Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Penningtons Manches Cooper
Sarah Kenshall, Partner - IP/IT/Commercial
What Does the Cyber Security and Resilience Bill Mean for You?


Organisations understand their obligations around systems and data at least as far as the GDPR goes, but only about 23 percent of companies proactively assess their wider supply chain risks, yet that is where much of the operational risk lies. The Cyber Security Resilience Bill (to be laid before Parliament later this year) seeks to remedy this lack of proactivity by imposing stronger supply chain duties on companies that fall within the bill's remit.
Service levels should be viewed not just as operational metrics, but as strategic performance indicators that align vendor accountability with business outcomes
Procurement Priorities: Service, Data, Resilience
Spend time ensuring the service description and service levels fully capture your needs. This is central to procurement. If the system being procured and developed is not well understood, it becomes difficult to define service requirements. If those requirements are not clearly articulated, allocating risk is equally difficult. While IT will view service and service levels through a functional lens, legal must ensure they are expressed in terms of obligations and responsibilities that link back to the operative contract provisions.
Service levels should be seen not just as operational metrics but as strategic indicators aligning vendor accountability with business outcomes. Conduct a risk assessment to clarify the who, what, where, when and how. This will help define and flesh out the service requirements that serve as the delivery benchmark.
Data flows. In addition to clarifying delivery and performance expectations, the risk assessment should help map data flows so you understand where your data will be globally once the system is live.
With that clarity, you can embed compliance obligations into the contract and cascade policies, procedures, training and audits down the supply chain.
Supply chain controls. The digital service will rely on digital infrastructure such as telecoms, power, data centres and connected devices. Your supplier will procure services from other digital providers for its use and for components of the service. These third parties will also rely on similar infrastructure. Complex supply chains like this, with the same supplier sometimes appearing at multiple levels, present specific risks to business continuity and operational resilience. These include cyber risks, errors and omissions and supplier insolvency. All must be addressed in the procurement contract. CIOs must ensure IT procurement reflects risk tolerance and supports enterprise resilience goals.
Operational Resilience: Embedding It in Contracts
The functional description of the service should be framed in terms of appropriate service delivery obligations. It should clearly identify the who, where, what, when and how.
Having established a benchmark for functionality in the service description, now look at reliability in the performance of that functionality. As with the service description, the service level schedule is not just for the IT department, the legal department need to make sure it's not too generic with vague performance metrics - too broad / too ambiguous makes it hard to enforce. Look for precisely drafted service level requirements backed up with meaningful service credits, the latter being reported by the supplier and automatically paid.
The contract should set compliance standards and cybersecurity certifications at the appropriate level, supported by audit provisions to ensure operational resilience is embedded across the supply chain (cascading risk management). This only works if best practice is already embedded within the organisation itself, including a company structure chart with clear roles up to board level, defined policies and procedures and training to embed them in practice.
Limitations of liability are often one of the crunch areas of discussion, typically the focus towards the end of contract negotiations when both parties have a much clearer idea of the balance of risk between them. Use your risk assessment when comparing allocation of risk through these clauses, remembering that the allocation of risk to the supplier does not and should not be a mirror image of the allocation of risk to the organisation.
Indemnities are an effective way to transfer risk, as they are primary obligations not dependent on an underlying warranty and allow for pound-for-pound recovery without relying on complex rules around the assessment of damages. Also there is no obligation for the organisation to take steps to minimise loss, unless the supplier negotiates this in.
Require the supplier to have good insurance in place as mission creep (where the service delivered no longer aligns to the service description) is a rich source for claims under errors and omissions insurance, bringing us back to the importance of a carefully drafted service description.
There is a lot to think about in the termination provision and, as it typically sits towards the end of a contract, it does not always get the attention it deserves, bearing in mind it is a risk mitigation clause. Also, if the termination triggers are not clear and precisely drafted, you risk exercising a right to terminate only to find it used against you in a repudiatory breach claim.
Finally, it is worth noting that contractual clarity around cyber and systems risk is not just a legal safeguard—it’s a board-level imperative. As mentioned under Compliance above, operational resilience is only really achieved when it is embedded in corporate practice, right up to board level. The government's 'Cyber Governance Code of Practice' (published April 2025) is a useful resource in this respect, providing a toolkit to support boards and directors to play their role in ensuring the operational resilience of their organisation.

