Cyber Attack in Serbia: Who Bears Liability – IT Provider, Client, or Subcontractor?
In October 2025, Serbia enacted a new Law on Information Security — and with it came a question that had never been answered unambiguously before: when a cyber attack occurs, who is legally responsible? The IT provider whose system was breached? The client whose data was exposed? The subcontractor who failed to apply a security patch?
The answer is rarely straightforward, and the consequences of a wrong assumption — financial, regulatory, and reputational — can be severe.
New Legal Framework: NIS2 Arrives in Serbia
The new Law on Information Security, which entered into force on October 31, 2025, aligns Serbian legislation with the EU’s NIS2 Directive and introduces comprehensive obligations for both the public and private sectors. The law establishes a distinction between priority and important operators of ICT systems of special significance, with differentiated obligations and penalties for each category.
Key changes directly affecting IT companies and their clients:
- Incident reporting within 24 hours of becoming aware of an incident with potentially significant impact on information security
- Mandatory risk assessment — the Risk Assessment Act must be revised at least annually
- User notification — ICT operators are required to promptly inform users about an incident and available protective measures
- Fines of up to 2,000,000 RSD (approx. €17,000) for priority operators; up to 1,000,000 RSD for important operators
The newly established Office for Information Security, which takes over the functions of the national CERT, will serve as the central body for incident coordination.
Who Is Liable for What: The Three-Party Relationship
The IT provider occupies the highest-risk position. If a cyber attack exploited a vulnerability in a system the provider maintains, and the provider failed to implement required technical safeguards (MFA, encryption, regular backups, penetration testing), the client can bring a damages claim under the Law on Obligations — regardless of whether the attack was “foreseeable.” SLA clauses must clearly define which security standard the provider guarantees, response timeframes, and consequences for non-performance.
The client is not automatically shielded by having engaged an external provider. If the client influenced the security architecture or ignored the provider’s recommendations (e.g., declined MFA implementation), their contribution to the damage may be a legally relevant factor for apportionment of liability.
The subcontractor who develops or integrates parts of the system is liable under the contract for services. This creates a liability chain: if the primary IT provider engaged a subcontractor who introduced a vulnerability, the client can sue the provider, and the provider can seek indemnification from the subcontractor — but only if the contract explicitly includes clauses binding the subcontractor to the same security standards.
Notification and Reporting — Obligation, Not Option
One of the most common failures in practice is delayed reporting. The new law draws a clear distinction between:
- Notification to the Office for Information Security — within 24 hours of becoming aware of the incident
- User notification — without delay, about the incident itself and available protective measures
- Reporting near misses that pose a serious threat
Late reporting can be an independent basis for a fine — even if no user harm has actually occurred.
Reputation: The Hidden Cost of an Attack
Research across the EU indicates that reputational damage following a cyber attack can ultimately exceed the direct financial loss. For domestic IT companies and cloud service providers with EU clients, a single incident can trigger a chain of contract terminations. This is precisely why the new law logically pairs technical obligations with communication obligations — immediate and transparent notification of users.
Contractual Protection — What Every IT Contract Must Include
To minimize legal exposure, every IT contract should contain:
- A clear definition of security standards (ISO 27001, SOC 2, or a proprietary data protection policy)
- An SLA clause on incident (Cyber Attack) response time (e.g., 4 hours for critical incidents)
- An incident notification clause — who notifies whom, when, and how
- Allocation of liability for damages resulting from ICT system breaches
- The client’s right to audit security measures (penetration tests)
- A clause binding subcontractors to the same security standards
Conclusion
A cyber attack is no longer just an IT problem — it is a legal, regulatory, and reputational event. Serbia’s new 2025 Law on Information Security introduces European-grade standards, along with new fines and obligations. Forward-thinking IT companies and their clients do not wait for an incident to structure their legal relationship — they do it contractually, in advance. If you are unsure whether your agreements comply with the new law, now is the right time to find out.
Follow for more legal insights:
