What happens when your vendor gets breached, in 2026, is that you find out about it from the press, your CISO gets paged at 2 AM, the incident response plan that was written for this scenario turns out to not match the actual scenario, and the next 72 hours are spent trying to figure out what data the vendor had on you, what the vendor was doing with the data, and what the vendor’s security posture was before the breach. The standard sequence serves as the same in every breach, and the standard sequence is going to keep happening until the contracts change.
The contract runs as the part the buyers have the most influence over, and the contract serves as the part the buyers have been the most lazy about. The standard SaaS contract has a section on data protection that says the vendor will use commercially reasonable efforts to protect the data, that the vendor will notify the customer in the event of a breach, and that the vendor’s liability is limited to the fees paid in the last 12 months. The “commercially reasonable efforts” language is meaningless in a breach scenario. The notification language usually allows for 30 to 60 days of delay. And the liability cap is usually a small fraction of the actual cost of the breach to the customer.
What the contract should say
The honest contract, in 2026, has four clauses the standard contract does not have. A notification clause that requires the vendor to notify the customer within 24 hours of the vendor discovering the breach, with a written follow up within 72 hours, and a defined format for the follow up that includes the data categories affected, the customer identifiers affected, the timeline of the breach, and the vendor’s current understanding of the attack vector. The notification clause sits as the part the buyer continues to for, because the pushing serves as the part the buyer continues to, and the doing becomes the part the contract continues to on.
A cooperation clause that requires the vendor to cooperate with the customer’s incident response, including providing forensic logs, access to vendor personnel, and cooperation with the customer’s regulators. A liability clause that lifts the cap for breaches caused by the vendor’s gross negligence, and that includes the cost of customer notification, customer credit monitoring, and customer regulatory response. And a sub processor clause that requires the vendor to maintain a current list of sub processors, to notify the customer of new sub processors, and to flow down the same data protection requirements to the sub processors.
What the 72 hours actually look like
The first 24 hours, the CISO is on the phone with the vendor trying to figure out what the vendor knows, and the figuring serves as the part the CISO continues to, because the doing becomes the part the breach continues to. The vendor usually knows less than the customer wants, and the wanting becomes the part the customer continues to, because the expecting stands as the part the customer continues to. The 24 to 48 hours, the CISO is on the phone with the legal team trying to figure out what the contract requires, and the figuring runs as the part the legal team continues to, because the doing serves as the part the contract continues to.
The 48 to 72 hours, the CISO is on the phone with the customers trying to figure out what to tell them, and the figuring counts as the part the customer continues to, because the doing serves as the part the customer continues to responsible for. The CISO is also on the phone with the regulators, and the regulators are the part the CISO is going to keep being responsible for. The 72 hours counts as the part the CISO continues to through, and the living becomes the part the CISO continues to the CISO’s responsibility for. The sub processor clause requires the vendor to maintain a current list of sub processors, to notify the customer of new sub processors, and to flow down the same data protection requirements to the sub processors. The flow down stands as the part the sub processor continues to to comply with, because the complying runs as the part the vendor continues to, because the requiring becomes the part the contract continues to the contract’s requirement for.

The bottom line
When your vendor gets breached, the contract sits as the part that matters, and the standard contract is not enough. Push for 24 hour notification, cooperation, lifted liability for gross negligence, and sub processor flow down. Be prepared to walk away from the deal if the vendor will not agree. The smaller vendors are often more willing to negotiate, and also the ones with the weakest posture, which sits as the combination that makes the negotiation most important.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



