This Checklist is designed to highlight key cybersecurity considerations which arise during the negotiation and drafting of technology services outsourcing agreements in the UK. For further guidance on wider (non-cybersecurity-specific) IT outsourcing agreement issues, see: IT outsourcing agreement—checklist. For template outsourcing agreements, see Precedents: Outsourcing agreement—long form and Outsourcing agreement—short form. UK law generally takes a ‘principles’ or ‘outcomes’-based approach to cybersecurity, often leaving it for organisations to determine how best to assess, monitor and tackle its cyber risks. For contracting, this means that there are few prescriptive contractual requirements. However, organisations may need to flow down terms to their suppliers so that they can meet their own obligations under other contractual arrangements they are party to. Regulators will also expect that, in the event of an incident, an organisation is able to demonstrate that they took appropriate measures, including contractual measures, to manage their cybersecurity risk (as well as complying with their contractual commitments to their customers). For further information on how cybersecurity is addressed under UK law, see: Cybersecurity, threats and risk management—overview.