Think your vendor agreements protect you when a breach happens? Many organizations only discover the gaps after an incident forces them to scrutinize the fine print.
Vendor contracts lay the groundwork for cyber risk transfer, but they don't eliminate your exposure. When a marketing agency loses your customer database or a cloud provider goes offline, the contract determines financial responsibility, but your operations still suffer. Review these agreements before an incident occurs, not during one.
This template provides a structured framework for evaluating vendor cyber contracts. Use it during renewals, before onboarding new vendors, or when your organization's risk profile changes.
Purpose of the Template
This review template helps identify coverage gaps between what your vendor contract promises and what your Stand-Alone Cyber Policy actually covers. Use it to:
- Verify that vendor insurance requirements match your actual exposure.
- Confirm indemnification language covers the incidents you care about.
- Spot conflicts between vendor obligations and your own policy terms.
- Document which party controls incident response decisions.
The template focuses on cyber-specific provisions. You'll still need legal review for broader contractual issues, but this provides the operational lens your risk and insurance teams need.
Prerequisites
Before using this template, gather:
- Current vendor contract (including all amendments and exhibits).
- Your organization's Stand-Alone Cyber Policy declarations and coverage forms.
- List of what data or systems the vendor accesses.
- Documentation of the vendor's current insurance certificates.
Understand which business functions this vendor supports. A payroll provider holding employee tax records creates different exposure than a marketing agency managing your social media accounts.
The Vendor Cyber Contract Review Template
Vendor Name: _______________
Contract Renewal Date: _______________
Reviewer: _______________
Review Date: _______________
Section 1: Insurance Requirements
Does the contract require the vendor to maintain Cyber Liability Insurance?
☐ Yes ☐ No
Required policy limit: $_______________
Is this limit adequate for the data/systems at risk?
☐ Yes ☐ No ☐ Uncertain
Does the contract specify coverage for:
☐ Data breach response costs
☐ Regulatory defense and penalties
☐ Business Interruption Coverage
☐ Data Restoration Coverage
☐ Cyber Extortion Coverage
Are you named as an additional insured?
☐ Yes ☐ No
If yes, does the contract specify:
☐ Whether coverage is primary or excess to your own policy
☐ What events trigger additional insured protection
☐ Whether you receive notice of policy changes or cancellations
Section 2: Indemnification Provisions
Does the vendor agree to indemnify you for cyber incidents?
☐ Yes ☐ No ☐ Partial
Indemnification covers:
☐ Third-party claims (lawsuits, regulatory actions)
☐ First-party losses (your own response costs, business interruption)
☐ Both
Are there carve-outs or limitations?
☐ Caps on indemnity amounts
☐ Exclusions for certain incident types
☐ Requirement that you prove vendor negligence
Notes on limitations:
Section 3: Incident Response Obligations
Who controls the incident response if a breach occurs?
☐ Your organization
☐ The vendor
☐ Joint decision-making
☐ Not specified
Does the contract require the vendor to:
☐ Notify you within a specific timeframe (specify: ___ hours/days)
☐ Preserve forensic evidence
☐ Cooperate with your Breach Coach and forensic team
☐ Cover costs of your independent investigation
Does the contract address Breach Notification Requirements?
☐ Vendor handles all notifications
☐ You retain control of customer/employee notifications
☐ Joint approach required
☐ Not addressed
Section 4: Security Standards and Audit Rights
Does the contract require the vendor to maintain specific security controls?
☐ Yes (specify framework: _______________)
☐ No
☐ Vague language only
Do you have the right to:
☐ Audit vendor security practices
☐ Review vendor SOC 2 reports or similar certifications
☐ Require remediation of identified vulnerabilities
☐ Terminate for security failures
Audit frequency allowed: _______________
Section 5: Limits of Liability
Does the contract cap the vendor's total liability?
☐ Yes (amount: $_______________) ☐ No
Does the cap apply to cyber incidents specifically?
☐ Yes ☐ No ☐ Unclear
If capped, does the amount exceed:
☐ The vendor's insurance policy limits
☐ Your potential losses from a vendor-caused incident
☐ Neither
Section 6: Gaps and Conflicts
Compare vendor contract to your Stand-Alone Cyber Policy:
Your policy's Contingent Business Interruption coverage:
☐ Covers vendor outages ☐ Excludes vendor events ☐ Requires specific trigger
If your policy excludes certain vendor-related losses, does the vendor contract fill that gap?
☐ Yes ☐ No ☐ Partial
Conflicts identified:
How to Customize It
Adjust Section 1 based on the vendor's role. A cloud infrastructure provider needs higher limits than a vendor with read-only access to non-sensitive data. If the vendor processes payment card data, add a line for PCI DSS compliance requirements.
In Section 3, specify notification timeframes that align with your own Breach Notification Requirements. If you operate in California, you may need vendor notification within specific windows to meet regulatory deadlines.
For Section 5, calculate realistic loss scenarios. If this vendor's failure could halt operations for three days, estimate your daily revenue loss and compare it to the liability cap. A vendor who agrees to a $100,000 liability cap but could cause $500,000 in business interruption creates a gap your Stand-Alone Cyber Policy needs to fill.
Add vendor-specific questions. If the vendor uses subcontractors, ask whether insurance and indemnification obligations flow down to those parties.
Validation Steps
After completing the template:
Cross-reference with your Cyber Insurance policy. Confirm that gaps in vendor coverage don't create uncovered exposure. If the vendor's indemnification excludes regulatory penalties, verify your policy covers those costs.
Request current certificates of insurance. Verify the vendor actually maintains the coverage the contract requires. Check policy effective dates and limits.
Escalate conflicts to legal and risk leadership. When vendor liability caps fall short or indemnification language contains broad carve-outs, document the exposure and decide whether to renegotiate, accept the risk, or increase your own coverage limits.
Schedule the next review. Vendor risk changes when contracts renew, when vendors add new services, or when your own operations evolve. Set a calendar reminder for 90 days before contract renewal.
This template doesn't replace legal counsel, but it gives you the operational framework to spot issues before they become claims. Contracts establish who pays. Your Stand-Alone Cyber Policy determines whether you can actually collect. Review both together, and you'll know what protection you actually have when a vendor causes the next incident.





