This clause decides who pays for losses if there's a computer security problem—like a hacked website, stolen data, or system downtime. For example, if a software company's code has a security flaw that lets hackers steal customer information, this clause determines whether the software company or the client pays for the investigation, notification letters, credit monitoring services, and potential lawsuits. This matters because cyber incidents are increasingly common and expensive; a single breach can cost hundreds of thousands of pounds or dollars. The clause is low-risk if it's clearly written because both parties can plan ahead and buy cyber insurance.
Make sure the clause clearly defines what "cyber liability" includes (data theft, system failure, ransomware, etc.) so there's no argument later about what's covered. If you're providing a digital service or software, try to cap your liability or exclude liability for client negligence (like weak passwords). If you're buying a digital service, push for the vendor to carry cyber insurance and require them to notify you quickly of any breach—don't accept a clause that lets them hide security problems. ---
Frequently Asked Questions
What does this clause mean in simple terms?
This clause decides who pays for losses if there's a computer security problem—like a hacked website, stolen data, or system downtime.
Why should I care about this clause?
For example, if a software company's code has a security flaw that lets hackers steal customer information, this clause determines whether the software company or the client pays for the investigation, notification letters, credit monitoring services, and potential lawsuits.
What are my options?
This matters because cyber incidents are increasingly common and expensive; a single breach can cost hundreds of thousands of pounds or dollars.
How does this affect small businesses?
The clause is low-risk if it's clearly written because both parties can plan ahead and buy cyber insurance.
