// Terms & Conditions

vCISO
RETAINER

Terms and conditions governing virtual CISO retainer engagements with Vincent Cyber Defence Ltd.

← All Terms & Conditions

Vincent Cyber Defence Limited · Company No: 16335932 · Effective: 4 September 2026

A. About These Terms — Please Read First

These Terms and Conditions govern the provision of Virtual CISO (vCISO) support services by Vincent Cyber Defence Limited.

vCISO services are advisory in nature. We are your security lead and guide - we are not your IT provider, incident responder, data protection officer, or legal adviser.

Please read these Terms carefully before purchasing a plan. By placing an order or making payment, you confirm you have read and agree to be bound by them.

These Terms cover all three vCISO plans - Foundation, Standard, and Elevated. Where a term applies only to a specific plan, this is stated clearly.

Any certifications or testing services (Cyber Essentials, Cyber Essentials Plus, DCC Level 0, penetration testing) delivered alongside your vCISO plan are governed by their own separate Terms and Conditions and invoiced separately. Your vCISO plan covers the advisory, coordination, and management work around those services - not the services themselves.

1. Definitions

1.1 In these Terms, the following definitions apply:

  • "Agreement" - these Terms and Conditions together with your Order.
  • "Advisory Services" - the virtual CISO support services described in your Order and on our website, comprising security advisory, policy maintenance, renewal management, vulnerability monitoring, and associated support as set out in the applicable plan.
  • "Business Day" - any day other than a Saturday, Sunday, or public holiday in England.
  • "Deliverables" - all written outputs we produce for you under your plan, including security policies, risk summaries, quarterly review reports, board-level reports, and any other documents produced in connection with the Services.
  • "Elevated Plan" - the Elevated tier vCISO plan as described on our website and in your Order.
  • "Fees" - the monthly fees payable by you for the Services as set out in your Order.
  • "Foundation Plan" - the Foundation tier vCISO plan as described on our website and in your Order.
  • "Initial Term" - the minimum three (3) month commitment period beginning on the date your plan commences.
  • "Minimum Term" - three (3) calendar months from the date your plan commences.
  • "Monthly Rolling Term" - the period following the Initial Term during which the Agreement continues on a rolling monthly basis until terminated in accordance with Clause 10.
  • "Order" - your order for Services, confirmed by payment or written instruction, setting out the plan selected, the Fees, and the commencement date.
  • "Plan" - the Foundation, Standard, or Elevated vCISO support plan selected in your Order.
  • "Services" - the Advisory Services provided under your selected Plan as described in these Terms and on our website.
  • "Standard Plan" - the Standard tier vCISO plan as described on our website and in your Order.
  • "We / Us / Our" - Vincent Cyber Defence Limited (Co. No: 16335932).
  • "You / Your / Client" - the person, company, or entity purchasing the Services, as identified in the Order.

1.2 Clause headings do not affect interpretation. Words in the singular include the plural and vice versa. A reference to a statute includes any amendment or re-enactment. Any words following "including", "such as", or "for example" are illustrative and do not limit the preceding words.

2. Your Order & These Terms

2.1 These Terms govern the provision of all vCISO support services by us. They take precedence over any inconsistent terms in your purchase order, confirmation of order, or specification, or implied by law, trade custom, or course of dealing.

2.2 Your Order is formed when you make payment or confirm acceptance of these Terms in writing, whichever occurs first. These Terms are incorporated into your Order by reference.

2.3 You acknowledge that the Services are advisory in nature and have not been developed to meet your individual requirements in their entirety. It is your sole responsibility to ensure that the scope and nature of the Plan selected meets your needs before purchasing. We are not obliged to adapt, customise, or modify the Services beyond the scope of your selected Plan unless separately agreed in writing.

2.4 Where there is any conflict between these Terms and your Order, your Order shall prevail on specific scope, fee, and delivery matters. On all other matters, these Terms prevail.

