Skip to content
Navigating Cyber Supply Chain Disputes: Litigation Risk for Customers and IT Suppliers

Navigating Cyber Supply Chain Disputes: Litigation Risk for Customers and IT Suppliers

Freshfields • July 23, 2026

In an increasingly interconnected digital landscape, businesses – particularly those operating critical infrastructure – rely heavily on IT suppliers for essential services, from managed services to cloud hosting. While these partnerships are crucial for operational efficiency, they can also introduce significant cyber risk. When supplier systems are compromised, customers are confronted with operational disruption, substantial financial and reputational losses, and regulatory scrutiny, while suppliers may face contractual claims, disclosure pressure and questions over the adequacy of their own security representations and incident response.

Supply chain hits are real

The threat of supply chain attacks is no longer theoretical. Reports from ENISA highlight a concerning increase in targeted attacks on IT providers serving critical sectors, in particular public administration but also transport, digital infrastructure, finance, manufacturing and energy, “ showing that attackers are actively leveraging indirect pathways through third-party providers .” For instance, the recent cyberattack on an external IT service provider severely disrupted public transport ticketing systems across Italy. Another example is the compromise of a technology provider serving Spain's largest oil and gas refiner leading to customer data leaks. There are many more examples of supply chain attacks in the cyber space.

Litigation risks follow closely behind: The SEC alleged in 2023 that SolarWinds and its security officer had violated U.S. securities laws by making misleading disclosures cybersecurity vulnerabilities prior to the 2020 Sunburst attack, with the U.S. District Court for the Southern District of New York sustaining a fraud claim linked to public security representations. Despite the court’s dismissal of the majority of the SEC’s claims, the case highlights a critical takeaway: a supplier's public statements regarding cybersecurity – regardless of the form or medium in which they are distributed – are discoverable and may form the basis for damage claims.

Implications of EU Cyber Security Requirements

EU cyber security requirements further amplify such supply chain due diligence expectations. The NIS2 Directive , EU-wide legislation on cybersecurity ((EU) 2022/2555), strengthens the European legal framework for cybersecurity and is intended to help raise and harmonise cybersecurity standards across the EU (for details, please see our blog post ). It requires organisations to implement comprehensive risk management measures to better protect themselves against digital threats, including conducting thorough supplier due diligence and ensuring supply chain security. This means organisations must generally check, rather than merely trust, their suppliers' security baselines and failing to do so may shift regulatory exposure back to the operator.

Article 21(2)(d) NIS2 Directive mandates measures addressing " supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers ," while Article 21(3) NIS2 Directive specifies that entities must " take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures ". Breaches of obligations regarding cybersecurity requirements, reporting significant incidents or communication of significant cyber threats are subject to severe GDPR-style fines set by national law.

In Europe, the CER Directive (EU 2022/2557) further raises the bar for organisations designated as critical entities. It is designed to strengthen resilience to systemic disruptions and in particular establishes resilience as a responsibility at board level. Together, NIS2 and CER Directive form a comprehensive framework focussing on cybersecurity as well as physical and operational resilience.

In addition, more specific sector frameworks exist, such as the Digital Operational Resilience Act ( DORA ) for financial services. For customers, these rules sharpen the need to evidence supplier due diligence and ongoing oversight; for suppliers, they increase the commercial and litigation importance of being able to substantiate security controls, development practices, subcontractor management and incident response decisions.

In a dispute following a supplier cyber incident, these statutory duties can shape the standard of care and provide a reference point for contractual claims, arguments on breach, and allocation of loss.

Key Strategic Issues in Cyber Supply Chain Disputes

There are several key strategic issues to be considered before and in case of disputes stemming from IT supplier breaches. They matter not only for customers seeking recovery, but also for suppliers seeking to manage liability, preserve evidence and defend their security posture:

Arbitration or ordinary courts: forum choice as a litigation lever

Once a supplier cyber incident escalates into a dispute, the choice between arbitration and ordinary courts becomes a strategic decision for both sides. Many IT supply agreements contain arbitration clauses, often treated as boilerplate at signing, although the dispute forum can materially affect leverage, evidence access, timing and public exposure. Customers should therefore review dispute resolution clauses before an incident occurs and, where possible, tailor them to the operational realities of cyber disputes; suppliers should do the same to ensure that confidentiality, emergency relief, expert evidence and multi-customer dispute management are workable in practice.

Arbitration may be attractive where confidentiality is important, technical expertise is needed on the tribunal or cross-border enforcement is likely. For suppliers, confidentiality may be particularly valuable where one incident affects several customers and public findings could influence parallel claims, customer negotiations or regulatory proceedings. Arbitration can also allow parties to agree cyber-specific procedural tools, such as fast-track timetables, confidentiality rings, expert evidence protocols and secure handling of forensic material. The downside is that arbitration may offer more limited coercive tools against third parties, fewer public-law disclosure mechanisms and potentially higher upfront costs. Urgent interim relief may also require parallel court support, particularly where systems, evidence or third-party data must be preserved quickly.

Ordinary courts may be preferable where the customer needs broad evidence-gathering tools, e.g. access to criminal investigation files, third-party involvement, public precedent or rapid injunctive measures. Court proceedings can also create public pressure on a supplier, which may be helpful in settlement dynamics. The trade-off is reduced confidentiality, less control over the decision-maker’s technical expertise and, in some jurisdictions, slower proceedings or more fragmented cross-border enforcement.

For customers and IT suppliers alike, the practical question is no longer whether supplier cyber risk exists, but whether each side can evidence that it managed that risk with sufficient rigour before the incident.

These steps help both parties to establish a sound procedural and evidential basis for any future disputes, even before an incident occurs: clear obligations, preserved technical evidence, tested notification chains and dispute clauses that provide real procedural advantage when systems are down and facts sit unevenly across the supply chain.

Extracted Entities

Companies (1)

Countries (2)

Malware (1)