What is included in a cybersecurity advisory/retainer agreement?

A professionally drafted cybersecurity advisory/retainer agreement (used by all my clients in Poland) always contains the following key sections:

SectionWhat it defines
Scope of servicesExact list of included activities (audits, pen-tests, incident response, trainings, on-demand forensics, compliance support, etc.)
Service tiers & monthly hoursBasic / Standard / Pro – number of guaranteed hours per month/quarter
SLA & response timesAcknowledgement < 15 min, first call < 1–4 h, on-site arrival (if needed) < 24 h, 24/7 option
Incident escalation procedureWho calls whom, dedicated emergency numbers, escalation matrix, decision-making authority
Access rightsWhat systems I get access to (read-only, admin, OT, cloud consoles), MFA requirements, logging of all actions
Confidentiality & NDAFull NDA, data processing agreement (DPA) compliant with GDPR, no disclosure even after contract end
Reporting & meetingsMonthly/quarterly status reports, executive summaries, scheduled steering committee calls
Testing & audit scheduleFixed dates or windows for pen-tests, vulnerability scans, compliance audits
Liability & insuranceProfessional liability insurance (I carry 5 mln PLN coverage), limitations of liability
Payment termsFixed monthly/quarterly fee, payment within 14 days, no extra charges even during major incidents
Contract duration & terminationUsually 12–36 months, 60–90 days notice period, automatic renewal

The contract is always clear, readable (no 50-page legalese) and written in Polish + English parallel version.

Result: from day one both parties know exactly:

Want to see a real (anonymised) contract template? Write or call – I’ll send it within an hour.