When a supplier suffers a cyber breach, your SME may face disruption, customer complaints and UK GDPR duties. This can apply even when the supplier caused the incident.
A supplier breach can still make you accountable
Your responsibility depends on the data involved, your contract role and your actions after learning of the incident.
If a cloud platform loses personal data, your business may be the controller. A controller decides why and how personal data is handled.
The supplier may be a processor. A processor handles data for the controller and must report a breach without undue delay.
You must assess whether the breach could risk people’s rights and freedoms. Risks include fraud, identity theft and loss of privacy.
You may need to report to the ICO within 72 hours.
A supplier can be at fault while your SME remains answerable to customers, the ICO and contract partners. First establish your data role. Then decide on notification from the facts you know.
Act before the supplier’s full report arrives
Start your response at once. Do not let the supplier’s investigation timetable control your decisions.
During the first 24 hours, open an incident log and keep all supplier emails. Identify affected services and restrict risky links where it is safe.
Check your policy notice requirements. Tell the insurer in line with the policy wording, even if fault is still unclear.
The insurer may appoint approved forensic, legal or communications advisers. Record known facts, unknown facts and the time of the supplier’s next update.
Do not admit liability or promise compensation without proper advice.
Supplier-breach response path for an England SME
1. Record
Note awareness time and the affected supplier.
2. Contain
Protect accounts, links and backups.
3. Assess
Check data risk, service loss and contracts.
4. Notify
Tell insurers, the ICO or customers if required.
5. Recover
Restore service and retain evidence.
Supplier outages need the right policy wording
Cyber insurance responds only when the policy wording covers the relevant supplier event and the resulting loss.
Standard business interruption cover may not pay for a supplier outage, as it may cover only a cyber event in your own network.
It may exclude failure at a payment provider, cloud host or software platform. Cover may apply only if it includes contingent business interruption.
This is also called dependent business interruption. It covers loss caused by a qualifying third-party outage.
Check supplier definitions, waiting periods, sub-limits and indemnity periods. Also check systemic-risk exclusions.
Compare these limits with the cost of a 2-to-7-day outage and with any supplier liability cap.
| Policy section | Potential supplier trigger | Check before buying |
| Incident response | Suspected data or security event | Panel-provider rules and notice terms |
| Privacy liability | Customer or data-subject claim | Definition of wrongful act |
| Regulatory defence | ICO investigation | Fines only where insurable |
| Business interruption | Your own network failure | Third-party exclusion wording |
| Contingent interruption | Qualifying supplier outage | Supplier definition, wait and sub-limit |
| Data recovery and extortion | Encrypted data or ransomware | Backups, consent and sanctions checks |
An encrypted external drive can provide a separate, tested offline backup. This may help where policy terms require sensible data-recovery controls.
It keeps a protected copy separate from cloud or managed-service accounts, which could become unavailable during a supplier incident.
✅
Nuestra recomendación
An encrypted external drive can give a small firm a separate recovery copy. It helps if a supplier account or cloud service is unavailable.
It should support regular tested backups and access controls. It should not replace them.
- Keeps a recovery copy outside the affected supplier environment
- Protects stored files if the device is lost or stolen
- Helps show insurers a practical data-recovery process
Ver disponibilidad →
This guidance is less relevant if your business has no key digital suppliers, if no supplier holds personal data or if there is no customer contract exposure. It does not replace prompt advice from your insurer, legal adviser, data-protection lead or incident responders.
Your questions answered
What happens if my supplier has a data breach?
Assess your data, customers, contracts and insurance duties at once. If you are the controller, ICO reporting may be required within 72 hours of awareness.
Reporting applies where the breach is likely to risk people’s rights and freedoms.
Who pays if a supplier is breached?
The supplier may owe costs under its contract, but your SME may fund response and recovery first. Liability depends on the contract, data roles, policy wording, loss evidence and customer claims.
Do I need to tell the ICO about a supplier breach?
You may need to tell the ICO if you are the controller and the breach is likely to risk people’s rights and freedoms.
The processor tells its controller without undue delay. The controller decides whether to report.
Does cyber insurance cover a supplier outage?
It can cover an outage only if the wording includes a qualifying third-party trigger. Check contingent business interruption, waiting periods, supplier definitions, sub-limits and systemic-event exclusions.
Do this before relying on the policy.
Can I tell customers before the supplier confirms the breach?
You can share verified facts before the supplier completes its report. Do so if a contract or data-risk assessment requires it.
Keep messages factual. Explain practical customer actions and avoid guesses about cause, scale or duration.
What should I check in a supplier contract now?
Check breach notice timing, security duties, liability caps, indemnities, sub-processors, SLAs and audit rights. A cap below your likely 2-to-7-day outage loss may require stronger cover.
It may also require a different commercial arrangement.
What matters most:- Your supplier’s fault does not remove your UK GDPR or customer duties.
- Tell the insurer early and keep a dated record of facts and decisions.
- Test contingent business interruption against every supplier that could stop trading.
- Use contract caps and outage estimates to spot losses your supplier may not repay.
Learn more
Here are some additional resources on this subject: