Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Technology Quotient
  4. Navigating Cyber Supply Chain Disputes: Litigation Risk for Customers and IT Suppliers
8MIN

Navigating Cyber Supply Chain Disputes: Litigation Risk for Customers and IT Suppliers

Jul 23 2026

In an increasingly interconnected digital landscape, businesses – particularly those operating critical infrastructure – rely heavily on IT suppliers for essential services, from managed services to cloud hosting. While these partnerships are crucial for operational efficiency, they can also introduce significant cyber risk. When supplier systems are compromised, customers are confronted with operational disruption, substantial financial and reputational losses, and regulatory scrutiny, while suppliers may face contractual claims, disclosure pressure and questions over the adequacy of their own security representations and incident response. 

Supply chain hits are real

The threat of supply chain attacks is no longer theoretical. Reports from ENISA highlight a concerning increase in targeted attacks on IT providers serving critical sectors, in particular public administration but also transport, digital infrastructure, finance, manufacturing and energy, “showing that attackers are actively leveraging indirect pathways through third-party providers.” For instance, the recent cyberattack on an external IT service provider severely disrupted public transport ticketing systems across Italy. Another example is the compromise of a technology provider serving Spain's largest oil and gas refiner leading to customer data leaks. There are many more examples of supply chain attacks in the cyber space. 

Litigation risks follow closely behind: The SEC alleged in 2023 that SolarWinds and its security officer had violated U.S. securities laws by making misleading disclosures about cybersecurity vulnerabilities prior to the 2020 Sunburst attack, with the U.S. District Court for the Southern District of New York sustaining a fraud claim linked to public security representations. Despite the court’s dismissal of the majority of the SEC’s claims, the case highlights a critical takeaway: a supplier's public statements regarding cybersecurity – regardless of the form or medium in which they are distributed – are discoverable and may form the basis for damage claims. 

Implications of EU Cyber Security Requirements

EU cyber security requirements further amplify such supply chain due diligence expectations. The NIS2 Directive, EU-wide legislation on cybersecurity ((EU) 2022/2555), strengthens the European legal framework for cybersecurity and is intended to help raise and harmonise cybersecurity standards across the EU (for details, please see our blog post). It requires organisations to implement comprehensive risk management measures to better protect themselves against digital threats, including conducting thorough supplier due diligence and ensuring supply chain security. This means organisations must generally check, rather than merely trust, their suppliers' security baselines and failing to do so may shift regulatory exposure back to the operator. 

Article 21(2)(d) NIS2 Directive mandates measures addressing "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers," while Article 21(3) NIS2 Directive specifies that entities must "take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures". Breaches of obligations regarding cybersecurity requirements, reporting significant incidents or communication of significant cyber threats are subject to severe GDPR-style fines set by national law.

In Europe, the CER Directive (EU 2022/2557) further raises the bar for organisations designated as critical entities. It is designed to strengthen resilience to systemic disruptions and in particular establishes resilience as a responsibility at board level. Together, NIS2 and CER Directive form a comprehensive framework focussing on cybersecurity as well as physical and operational resilience. 

In addition, more specific sector frameworks exist, such as the Digital Operational Resilience Act (DORA) for financial services. For customers, these rules sharpen the need to evidence supplier due diligence and ongoing oversight; for suppliers, they increase the commercial and litigation importance of being able to substantiate security controls, development practices, subcontractor management and incident response decisions. 

In a dispute following a supplier cyber incident, these statutory duties can shape the standard of care and provide a reference point for contractual claims, arguments on breach, and allocation of loss.

Key Strategic Issues in Cyber Supply Chain Disputes

There are several key strategic issues to be considered before and in case of disputes stemming from IT supplier breaches. They matter not only for customers seeking recovery, but also for suppliers seeking to manage liability, preserve evidence and defend their security posture:

