When the Breach Comes Through a Vendor
An Israeli SaaS company wakes up one morning to find that data belonging to tens of thousands of its customers has leaked online. The investigation reveals that the company's own systems were never breached. The breach occurred at a third-party vendor that operates its customer management system, which had suffered a ransomware attack weeks earlier without reporting it. Customers, regulators, and the press are not interested in exactly where the technical breach occurred. They turn to the company that collected the data in the first place.
This scenario has repeated itself in various forms in recent years, and it points to a clear trend: attackers increasingly recognize that the most effective way to compromise an organization is not always a direct attack, but rather infiltration through the weakest link in the chain — a cloud services provider, a development contractor, a technical support vendor, or any third party with access to the organization's data or systems.
For Israeli technology companies, this means that cyber risk management can no longer be limited to securing internal infrastructure. It must include mapping, oversight, and contractual control of every vendor connected to the company's data and systems — before signing, throughout the engagement, and at its conclusion.
The Relevant Legal Framework in Israel
The Privacy Protection Regulations (Data Security), 5777-2017, enacted pursuant to the Privacy Protection Law, 5741-1981 (as amended by Amendment 13), impose on a database owner a duty to ensure an adequate level of security even when the actual processing of data is carried out by an external party. In other words, handing data over to a vendor does not transfer legal responsibility toward data subjects.
Amendment 13 to the Privacy Protection Law, in force since 14.8.2025, expanded the enforcement powers of the Privacy Protection Authority and added a duty to report serious security incidents. This obligation is particularly relevant when the incident occurs at a vendor, since the company must receive prompt and accurate information from the vendor in order to meet the statutory deadlines. It is worth emphasizing: the database registration requirement under Amendment 13 has been narrowed and now applies primarily to public bodies and to data brokers as defined by the legislature, rather than as a blanket obligation on every business — but this is a separate matter from the data security duty itself, which remains in force and applies to all database owners.
Beyond privacy law, general contract law and tort law impose on companies a duty of care in selecting and supervising subcontractors. Where harm is caused to a third party as a result of negligence in selecting a vendor or in the absence of oversight over it, the company may bear independent liability — in addition to any remedy it may have against the vendor itself.
Due Diligence Before Engaging a Vendor
Effective due diligence begins with classifying the vendor according to the level of risk it poses — the scope of its access to data, which systems it connects to, and what type of data it processes. A vendor holding admin access to a core system or processing sensitive data requires far more thorough review than one providing a peripheral service with no access to data.
- Reviewing recognized security certifications (such as ISO 27001 or SOC 2) and their validity
- A security questionnaire detailing the vendor's access policy, encryption practices, and permissions management
- Inquiring whether the vendor itself relies on subcontractors (a "fourth-party" risk) and the degree of oversight it exercises over them
- Reviewing the vendor's history of prior security incidents, to the extent it can be identified
- Assessing the vendor's financial and operational stability, as an indirect measure of its ability to meet security commitments over time
It is advisable to build a tiered and documented review process, so that the highest risk tier requires a full review including interviews with the vendor's security team, while lower risk tiers can be handled through a short questionnaire and self-certification.
Clauses That Must Appear in Every Vendor Contract
A contract lacking clear data security commitments leaves the company exposed even where the vendor itself was negligent. The following are the key clauses that should appear in any agreement with a vendor holding access to data or systems:
- A defined security standard — a vendor commitment to meet a concrete security standard, rather than a general obligation to take "reasonable measures"
- Audit rights — the company's ability to conduct a security audit or require an independent audit report at fixed intervals
- Prior approval for subcontractors — an obligation on the vendor to obtain the company's approval before transferring data processing to an additional party
- Immediate breach notification duty — with a defined timeframe in the contract, short enough to allow the company to meet its own regulatory obligations
- Data segregation — a commitment to secure the company's data separately from other customers' data held by the vendor
- Deletion or return of data upon termination — including written confirmation that deletion has been carried out
It is advisable to avoid generic language copied from the vendor's standard template. A contract drafted by the vendor tends to protect the vendor's interests, not the client's.
Advance Coordination for Responding to a Vendor Cyber Incident
One of the most common failures in vendor engagements is the absence of a clear mechanism for coordination during a security incident. When a vendor discovers a breach, the company has a direct and immediate interest in learning of it right away — not only to protect its customers, but also to meet its own reporting obligations under law.
A well-drafted contract will include an explicit reporting timeline, a specification of the information the vendor must provide (the nature of the incident, the type of data exposed, the scope of affected individuals), and a duty of full cooperation in investigating the incident. For critical vendors, it is advisable to run joint response exercises in advance, so that in real time both parties know who is responsible for what.
It is also worth incorporating the map of critical vendors into the organization's overall cyber incident response plan, so that the board of directors receives a complete picture of exposure — not only through internal systems, but through the vendor supply chain as well.
Allocating Liability, Indemnification, and Cyber Insurance
When a security incident occurs at a vendor, the question of who bears the cost of the damage — customer notifications, regulatory handling, compensating affected individuals — depends heavily on how the liability and indemnification clauses are drafted. A well-drafted indemnification clause obligates the vendor to indemnify the company for damages resulting from a breach of its security commitments.
Particular attention should be paid to limitation of liability clauses. Many vendors attempt to cap their exposure at the amount of service fees paid to them — a figure that is often substantially lower than the actual cost of handling a real data breach. It is advisable to negotiate a separate, higher liability cap specifically for data security damages, distinct from the general liability cap in the contract.
Alongside this, companies should consider whether to require the vendor to present an active cyber insurance policy, with coverage scaled to the sensitivity of the data it processes. Such a policy provides an additional layer of protection beyond the contractual commitment alone, and reduces the risk that the vendor will be unable to meet its indemnification obligation in the event of an actual incident.
What Companies Should Actually Do
Managing supply chain risk is not a one-time project but an ongoing process. The following practical steps are worth implementing:
- Complete mapping of all vendors with access to data or systems, ranked by risk level
- Updating vendor contract templates to include the security, reporting, and indemnification clauses described above
- Setting a periodic review schedule for critical vendors, not only at the time the original contract is signed
- Incorporating vendor risk management into the security reports presented to the board of directors
- Revisiting existing contracts with long-standing vendors, many of which were signed before this issue received the attention it deserves
Companies that embed contractual and operational discipline into their vendor management do more than reduce the likelihood of a security incident. They also significantly improve their legal position if and when such an incident nonetheless occurs. That gap, between a company that prepared in advance and one caught unprepared, is often what ultimately determines the scope of legal liability.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.