Master Service Agreement
Effective Date: The date You accept Our Proposal referenced in this Agreement.
Welcome Letter
Dear Client,
Thank you for trusting Reef Cyber Security to look after your cybersecurity. We don’t enjoy writing long legal documents any more than You enjoy reading them, but a few things need to be in writing so that we both know what’s expected, who does what, when, and what happens if something goes wrong.
We try hard to avoid complicated legal terms and unreadable passages. We have no desire to trick You into signing something We’ve hidden in legalese. That said, we do want what’s best for the safety of both parties — now and in the future.
We look forward to working with You.
Regards,
Justin Riddle, Owner — Reef Cyber Security
Overview
We like simplicity, so in short:
You, [Client Name] (located at [Client Address]) (“You”, “Yourself”, or “Your”), are engaging Us, Reef Cyber Security LLC (“Reef Cyber Security”, “We”, “Us”, or “Our”), to provide the cybersecurity services outlined in this Agreement for the pricing as outlined in Our initial Proposal.
You have the authority to enter into this Agreement on behalf of Your Business and will do everything You can to allow Us to provide Our services to You.
Us — Reef Cyber Security has the experience and ability to perform the services. We have agreed with You, and We will do it all in a professional and timely manner. We will use commercially reasonable efforts to provide excellent support to You, and on top of that We will maintain the confidentiality of everything We come across.
Of course, it’s a little more complex than that, so let’s get down to the Finer Details.
The Finer Details
Our General Terms and Conditions
All of the Terms in this Agreement are in addition to Our General Terms and Conditions, which can be found at https://reefcybersecurity.com/terms-and-conditions/.
By signing this Agreement, You also agree to those General Terms and Conditions. For any terms that exist in both, the terms in this Agreement will override.
Commitment Term
The minimum term that You have agreed to use Our Services is outlined in Our Proposal to You and is referred to as the Commitment Term. The Commitment Term begins from the first day of the next month after the date of accepting Our Proposal.
After the expiry of the Commitment Term, an extension of the Term will automatically commence equal to the period of the original Commitment Term, unless earlier terminated as outlined in the Termination section below.
Termination
If You need to terminate this Agreement before the end of the Commitment Term, You agree to pay Us the current Agreement Fee multiplied by the number of months remaining in the current Commitment Term, payable within 14 days of providing Us with written notice of termination.
If there are any pricing adjustments made to this Agreement during a Commitment Term, the Plan Fee used to calculate any Termination Payment will be based on the latter of the original Proposal or any updated pricing adjustments made in writing from Us to You.
All termination requests must be made in writing to: info@reefcybersecurity.com with the subject line “Termination — [Your Company Name]“.
Escalation
While We strive to provide You with the best possible support at all times, We leave an open communication channel right up to the owner in the event You ever need to escalate an issue further.
If You ever need to escalate a Service Request or issue, please use the following contact:
- Owner: Justin Riddle
- Email: justin@reefcybersecurity.com
- Phone: (727) 620-5525
Please note that this escalation channel is not to be used for lodging Service Requests. All Service Requests must be lodged through the normal methods as outlined in Our General Terms and Conditions. If You lodge a Service Request through this escalation channel, it will be treated as an Emergency Upgrade and will be charged at the Emergency Upgrade rate found on Our Rate Schedule.
Our Responsibilities
Response Time Guarantee
We agree to respond to Your Service Requests within the maximum time frames set out in Appendix A.
If Our response time to an incident exceeds the times set out in Appendix A, and provided that You reported the incident to Us via the methods set out in Our General Terms and Conditions, You may make a claim for service credit within 7 days of the incident in writing to info@reefcybersecurity.com.
If We agree Your claim is valid, You will be credited 5% of the monthly Agreement Fee (excluding any additional charges incurred in that month) for the month of the incident, to a maximum of 25% per month.
If the support request is lodged outside Our Business Hours, Our Response Time Guarantee does not apply. We will still work on Your Service Request as fast as possible; however, it will be on a best-efforts basis.
Response Times are calculated as per the Definitions outlined in Appendix E.
Please see Appendix B for a list of the types of Service Requests that Our Response Time Guarantee does not apply to.
Service Request Priorities
We classify Service Request priorities as shown in Appendix A. These priorities tie directly in with Our Response Time Guarantee to provide You with information about how quickly We will respond to Your issues.
