower than main BI limits.
- Exclusions for communicable-economy losses, war or sanctioned actors.
When CBI is worth it
- When the SME relies critically on a small number of suppliers for revenue or service delivery.
- When the cost of a day or two of downtime would materially damage cashflow.
When CBI is less useful
- For SMEs with minimal supplier dependence or diversified supply chains.
- If the insurer's sub-limits, waiting periods and excesses make payouts unlikely or too small.
Indicative cost-effectiveness: for many UK SMEs, CBI is valuable if the anticipated downtime cost exceeds the premium over a short term, but assessment should use scenario modelling (expected lost margin × likelihood × insurer sub-limits).
What happens to GDPR fines after a supplier breach?
GDPR liability depends on the roles: controller, processor, or joint controllers. The ICO’s approach focuses on responsibilities under the GDPR rather than simple contractual blame.
- If the SME is the data controller and a supplier (processor) is breached, the controller may be held responsible for failing to ensure adequate technical and organisational measures. The ICO can impose fines or corrective measures against the controller.
- If the SME is a processor and the supplier acts as a sub-processor, the controller may still hold the processor accountable and the ICO can act against the controller or processor depending on the facts.
Insurance notes:
- Many cyber policies exclude fines and penalties imposed by regulators, or treat fines differently. Some insurers cover regulatory investigations and response costs but exclude statutory fines.
- The ICO has published guidance and enforcement examples; the National Cyber Security Centre (NCSC) offers technical guidance on incident handling. Cite regulators: ICO, NCSC.
Legal recourse:
- Contractual indemnities can attempt to transfer GDPR fines, but public policy and statutory rules limit full contractual transfer of regulatory fines. This area is complex; legal advice is typically required when fines are realistically possible.
Common contract mistakes that increase SME exposure:
- No minimum insurance clause for the supplier, or an unspecified cover requirement.
- Indemnity caps that are lower than likely losses (e.g. £50k cap while realistic loss could be hundreds of thousands).
- Broad exclusions for indirect or consequential losses that remove recovery rights.
- Missing data processing agreement (DPA) or weak DPA lacking security specifications.
- Failure to require incident notification timelines or forensic cooperation clauses.
Example contractual clause errors (practical list)
- Vague security standard: "supplier will maintain reasonable security", ambiguous and hard to enforce.
- No audit rights: SME cannot verify supplier’s security posture.
- Liability cap linked to fees paid: small suppliers with low fees effectively cap liability at low amounts.
How these errors translate into costs
- Immediate recovery fees (forensics, PR) met by SME cashflow.
- Compensatory payments to customers or partners not covered by supplier.
- Regulatory costs where the SME is treated as controller.
Table: typical payer for common cost types after supplier breach
| Cost type |
Typical payer (contract + insurance dependent) |
Common complications |
| Immediate incident response (forensics, emergency IT) |
SME or SME insurer |
Supplier may delay or be insolvent; insurer causation disputes |
| Customer notification & credit monitoring |
SME or supplier, per DPA/contract |
Regulatory expectations; cost caps |
| GDPR fines |
Controller usually liable; insurer may exclude fines |
Public policy limits on transferring fines contractually |
| Business interruption (lost revenue) |
SME insurer if CBI bought; otherwise SME pays or sues supplier |
Sub-limits and waiting periods reduce payouts |
| Third-party claims (clients suing SME) |
SME PI or cyber liability insurer |
Insurer subrogation against supplier
|
Who pays: quick decision timeline
1️⃣
Immediate response
SME funds or SME insurer pays for forensics and continuity.
2️⃣
Contract check
Review supplier indemnities, insurance clauses and DPAs.
3️⃣
Notify insurers
Alert both SME and supplier insurers, preserve evidence for subrogation.
4️⃣
Claim coordination
Insurers determine causation; subrogation may reallocate costs later.
Analysis: advantages, risks and common errors
✅ Benefits / when to rely on supplier insurance or indemnities
- When suppliers are financially robust and carry substantial, named cyber insurance.
- When contracts include clear, uncapped indemnities for direct losses and tight DPAs.
- When the SME’s own insurer requires supplier insurance as a condition, this reduces double exposure.
⚠️ Errors to avoid / risks
- Relying on a supplier’s verbal assurance without contractual evidence or insurance certificate.
- Accepting wide liability caps tied to supplier fees.
- Failing to document dependency-critical suppliers (single points of failure).
How to manage a claim after a supplier breach: step-by-step (practical)
- Preserve evidence and record timelines. Log communications, system snapshots and invoices.
- Notify the supplier, the SME’s insurer and (if appropriate) the supplier’s insurer. Early notification preserves rights.
- Invoke contractual obligations: require the supplier to defend, indemnify or provide insurance certificates per contract.
- Document all losses carefully: revenue, extra costs, refunds and customer losses, insurers require precise proof.
- If necessary, engage legal counsel for subrogation or regulatory response regarding data protection.
Questions frequently asked
What happens if a supplier becomes insolvent after a breach?
Contractual rights still exist, but practical recovery may be limited. The SME’s own insurance often becomes the primary route for recovery.
Can an SME claim against its own insurer for supplier-caused downtime?
Yes, if the SME’s policy includes contingent business interruption or supply-chain extensions and the event meets the policy definitions.
Are GDPR fines always excluded from cyber insurance?
Not always. Some policies cover investigation costs and legal defence but exclude statutory fines; policy wording must be checked.
How long does insurer subrogation take?
Subrogation timelines vary: from months to years depending on dispute complexity, litigation and insurer coordination.
Is it enough to ask for proof of supplier insurance once?
No. Periodic certificate checks and audit rights provide stronger risk assurance than a one-off check.
What minimum insurance should be requested from suppliers?
Many SMEs ask for at least £1m–£5m cyber and PI limits, but the appropriate level depends on exposure and contract value.
Can contractual indemnities transfer regulatory liability?
Contractual indemnities may attempt to transfer responsibility but regulators (e.g. ICO) will still enforce statutory obligations against controllers/processors under GDPR.
Conclusion
The answer to "Supply chain dependence: Who pays when a supplier is breached?" is: it depends. The practical payer is determined by the contract, insurance policies and the supplier's ability to pay. Often the SME or its insurer meets immediate costs, while recovery from the supplier or subrogation by insurers follows later, if it succeeds.
Next steps
- Review critical supplier contracts and require clear indemnities and minimum named insurance limits.
- Verify that SME cyber insurance includes contingent business interruption and adequate sub-limits suited to supplier risk.
- Implement supplier monitoring: regular certificate checks, security questionnaires and documented incident notification timelines.
For regulator guidance, consult the ICO and technical advice at the NCSC.