In the Nordlo judgment of 30 June 2026, Gulating Court of Appeal held that Btec AS, which lost its production data in a ransomware attack on its IT supplier and claimed over NOK 57 million, was bound by the supplier's unsigned standard terms. The attack was not force majeure, the supplier was not grossly negligent, and a cap of three months' fees gave NOK 8,280.
Picture an engineering workshop with fifteen employees that has handed its entire production planning system to a local hosting provider. The fee is under NOK 3,000 a month. One night a ransomware group encrypts the provider’s servers, and the backup sits on a server in the same network. Drawings, cost calculations and order history are gone for good.
That is, in outline, the facts of the judgment of Gulating Court of Appeal of 30 June 2026. The customer won on the point that the supplier had breached the contract. It was awarded NOK 8,280, and it has to pay the other side’s legal costs for two instances.
What was the Nordlo judgment about?
Btec AS is an industrial company that makes custom metal components for the maritime and offshore sectors. From March 2017 it bought an ASP service from Nordlo Haugesund AS (then Appex AS), under which the supplier ran the software on its own servers and took a backup every working day. The fee was NOK 2,760 a month. No written agreement was ever signed.
On 22 April 2021 Nordlo was hit by the “Ryuk” ransomware. The evening before, the attackers had logged in with a customer account that had no multi-factor authentication. Most of Nordlo’s backups sat in a separate administration network that withstood the attack, but one backup server was still in the production network that was hit. That server held the copy of the server where Btec’s data in the AutoCalc production system was stored. Both the data and the copy were lost. Of Nordlo’s 255 customers, four lost data in whole or in part.
Btec put its loss at between NOK 57.2 million and NOK 64.2 million, including 14,000 lost production models, lost profit and the cost of replacing machinery. Haugaland and Sunnhordland District Court awarded NOK 8,280 on 20 June 2025. The Court of Appeal dismissed the appeal unanimously.
How could unsigned standard terms bind the customer?
Norwegian contract law has no formal requirements for agreements between businesses. The question was whether Nordlo’s standard terms, with the limitation of liability in clause 10, had become part of the contract even though Btec had never seen them.
The Court of Appeal started from HR-2026-780-A, in which the Supreme Court held in April 2026 that incorporation depends on whether a party had reasonable grounds to expect that the other party had accepted the terms. Attempts to hide onerous terms count against incorporation. In that case the Supreme Court found that the limitations of liability in a subcontractor’s general terms did not apply.
In the Nordlo case the assessment went the other way. Btec’s managing director was also managing director of its sister company DM, which had had a written ASP agreement with Nordlo since 2011. He used the service himself through DM’s agreement, referred to it in an email and on the same day ordered the same service for Btec in order to “samkjøre” (align) the two companies. The price was set by reference to what DM paid. Nordlo invited Btec to meetings on 20 and 22 March 2017, and the salesperson tried to get a contract in place. Btec did not turn up and did not reply.
The court put it this way (our translation).
When the company, despite the background, did not follow up the contact or take steps to clarify which terms applied, Btec must bear the risk of that.
The court also looked at the content of the term. A cap of three months’ fees and an exclusion of indirect loss are common in the industry, and a cheap standard subscription service without any limitation of liability would have left the supplier with a risk out of all proportion to the fee. The term was neither surprising nor tucked away.
Was the cyber attack force majeure?
No. Clause 8 of the terms suspended the parties’ obligations in the event of obstacles beyond their control. The Court of Appeal found that the data loss was neither extraordinary nor unforeseeable. Ransomware has been a known risk in the IT industry since the mid-2010s, “Ryuk” was a known threat actor, and the Norwegian National Security Authority (NSM) had warned of advanced cyber attacks as early as 2017.
So the supplier was in breach. A backup that cannot be restored after an attack does not fulfil the obligation to take backups. That did the customer little good, because liability was capped in any event.
Why was Nordlo not grossly negligent?
As a rule, gross negligence sets a limitation of liability aside. The Court of Appeal described the threshold as a marked departure from prudent conduct that appears clearly blameworthy, and made clear that between professionals the assessment is made in light of the agreed service, price and risk allocation. Btec had bought a standard service and had not ordered any additional security.
The court used NSM’s Basic Principles for ICT Security as a yardstick, but stressed that falling short of a recommended standard is not in itself gross negligence. The level of security was to be measured against industry practice for similar services in 2021, at a local supplier serving small and medium-sized businesses. The solutions used by large groups were a less apt benchmark.
| Weakness at Nordlo | The Court of Appeal’s assessment |
|---|---|
| The backup server was in the same network as the production data | A vulnerability, but segmentation had started in 2019 and was almost complete. Under best practice, customer data should sit on the file server, and everything there was restored. |
| Multi-factor authentication not required for customers | Offered but not mandatory. Microsoft did not require it until January 2025, and it was not a general requirement in 2021. |
| Lack of written procedures | Blameworthy, but would not have prevented the loss. |
| Limited monitoring and logging | More advanced tools could have detected the attack earlier, but round-the-clock monitoring was outside a standard service. |
The court also gave some weight to the fact that Btec had not insured the value of its own data, as the terms assumed, and that Nordlo did not know that AutoCalc held the customer’s most critical data. That the management network held and only four of 255 customers lost data suggested that the security work had been effective.
