Skip to content
The Cyber Security Place

When the breach is somebody else's, you still own the clock

Event dated 20 March 2026 · Published 2 September 2026 · 3 sources

Across March 2026 a common shape appeared in reported incidents at Telus Digital, Cognizant's Intuitive platform, TriZetto, Navia and CIBM: a single compromised point reaching several organisations at once through shared platforms and integrations. The operational consequence is a split that regulation does not recognise. The obligation to notify sits with the organisation whose customers were affected. The facts — what was reached, when, and how far — sit with the supplier. One party owns a statutory clock and the other owns the information needed to stop it.

Shared platforms are efficient for the same reason they concentrate risk: work done once serves many. A claims processor, a benefits administrator or a customer-experience platform does something specialised well enough that a hundred organisations would rather buy it than build it, and they are usually right.

The arrangement holds until an incident, at which point an asymmetry that nobody negotiated becomes the central problem. The supplier knows what happened. The customer has the legal duty and the angry callers, and learns the facts on the supplier's schedule.

Why the timing does not work

Notification deadlines run from awareness, and awareness begins earlier than certainty. An organisation told by a supplier that there has been an incident affecting an unspecified subset of its customers is aware. It cannot yet name a single affected person.

Meanwhile the supplier is doing exactly what any organisation does in the same position: establishing scope before making statements, because a wrong statement is worse than a late one. Both behaviours are correct. Together they produce a customer organisation obliged to notify people it cannot identify about an event it cannot describe.

What can be fixed in the contract

More than most organisations attempt, and it is unglamorous work done long before anything happens. A notification commitment in hours rather than the vague promptly. A named contact with a telephone number rather than a support queue. An obligation to provide the list of affected customers, not merely a count. And the right to have your own advisers see the findings rather than a summary.

Each of those is refused routinely, and each is far easier to obtain during procurement than during an incident, which is the entire argument for raising them when nobody feels any urgency.

The dependency worth mapping

Not the supplier list, which every organisation has. The list of suppliers that hold customer data or run a process that customers would notice stopping — usually a small fraction of the total, and usually not the ones with the largest invoices.

That shorter list is where the contract terms above are worth the argument. Applying them to every supplier is how the exercise stalls; applying them to the handful that could put your name in somebody else's incident report is how it gets done.