Survey findings from the Society for Computers and Law reveal a growing focus on resilience, accountability and practical outcomes over compliance-driven drafting.
Yet despite increasingly sophisticated drafting, an important question remains: which contractual protections actually matter when a cyber incident occurs?
At a recent Society for Computers and Law event, we surveyed lawyers specialising in technology and cybersecurity law to understand how practitioners assess cyber risk in commercial negotiations. Across eight questions lawyers voted on the issues they encounter most often in practice.
Lawyers generally agreed that a pragmatic approach focusing on business continuity, meaningful accountability and whether contractual protections can genuinely be enforced when things go wrong was the priority.
Liability Caps Remain the Principal Battleground
The first question asked respondents what single concession they would seek from a vendor if they could secure only one thing during negotiations.
The answer was decisive.
59% of respondents chose a meaningful increase in the liability cap, combined with an uncapped carve-out for breaches caused by a vendor’s gross negligence or wilful misconduct.
By comparison:
- 17% chose enhanced audit rights and annual penetration testing reports.
- 15% selected mandatory cyber insurance with the customer named as an additional insured.
- 10% prioritised a 24-hour breach notification obligation.
The result demonstrates that lawyers continue to view financial accountability as the cornerstone of effective cyber risk allocation.
However comprehensive a supplier’s cybersecurity commitments may appear, they become significantly less valuable if the customer’s ability to recover losses is constrained by a low liability cap. Experienced practitioners recognise that sophisticated security obligations are of limited practical value if the contractual remedies available following a serious incident fail to reflect the scale of potential business losses.
The relatively modest support for accelerated notification requirements is also notable. While reporting obligations remain important, particularly where customers face their own regulatory deadlines, respondents appear to regard notification as just one element of a broader incident-response framework rather than the most valuable protection available.
Operational Disruption Has Overtaken Regulatory Fear
For many years, discussion around cybersecurity has been dominated by the threat of regulatory investigations and fines.
The survey suggests lawyers have a different perspective.
When asked which risk concerns them most when advising on vendor cybersecurity, 73% identified operational disruption to the client as the primary concern.
The remaining responses were:
- 12% inability to recover losses because of liability caps;
- 10% reputational damage;
- 5% regulatory investigations and penalties.
Cyber incidents increasingly create their greatest impact through business interruption rather than regulatory enforcement. Whether the cause is ransomware, software failure, compromised suppliers or cloud-service outages, the immediate consequence is often the inability to conduct business.
The survey suggests that lawyers advising on cyber risk have become deeply conscious of this reality. Increasingly, cyber resilience is viewed through the lens of operational continuity rather than pure regulatory compliance.
The key question is no longer simply whether a breach will result in regulatory scrutiny, but whether the organisation can continue functioning when technology fails.
Audit Rights: Powerful on Paper, Elusive in Practice
Audit rights have become a staple feature of cybersecurity schedules.
Customers frequently demand rights to inspect security controls, review reports, access facilities and investigate incidents. Yet the survey reveals considerable scepticism regarding their effectiveness.
When asked how realistic contractual audit rights are when a security incident actually occurs:
- 73% described them as “mostly theoretical” and difficult to enforce;
- 24% said it depends on the vendor;
- 2% believed they are routinely exercised in practice.
The result highlights a recurring challenge in cyber contracting.
In theory, audit provisions provide transparency and oversight. In practice, vendors often cite confidentiality concerns, security sensitivities, legal privilege, third-party restrictions or operational disruption when customers attempt to exercise those rights following an incident.
Many organisations ultimately receive executive summaries, independent assessor reports or certifications rather than the broad investigative access originally envisaged during negotiations.
The finding may explain why enhanced audit rights were not viewed as the highest-priority concession in Question One. Practitioners appear unconvinced that audit provisions consistently translate into meaningful leverage when a crisis occurs.
Notification Clauses Still Contain Fundamental Weaknesses
The fourth survey question examined vendor breach notification provisions and asked respondents to identify the biggest weakness they encounter.
The responses revealed a clear split between two concerns.
Both of the following received 33% of votes:
- overly narrow definitions of “security incident”;
- insufficient detail regarding the information that must be provided following an incident.
Other responses included:
- 21% concern about notification only being required after confirmation of a breach;
- 13% concern about lengthy notification timelines.
These results suggest practitioners are focused on substance rather than speed alone.
A narrow definition of “security incident” can allow a supplier to delay notification until it has completed extensive internal investigations. Similarly, an obligation simply to notify the customer may provide little practical assistance if it does not specify what information must be shared.
During a cyber incident, customers need actionable information. They need to understand what systems are affected, what data is involved, the likely impact of the incident and the mitigation measures already deployed.
The survey suggests that modern notification clauses should focus as much on information quality as notification timing.
What the Vendors Lawyers Find Most Difficult
Question Five produced one of the most decisive results in the survey.
When asked which category of supplier is hardest to negotiate robust cybersecurity provisions with:
79% chose large US technology providers.
The remaining responses were:
- 11% start-ups and scale-ups;
- 8% other SaaS providers;
- 3% professional services firms.
The result reflects a reality familiar to many technology lawyers.
Large global technology providers frequently possess significant bargaining power. Their services are often mission-critical and deeply embedded within customer operations. As a result, many negotiate using standardised global contracting positions with limited scope for customer amendments.
At the same time, many of these organisations operate some of the world’s most sophisticated cybersecurity programmes. Yet they are often among the least willing to accept bespoke contractual obligations around liability, audit rights, indemnities or security commitments.
The survey illustrates the tension between dependence and leverage. The more important the supplier becomes, the harder it may be to achieve meaningful contractual concessions.
Commercial Pressure Still Wins
Perhaps the most candid result emerged when respondents were asked how much cyber risk influences commercial outcomes in practice.
The answers were revealing:
- 53% said cyber concerns are often overridden by commercial pressure;
- 39% said cyber risk is noted but rarely drives change;
- 8% regarded cyber risk as a deal-breaker;
- 0% believed it materially affects pricing or transaction structure in most cases.
In effect, more than nine in ten respondents indicated that cybersecurity concerns rarely dictate commercial outcomes.
Lawyers may identify risks, explain vulnerabilities and recommend stronger protections. However, many organisations ultimately balance those concerns against delivery deadlines, budget pressures, operational needs and strategic objectives.
The result should not necessarily be viewed as a failure of cyber governance. Businesses are rarely seeking to eliminate all risk. Rather, they are making informed decisions about acceptable levels of risk in pursuit of wider commercial goals.
Nonetheless, the finding serves as a reminder that contractual drafting alone cannot solve cybersecurity challenges. Governance, procurement practices and executive decision-making remain equally important.
What Gives Lawyers Confidence?
The seventh survey question moved beyond drafting and asked respondents which cybersecurity control they would mandate if they could require only one.
The results were striking.
38% selected independent security certifications such as ISO 27001.
Other responses included:
- 27% incident response planning and tabletop exercises;
- 22% regular penetration testing;
- 14% security awareness training.
The popularity of independent certification suggests lawyers place considerable value on externally verified governance frameworks.
Certifications provide evidence not merely of technical controls but of organisational discipline, documented processes and ongoing oversight. They offer reassurance that cybersecurity has been embedded across the organisation rather than treated as a standalone compliance requirement.
The strong support for incident response planning is equally revealing. More than a quarter of respondents preferred preparedness over preventative controls.
Experienced practitioners understand that cyber incidents cannot always be prevented. The organisations that perform best are often those that have rehearsed how they will respond when prevention fails.
Cyber Insurance: Coverage Matters More Than Limits
The final question focused on cyber insurance provisions.
When reviewing a vendor’s cyber insurance obligation, respondents were asked what they regarded as most important.
The winner was clear.
46% prioritised the scope of cover, including protection against ransomware, social engineering attacks and other common cyber risks.
The remaining responses were:
- 29% said they never rely on a vendor’s cyber insurance;
- 23% focused on policy limits;
- 3% prioritised being named as an additional insured;
- 0% focused on insurer quality or credit rating.
The result challenges a common assumption seen in many contract negotiations. Policy limits frequently dominate discussions. Yet lawyers appear far more interested in understanding what the policy actually covers.
Broad coverage is often more valuable than large limits if key cyber risks are excluded from the policy. Coverage for ransomware, supply-chain compromise, incident response costs and business interruption can be more important than the headline figures appearing on the certificate of insurance.
Perhaps even more striking is that almost one-third of respondents do not rely on vendor cyber insurance at all.
This aligns closely with the survey’s broader findings. Practitioners appear to view insurance as supplementary protection rather than a substitute for meaningful liability provisions and strong cybersecurity practices.
From Compliance to Resilience
Taken together, the survey results paint a remarkably consistent picture.
The lawyers surveyed are focused less on theoretical compliance and more on practical resilience.
They want stronger liability positions because accountability matters. They worry most about operational disruption because that is where genuine business harm occurs. They are sceptical of audit rights because they are difficult to enforce. They believe notification clauses often fail to provide meaningful information. They recognise the immense negotiating power of major technology providers. They acknowledge that commercial pressures frequently override cyber concerns.
Most importantly, when asked what gives them confidence in a supplier, they favour independently verified security programmes, tested incident-response capabilities and realistic protections over contractual rhetoric.
For years, negotiations have centred on increasingly lengthy security schedules and ever-expanding compliance requirements. Yet the practitioners surveyed appear to be reaching a more pragmatic conclusion: the true value of a cybersecurity provision is measured not by how impressive it looks during contract negotiations, but by whether it delivers meaningful protection when a cyber incident occurs.
As cyber attacks continue to evolve and technology dependencies deepen, that distinction may become the defining challenge for technology lawyers over the coming decade.
The future of cybersecurity contracting may not lie in drafting longer clauses. It may lie in negotiating provisions that actually work when organisations need them most.