2.5 We may update these Terms from time to time. Changes will be notified to you at least 30 days before they take effect. Where a change is material and you do not accept it, you may terminate your Plan under Clause 10 before the change takes effect.

3. What Is Included in Your Plan

Certifications and testing (CE, CE+, DCC L0, pen testing) are not included in your monthly fee - they are billed separately at standard pricing. Your vCISO plan covers the advisory, scoping, coordination, and management work around those services.

All Plans — Foundation, Standard & Elevated

3.1 All Plans include:

  • Annual Cyber Essentials and Cyber Essentials Plus recertification managed start to finish - we handle the process and you sign the declaration. Certification fees are billed separately at standard pricing.
  • A security policy pack covering MFA, access control, acceptable use, and incident response policies - written, maintained, and kept current throughout your plan.
  • Continuous patch and vulnerability monitoring for up to 8 devices - plain English reporting, not raw scan output.
  • Email advisory support - a business-hours channel for security questions arising from your certifications, policies, or a specific tender. This is not a general IT helpdesk or emergency response line.
  • A named point of contact from day one - your lead contact from onboarding through to every renewal. No account managers, no handoffs.
  • Cyber insurance readiness - current certifications, up-to-date policies, and patching evidence maintained and available to share at insurer renewal.

Standard Plan & Elevated Plan Only

3.2 Standard and Elevated Plans include everything in the Foundation Plan, plus:

  • Tender and procurement questionnaire support - we answer the security questions in your procurement documents. Legal interpretation remains with your solicitor.
  • Penetration test scoping and remediation coordination - we scope the test and coordinate remediation. Test delivery is by a specialist third party and billed separately.
  • Quarterly risk review with a written summary.
  • Priority email advisory - response within 1 Business Day.
  • 5% discount on all certifications and testing (Standard Plan).

Elevated Plan Only

3.3 The Elevated Plan includes everything in the Standard Plan, plus:

  • Monthly vCISO call - one scheduled call per calendar month of up to 60 minutes with your named lead contact.
  • Incident response readiness planning - we prepare you for an incident and your cyber insurer's response panel. We are not on the incident response call itself.
  • DCC Level 0 process managed for you - we coordinate and manage your DCC L0 assessment end to end. DCC L0 certification fees are billed separately under our DCC L0 Terms and Conditions.
  • Annual board-level risk report - one written report per year summarising your security posture, certification status, and risk position in plain English.
  • IASME Cyber Assurance roadmap - advisory support on your pathway toward IASME Cyber Assurance certification.
  • 10% discount on all certifications and testing.

4. What Is Not Included

A clear scope means no surprises. The following fall outside every Plan. Additional advisory time is available if needed.

4.1 The following are explicitly excluded from all Plans and do not form part of the Services:

  • Day-to-day IT support - IT helpdesk queries, device management, patching, and software upgrades. We advise on what needs doing; implementation sits with your IT provider or MSP.
  • Technical incident response - incident response sits with your cyber insurer's panel. We prepare you for that engagement; we are not on the call. The same applies to 24/7 monitoring and SOC coverage.
  • Legal or contract review - we answer security questions in procurement documents. Legal interpretation remains with your solicitor.
  • Implementation work - configuring firewalls, deploying MDM, installing security tools, or running penetration tests is implementation, not advisory. We scope and coordinate; delivery sits with your IT team or a specialist third party.
  • Security awareness training - staff training programmes, phishing simulations, and e-learning platforms. We can recommend providers; delivery sits elsewhere.
  • Acting as Data Protection Officer (DPO) or GDPR lead - a vCISO manages your security posture, not your data protection compliance programme. If you need a DPO, that is a separate appointment.
  • More than 8 devices for vulnerability monitoring - additional device coverage is available at an agreed additional fee.

4.2 Where you request work that falls outside your Plan, we will confirm whether it falls within scope before proceeding. Out-of-scope advisory work may be provided, agreed in writing before it is commenced.

5. Our Obligations

5.1 We will provide the Services with reasonable care and skill in accordance with generally accepted cyber security advisory standards.

