APPENDIX: IT SECURITY AND RESPONSIBILITY PROCEDURE
§1. General Provisions and Allocation of Responsibilities
- The Contractor (IT Company) undertakes to exercise due diligence in maintaining the functionality and security of the Client’s information and telecommunications systems.
- The Parties acknowledge and agree that cybersecurity is an ongoing process dependent on the cooperation of both Parties. The Contractor provides the necessary tools, recommendations, and configuration, while the Client and its employees are required to comply with basic cybersecurity hygiene principles.
§2. Obligations of the Client and Its Employees
In order to ensure the effectiveness of system protection, the Client undertakes to:
- Restarting devices: Each employee of the Client is required to perform a full restart of their computer at least once a week (Friday after the end of the working day is recommended) in order to ensure the proper installation of automatic system updates.
- Updating web browsers: Employees are required to regularly restart their web browsers (Chrome, Edge, etc.), no less frequently than once every 3 days, in order to ensure that critical security patches are properly applied.
- Not changing system configurations: Employees are prohibited from independently disabling built-in antivirus software (Microsoft Defender), firewalls, or automatic update functionality.
- Reporting incidents: The Client undertakes to immediately report to the Contractor any unusual or suspicious behavior of equipment or systems (e.g. sudden slowdowns, suspicious messages, or loss of access to files).
§3. Exclusion and Limitation of the Contractor’s Liability
- The Contractor shall not be liable for any damage, data loss, downtime, reputational or financial losses suffered by the Client if a system infection with malicious software (e.g. ransomware or malware) or a data breach occurred as a result of:
- The Client or its employees ignoring explicit security recommendations or notifications concerning the need to perform an update or restart.
- Intentional actions by an employee of the Client (e.g. opening a malicious attachment received in a phishing email or entering passwords on a fraudulent website).
- Employees using local administrator privileges to install software that has not been authorized by the Contractor.
- The Contractor does not guarantee 100% protection of systems against cyberattacks, in particular against attacks exploiting previously unknown vulnerabilities (so-called Zero-Day vulnerabilities).
- The Contractor’s total liability for damages arising from improperly performed IT services (including failures and security incidents) shall be limited to an amount equal to one monthly subscription fee (or the amount of the most recent invoice) paid by the Client.
§4. Procedure in the Event of a Vulnerability Being Detected
- The Contractor monitors the security status of the systems using built-in mechanisms and technical tools.
- If Microsoft Defender detects a vulnerability on an employee’s computer, the Contractor will attempt to remediate it automatically by remotely deploying the required update.
- If applying the patch requires direct action by the user (e.g. restarting the device), the Contractor will notify the Client and provide the appropriate recommendation. From the moment such information is provided, responsibility for implementing the required update shall rest with the Client.