If You require a Service Request that would normally be classed as a High, Medium, or Low priority to be escalated and remediated as a Critical Priority, You can request an “Emergency Upgrade”. Please see Our Rate Schedule for more information on Emergency Upgrades.
The final decision on classifying the priority of an issue will be made by Our responding technician.
What’s Covered
As part of this Agreement, We include the cybersecurity services typically required to maintain a small business security posture:
- Security Consulting (fractional CISO)
- Penetration Testing (external and internal)
- Third-Party Security Assessments
- Compliance Services (HIPAA, GLBA, SEC, CMMC, PCI, FTC Safeguards, FIPA)
- Cyber Hygiene and Managed Detection / Response coordination
- Phishing simulations and security awareness training
- Quarterly Business Reviews (QBRs)
You can see a list of all items We will cover under this Agreement in Appendix C. Anything not included in Appendix C is explicitly excluded from Your Agreement and will be billed at Our normal rates as found on Our Rate Schedule.
From time to time, We may provide support for items not explicitly included in Appendix C without charge; however, We will do this at Our sole discretion.
Scheduled Meetings
As part of this Agreement, We will perform Quarterly Business Review (QBR) sessions as indicated in the Proposal. Each QBR is approximately 60 minutes long and will be attended by Justin Riddle (Owner).
During these sessions, We will review:
- Last quarter’s security metrics and findings
- Your security plans and initiatives for the next quarter
- Refresh cycle update and Minimum Standards review
- Compliance and regulatory status
- Emerging threats relevant to Your industry
- Anything else You need to raise
We will send Your Primary Contact a reminder email 7 Business Days before every QBR. You agree to give Us at least 5 Business Days’ notice if You need to reschedule; otherwise the QBR will still be counted as used.
Reporting
Each month, We will email an Executive Summary report to Your Primary Contact with metrics from the previous month’s use of Our services. This report will contain metrics such as:
- Number of Service Requests opened and closed for the month
- Top categories of findings (vulnerabilities, incidents, etc.)
- Outstanding remediation items by severity
- Upcoming compliance deadlines
- Notable industry threat updates
We may modify the metrics We use in this report from time to time as We continually improve how We report to Our clients.
Your Responsibilities
Minimum Standards
There are some baseline cybersecurity requirements that You need to have in place in order for Us to meet Our Service obligations. These include (but are not limited to):
- Multi-factor authentication enabled on all email, financial, and admin accounts
- Endpoint protection (EDR or equivalent) on all company devices
- Verified, tested backups with at least one offline / immutable copy
- Documented asset inventory (Workstations, servers, network gear, cloud services)
- Current patch posture (operating systems and third-party applications)
- Active security awareness training for all staff
If You do not have all of these Minimum Standards in place before Your Agreement start date, We will work with You on a plan to bring Your environment up to Our Minimum Standards. We understand that this may take time depending on timing and budget, so We will do Our best to support any items that do not currently meet Our Minimum Standards. However, if an item requiring support does not meet Our Minimum Standards, it will be at Our sole discretion whether We charge You for any time incurred supporting that item.
Approved Software and Services
The list in Appendix D shows all of the Approved software, services, and platforms that are supported under this Agreement.
This does not mean that other software cannot be installed — it simply means that if other software is installed, it is at Our sole discretion whether We cover any Service Requests related to other Software under the scope of this Agreement. If We deem any Service Requests to be out of scope, We will ask for Your approval before performing any work.
This list may change over the time We work together under this Agreement. We will email any updates to this list to Your Primary Contact.
Lodging of Service Requests
The process for lodging Service Requests is outlined in Our General Terms and Conditions. Critical and High Priority Service Requests must be lodged by phone; otherwise Our Response Time Guarantee will apply only at the Medium priority level for those priorities.
You agree to make sure Your team is aware of any restrictions You have in place regarding who is authorized to lodge Service Requests, as all requests received by Us will be chargeable and/or allocated against this Agreement.
Access Requirements
You agree to allow Us full and free access to Your systems, associated equipment, premises, and Your team for the purposes of providing the Services in this Agreement. This may include read-only access to logs, configurations, and security tooling.
If there is anything that interferes with Our access, We may in Our absolute discretion charge You for any extra time incurred.
Primary Contact
You agree to nominate from Your team a Primary Contact and a Secondary Contact (who We will treat as the Primary Contact should the current Primary Contact not be available).
