Blog Post

Cyber Loss When the Company Is Someone Else's Fourth Party

September 28, 2026

Table of Contents

Third-party risk content is written from the customer's side. Assess your provider, tier your vendors, understand your concentration.

‍

A technology provider is on the other end of every one of those assessments, and its own incident propagates outward through contract rather than inward through remediation. The instinct is that the contracts therefore determine the loss. They determine the smaller half of it.

‍

What Do the Contracts Cap?

‍

What the provider owes, which is computable from billing data and considerably smaller than expected.

‍

Service credits are typically the sole remedy for a service level miss, overall liability is commonly capped at a multiple of the fees received over a set period, frequently twelve months of fees or a multiple of monthly fees, and consequential damages including lost profits and lost revenue are almost universally excluded.

‍

Which Makes the Contractual Exposure Unusually Estimable

‍

Published analysis of the arithmetic puts a provider at a billion of annual recurring revenue with one major outage dropping half its customers into a twenty-five percent credit tier at around ten million of theoretical credit liability, with realized liability typically thirty to sixty percent of that because customers have to claim and many do not. So three to six million, reserved against in the affected quarter.

‍

What Do the Contracts Not Touch?

‍

The larger half, and it is roughly an order of magnitude larger in the same scenario.

‍

Exceedance curve showing the likelihood of annual loss exceeding successive percentages of revenue with the average marked on the curve
Expressing exposure against revenue is the right frame where the dominant term lands in next year's revenue rather than in incident cost.

The same analysis puts a four hundred basis point drop in net revenue retention at forty million of revenue loss the following year, two hundred basis points of incremental logo churn at twenty million, and a ten percent degradation in new business win rate against a two hundred million new-revenue target at another twenty million of opportunity cost.

‍

Which Inverts the Usual Framing

‍

The contract caps what a provider owes and says nothing about what it loses. Retention, churn and win rate operate independently of any limitation of liability clause, and they land in next year's revenue rather than in an incident ledger, which is why they are frequently absent from the figure.

‍

What Pierces the Cap?

‍

Several categories, and one of them transmits somebody else's regulatory exposure into your own accounts.

‍

  • Conduct exclusions: Gross negligence and willful misconduct are commonly carved out of the limitation entirely.
  • Indemnification obligations: Including indemnity for a customer's downstream notification costs following a breach originating with you.
  • Statutory liability: Penalties that legislation does not permit contracting around.

‍

Intellectual property claims complete the usual set. The notification indemnity is the one worth pricing carefully, because it scales with the customer's record count rather than with your fees, so a small contract can carry a large indemnity.

‍

What Has Changed in Negotiation?

‍

The caps are no longer uniform, so a provider's exposure is a portfolio rather than a clause.

‍

Breakdown of extreme annual loss by damage type showing which categories contribute most at the one-in-hundred level
Separating damage types is what shows a capped contractual category sitting beneath an uncapped commercial one.

Following widely reported provider incidents, large customers routinely request uncapped recovery for vendor-caused multi-day outages. Providers resist, and the settlement is frequently a higher per-event sublimit in the tens of millions rather than full uncapping. It is the most actively contested provision in current enterprise negotiation.

‍

Which Concentrates Exposure Where It Already Hurts

‍

The customers with the highest negotiated sublimits are the largest ones, and they are also the customers whose departure moves retention most. So contractual and commercial exposure correlate rather than offsetting, and both peak in the same accounts, which concentration you cannot diversify away covers from the dependency side.

‍

How Should the Exposure Be Measured?

‍

As a sum across the contract portfolio rather than as a single cap, which is a different exercise from reading the standard terms.

‍

The relevant figure is the total of per-event sublimits across all agreements, plus the credit liability computed from the billing base, plus the notification indemnity exposure computed from customer record counts. Three sums, each from a different system, and none of them is the standard contract template.

‍

Who Can Produce It?

‍

Nobody alone. Legal holds the negotiated variations, finance holds the billing base and the retention sensitivity, and security holds the scenario that would trigger any of it. The figure exists across three functions and belongs to none, and an obligation split across functions is how it stays unmeasured.

‍

Does Insurance Reach It?

‍

Partly, and the split follows the same line as the caps.

‍

Technology errors and omissions cover responds to claims from customers, which is the contractual half. Lost future revenue from churn and degraded win rate is not a claim by anybody and is uninsured almost everywhere. So the larger term is retained by construction rather than by decision.

‍

Which Affects the Funding Case

‍

A retained exposure of that size argues for prevention and for recovery speed more strongly than a transferable one would, since nothing else absorbs it. Reliability investment is being justified against the wrong number wherever the case rests on credit liability alone, and cyber risk quantification separating retained from transferred is what shows the difference.

‍

What Does the Customer Assessment Cost?

‍

A second exposure entirely, and it arrives whether or not anything goes wrong.

‍

A provider serving regulated customers is inside their third-party risk programs, so questionnaires, evidence requests, audit rights and in some sectors a place on a register submitted to a supervisor. The effort is continuous rather than incidental, and it grows with the customer base rather than with the risk.

‍

Which Turns Evidence Into a Commercial Function

‍

A provider able to answer an assessment from standing records closes faster than one assembling answers per request. The same artifacts serve every customer, so the cost of producing them once is recovered across the portfolio, and producing evidence on somebody else's timeline is the capability being tested.

‍

What Happens After an Incident?

‍

The assessment burden rises sharply and permanently. Every customer reassesses, prospects ask about it in diligence, and the questions become specific rather than generic. The additional effort is a real cost of the incident and appears in nobody's loss estimate, which is a third term alongside the capped and the retained ones.

‍

What Should Be Established?

‍

Four figures, and the first is the one nobody has.

‍

The total of negotiated per-event sublimits across the contract portfolio, and what proportion of revenue sits under negotiated rather than standard terms. Credit liability at the theoretical maximum and at a realistic claim rate. The notification indemnity exposure, computed from customer record counts rather than from fees. Then the retention sensitivity, meaning what a stated drop in net revenue retention costs, which finance can supply and which is the largest term of the four.

‍

The Contract Caps What You Owe

‍

A provider's incident travels outward through its contracts, and the contractual half is capped, credit-based and computable from billing data, arriving at single-digit millions for a large provider after a realistic claim rate is applied. The uncapped half is roughly an order of magnitude larger, since retention, churn and win-rate degradation operate independently of any limitation clause and land in the following year's revenue rather than in incident cost. Several categories pierce the cap, and the notification indemnity is the one to price carefully because it scales with the customer's record count rather than with your fees. Negotiated sublimits mean exposure is now a portfolio rather than a clause, concentrated in the same accounts whose departure hurts retention most. Kovrr's cyber risk quantification separates the capped term from the retained one.

‍

To see provider-side exposure separated into capped and retained components, book a demo with our risk experts.

Tomer Shoolman

Product Manager

Provider-Side Exposure FAQs

Speak to an Expert

What is a typical SaaS liability cap?

Is the contractual exposure the largest part of a provider's outage loss?

What is excluded from a SaaS limitation of liability?

Are customers negotiating uncapped damages for outages?

How do you size a provider's own outage exposure?

Does insurance cover a provider's outage loss?