5.2 We will provide you with a named lead contact from the date your Plan commences. We will use reasonable endeavours to ensure continuity of that contact throughout your Plan, but reserve the right to reassign your lead contact where necessary, with reasonable notice to you.

5.3 Email advisory response times are as follows: Foundation Plan - within 2 Business Days; Standard and Elevated Plans - within 1 Business Day. Response times apply to business-hours queries on Business Days. They do not apply to emergency or out-of-hours situations, which fall outside the scope of all Plans.

5.4 We will manage your annual CE and CE+ recertification process on your behalf, including liaising with you on the self-assessment questionnaire and coordinating submission. You remain responsible for the accuracy of all declarations and answers submitted. Certification fees are billed separately.

5.5 We will use reasonable endeavours to keep your security policy pack current and relevant to your business. You are responsible for reviewing, approving, and implementing those policies within your organisation.

5.6 We do not warrant that any specific security outcome will be achieved as a result of the Services. Advisory guidance is based on the information you provide to us and on our assessment of your circumstances at the time. We are not responsible for outcomes arising from your failure to implement our recommendations.

5.7 We do not warrant that the Services will prevent any security breach, cyber attack, data loss, regulatory enforcement action, or loss of tender or contract eligibility. The Services reduce risk - they do not eliminate it.

6. Your Obligations

6.1 To enable us to deliver the Services effectively, you agree to:

  • Engage with us in good faith and provide timely, accurate, and complete information about your IT environment, certifications, policies, and any relevant changes to your business.
  • Notify us promptly of any material changes to your organisation, IT environment, or certification scope that may affect the Services - including changes to staff, devices, systems, or supply chain relationships.
  • Review, approve, and implement security policies and recommendations we provide within a reasonable timeframe. We advise; implementation is your responsibility.
  • Attend scheduled reviews and calls within your Plan, or notify us in advance if you need to reschedule.
  • Provide accurate information when completing certification questionnaires or other scheme documentation. You remain solely responsible for the accuracy and completeness of all submissions made in your name.
  • Not use the email advisory channel as a general IT helpdesk, emergency response line, or substitute for specialist legal, HR, or technical support.
  • Ensure that the person dealing with us has the authority to make decisions on behalf of your organisation in relation to the Services.

6.2 You represent and warrant that all information you provide to us in connection with the Services is accurate and not misleading, and that you have the authority to instruct us on behalf of your organisation.

6.3 If we are prevented or delayed in performing our obligations by any act or omission of yours, we shall not be liable for any resulting delay or failure, and shall be entitled to an extension of time and recovery of any additional costs reasonably incurred as a result.

7. Fees & Payment

7.1 The monthly Fees for your selected Plan are as set out in your Order. Fees are payable monthly in advance, on or before the first day of each calendar month, starting from the date your Plan commences.

7.2 All Fees are exclusive of VAT, which shall be payable at the prevailing rate where applicable.

7.3 All Fees are payable in British Pounds (GBP). You are responsible for all bank charges, intermediary fees, and currency conversion costs.

7.4 Certification and testing fees (Cyber Essentials, CE+, DCC L0, penetration testing, and any other certifications) are billed separately at our standard pricing at the time of engagement, or at the discounted rate applicable to your Plan where a discount applies. Discounts apply to the then-current standard price at the time of invoicing.

7.5 If you fail to pay any amount due by the due date, we reserve the right to: (a) charge interest at 8% per annum above the Bank of England base rate under the Late Payment of Commercial Debts (Interest) Act 1998, accruing daily from the due date; (b) suspend the Services without liability until payment is received in full; and (c) recover fixed-sum compensation and reasonable debt recovery costs permitted by that Act.

7.6 Suspension of Services under Clause 7.5 does not release you from your obligation to pay Fees during the suspension period or to complete the Minimum Term.

7.7 We reserve the right to increase Fees at the end of the Initial Term or at any subsequent annual anniversary, with at least 30 days' written notice. If you do not accept the increase, you may terminate under Clause 10 before the increase takes effect.

8. Plan Commencement & Onboarding

8.1 Your Plan commences on the date confirmed in your Order. We will contact you within 5 Business Days of commencement to arrange your onboarding call.

8.2 The onboarding call covers: your current certification status, existing policies and documentation, your IT environment and device estate, and the scope of your Plan. We will agree a starting point and any immediate priorities.

8.3 If you are an existing Vincent Cyber Defence client, we may use information already held about your setup to streamline onboarding. You should notify us of any changes since your last engagement with us.

8.4 The Services commence in full following onboarding. We are not responsible for any delay in onboarding caused by your failure to engage or provide required information.

9. Contract Term

All Plans have a 3-month minimum term. After that, your plan rolls monthly and you can cancel at any time with 30 days' written notice.

9.1 All Plans are subject to a Minimum Term of three (3) calendar months from the date of commencement. You may not cancel your Plan during the Minimum Term except in accordance with Clause 10.3.

9.2 Following the expiry of the Minimum Term, your Plan automatically continues on a rolling monthly basis until terminated in accordance with Clause 10.

9.3 You may upgrade your Plan at any time by notifying us in writing. An upgrade takes effect from the next monthly billing date. Additional Fees applicable to the upgraded Plan are payable from that date.

9.4 You may downgrade your Plan at any time after the Minimum Term by giving us at least 30 days' written notice. A downgrade takes effect from the next monthly billing date following the notice period.

9.5 Where your business circumstances change materially during your Plan - including significant growth in device estate, acquisition of another business, entry into a regulated sector, or a material increase in the scope of security support required - you must notify us in writing. We will assess whether the change falls within your existing Plan or requires re-scoping. Where re-scoping is required, we will propose revised terms before any additional work is undertaken. We are not obliged to absorb material scope increases within your existing monthly Fee.

10. Cancellation & Termination

10.1 After the Minimum Term, you may cancel your Plan at any time by giving us at least 30 days' written notice. Your Plan will continue and Fees will remain payable during the notice period. No refund is due for any prepaid Fees covering the notice period.

10.2 We may terminate your Plan at any time after the Minimum Term by giving you at least 30 days' written notice. Where we terminate your Plan under this clause, we will refund any prepaid Fees covering the period after the termination date on a pro-rated basis.

10.3 Either party may terminate this Agreement immediately on written notice if the other: (a) commits a material breach that remains uncured for 14 days after written notice; or (b) becomes insolvent or unable to pay its debts as they fall due. Where you terminate under this clause during the Minimum Term due to our material breach, we will refund any prepaid Fees for the remaining portion of the Minimum Term on a pro-rated basis. For the avoidance of doubt, failure to pay any monthly Fee by the due date that remains outstanding for more than 7 days after written notice constitutes a material breach entitling us to terminate immediately.

10.4 If you attempt to cancel during the Minimum Term other than under Clause 10.3, the Fees for the remainder of the Minimum Term remain payable in full. We may invoice for those Fees immediately on notice of cancellation.

10.5 We reserve the right to suspend or terminate the Services immediately and without notice where we reasonably consider that: (a) continuing the relationship poses a material risk to our professional reputation or standing; (b) you have suffered a significant security incident and have publicly attributed responsibility for that incident to us without basis; or (c) your actions or omissions in connection with the Services expose us to legal, regulatory, or reputational liability. Where we exercise this right, we will refund any prepaid Fees for the period after the suspension or termination date on a pro-rated basis.

10.6 Scheduled reviews, calls, and advisory sessions that are part of your Plan will be offered to you at a mutually agreed time. Where you are unavailable, fail to attend, or fail to respond to two or more scheduling attempts in any calendar quarter, our obligation to deliver that review or session for that quarter is discharged. No credit, refund, or rollover applies. We will use reasonable endeavours to reschedule on request but are not obliged to carry forward missed sessions.

