TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Litigation
№ 270 Case Study — Litigation

Why Did Our Systems Keep Failing When the Contract Said They Would Not

A Rockland not-for-profit's outsourced IT provider kept missing its uptime commitments, and the question its board kept asking finally had to be answered with a claim.

Litigation8 min readRockland, OntarioIT and managed service failures
All Litigation case studies
ClientDeniz, executive director of a Rockland not-for-profit organization
The issueAn outsourced IT provider missed its contracted uptime commitments repeatedly, and key outage records had never been properly kept
ServiceReconstructed the missing documentation from secondary sources and pursued a breach of contract claim against the provider
ResolutionThe provider agreed to a settlement covering the bulk of the organization's losses after being shown the reconstructed record

The situation

Why do our systems keep going down when the contract guarantees they will not? That was the question Deniz brought to her board meeting after the fourth outage in five months, and it was the question that, eighteen months later, sat at the centre of a claim worth well over a million dollars.

Deniz ran a mid-sized not-for-profit based in Rockland that delivered services across the region and depended heavily on a case management system to track its clients, funding, and reporting obligations to government partners. Two members of her board pressed hardest for answers, Burak, who owned a multi-unit franchise operation and chaired the finance committee, and Hodan, a partner in an engineering firm who sat on the risk committee, both of whom understood contract performance from their own industries and were first to ask why the organization had no formal record of what the outages were costing it. Several years earlier, the organization had outsourced its entire IT infrastructure, servers, network security, help desk, and the case management platform itself, to a managed service provider under a multi-year agreement. The contract set out specific uptime commitments: the systems were guaranteed to be available a defined, high percentage of the time, with financial credits owed to the organization for any month that commitment was missed.

For the first two years the arrangement worked as intended. Then the outages began. What started as an occasional evening disruption became a pattern: systems down for hours at a time, sometimes during business hours, sometimes coinciding with reporting deadlines the organization owed to its funders. Deniz's team logged what they could, screenshots, emails to the help desk, notes from staff meetings, but there was no formal, systematic record. Nobody had been assigned to track outages against the contract's uptime formula, because nobody had expected to need one.

Two things eventually forced Deniz's hand. The outages began costing the organization directly, through missed funder deadlines, staff overtime spent on manual workarounds, and at least one lost grant renewal attributed partly to late reporting. And when Deniz finally asked the provider for its own uptime logs, covering the period the contract said it was obligated to maintain them, the provider could not produce a complete set. Some records, the provider said, had simply not survived a system migration eight months earlier.

The gap nobody had noticed

A breach of contract claim for missed service levels depends almost entirely on proof: showing, month by month, that the systems were unavailable for longer than the contract permitted. Without the provider's own monitoring logs, that proof had to come from somewhere else, and the somewhere else had to be reconstructed from records that were never designed to serve as evidence.

The organization's own documentation was fragmented across several sources. Staff emails to the help desk, timestamped and often including screenshots of error messages, existed in individual inboxes rather than any central file. Internal messaging logs from the organization's team channels captured real-time complaints about systems being down, often more precise about timing than the emails. Funder correspondence showed at least two instances where reporting deadlines were missed and an explanation involving system outages was given at the time, which mattered because it showed the outages had been reported contemporaneously, not asserted only after the dispute arose.

None of these sources alone would have been persuasive. A single email complaining about a slow system does not establish a breach of a specific uptime percentage. What mattered was building, from many partial and imperfect sources, a timeline detailed enough to reconstruct actual outage duration for each month in dispute, and cross-referencing that timeline against the contract's own uptime formula to calculate, month by month, whether the guaranteed threshold had actually been missed and by how much.

The provider's position, once the claim was raised, was that without its own logs there was no reliable way to establish the extent of any outages, and that the organization's informal internal records could not substitute for the technical monitoring data the contract contemplated. That argument had real force. The reconstruction effort had to be rigorous enough to withstand exactly that challenge, corroborated across independent sources rather than resting on any single account, before it could support a credible claim for the financial credits and consequential losses the missed uptime commitments had caused.

Ontario contract law does not require a party proving breach to produce perfect, contemporaneous technical records. A civil claim only has to be established on a balance of probabilities, meaning the evidence has to show a version of events that is more likely true than not, not proof beyond doubt. That lower bar mattered here: a reconstructed timeline, built from multiple independent sources that lined up consistently with each other, could satisfy that standard even without the provider's own monitoring logs, provided the reconstruction was careful enough that a court would trust the numbers it produced. The risk was not that reconstructed evidence could never be enough, but that a sloppy or inconsistent reconstruction would hand the provider an easy argument that the whole claim rested on guesswork.