  • Technical and organisational measures (TOMs): Assessing whether supplier's security measures were truly "state-of-the-art" is a highly fact-intensive exercise, often requiring reliance on forensic experts. Customers will focus on whether promised controls were implemented and monitored; suppliers should be ready to evidence design decisions, patching, access controls, logging, secure development and the risk-based rationale for their security architecture.
  • Discovery: Litigants are increasingly seeking to leverage tools like GDPR Article 15 requests, Data Protection Authority proceedings, and access to criminal files to obtain internal supplier documentation, providing deeper insights into their security posture and incident response. Suppliers should therefore anticipate that internal security narratives, incident timelines and customer communications may later be tested against forensic evidence and regulatory records.
  • External Specialised Counsel: Instructing forensic investigators through counsel to preserve attorney-client privilege (where applicable) over their findings and advice. Privilege considerations should be built into the investigation from the outset, given that privilege protection may differ significantly between jurisdictions.
  • Regulatory exposure: Taking account of potential investigations under the CER Directive and the NIS2 Directive by competent national authorities for inadequate supply chain security as well as potential GDPR fines, if personal data are exfiltrated. Customers may need to justify supplier selection, contractual safeguards, oversight and escalation decisions, while suppliers may need to defend the adequacy of their own cyber controls, incident notifications, subcontractor management and customer-facing statements.
  • Damages: Customers should carefully assess, quantify and document potential damages at an early stage, such as business interruption and lost margin from system downtime, emergency IT, legal and forensic costs, costs of restoring data or rebuilding systems, contractual penalties or damages owed to customers, increased costs of substitute services, loss of customer contracts, third-party claims and, where recoverable, indemnification for regulatory fines. In particular, customers are well advised to substantiate these losses with invoices, purchase orders and time records; downtime logs identifying affected systems, duration and business impact; records of internal time spent on containment, remediation and customer communications; board papers and incident decision logs; and evidence of customer complaints and lost contracts. Suppliers should likewise preserve evidence of mitigation steps, root-cause analysis, customer communications, alternative service arrangements and whether the claimed losses stem from the incident, pre-existing vulnerabilities or the customer’s own response.
  • Liability exclusion or limitation: Both suppliers and customers are well advised to scrutinise their contractual set-up, in particular liability architecture such as caps, exclusions for indirect or consequential loss, loss of profit, loss of data, business interruption, regulatory fines and force majeure language that can materially narrow recovery after a supplier cyber incident. Customers will test whether carve-outs for confidentiality, data protection, wilful misconduct, gross negligence or regulatory fines preserve meaningful recovery; suppliers will focus on whether liability caps, exclusions, mitigation duties and causation requirements are enforceable.
  • Burden of proof and evidence: Observing rules of burden of proof is critical since the customer must in general be able to prove the content of the applicable security obligation, the supplier’s technical failure, the causal link to the incident and the resulting loss. Because much of this evidence sits with the supplier, contracts and incident playbooks should require prompt preservation and disclosure of logs, patching histories, access records, forensic images and internal incident reports. Otherwise, the customer may face a proof gap precisely where the supplier controls the relevant facts. From the supplier perspective, the same evidence can be decisive in showing that controls were appropriate, the incident was caused by a third-party exploit or customer-side vulnerability, or that claimed losses were not caused by the supplier’s breach. Whether the customer can force preservation or review those materials depends on the contract, applicable law and dispute forum. Clear audit, cooperation and evidence-preservation clauses can therefore strengthen the customer’s position while giving suppliers a structured process to protect security-sensitive information, trade secrets and personal data, for example through forensic experts, confidentiality rings or secure data rooms.

Arbitration or ordinary courts: forum choice as a litigation lever

Once a supplier cyber incident escalates into a dispute, the choice between arbitration and ordinary courts becomes a strategic decision for both sides. Many IT supply agreements contain arbitration clauses, often treated as boilerplate at signing, although the dispute forum can materially affect leverage, evidence access, timing and public exposure. Customers should therefore review dispute resolution clauses before an incident occurs and, where possible, tailor them to the operational realities of cyber disputes; suppliers should do the same to ensure that confidentiality, emergency relief, expert evidence and multi-customer dispute management are workable in practice.

Arbitration may be attractive where confidentiality is important, technical expertise is needed on the tribunal or cross-border enforcement is likely. For suppliers, confidentiality may be particularly valuable where one incident affects several customers and public findings could influence parallel claims, customer negotiations or regulatory proceedings. Arbitration can also allow parties to agree cyber-specific procedural tools, such as fast-track timetables, confidentiality rings, expert evidence protocols and secure handling of forensic material. The downside is that arbitration may offer more limited coercive tools against third parties, fewer public-law disclosure mechanisms and potentially higher upfront costs. Urgent interim relief may also require parallel court support, particularly where systems, evidence or third-party data must be preserved quickly.

Ordinary courts may be preferable where the customer needs broad evidence-gathering tools, e.g. access to criminal investigation files, third-party involvement, public precedent or rapid injunctive measures. Court proceedings can also create public pressure on a supplier, which may be helpful in settlement dynamics. The trade-off is reduced confidentiality, less control over the decision-maker’s technical expertise and, in some jurisdictions, slower proceedings or more fragmented cross-border enforcement.

Call to action

For customers and IT suppliers alike, the practical question is no longer whether supplier cyber risk exists, but whether each side can evidence that it managed that risk with sufficient rigour before the incident. 

  • Customers should use the current regulatory momentum to stress-test their most important IT supply contracts and incident playbooks: identify business-critical suppliers, map notification and cooperation duties, check whether a robust contractual framework is in place, quantify and document potential damages at an early stage, scrutinise potential liability exclusions and burden-of-proof clauses and tailor dispute resolution clauses to the operational realities of cyber disputes.
  • Suppliers should conduct the same exercise from the opposite direction: align security promises with actual controls, document patching and secure development decisions, prepare evidence-preservation and customer-communication protocols, review subcontractor dependencies and ensure that liability caps, audit rights, disclosure duties and arbitration clauses are commercially and procedurally defensible. 

These steps help both parties to establish a sound procedural and evidential basis for any future disputes, even before an incident occurs: clear obligations, preserved technical evidence, tested notification chains and dispute clauses that provide real procedural advantage when systems are down and facts sit unevenly across the supply chain.

Tags

cyber securityeu nis2 directiveinfrastructure and transportlitigationenergy and natural resourcescommercial litigationdata cybersecurity and tech regulationdigital infrastructureenergyinfrastructuretechnology

Authors

Düsseldorf

Moritz Becker

Partner
Düsseldorf, Frankfurt am Main

Theresa Ehlen

Partner
Düsseldorf

Christoph Werkmeister

Global Co-Head of Data & Technology
Düsseldorf

Sarah Hillebrand

Counsel
Düsseldorf

Christian Sosna

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome