Skip to content

Life. Adventure. Consulting. Technology.

Technology

You Outsourced the Work. So Who Answers to Your Customers?

The Cyber Security and Resilience Bill will require suppliers to tell their customers about incidents likely to affect them. That this needs legislating is the interesting part, and it says something about what most contracts leave out.

Chris Cooper 4 min read
A service bridge carrying pipework across a road under a bright open sky

The Cyber Security and Resilience Bill had its second reading in the Lords this afternoon. It brings managed service providers, data centres and critical suppliers into a statutory regime for the first time.

One provision is worth pausing on. Those providers will be required to tell their customers about incidents likely to affect them.

1. The Bill Itself Is Modest and Sensible

Most of it updates the 2018 regulations rather than replacing them — wider scope, more incidents reported, regulators able to enforce consistently across sectors, and penalties with some real weight behind them.

It has had cross-party support at every stage and cleared the Commons without a division. Much of it originates in a review begun under the previous government, which is part of why it has travelled so quietly.

There is no controversy here worth manufacturing. What is interesting is what the legislation implies about the market it is correcting — and that shows up in a single clause.

2. Why Does That Need a Law?

Consider the notification duty on its own. Providers and data centres will have to inform customers of incidents likely to affect them adversely.

Read plainly, that is Parliament requiring suppliers to do something most people assume happens already. If the company running your systems has an incident that will reach you, being told seems a low bar.

The fact that it needs legislating at all tells you it was not reliably in the contracts.

3. Service Levels Describe the Good Days

Third-party arrangements are almost universally governed on availability. Uptime, response times, resolution targets, service credits attached to each.

All of that describes performance while things are broadly working — a measure of ordinary operation, with a tolerance drawn around it.

Very few contracts describe the other case — what the supplier owes when it stops entirely, for how long, and what it must tell you while that is going on.

4. You Can Contract Out the Work, Not the Consequence

Your customers do not care who runs your systems. Most have no idea anybody else does, and they care only whether they can be served this morning.

An organisation can contract out the operation of something. It cannot contract out the consequence of that thing failing — and over twenty years the two have drifted a long way apart.

The regulator has arrived precisely because the market did not close that gap on its own.

5. The Gap Between Assent and Effect

Royal Assent is expected before the end of the year. Substantive obligations are not expected until somewhere around 2028, arriving through secondary legislation after a consultation.

That gap is exactly why this is worth attention now rather than later. Read as a deadline, it invites two years of nothing followed by a scramble in 2028.

Read instead as a description of where accountability is heading, it is a reasonable prompt to examine arrangements signed long before any of this was contemplated.

6. Outsourcing Was and Remains the Right Answer

None of which argues against using third parties. For most organisations a specialist provider runs the thing better, more cheaply and more securely than any in-house team could manage.

That was true when the decision was taken, and it is still true now. The decision was never the mistake.

What did not happen alongside it was any matching change to how accountability was written down. The work moved — and the model for what happens when it fails stayed exactly where it was.

7. What to Establish in Your Own Arrangements

None of this waits on legislation. Four things are worth knowing about every significant supplier:

  • what they must tell you, how quickly, and who they tell
  • which of your customers are affected if that supplier stops, and for how long
  • who in your organisation speaks to those customers while recovery is under way
  • which of your suppliers depend on the same few providers underneath

The third is usually unassigned, and it determines how the whole week is remembered afterwards.

8. The Regulator Is Not Your Risk Committee

There is a temptation to treat legislation as the answer. Comply with it, and the exposure has been dealt with.

It has not. The Bill raises a floor across a whole market — it does not tell any particular organisation which of its own suppliers it could not survive the loss of.

That question was always the organisation’s own to answer, and it still will be long after the regime takes effect.

Final Thought

The most useful thing in this Bill may turn out to be its least dramatic provision. Somebody has finally written down that a supplier ought to tell its customers when something has gone wrong.

Every organisation reading that should ask whether its own contracts say the same — and, if they do not, how it expects to find out.

Stay in touch

Occasional writing, straight to your inbox

A short note when I publish something worth reading. No noise, and easy to leave whenever you like.