10.7 On termination or expiry of this Agreement for any reason: (a) all licences granted to you cease immediately, save as provided in Clause 13.6; (b) all outstanding amounts become immediately due; (c) each party shall return or permanently delete the other's confidential information on written request, except where retention is required by law; and (d) you shall cease representing yourself as a current vCISO client of Vincent Cyber Defence.

10.8 Termination does not affect any accrued rights or liabilities of either party at the date of termination.

11. Liability

11.1 The following provisions set out the entire liability of Vincent Cyber Defence Limited (including any liability for the acts or omissions of our employees, officers, agents, and subcontractors) to you arising out of or in connection with this Agreement. Any reference to liability means any liability whether in contract, tort (including negligence), misrepresentation, breach of statutory duty, or otherwise.

11.2 We will perform the Services using reasonable skill and care in accordance with generally accepted cyber security advisory standards.

11.3 Nothing in these Terms excludes or limits our liability for: (a) death or personal injury caused by our negligence; or (b) fraud or fraudulent misrepresentation.

11.4 You acknowledge that: (a) the Services are advisory in nature and the implementation of any recommendation or guidance rests entirely with you; (b) we are a specialist advisory consultancy providing support based on the information you provide to us; (c) the Fees charged reflect the nature, scope, and risk profile of an advisory service; (d) you had the opportunity to seek independent advice before entering into this Agreement; and (e) you could have obtained similar services from alternative providers. You confirm that the limitations and exclusions of liability in this clause are reasonable in all the circumstances and represent a fair allocation of risk.

11.5 Subject to Clause 11.3, all warranties, representations, conditions, and other terms implied by statute or common law are, to the fullest extent permitted by law, excluded from this Agreement, including any implied warranties of merchantability, satisfactory quality, or fitness for a particular purpose. The Services and Deliverables are provided on an "as is" basis.

11.6 All Deliverables - including security policies, risk summaries, reports, and any written outputs - are prepared on the basis of the information you provide to us and are accurate only as at the date of preparation. They are advisory documents only and do not constitute legal, regulatory, compliance, financial, or technical implementation advice. You are responsible for reviewing all Deliverables before relying on or sharing them and for obtaining any specialist advice required to supplement them.

11.7 We shall have no liability to any third party to whom you disclose or share any Deliverable, including regulators, auditors, insurers, clients, or any other party. You may share Deliverables with third parties for your legitimate business purposes, provided you do not remove any disclaimers and you make recipients aware that the Deliverables are advisory documents prepared for your internal use. Third parties may not rely on any Deliverable as if it were prepared for them.

11.8 We shall have no liability for any loss, damage, or liability: (a) arising from information, data, or instructions you provide to us that are inaccurate, incomplete, or misleading; (b) arising from your failure to implement recommendations, policies, or remedial actions we provide; (c) arising from your failure to notify us of material changes to your organisation or IT environment; (d) arising from decisions you make based on our advisory guidance; or (e) arising from actions taken or not taken by your IT provider, MSP, or any third party.

11.9 We shall not be liable for any security breach, data loss, cyber attack, regulatory enforcement action, ICO fine, loss of certification, loss of contract or tender eligibility, or any other loss arising from your cyber security posture or incidents, regardless of whether we have provided advisory Services in relation to the relevant area.

11.10 Regulated sectors. Where you operate in a regulated sector - including but not limited to legal services, healthcare, education, financial services, or the MOD supply chain - you acknowledge that: (a) we are not an approved adviser, auditor, or compliance body for any regulatory framework applicable to your sector; (b) our advisory guidance does not constitute regulatory compliance advice and does not confirm or certify compliance with any regulatory obligation; (c) you remain solely responsible for your obligations under all applicable regulatory frameworks; and (d) you should seek sector-specific regulatory advice from an appropriately qualified and authorised adviser in your sector.