When issues of Critical and High Priority are happening, Your team is to channel all communication through these people during business hours. This allows Our team to work most effectively in restoring Your security posture as fast as possible, instead of fielding calls from multiple sources about the same problem.
The Primary Contact is to inform all staff at these times, to ensure fast resolutions. The role of the Primary Contact is also to assist Our team as the eyes and hands onsite, to allow Us to remotely diagnose and solve issues in the fastest possible manner.
You will be asked to provide the details of Your nominated Primary and Secondary Contacts during Your onboarding process, and You agree to update Us if and when these Contacts change during the Term of this Agreement.
Third-Party Authorizations
In order to assist You quickly in times of need, You need to make sure We are authorized to work with all of Your external Vendors that We may require to work with to provide You Our Service. This includes but is not limited to Your Internet Service Provider, Your Web and Domain Hosting Provider, Your Cloud Service Provider (Microsoft 365, Google Workspace, AWS, etc.), and Your Backup or Managed Service Provider.
During Your onboarding process, We will run through with You to determine all the Vendors You will need to give authorization to.
If We are not authorized for a particular Vendor, We may in Our absolute discretion charge You extra for any time it takes Us to obtain authorization to deal with that Vendor on Your behalf when needed.
Appendix A — Guaranteed Response Times and Priority Levels
The following table shows the Guaranteed Response times for each priority level, with priority level examples tailored to cybersecurity engagements:
| Priority | Examples | Guaranteed Response Time |
|---|---|---|
| Critical | Active security incident (ransomware, data breach, compromised credentials in active use). Production systems down due to security event. Regulator or law enforcement notification required. |
1 hour |
| High | Confirmed intrusion indicator requiring triage. Critical patch advisory (CVSS 9.0+) affecting Your environment. Audit finding requiring remediation before deadline. |
2 hours |
| Medium | Vulnerability finding requiring planned remediation. Security tool misconfiguration affecting visibility. Phishing investigation (no confirmed compromise). |
4 hours |
| Low | Policy or procedure question. Quarterly compliance report review. General security guidance. |
1 business day |
| No Priority | Proactive maintenance, scheduled assessments, training sessions. | Scheduled |
Appendix B — Response Time Guarantee Exclusion List
The Response Time Guarantee does not apply to:
- Additions, moves, or changes to users, devices, configurations, or networks
- Issues lodged in any manner other than specified in this Agreement and Our General Terms and Conditions
- Issues lodged outside Our Business Hours
- Items caused by hardware or software not meeting Our Minimum Standards
- Service Requests related to software or services not on Our Approved Software and Services List (see Appendix D)
- Service Requests for issues that have been caused by You not acting on advice or recommendations given by Us
- Service Requests for issues caused by You or third parties modifying any hardware, software, or security configuration
- Service Requests for issues related to user-initiated security incidents (e.g., clicking a phishing link, ignoring EDR warnings)
- Service Requests for issues involving the sourcing of hardware or software
- Service Requests for hardware and software issues of items that are not under current warranty or maintenance coverage
- Force majeure events (as defined in Our General Terms and Conditions)
Appendix C — Agreement Inclusion List
Services included under the standard Agreement Fee. Frequency: included in scope.
| Service Category | Description | Frequency |
|---|---|---|
| Security Consulting | ||
| Quarterly Business Review (QBR) | Quarterly | |
| Fractional CISO advisory hours | Per Plan | |
| Security roadmap and budget planning | Ongoing | |
| Assessments | ||
| Third-Party Security Assessments (external + internal) | Annual or Per Plan | |
| Penetration testing (web, network, wireless, social engineering) | Annual or Per Plan | |
| Phishing simulations | Quarterly | |
| Compliance | ||
| HIPAA, GLBA, SEC, CMMC, PCI, FTC Safeguards, FIPA gap assessments | Annual | |
| Policy and procedure review (information security, acceptable use, BYOD, incident response, business continuity) | Annual | |
| Vendor risk assessments (review of third-party security posture) | Per Plan | |
| Cyber Hygiene (Managed Coordination) | ||
| Endpoint protection health monitoring (in coordination with Your MSP / IT provider) | Daily | |
| Patch advisory review (per published CVE bulletins, prioritized for Your stack) | Weekly | |
| Backup verification (review of backup job logs and test-restore attestations) | Monthly | |
| Phishing-report triage (review user-submitted reports, escalate true positives) | Daily | |
| Awareness & Training | ||
| Security awareness training program administration (in coordination with Your LMS / provider) | Ongoing | |
| Tabletop exercise design and facilitation (phishing, ransomware, BEC) | Annual | |
| Reporting | ||
| Monthly executive summary report | Monthly | |
| Annual security posture report | Annual | |
Note: Reef Cyber Security is a cybersecurity consultancy. We coordinate with Your existing IT provider or internal IT team for endpoint, network, and infrastructure tasks. Items that fall outside the cybersecurity scope (e.g., helpdesk support, hardware repair, application development) are not included in this Agreement.
