A professionally drafted cybersecurity advisory/retainer agreement (used by all my clients in Poland) always contains the following key sections:
| Section | What it defines |
|---|---|
| Scope of services | Exact list of included activities (audits, pen-tests, incident response, trainings, on-demand forensics, compliance support, etc.) |
| Service tiers & monthly hours | Basic / Standard / Pro – number of guaranteed hours per month/quarter |
| SLA & response times | Acknowledgement < 15 min, first call < 1–4 h, on-site arrival (if needed) < 24 h, 24/7 option |
| Incident escalation procedure | Who calls whom, dedicated emergency numbers, escalation matrix, decision-making authority |
| Access rights | What systems I get access to (read-only, admin, OT, cloud consoles), MFA requirements, logging of all actions |
| Confidentiality & NDA | Full NDA, data processing agreement (DPA) compliant with GDPR, no disclosure even after contract end |
| Reporting & meetings | Monthly/quarterly status reports, executive summaries, scheduled steering committee calls |
| Testing & audit schedule | Fixed dates or windows for pen-tests, vulnerability scans, compliance audits |
| Liability & insurance | Professional liability insurance (I carry 5 mln PLN coverage), limitations of liability |
| Payment terms | Fixed monthly/quarterly fee, payment within 14 days, no extra charges even during major incidents |
| Contract duration & termination | Usually 12–36 months, 60–90 days notice period, automatic renewal |
The contract is always clear, readable (no 50-page legalese) and written in Polish + English parallel version.
Result: from day one both parties know exactly:
- what is included,
- how fast I react,
- who has access to what,
- how incidents are handled.
Want to see a real (anonymised) contract template? Write or call – I’ll send it within an hour.