11.11 Fair and reasonable use. The email advisory channel and other advisory contact included in your Plan are intended for reasonable business-hours use in connection with your cyber security posture, certifications, and policies. You agree to use these channels in a reasonable manner consistent with the nature of your Plan. Where your use is, in our reasonable opinion, excessive or materially beyond what your Plan was designed to accommodate, we will notify you and may propose an upgrade or out-of-scope arrangement before additional advisory time is provided.

11.12 We maintain records of advice given under this Agreement, including the date, subject matter, and nature of guidance provided. In the event of any dispute about what was advised, when, or on what basis, our records shall be the primary reference. You are encouraged to maintain your own contemporaneous records of the advice you receive and the actions you take in response.

11.13 We shall not be liable for any loss of profits, loss of business, loss of opportunity, loss of contract, loss of data, depletion of goodwill, or any indirect, special, punitive, exemplary, or consequential loss or damage, howsoever arising, even if we have been advised of the possibility of such loss.

11.14 Our total aggregate liability to you arising out of or in connection with any one month's Services, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in all circumstances be limited to the total Fees paid by you in the three (3) months immediately preceding the event giving rise to the claim.

11.15 Your sole and exclusive remedy in respect of the Services is against Vincent Cyber Defence Limited in its corporate capacity. To the fullest extent permitted by law, we shall have no liability for any act, omission, negligence, error, or failure of any individual employee, officer, agent, or subcontractor engaged in connection with the Services.

11.16 Any legal action or claim arising under this Agreement must be commenced within 12 months of the date on which you first became aware (or ought reasonably to have become aware) of the act or omission giving rise to the claim. After this period, all claims are absolutely time-barred.

12. Your Indemnity to Us

12.1 You shall defend, indemnify, and hold harmless Vincent Cyber Defence Limited and its employees, officers, agents, and subcontractors against any and all claims, liabilities, losses, damages, expenses, and costs (including reasonable legal fees and enforcement costs) arising out of or in connection with:

  • Any inaccurate, incomplete, or misleading information you provide to us in connection with the Services, including information used to complete certification questionnaires or tender submissions.
  • Your failure to implement recommendations, policies, or remedial actions identified in the course of the Services.
  • Any third-party claim arising from your reliance on, use of, or implementation of any advice, guidance, or Deliverables we provide.
  • Any breach by you of applicable law, regulation, or industry standard in connection with your cyber security practices or the Services.
  • Any claim arising from your certification questionnaire submissions or tender responses that are completed using our advisory support.

13. Intellectual Property

13.1 We retain ownership of all Intellectual Property Rights in the Services, Deliverables, and all materials we create in connection with this Agreement, including security policy templates, frameworks, methodologies, tools, and report templates. Nothing in this Agreement transfers any Intellectual Property Rights from us to you.

13.2 Upon payment of Fees for the relevant month, we grant you a non-exclusive, non-sublicensable, non-transferable licence to use the Deliverables produced in that period for your reasonable internal business purposes only. This licence terminates on termination of the Agreement, subject to Clause 13.6.

13.3 Security policy documents and templates we produce for you under the Services are licensed for your internal use only. You may not share them with third parties as generic templates, sell them, or use them to provide services to others.

13.4 You own all rights in the information and materials you provide to us. You grant us a non-exclusive licence to use, review, and copy those materials to the extent necessary to perform the Services.

13.5 To the extent you provide any feedback or ideas regarding our methodologies, templates, or processes, you hereby assign all intellectual property rights in such feedback to us.

13.6 Post-termination policy use. On termination of this Agreement, we grant you a non-exclusive, perpetual, non-transferable licence to continue using the security policy documents we produced for you solely for your own internal operational purposes. This licence does not extend to any other Deliverables, does not permit sharing or onward use, and does not entitle you to receive updates, maintenance, or support in respect of those policies after termination.

14. Confidentiality

14.1 Each party agrees to keep confidential all technical, commercial, and business information disclosed by the other in connection with the Services, including your IT environment details, security findings, policy content, and business information.