Appendix D — Approved Software and Services List
The following categories of tools, platforms, and services are supported under this Agreement. Specific products within each category may be updated as the threat landscape evolves.
- Endpoint Detection and Response (EDR): CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Sophos Intercept X
- Multi-Factor Authentication (MFA): Duo Security, Microsoft Entra ID, Okta, Google Authenticator, YubiKey
- Email Security: Microsoft 365 Defender, Proofpoint, Mimecast, Barracuda, Google Workspace security
- Identity and Access Management: Microsoft Entra ID, Okta, Active Directory
- Backup and Recovery: Veeam, Acronis, Datto, Backblaze, AWS S3 with versioning
- Network Security: Cloudflare, pfSense, Ubiquiti UniFi, Fortinet, Meraki, Palo Alto
- Vulnerability Scanning: Tenable Nessus, Qualys, Rapid7 InsightVM, Microsoft Defender Vulnerability Management
- Security Awareness Training: KnowBe4, Proofpoint Security Awareness, Curricula, Ninjio
- SIEM / Log Management: Microsoft Sentinel, Splunk, Elastic, Datadog
- Password Management: 1Password, Bitwarden, LastPass, Keeper
- Patch Management: Microsoft Intune, NinjaOne, ConnectWise Automate, Action1
Appendix E — Definitions and Interpretations
- “Agreement” means any arrangement between Us and You (whether alone or in conjunction with any other person) for Services and/or the provision of Goods provided by Us under an arrangement in connection with Work agreed to be done or progressed for or on behalf of You or any other person at Your request, including as set out in this Agreement and any corresponding Proposal.
- “Plan Fee” means the recurring monthly fee stated in the Proposal for the Services covered by this Agreement.
- “Proposal” means a quote or proposal provided to You by Us.
- “Rate Schedule” means the schedule of rates, charges, and conditions for the Services of Ours as set, and as may be varied, by Us from time to time in Our absolute discretion.
- “Business Hours” means Monday through Friday from 9:00 AM to 5:30 PM Eastern Time (America/New_York), excluding U.S. federal holidays and the days Reef Cyber Security observes as holidays.
- “After Hours” means any time outside Business Hours.
- “Response Time” is the difference between the time We are first notified of a New Service Request as per the process outlined in Our General Terms and Conditions and the time that We start providing Service on the Service Request. We do not count triage, scheduling, or dispatch work when calculating Response Times.
- “Services” means the provision of any services by Us including Work, advice, and recommendations.
- “Service Request” means any request for work that either You ask Us to perform or We perform proactively on Your behalf.
- “Software” includes software and any installation, update, associated software, and any services provided in connection with any of these things.
- “Work” means anything We may do, provide, customize, produce, or acquire, whether or not in connection with, or for the purposes of, You or Your use or benefit, and includes testing, troubleshooting, installation, and configuration of new equipment or software, consulting, scoping, planning, documenting, and quoting for complex items.
Appendix F — Letter to Vendors for Authorization
Copy and paste the text below onto Your letterhead, then modify to suit each vendor that We will need to work with while We support You.
To Whom It May Concern,
This letter is to inform You that we have contracted Reef Cyber Security to manage our cybersecurity and information security needs. To be able to do this effectively, Reef Cyber Security needs to be able to support and manage all of our technology suppliers on our behalf.
As such, this letter authorizes anyone from the team at Reef Cyber Security to access and modify all aspects of our account and all the products and services that we have with [vendor name] effective immediately.
This authorization is valid until we give You written notice otherwise.
Should You require any further details, please let us know.
Regards,
[Client Name]
[Title]