We require every client to maintain a documented set of controls: phish-resistant MFA, application control, vulnerability management, awareness training, a password manager with SSO, HR-driven onboarding and offboarding, backups, and an incident response plan. These either run on our services or an equivalent from another provider. Where one genuinely does not fit how a business works, we agree an alternative with you and write it down.
Where the standard isn't met, everything else we do works less well and our exposure rises. We notify you in writing, give you 30 days to remedy or agree a plan, and can suspend or terminate if the gap becomes material. That isn't a penalty. We can't defend an environment that refuses to cover its own basics.
The controls are written out in full in our Managed IT Complete Service Terms.