As businesses increasingly rely on cloud providers, payment processors, software developers and other technology service providers, cyber risk no longer stops at the boundaries of the organisation. A vendor’s compromised system can trigger data breaches, operational disruption, regulatory exposure, financial losses and reputational damage for the business that engaged it.
The real question isn’t just who caused the breach, but who bears liability when things go wrong, particularly when the cyber incident comes from a third party vendor you relied on to keep your business running
This article unpacks Nigeria’s evolving contractual and regulatory landscape for managing third party cyber risk, why enforcement is often harder than it looks, and why robust vendor due diligence and carefully drafted risk allocation clauses are now nonnegotiable for cybersecurity governance. In Nigerian commercial practice, the real battle is often fought in the fine print: limitation of liability clauses, indemnities, exclusions, and the obligations imposed by the Nigeria Data Protection Act 2023 ultimately decide whether the financial and legal fallout of a cyber incident lands on the customer, the vendor, or both.
When you outsource the service, you may not be outsourcing the risk.