14.2 Confidential Information shall not be disclosed to any third party without prior written consent, except to employees, contractors, professional advisers, or insurers bound by equivalent confidentiality obligations, or where disclosure is required by law.

14.3 This obligation does not apply to information that is publicly available (other than through breach), independently developed, or lawfully received from a third party.

14.4 These confidentiality obligations survive termination of this Agreement for five (5) years.

15. Data Protection

15.1 Both parties shall comply with all applicable data protection laws, including the UK GDPR and the Data Protection Act 2018. You are the Data Controller and we are the Data Processor in relation to any personal data processed in connection with the Services.

15.2 We will process personal data only on your documented instructions to perform the Services. All staff processing personal data are subject to confidentiality obligations and appropriate technical and organisational security measures.

15.3 We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of any personal data breach or significant security incident affecting your data held by us.

15.4 We will retain records of the Services, including Deliverables and correspondence, for 6 years following termination of this Agreement for legal, regulatory, and insurance purposes.

16. General

16.1 Governing Law & Jurisdiction. These Terms are governed by the laws of England and Wales. The parties irrevocably agree that the courts of England and Wales have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms, regardless of your country of residence, incorporation, or the location from which you access the Services.

16.2 Dispute Resolution. Before commencing court proceedings (except for urgent interim relief), the parties agree to first attempt good faith negotiation for 14 days, then mediation administered by the Centre for Effective Dispute Resolution (CEDR) for up to 30 days. If unresolved, either party may commence court proceedings.

16.3 Invoice Disputes. If you dispute any invoice, you must notify us in writing within 7 days of receipt, setting out the grounds and specific amount disputed. Failure to do so constitutes acceptance of the invoice. You must pay all undisputed amounts by the due date regardless of any dispute.

16.4 Variation. No variation to these Terms is effective unless agreed in writing and signed by both parties. We may update these Terms in accordance with Clause 2.5.

16.5 Entire Agreement. These Terms, together with your Order, constitute the entire agreement between us and supersede all prior arrangements, representations, or understandings. You confirm you have not relied on any representation or warranty not set out in these Terms.

16.6 Severability. If any provision is found unenforceable, the remaining provisions remain in full force.

16.7 Waiver. No failure or delay to exercise any right or remedy constitutes a waiver of that right or remedy.

16.8 Assignment. You may not assign or transfer your rights or obligations without our prior written consent. We may assign or transfer this Agreement at any time.

16.9 No Partnership. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties. We are an independent advisory contractor.

16.10 Third Party Rights. These Terms do not confer any rights on any third party. The Contracts (Rights of Third Parties) Act 1999 does not apply to this Agreement.

16.11 Notices. Any notice under these Terms must be in writing and sent by email to the address provided in your Order. Email notices are deemed received at 9am on the next Business Day following transmission.

16.12 Non-Solicitation. You agree not to solicit, hire, or engage any of our employees or contractors involved in your Services for 12 months following termination. If you breach this clause, you shall pay us a sum equal to 50% of that individual's annual gross salary or fees as liquidated damages.

16.13 Force Majeure. Neither party is liable for delays or failures caused by events beyond their reasonable control. If such an event continues for more than 30 days, either party may terminate on written notice. You remain liable for all Fees for Services already delivered up to the date of termination.

B. Acceptance

By placing an order, making payment, or confirming acceptance of these Terms in writing, you confirm that:

  1. You have read and understood these Terms and Conditions in full.
  2. You agree to be bound by these Terms.
  3. You have the authority to enter into this Agreement on behalf of your organisation.
  4. You understand that the Services are advisory in nature and that implementation of any recommendation is your responsibility.
  5. You understand that the vCISO plan monthly fee does not include certification or testing fees, which are billed separately.
  6. You understand that your plan has a 3-month minimum term, after which it rolls monthly with 30 days' notice to cancel.

We reserve the right to update these Terms at any time in accordance with Clause 2.5. The version in force at the date of your Order applies to that Order.

Vincent Cyber Defence Limited · Company No: 16335932 · Registered in England and Wales