Blog

You can outsource the work, but never the accountability

A Norwegian court case delivers a €5.6 million lesson on business continuity, supplier management, and why manufacturing executives can't outsource operational accountability

By Sten EikremUpdated 21 August 2026

A contract at the top feeds a straight arrow carrying work from a company to its supplier. Beneath them a heavy curve leaves the supplier, sweeps back across the frame and returns to the company it started from.

Update, 21 August 2026. Btec appealed, and lost again. Gulating Court of Appeal ruled on 30 June 2026 that Nordlo had breached the contract, because the backup server sat on the same network as the production server. Then it awarded 8,280 kroner, approximately €760. That is three months of subscription fees, against a claim of more than 60 million kroner, approximately €5.5 million. Btec carries a further 2.3 million kroner of the other side’s legal costs, approximately €210,000. The court found the security failings open to criticism but short of gross negligence, which left the standard liability cap standing and excluded indirect loss altogether. On backup, that finding differs from the account below, which placed the gap on Btec’s side rather than the provider’s.

Btec proved their supplier was in breach and recovered three months of fees. The contract, not the security posture, decided what the breach was worth. The court was explicit about why: subscription services are priced on standardisation, and a provider cannot carry tens of millions in exposure on a low-cost contract. The price stated the liability limit years before the attack.

A Norwegian court just delivered a €5.6 million lesson that every manufacturing executive needs to understand.

The case

Btec, an industrial machining company, lost everything in a ransomware attack. They sued their IT provider Nordlo for €5.6 million in damages. They lost the case and got hit with €190,000 in legal costs.

The reality check

Btec paid €270 per month for IT services while running operations worth millions. When disaster struck, they discovered they’d bought basic IT support, not business continuity.

This wasn’t a cybersecurity failure. It was a business continuity planning failure.

The critical gap

The court found that backup systems existed but weren’t properly integrated into Btec’s operations. They lost 14,000 product specifications and manufacturing processes because they never defined what recovery actually meant for their business.

The technical backups worked. The business continuity plan didn’t exist.

Lessons for manufacturing

1. Price doesn’t reflect risk

Your €270/month IT contract doesn’t cover your €5.6M business risk. Standard IT support agreements are about keeping systems running, not ensuring business operations survive disasters.

2. Standard agreements aren’t business plans

IT service contracts define technical obligations: uptime targets, response times, backup schedules. They don’t define your business recovery requirements, production dependencies, or operational continuity needs.

3. Accountability can’t be outsourced

You can outsource technical execution. You can’t outsource responsibility for understanding what your business needs to survive. That accountability stays with business leadership.

4. Recovery requires business context

Technical teams can restore systems. Only business leaders can define:

  • Which manufacturing processes are critical
  • What production data is irreplaceable
  • How operations restart after recovery
  • What ‘acceptable’ downtime actually means

The questions you need to answer

Before the next incident, manufacturing executives must document:

  • How long can production actually stop, and what’s the financial impact per hour?
  • Which systems and data keep production running, and where are the single points of failure?
  • Who owns the decision to declare a disaster, and who executes recovery beyond just technical restoration?
  • How do you restart production processes and validate recovered data?
  • What’s the cascade effect when one system fails, and which suppliers are critical to operations?
  • Who accepts residual risk during recovery?

The accountability trap

Btec’s mistake wasn’t technical. They assumed their IT provider understood their business continuity needs. The provider assumed Btec had communicated those needs. Neither assumption was tested until disaster struck.

The gap between technical capability and business requirement is where companies fail.

What this means for you

If you’re relying on standard IT support contracts to protect your manufacturing operations:

  • Document your actual recovery requirements based on business impact, not technical capabilities.
  • Validate your provider understands manufacturing-specific continuity needs.
  • Test recovery procedures that include business process restart, not just system restoration.
  • Define accountability clearly for business continuity decisions and execution.

The Norwegian court was clear: business leaders own business continuity accountability. Technical providers execute technical contracts. The gap between those two is where companies die.


Have you validated that your IT service agreements actually cover your business continuity requirements? The time to discover gaps in your recovery planning is before the incident, not in court afterward. For a deeper look at why recovery plans break down in practice, see Your Recovery Targets Are Probably Right. Your Ability to Meet Them Probably Isn’t.


Originally published: LinkedIn

Case Reference: Btec AS v. Nordlo Norge AS, Norwegian court ruling, 2025 Source: Norwegian court ruling coverage

Appeal: Btec AS v. Nordlo Norge AS, Gulating lagmannsrett, 30 June 2026 Currency: Kroner figures converted at 10.87 NOK to the euro, the Norges Bank rate on 21 August 2026. Appeal coverage: Metal Supply on the rulingMetal Supply on the contract reasoning

I advise industry and energy companies on security governance and risk management. More about my work.

Connect: Follow for more insights on risk management and security governance on LinkedInMastodonBluesky