More Posts

Editor’s Note: We recently launched a graphic illustrating our Cyber Risk Mitigation Services. This week, our attorneys will be writing about specific examples of those services.

Vendor contract review—what does that mean to you? Does it bring back bad memories? A last minute scramble to close a deal? Capitulating to oppressive limits on liability to meet a deadline? Dragging and dropping an executed .pdf file into an electronic folder where it will gather virtual dust? We like to tell a different story when it comes to vendor contract review and cyber risk mitigation. It is a bit more mundane but, if handled correctly, it will save you from unnecessary drama for years to come.

A vendor contract review should be a process during which all the real action happens long before you ever start drafting and redlining a contract. I am talking about the internal and provider-facing due diligence that should precede your “contract review.” That pre-negotiation review is an opportunity to explore your organization’s worst nightmares and appetite for risk. Data breach in the cloud, anyone? How about an HVAC vendor whose remote access account was used to gain access to customer payment card data? Vendor “contract review” really begins with a bit of introspection – an internal analysis with all the stakeholders.

The good news? If done right, on the other side of this internal evaluation and due diligence is an opportunity to find true partners. Service providers who understand the risks associated with your business model and the data that comes with it. Service providers who will engage in a meaningful discussion about risk allocation and who are in it with you for the long haul. Those contracts—the ones that emerge after thoughtful internal evaluation and due diligence, an in-depth RFP process, and a friendly negotiation of terms—those contracts will mean much more than words on paper.