
Blog Post
Cyber Loss When the Company Is Someone Else's Fourth Party
September 28, 2026
Third-party risk content is written from the customer's side. Assess your provider, tier your vendors, understand your concentration.
A technology provider is on the other end of every one of those assessments, and its own incident propagates outward through contract rather than inward through remediation. The instinct is that the contracts therefore determine the loss. They determine the smaller half of it.
What Do the Contracts Cap?
What the provider owes, which is computable from billing data and considerably smaller than expected.
Service credits are typically the sole remedy for a service level miss, overall liability is commonly capped at a multiple of the fees received over a set period, frequently twelve months of fees or a multiple of monthly fees, and consequential damages including lost profits and lost revenue are almost universally excluded.
Which Makes the Contractual Exposure Unusually Estimable
Published analysis of the arithmetic puts a provider at a billion of annual recurring revenue with one major outage dropping half its customers into a twenty-five percent credit tier at around ten million of theoretical credit liability, with realized liability typically thirty to sixty percent of that because customers have to claim and many do not. So three to six million, reserved against in the affected quarter.
What Do the Contracts Not Touch?
The larger half, and it is roughly an order of magnitude larger in the same scenario.

The same analysis puts a four hundred basis point drop in net revenue retention at forty million of revenue loss the following year, two hundred basis points of incremental logo churn at twenty million, and a ten percent degradation in new business win rate against a two hundred million new-revenue target at another twenty million of opportunity cost.
Which Inverts the Usual Framing
The contract caps what a provider owes and says nothing about what it loses. Retention, churn and win rate operate independently of any limitation of liability clause, and they land in next year's revenue rather than in an incident ledger, which is why they are frequently absent from the figure.
What Pierces the Cap?
Several categories, and one of them transmits somebody else's regulatory exposure into your own accounts.
- Conduct exclusions: Gross negligence and willful misconduct are commonly carved out of the limitation entirely.
- Indemnification obligations: Including indemnity for a customer's downstream notification costs following a breach originating with you.
- Statutory liability: Penalties that legislation does not permit contracting around.
Intellectual property claims complete the usual set. The notification indemnity is the one worth pricing carefully, because it scales with the customer's record count rather than with your fees, so a small contract can carry a large indemnity.
What Has Changed in Negotiation?
The caps are no longer uniform, so a provider's exposure is a portfolio rather than a clause.

Following widely reported provider incidents, large customers routinely request uncapped recovery for vendor-caused multi-day outages. Providers resist, and the settlement is frequently a higher per-event sublimit in the tens of millions rather than full uncapping. It is the most actively contested provision in current enterprise negotiation.
Which Concentrates Exposure Where It Already Hurts
The customers with the highest negotiated sublimits are the largest ones, and they are also the customers whose departure moves retention most. So contractual and commercial exposure correlate rather than offsetting, and both peak in the same accounts, which concentration you cannot diversify away covers from the dependency side.
How Should the Exposure Be Measured?
As a sum across the contract portfolio rather than as a single cap, which is a different exercise from reading the standard terms.
The relevant figure is the total of per-event sublimits across all agreements, plus the credit liability computed from the billing base, plus the notification indemnity exposure computed from customer record counts. Three sums, each from a different system, and none of them is the standard contract template.
Who Can Produce It?
Nobody alone. Legal holds the negotiated variations, finance holds the billing base and the retention sensitivity, and security holds the scenario that would trigger any of it. The figure exists across three functions and belongs to none, and an obligation split across functions is how it stays unmeasured.
Does Insurance Reach It?
Partly, and the split follows the same line as the caps.
Technology errors and omissions cover responds to claims from customers, which is the contractual half. Lost future revenue from churn and degraded win rate is not a claim by anybody and is uninsured almost everywhere. So the larger term is retained by construction rather than by decision.
Which Affects the Funding Case
A retained exposure of that size argues for prevention and for recovery speed more strongly than a transferable one would, since nothing else absorbs it. Reliability investment is being justified against the wrong number wherever the case rests on credit liability alone, and cyber risk quantification separating retained from transferred is what shows the difference.
What Does the Customer Assessment Cost?
A second exposure entirely, and it arrives whether or not anything goes wrong.
