This clause says that if a cyber attack prevents you or the other party from performing the contract, you are NOT excused from your obligations—you still have to pay damages or face breach of contract claims. Cyber attacks are increasingly common, but many contracts don't treat them as force majeure because they're seen as foreseeable and preventable with proper security. However, a major attack on critical infrastructure (like the 2017 NotPetya ransomware) might be so large that even reasonable security couldn't stop it. Courts in both the UK and US are still developing the law here, so the contract language is crucial.

💡
Key Recommendation

Negotiate a middle ground: agree that routine cyber attacks (phishing, minor breaches) are your responsibility, but that large-scale attacks affecting multiple companies are excused. Define "cyber attack" clearly and require both parties to maintain reasonable security standards. Also add a notice requirement: if you're hit by a cyber attack, you must tell the other party within 24-48 hours so they can plan around the disruption. Don't accept a blanket exclusion that leaves you liable even if you're a victim.

Frequently Asked Questions

What does this clause mean in simple terms?

This clause says that if a cyber attack prevents you or the other party from performing the contract, you are NOT excused from your obligations—you still have to pay damages or face breach of contract claims.

Why should I care about this clause?

Cyber attacks are increasingly common, but many contracts don't treat them as force majeure because they're seen as foreseeable and preventable with proper security.

What are my options?

However, a major attack on critical infrastructure (like the 2017 NotPetya ransomware) might be so large that even reasonable security couldn't stop it.

How does this affect small businesses?

Courts in both the UK and US are still developing the law here, so the contract language is crucial.

✅ Action Checklist