Managed Vulnerability Scanning


This Consultant Agreement and Statement of Work (collectively the "Agreement" and individually the "Consultant Agreement" and the "SOW"), and the date shown on the signature block of the Consultant Agreement, is made and entered into by and between BLACK BREACH, LLC, and the Client identified on the SOW (collectively, the "Parties"), and shall be effective on the date fully executed by Client and Consultant (the "Effective Date"). 

All references herein to Consultant include all Principals, Employees, Consultants, and Contractors.

RECITALS

WHEREAS, this Agreement is governed by and subject to the terms and conditions of the Master Service Agreement entered into between Client and Consultant. In the event of any conflict between the terms and conditions of this Agreement and the Master Service Agreement, the terms and conditions of this Agreement shall prevail.

WHEREAS, the Parties agree that the services to be provided under this Agreement shall be governed by the provisions set forth in the Master Service Agreement, and the Parties further acknowledge and agree that any additional terms, conditions, or statements of work relating to specific services shall be incorporated as exhibits to the Master Service Agreement.

NOW, THEREFORE, in consideration of the promises, mutual covenants, and agreements set forth herein, and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties hereto agree as follows:

SCOPE OF SERVICES. 

The Consultant shall provide Managed Vulnerability Scanning. 

1. Managed Vulnerability Scanning

1. Provide a Client Success Manager (CSM) to you

2. Provide a Systems Engineer (SE) to you

3. Provide vulnerability scanning strategy template and guidance

4. Assist in vulnerability scanning design and architecture creation

5. Identify external scanning targets

6. Identify in-scope network scan subnets

7. Identify machines requiring deployed scanning agent

8. Configure Client-requested scan schedules

9. Configure Client-provided credentials where required to enable authenticated scans

10. Provide agent licensing

11. Configure automated reporting to email target

12. Alert Client Incident Handler when dark web hits occur

13. Configure Azure AD integration using Client-provided API credentials

10. Continuous monitoring of operational health checks that include:

11. Scan job completion

12. Expired credentials

13. Regularly update agents as they become generally available

2. Incident Response Triage

If the Client becomes the victim of a cybersecurity incident, the Consultant agrees to provide three (3) hours of incident response triage free of charge. Incident response triage includes all verbal expert recommendations on attempt recovery and recommended actions to be taken. Recovery is not guaranteed. Additional fees may apply hourly if additional services are required or requested.

Deliverables

1. Supporting documentation outlining all required items related to appropriate services to be deployed

2. If applicable, access to the XDR management platform

3. Access to ticketing platform

4. If applicable, access to the endpoint cloud management portal

5. Deployment audit document after 60 days of initial client engagement

6. If applicable, Curated playbooks based on SIEM security detections

7. If applicable, provide a vulnerability scanning report generated by the scanning platform via email

8. 24/7/365 monitoring of security alarms leveraging default and curated playbooks

9. 24/7/365 support for all security incidents from security analyst based on an incident response

plan (to the extent the purchased platforms can provide)

10. Full security incident report in the event of a confirmed compromise within the environment (to the extent the purchased platforms can provide)

Term

This Agreement commences on the Effective Date and will remain in effect through the Initial Term and all Renewal Terms, as specified in the SOW, unless otherwise terminated in accordance with the MSA (the Initial Term and all Renewal Terms collectively the "Term"). The Initial Term will be three (3) years from the Effective Date and will automatically renew for successive one-year periods, subject to the then-current conditions and price at the time of renewal. 

Payment Schedule

For monthly project services, the Client may pay annually or monthly at the Client's convenience. Payment will be due the first-month services start and as per terms outlined in the Consultant Agreement and Statement of Work and within (30) days of the invoice date. Amounts not paid when due will be subject to a late charge of one and one-half percent (1.5%) per month. Late charges are reasonable liquidated damages for collection fees and are not a penalty.

Invoice Remittance

Payment may be made as follows:

1. Mailed to: Black Breach, LLC, 1025 Rose Creek Drive, Suite 620-214, Woodstock, GA, 30189

2. Provided to Justin Shanken (or designee) in person

3. Wired directly to an account provided by Black Breach to Client

4. ACH directly to an account provided by Black Breach to Client

Last modified April 16, 2024