This is a specific assessment of the facts in 2021. A supplier that today does not require multi-factor authentication, or keeps backups in the same network as production, cannot count on the same result.
What did the case cost the customer?
Btec received NOK 8,280, which is three months’ fees at NOK 2,760. Indirect losses such as lost profit, business interruption and lost customers were excluded under the terms.
Under the Dispute Act (tvisteloven) § 20-2, the losing party must as a rule cover the other side’s legal costs. The district court ordered Btec to pay NOK 2,152,570. The Court of Appeal added NOK 2,320,647 for the appeal, and Btec must also pay NOK 62,432.60 for the expert lay judges it had itself asked for. In total that is more than NOK 4.5 million, before Btec’s own lawyers’ fees.
Is the judgment final?
We do not know for certain. As of 4 October 2026, Lovdata’s case history field shows no proceedings in the Supreme Court. Metal Supply reported on 8 July that Btec would discuss an appeal with its lawyer over the summer. An appeal to the Supreme Court requires leave from the Appeals Selection Committee under Dispute Act § 30-4, and a case that mainly turns on the evaluation of evidence and a specific assessment of negligence normally has slim prospects. Until this is settled, the judgment should be read as a Court of Appeal decision with limited value as precedent.
What should customers buying hosting or SaaS do?
A customer does not escape the supplier’s terms by not reading them. The same goes for click-through agreements and terms referred to on an invoice. The limitation of liability in SaaS and hosting agreements normally holds, as we discuss in the article on SaaS limitation of liability. Other contract issues in buying cloud services are covered on the contracts topic page.
- Ask for the terms in writing before the service goes live, and read the limitation of liability, the definition of indirect loss and the force majeure clause.
- Tell the supplier in writing which systems and data are business-critical, and where they are held. In the Nordlo case it counted against the customer that the supplier did not know this.
- Require backups to be stored separately from the production environment and tested by restoring them, and require multi-factor authentication on accounts with access to the service.
- Keep your own copy of the most important data, or buy an extended security service. A cap of three months’ fees means the customer bears almost all of the loss itself.
- Consider insurance for loss of data and business interruption. Nordlo’s terms expressly placed this responsibility on the customer.
- Make sure there is a plan for cloud exit, so that the data can be retrieved and read in another system.
If the data includes personal data, the supplier will normally be a processor. The data processing agreement and the supplier’s security measures must then meet the requirements of the GDPR in GDPR Art. 28 and GDPR Art. 32. The liability cap in the main agreement does not relieve the customer of its own obligations towards data subjects and the Norwegian Data Protection Authority (Datatilsynet). Loss of personal data in a ransomware attack will usually also be a personal data breach that must be notified to Datatilsynet within 72 hours under GDPR Art. 33.
What can suppliers learn?
Nordlo won on incorporation because the customer knew the service and the terms through its sister company. A supplier that starts delivering without an accepted agreement will later have to prove that its terms apply, and that is a poor place to be. Get the customer to accept the terms in writing or electronically before start-up. Keep written security procedures up to date and retain them. Nordlo’s procedures from 2021 had been deleted by the time the case came to court, and the Court of Appeal did not find it shown that they had been adequate.
Questions and answers
Can standard terms apply even if the customer never signed them?
Yes. Norwegian law sets no formal requirements for commercial contracts. Under HR-2026-780-A, the question is whether the supplier had reasonable grounds to expect that the customer had accepted the terms. In the Nordlo judgment it was enough that the customer ordered the same standard service that a company it owned already used, and did not follow up the supplier's invitations to meetings.
Is a cyber attack force majeure for an IT supplier?
As a rule, no. The Court of Appeal found that ransomware has been a known risk in the IT industry since the mid-2010s and that a professional supplier must expect such attacks. The supplier was therefore in breach of contract, even though its liability was limited by the cap.
What liability cap is usual in IT operations and cloud agreements?
The Court of Appeal noted that comparable suppliers limit liability to the fees for the last three, six or twelve months, and that the Norwegian government standard agreement SSA-L uses twelve months. Three months is at the lower end of what is usual.
- Gulating Court of Appeal, judgment of 30 June 2026 (Btec AS v Nordlo Haugesund AS) LG-2025-156056
- Haugaland and Sunnhordland District Court, judgment of 20 June 2025 (Btec AS v Nordlo Haugesund AS) THOS-2024-65519
- Supreme Court of Norway, judgment of 8 April 2026 on the incorporation of standard terms HR-2026-780-A paras. 23 and 24
- Norwegian Dispute Act (tvisteloven) § 20-2 and § 30-4
- General Data Protection Regulation (EU) 2016/679 Arts. 28, 32 and 33
- Norwegian National Security Authority (NSM), Basic Principles for ICT Security
- Metal Supply, Court of Appeal: Btec loses multi-million claim after ransomware attack (8 July 2026)
Next legal review: 1 December 2026