A provider serving regulated customers is inside their third-party risk programs, so questionnaires, evidence requests, audit rights and in some sectors a place on a register submitted to a supervisor. The effort is continuous rather than incidental, and it grows with the customer base rather than with the risk.
Which Turns Evidence Into a Commercial Function
A provider able to answer an assessment from standing records closes faster than one assembling answers per request. The same artifacts serve every customer, so the cost of producing them once is recovered across the portfolio, and producing evidence on somebody else's timeline is the capability being tested.
What Happens After an Incident?
The assessment burden rises sharply and permanently. Every customer reassesses, prospects ask about it in diligence, and the questions become specific rather than generic. The additional effort is a real cost of the incident and appears in nobody's loss estimate, which is a third term alongside the capped and the retained ones.
What Should Be Established?
Four figures, and the first is the one nobody has.
The total of negotiated per-event sublimits across the contract portfolio, and what proportion of revenue sits under negotiated rather than standard terms. Credit liability at the theoretical maximum and at a realistic claim rate. The notification indemnity exposure, computed from customer record counts rather than from fees. Then the retention sensitivity, meaning what a stated drop in net revenue retention costs, which finance can supply and which is the largest term of the four.
The Contract Caps What You Owe
A provider's incident travels outward through its contracts, and the contractual half is capped, credit-based and computable from billing data, arriving at single-digit millions for a large provider after a realistic claim rate is applied. The uncapped half is roughly an order of magnitude larger, since retention, churn and win-rate degradation operate independently of any limitation clause and land in the following year's revenue rather than in incident cost. Several categories pierce the cap, and the notification indemnity is the one to price carefully because it scales with the customer's record count rather than with your fees. Negotiated sublimits mean exposure is now a portfolio rather than a clause, concentrated in the same accounts whose departure hurts retention most. Kovrr's cyber risk quantification separates the capped term from the retained one.
To see provider-side exposure separated into capped and retained components, book a demo with our risk experts.
Provider-Side Exposure FAQs
Speak to an ExpertWhat is a typical SaaS liability cap?
Overall liability is commonly capped at a multiple of the fees received over a set period, frequently twelve months of fees or a multiple of monthly fees, with service credits typically the sole remedy for a service level miss and consequential damages including lost profits and lost revenue almost universally excluded. That makes the contractual exposure unusually estimable, since it can be computed from the provider's own billing data.
Is the contractual exposure the largest part of a provider's outage loss?
No, and it is roughly an order of magnitude smaller. Published analysis puts a provider at a billion of annual recurring revenue with one major outage at around ten million of theoretical credit liability, and three to six million realized. The same analysis puts a four hundred basis point drop in net revenue retention at forty million of revenue loss the following year, plus twenty million from incremental logo churn and twenty million of opportunity cost from degraded win rate.
What is excluded from a SaaS limitation of liability?
Several categories commonly sit outside the cap. Gross negligence and willful misconduct are usually carved out entirely, as are intellectual property claims. Indemnification obligations frequently are too, including indemnity for a customer's downstream notification costs following a breach originating with the provider. And statutory liability covers penalties that legislation does not permit contracting around.
Are customers negotiating uncapped damages for outages?
Requesting them, and settling for higher sublimits. Following widely reported provider incidents, large customers routinely request uncapped recovery for vendor-caused multi-day outages, providers resist, and the settlement is frequently a higher per-event sublimit in the tens of millions rather than full uncapping. It is the most actively contested provision in current enterprise negotiation, so a provider's exposure is a portfolio rather than a clause.
How do you size a provider's own outage exposure?
As three sums from three systems. The total of per-event sublimits across all agreements, the credit liability computed from the billing base at both theoretical maximum and a realistic claim rate, and the notification indemnity exposure computed from customer record counts. Legal holds the negotiated variations, finance holds the billing base and retention sensitivity, and security holds the scenario, so the figure exists across three functions and belongs to none.
Does insurance cover a provider's outage loss?
The contractual half, largely. Technology errors and omissions cover responds to claims from customers, which is the capped portion. Lost future revenue from churn and degraded win rate is not a claim by anybody and is uninsured almost everywhere, so the larger term is retained by construction rather than by decision, which argues for prevention and recovery speed more strongly than a transferable exposure would.




