21 September 2026 6 min

When Your IT Provider Gets Hacked, Your Balance Sheet Could Be Next

Written by: Jenny Jooste Save to Instapaper
When Your IT Provider Gets Hacked, Your Balance Sheet Could Be Next

Why third-party cyber risk is a financial risk for South African businesses

For many South African businesses, critical operations and customer data now rely on outsourced IT service providers (OSPs), including cloud hosts, software platforms, managed service providers and payment and fintech vendors.

This dependence creates a risk that is often underestimated and known in the risk management sector as a systemic cyber accumulation event or single point of failure risk. When an OSP suffers a cyber breach or outage, the consequences can quickly extend beyond the technology provider to the businesses that depend on it - affecting revenue, cash flow, business continuity and potentially the balance sheet. Recent global incidents show that a single outage at a key cloud or payments provider can generate simultaneous losses across dozens of clients, from lost sales to regulatory fines.[1]

“Outsourcing your IT does not mean outsourcing the financial consequences of a cyber incident,” says Jenny Jooste, Principal Broker for Cyber Solutions at Aon South Africa. “A third-party breach within your technology supply chain can become your own business interruption, liability and reputational risk very quickly.”

The risk sits closer to home than businesses may think

A cyber incident at an OSP can disrupt critical systems, prevent transactions, interrupt customer services or expose sensitive information. In South Africa, there is also the added consideration of obligations under the Protection of Personal Information Act (POPIA).

Where personal information is compromised at an operator, the responsible organisation may still have notification, remediation and customer communication obligations. “Businesses need to understand that a third-party incident does not necessarily mean a third-party liability,” Jooste warns. “If your customers’ information is compromised or your operations are disrupted, your business may still be the one dealing with the immediate financial and regulatory consequences.”

Contracts and insurance may not close the gap

It is easy to assume that contractual agreements with OSPs will transfer the risk to the provider. In practice, this may not always be the case. The client remains the ultimate custodian and owner of its data. When OSPs experience a cyber incident or data breach, we commonly see several recurring issues:

  • In many cases, there is either no formal contract in place or the contract contains vague terms and conditions, providing limited recourse or remediation for the business whose data has been compromised.
  • Organisations often do not conduct regular audits or assessments of the security controls implemented by OSPs.
  • Not many businesses know they can request copies of their OSP’s Professional Indemnity (PI), Technology E&O and Cyber insurance policy documentation to validate their scope and adequacy of cover.
  • Operational changes and third-party arrangements can result in a disparity between what was contractually agreed and what is operationally occurring, which becomes critical once a legal team needs to step in.
  • Because policies are issued on an aggregated claims-made basis, an OSPs available insurance limits may be shared across numerous claims if they service multiple clients, reducing the protection available to your business.

Contracts can provide recourse, but recovering a loss from a supplier may take time or may not cover the full extent of the damage. “The contract and insurance programme need to be considered together,” Jooste explains. “Businesses should understand exactly where the financial responsibility sits if a critical third party fails, rather than assuming the risk automatically transfers to the supplier.”

Informed decision-making around third-party risk

Often, third-party risk is assessed according to the value of a contract rather than the potential impact of a failure. It can be that a relatively small technology provider may have access to highly sensitive information or operate a system that is essential to the business. Its failure could therefore create a far greater financial exposure than its contract value suggests.

It is essential for a business to take a much closer look at their OSP providers and identify how a compromise or failure can affect the day-to-day running of the business:

  • Is such a compromise or failure incorporated in your business continuity plan.
  • Is there a disaster recovery plan for your business and that of the OSP to get operations back up and running.
  • Is there a documented incident response playbook that clearly outlines roles, responsibilities, escalation procedures, and recovery actions in the event of an OSP-related cyber incident.

For South African organisations, understanding third-party cyber risk therefore means looking beyond the supplier itself and considering the potential financial impact on the business. This includes identifying critical dependencies, assessing the consequences of a prolonged outage or breach, reviewing contractual protections and testing whether their own cyber liability policy extends to losses arising from a cyber incident affecting an OSP, whether IT-related or non-IT-related. It is equally important to understand whether consequential losses, including contingent and dependent business interruption, would be covered if the OSP were compromised.

Specialist brokers and advisors can help quantify these third‑party exposures, align contracts and insurance, and test how a severe OSP event would flow through to the balance sheet.

“Ultimately, the key question for boards and risk managers is simple: if a critical IT provider is breached or goes offline tomorrow, how much could it cost the business – and are its contracts, controls and insurance structured to absorb that loss. Until boards can answer that with confidence – third party OSP cyber risks remain a major vulnerability,” Jooste concludes.  

Ends…

Disclaimer

The contents hereof should not be construed as legal advice on any matter. You should not act or refrain from acting on the basis of any content included in this communication without seeking professional legal counsel. This communication does not constitute or create a lawyer-client relationship between us.

About Aon

Aon plc (NYSE: AON) exists to shape decisions for the better — to protect and enrich the lives of people around the world. Our colleagues provide our clients in over 120 countries and sovereignties with advice and solutions that give them the clarity and confidence to make better decisions to protect and grow their businesses. 

Follow Aon on LinkedIn, Twitter, Facebook and Instagram. Stay up-to-date by visiting the Aon Newsroom and sign up for News Alerts here.

Media Contact:

Deidre Beylis                                                

This email address is being protected from spambots. You need JavaScript enabled to view it.

+27 84 426 0410

[1] https://gitprotect.io/blog/12-cloud-outages-with-devastating-effects/

Total Words: 1067

Submitted on behalf of

Press Release Submitted By

  • Agency/PR Company: Teresa Settas Communications
  • Contact person: Teresa Settas
  • Contact #: 011 894 2767
  • Website
  • LinkedIn