What we did

  1. Mapped every internal source that might contain outage evidence, identifying staff email accounts, the organization's team messaging platform, help desk ticket confirmations, and funder correspondence, before beginning any analysis, so the reconstruction effort would draw on the full universe of material available rather than the first convenient handful of records Deniz's staff happened to remember, since a source overlooked at this stage could never be added back in credibly later.
  2. Collected and time-stamped every relevant entry across those sources, cross-referencing emails against messaging logs to identify when the same outage had been reported through more than one channel, which strengthened the reliability of the timeline being built for each incident and reduced the chance any single entry could be dismissed as a one-off complaint rather than a documented outage.
  3. Built a month-by-month outage log against the contract's uptime formula, converting the reconstructed incident timeline into the specific percentage calculation the agreement used, to show precisely which months fell below the guaranteed threshold and by how much, translating scattered anecdotal complaints into a structured record a court or the provider's own counsel could actually evaluate on its own terms.
  4. Obtained a partial set of surviving logs from the provider through formal document requests, pressing on the migration explanation with specific questions about backup practices and retention policies, which produced a smaller but genuine set of records covering roughly a third of the disputed period and corroborating the reconstructed timeline for those months, lending credibility to the reconstruction for the months no provider records survived at all.
  5. Retained an independent IT consultant to assess the reconstructed record, having someone outside the organization confirm that the methodology used to convert scattered internal records into outage duration figures was sound and technically defensible, which mattered directly to countering the provider's anticipated argument that informal records could not substitute for proper monitoring data, and gave the eventual demand a credibility a purely internal analysis would not have carried on its own.
  6. Calculated the organization's consequential losses separately from the contractual credits, distinguishing the straightforward uptime credits owed under the contract from the harder-to-quantify costs of staff overtime and the lost grant renewal, supporting each category with its own evidence, including timesheets for the overtime claim and the funder's own correspondence for the grant loss, rather than a single blended figure that would have invited challenge on its weakest component.
  7. Briefed Burak and Hodan on the board's exposure and the settlement strategy before any demand went out, since both had pressed hardest for the organization to act and needed a clear picture of what the reconstructed evidence could and could not prove, to manage the board's expectations about how much of the claim would likely be recoverable and where the provider was most likely to push back.
  8. Sent a detailed demand setting out the reconstructed record and the calculation, laying out the month-by-month analysis and the independent consultant's assessment before filing a claim, to give the provider a clear basis to evaluate its exposure and negotiate rather than force a lengthy discovery process over documents it had already admitted it could not fully produce, and to set a realistic deadline for a response.

The outcome

Faced with a reconstructed record that an independent consultant had reviewed and that lined up with the partial logs the provider itself eventually produced, the provider's position shifted from disputing the outages to negotiating their value. Once the demand went out, negotiations moved relatively quickly, a matter of a few months rather than the multi-year timeline litigation over a dispute this size might otherwise have taken, in part because the provider's own counsel recognized how difficult it would be to challenge a record that had already survived independent technical review. The parties reached a settlement covering the bulk of the organization's claimed losses, both the contractual uptime credits and a portion of the consequential costs tied to the missed grant renewal and staff overtime.

The settlement did not recover everything the organization had claimed. The lost grant renewal, in particular, was discounted in the negotiation because funding decisions depend on more than one factor, and the provider's counsel argued, with some legitimate force, that the outages could only be shown to have contributed to that loss rather than caused it outright. The final figure reflected that uncertainty rather than treating the claim as fully proven on every head of damage, and Deniz reported the settlement to Burak and Hodan's committees in those terms, as a strong recovery rather than a complete one.

Deniz's organization also came away from the file with a changed practice going forward: a formal, centralized outage log is now maintained against every service commitment in its contracts, reviewed monthly by a staff member with clear responsibility for the task, rather than left to individual employees to notice and report informally when something went wrong. The eighteen months of reconstruction work that resolved this dispute would not have been necessary had that discipline existed from the start, a lesson the board took directly into how it now manages every vendor relationship the organization depends on, and Burak in particular pushed to have the same monitoring discipline applied to the organization's other major service contracts once the settlement closed.

What you can learn from this

  • If a contract guarantees a service level, track performance against it from day one. Waiting until a dispute arises to look for proof means relying on records that were never designed to serve as evidence.
  • A vendor's failure to produce its own monitoring data does not end a claim. Internal records, even scattered across emails and messaging platforms, can be reconstructed into credible evidence if corroborated carefully.
  • Independent technical review of a reconstructed record adds real weight in a negotiation, particularly when the other side's first move is to attack the reliability of your evidence.
  • Separate straightforward contractual damages, like missed service credits, from harder-to-prove consequential losses, like a lost funding opportunity. Each needs its own supporting evidence and will be valued differently.
  • After any vendor dispute, put a monitoring practice in place for the future. The cost of tracking service commitments as they happen is far lower than the cost of reconstructing a record after the fact.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a litigation problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →