It covers the security monitoring work I’ll do for you, and it sits alongside the proposal you accepted, including any written scope notes and pricing in that proposal.
If there is a conflict between what I’m doing day to day and what’s written down, I’ll flag it early and I’ll ask you to confirm the plan in writing before I change what I’m doing. My goal is simple: you know what I’m watching, what I’m not, and when I’ll call you.
What I monitor
Security monitoring runs as a retainer: there is a one-time setup phase to get coverage into shape, then ongoing monitoring and monthly review on a repeating monthly cycle. Setup includes log source intake and a coverage map, a baseline week to clean up alert noise, and an agreed escalation matrix and call tree.
After setup, I monitor the agreed consoles, handle after-hours alerts using the escalation matrix, and I send a monthly report with a review call. The proposal lists the deliverables for this retainer, including:
* 24/7 SIEM monitoring * Managed EDR monitoring * Log source onboarding * Detection tuning * Alert suppression * Reporting and review call
Response and escalation
I treat alerts by severity using the escalation matrix you approve during the baseline week. I use plain-language criteria such as likely compromise, active misuse, or high-confidence credential abuse. If something looks like noise, I tune it. If it looks real, I call.
I’ll confirm your contact methods and call tree before monitoring starts. For each severity level, I’ll also confirm the response target times with you in writing so you know what to expect after hours versus during business hours. If I miss a service level, I’ll tell you what happened, what I did to prevent a repeat, and I’ll apply a fair service credit or make-good we agree in writing.
Payment
Setup is billed in two parts: I invoice 40% to start setup work, and I invoice the remaining 60% when setup is complete. Each setup invoice is payable within 7 days of its date.
Ongoing security monitoring is invoiced at the start of each month, covering that month’s retainer period. Each monthly invoice is payable within 7 days of its date.
If you ask for work outside security monitoring, such as incident response, cleanup, or forensic support, I will pause and ask before doing billable work outside this retainer. If you want me to proceed, I’ll quote it separately and get your okay in writing first.
Price changes
I review retainer pricing at a regular interval, based on what I’m actually monitoring, how many log sources are in scope, and how much alert volume is landing in the consoles. I also take into account material changes on your side, like adding a new firewall, expanding Microsoft 365 usage, rolling out a new VPN, or onboarding a new site.
If I’m proposing a price change, I’ll send it to you in writing before it takes effect, along with the reason in plain terms. The notice period is whatever I state in writing at the time. If you don’t want to continue at the new price, you can end the retainer using the notice process in this agreement.
Access I need
You provide least-privilege access to the SIEM, EDR, and any consoles we agree are needed for security monitoring. I only ask for the access required to investigate and validate alerts, tune detections, and document changes. I do not need, and I do not want, broad admin access unless we agree it is required for a specific task.
I will not send or receive passwords, keys, or recovery codes in a form or a normal email. Access details are shared and stored using your approved password process. If your access method changes, you tell me and I’ll re-confirm what still works before I rely on it for after-hours escalation.
What I need from you
You name one primary contact and at least one backup for escalation. You also tell me who can approve changes to detections, suppression rules, and log onboarding. If I cannot reach anyone using the call tree for a high-severity alert, I will keep investigating within the access you’ve provided and I will document what I did and what I could not confirm.
You tell me about changes that affect monitoring before they go live when you can. Common examples are new remote access paths, new identity providers, a new firewall policy, adding or removing EDR from endpoints, or major Microsoft 365 policy shifts. If you make changes without notice, I may treat the following days as a temporary re-baseline period so I don’t page you for expected behavior.
Insurance
I keep the kinds of business insurance that make sense for security monitoring work, including coverage for professional mistakes and general business risks. If you want to see a certificate, ask and I’ll provide it.
On your side, you are responsible for carrying insurance that fits your business, your systems, and your regulatory reality. This commonly includes cyber coverage and any coverage tied to business interruption, data breach response, and third-party claims. Monitoring reduces risk, but it does not remove it. Insurance is one of the ways you protect the business for the edge cases nobody wants to test in real time.
If something goes wrong
If I notice anything that looks like an error I caused, such as a mis-tuned rule that suppresses a real signal or a change that breaks expected alerting, I will tell you as soon as I see it and I will put it in writing. The same goes for anything you report to me that you believe ties back to my monitoring changes.
My first step is to stop the impact, then explain what happened, then fix what I can within security monitoring. If putting it right requires work outside this retainer, I’ll outline options and costs in writing before I proceed. If the issue is on your side, I’ll still help you sort cause and next steps, and I’ll document what I saw in the consoles.
No direct hiring
The length of that post-end period is what I state in writing.
This matters because the retainer price assumes continuity. The setup work, baseline cleanup, and runbook design are part of getting to the point where after-hours calls are accurate and calm. If you want to expand the relationship, add projects, or change how the work is structured, I’m happy to discuss it. I just need it to stay above board and agreed in writing.
Retainer cycle
This is a monthly retainer. It renews each month automatically unless you or I end it with written notice. The notice period is whatever I state in writing. Written notice can be an email from an authorized contact on your side to the contact method I provide for contract notices.
If you end the retainer, you are responsible for paying for security monitoring provided up to the effective end date, plus any setup amounts already invoiced under the setup terms. If I end the retainer, I will give the same written notice and I will help you transition in a practical way during that period, including handing back documentation and removing my access as described below.
Your logs and my notes
Your raw logs stay in your SIEM. As part of security monitoring, I do not export your raw logs into my own system. What I keep on my side is limited to working notes needed to do the job, such as escalation records, tuning and suppression decisions, and a history of recommendations and what you approved.
When the retainer ends, I will give you a usable handover package in a common format. That typically includes the current escalation matrix, call tree details you provided, a summary of log sources onboarded, and a list of the key tuning and suppression changes made during the term. I will also remove my access and confirm in writing when it is done.
What I’m responsible for
I’m responsible for doing security monitoring with care, using the consoles and access you provide, and following the escalation matrix we agreed. I’m also responsible for being honest about uncertainty. If I cannot verify something because the logs are missing, the tool is down, or access is broken, I will say so.
What I cannot promise is that monitoring will catch every attack, prevent an outage, or undo weaknesses in systems I do not control. Attackers change tactics, tools can fail, and some events are only visible if the right logs exist and are retained. I also am not responsible for business losses caused by your internal decisions or delays, such as choosing not to act on an escalation or not applying a critical fix after it is raised.
Ending this agreement
Either you or I can end this agreement with written notice. The notice period is whatever I state in writing. If you want the end date to line up with the monthly billing cycle, tell me and I’ll confirm the clean cutoff date in writing.
On termination, you pay for security monitoring delivered up to the end date under the normal invoice terms. I will deliver the handover items described above, and I will remove my access from your SIEM, EDR, and related consoles. If you want me to stay available after the end date to help your next provider settle in, I can do that as a separate, agreed piece of work.
Signature






