Your Vendor's Breach Is Your Problem
A third party was involved in 55 percent of breaches at small and mid-size organizations. When your payroll processor gets compromised, the notification duty, the regulatory exposure, and most of the bill land on you.

You Outsourced the Work. You Did Not Outsource the Liability.
Small operators believe that using a vendor moves risk onto the vendor. It is an entirely reasonable belief and it is wrong, in a way that only becomes apparent at the worst possible moment.
When your payroll provider, billing service, or cloud storage vendor gets breached and your employees' data is in it, most state breach notification statutes assign the notification duty to the data owner. That is you. You notify. You pay for credit monitoring. You answer the regulator. You take the reputational hit and, if there is one, the class action.
The vendor's security failed. Your name is on the letter.
Here's What's Actually Happening
The third-party attack path is not a niche scenario anymore. It is the main one.
Verizon's 2026 DBIR logged 7,152 breaches at small and mid-size organizations, with a third party involved in 55 percent of them. Fifty-eight percent of ransomware attacks on SMBs originated from a compromised third-party vendor. Third-party and supply chain compromise ranked as the second most prevalent attack vector and the second costliest, at $4.91 million average.
The reason is not complicated. Attacking a 12-person company directly yields a 12-person company. Attacking its payroll vendor yields every client that vendor has. Attackers optimize, and consolidation in the SMB software market has built exactly the concentration they were looking for.
Breaches involving a third party also cost roughly $370,000 more than first-party incidents, because the forensics cross organizational boundaries and you are dependent on someone else's incident response team, someone else's logs, and someone else's lawyers deciding what they are willing to tell you.
One Statistic You Should Stop Repeating
You will see a claim that 60 percent of small businesses close within six months of a significant cyber attack. It is quoted constantly, usually by people selling security products.
Nobody has ever been able to source it to a study. It gets attributed to various agencies that disclaim it when asked. I bring it up because the real numbers are alarming enough without it, and because a category that leans on a fabricated statistic invites you to discount the true ones. The $3.31 million average breach cost for organizations under 500 employees, up 13.4 percent year over year, has an actual methodology behind it. Use that one.
The Liability Cap Is the Clause That Decides Everything
Now the contract, which is where this is actually won or lost, and which almost nobody reads before signing.
Nearly every SaaS agreement caps the vendor's total liability at some multiple of what you paid them. Twice the annual fees is the standard. It sounds reasonable in the abstract.
Put numbers on it. You pay a payroll vendor $9,000 a year. Their cap is $18,000. Their breach exposes 40 employees' Social Security numbers and direct deposit details. Your notification costs, credit monitoring, forensic consultant, and outside counsel run past $150,000 before anyone files anything.
You recover $18,000. You eat the rest. And the cap was not hidden; it was in section 11 in the same font as everything else.
That is the entire mechanism. The vendor's maximum downside is bounded by your subscription fee. Your downside is bounded by the number of records they hold.
The Indemnity Usually Runs the Wrong Direction
Pull up any vendor agreement you have signed and search for indemnify. Read who is indemnifying whom.
In most standard agreements, you indemnify the vendor against claims arising from your use of the service. The vendor indemnifies you against intellectual property claims, meaning if someone sues because their patent is in the software, they will handle it. What you will frequently not find is the vendor indemnifying you against claims arising from their own security failure.
That is the gap. The clause that matters most in the scenario most likely to actually happen is the one that is usually absent, and its absence reads as normal because the section is full of other indemnity language.
What to Negotiate, and What You Will Actually Get
Small buyers assume they have no leverage. Less than you would like, more than zero, and the ask costs nothing.
Push for a carve-out from the liability cap for data breaches caused by the vendor's failure. This is the highest-value change available and it is more commonly granted than people expect, because vendors have insurance for exactly this and would rather concede the clause than lose the deal. A carve-out means the cap does not apply to breach costs, which is materially different from raising the cap.
Ask for a certificate of insurance showing cyber liability coverage, and ask to be named as an additional insured. A vendor with no cyber policy is telling you something important, and it takes one email to find out.
Get a breach notification window in writing, measured in hours. Something like 48 or 72 hours from discovery. Your own statutory notification clocks start running whether or not your vendor has told you anything, and vendors that discover a breach in March and tell clients in July have put those clients in violation of deadlines the clients never knew had started.
And ask what happens to your data when the relationship ends. Deletion timelines, backup retention, and whether their subprocessors also delete. This is the same lock-in question that governs picking a platform you can leave, except the stakes are records rather than convenience.
Insurance Is the Backstop, With a Catch
A cyber liability policy for a small business is not expensive relative to the exposure, and it typically covers the notification costs, forensics, legal, and business interruption that the vendor's cap will not.
Read the application carefully, because that is where these policies fail. Applications ask whether you have multi-factor authentication, whether you maintain offline backups, whether you have a written incident response plan. Answer optimistically and you have handed the insurer a rescission argument at claim time. An accurate no is far better than an aspirational yes.
Also check whether the policy covers incidents originating at a third party. Some do not without an endorsement, which would exclude the majority of how these incidents actually begin.
The Three Clauses to Read Before You Sign
You are not going to read a 40-page master services agreement and you should not pretend you will. Three sections carry nearly all of the risk, and you can find them in about fifteen minutes.
Limitation of liability, which tells you the ceiling on anything you can recover. Indemnification, which tells you who defends whom and in which direction. And the data security or data processing addendum, which tells you what they have actually promised to do and what they have promised to tell you when it fails.
Read those three before signing rather than after a breach. Fifteen minutes at the front of a relationship, against a number that has no ceiling at the back of one. That is not a close call, and the fact that almost nobody does it is the reason vendors keep drafting the clauses this way.
Ready to dig into the numbers? We have side-by-side breakdowns for every product mentioned in this article.

