For added context, my question assumes that any business storing sensitive data, including the services they use to do so, is going to be responsible for reporting and monitoring. At least that is how my state’s laws appear to read.
If an outsourced provider incurs a breach and it affects the business using its services, there could be reason to believe expenses will be incurred in the course of the small business acting responsibly. Presumably, these are expenses that could be reclaimed.
I realize there are a lot of factors, but businesses without the funds to build their own systems, if compromised, likely don’t have the funds to pay for all the reporting requirements.
– Nick