Third parties and vendors

Has any service provider with access to Applicant's network sustained outage longer than 4 hours?

Contingent business interruption covers your loss when someone else goes down. This question is how the carrier sizes that exposure.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether any provider with access to your network, or on which you depend, has suffered a significant outage. It is looking at your dependency concentration and your history of being affected by it.

Why it is underwritten

Contingent business interruption is a growing part of cyber cover and a growing part of cyber loss, because so many organisations depend on the same small set of platforms. A carrier assessing aggregate exposure wants to know which providers you depend on and how you have fared when they failed.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Vendor outage history comes from your records and theirs, so this is attested. Your dependency map is the more useful artefact.

PlatformWhere the setting livesWhat has to be true
Operations recordsIncidents caused by third-party outages, with duration and impactActual events with business impact recorded. Attested
Vendor registerCritical dependencies and what fails if each is unavailableA dependency map, which is what makes the forward-looking half of the answer credible
ContractsService level agreements and their remediesWhat the vendor owes you, which is usually service credits rather than compensation for your loss
Continuity planWorkarounds for critical vendor unavailabilityDocumented alternatives, since the response to a vendor outage is entirely procedural
Provider recordsPublished incident reports from your major providersThe provider record, which is public for most major platforms and easy to reconcile against your own
Service credits are not indemnity

A service level agreement typically returns a fraction of your monthly fee. It does not compensate for a day of lost trading. That gap is precisely what contingent business interruption cover exists to fill, which is why the carrier is asking about the dependency rather than about the contract.

What a defensible yes requires

  • Vendor-caused outages are disclosed with duration and business impact.
  • A dependency map identifies which providers are critical and what fails without them.
  • Continuity plans include vendor unavailability, not only your own systems.
  • Concentration is understood, including where several vendors depend on the same underlying platform.
  • What changed after each outage is recorded.

How this answer goes wrong

Only providers with network access are considered, so a day-long outage at the software-as-a-service platform that runs a core business process is omitted. The question is about dependency, and that platform is the dependency most likely to produce a contingent claim.

Frequently asked

Do cloud provider outages count?

Yes, if they affected you. They are also the most likely source of a contingent claim, so disclosing them accurately helps the cover match the risk.

What about a vendor breach rather than an outage?

Usually captured by the prior incident question rather than this one. Disclose it in whichever place fits, and do not let the distinction cause an omission.

How do we assess concentration?

Map your critical vendors to their underlying infrastructure. Several independent-looking suppliers frequently run on the same platform, which turns one outage into several.

Does this affect contingent cover?

Directly. Carriers may name specific dependencies or apply sub-limits, and an accurate dependency picture is what makes that structure correct.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture