cyber insurance requirements

How to Draft and Enforce a Cybersecurity Addendum in Vendor Contracts Under the New SEC Cyber Disclosure Rules (2026)

How to Draft and Enforce a Cybersecurity Addendum in Vendor Contracts Under the New SEC Cyber Disclosure Rules (2026)

New SEC cybersecurity disclosure rules require public companies to report “material” incidents within 4 business days—making vendor-caused breaches a board-level timing risk. Most incidents start with third parties, so contracts now function as your compliance clock and evidence file. This article shows how to draft, negotiate, and enforce a cybersecurity addendum that supports SEC disclosures, […]

How to Draft and Enforce a Cybersecurity Addendum in Vendor Contracts Under the New SEC Cyber Disclosure Rules (2026) Read More »

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law

A well-drafted vendor cybersecurity addendum can cap breach-related exposure through three core levers: tight indemnity language, a defined liability cap, and clear security/notice duties. Under New York law, these clauses are generally enforceable in commercial contracts when negotiated and not barred by public policy. This article explains how to draft an addendum that reduces post-breach

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law Read More »

Scroll to Top