POLICIES & ENGAGEMENT
Client Engagement Terms
The framework for agreeing cybersecurity consulting work.
Agreement before work
These published terms explain our engagement process. They become contractual terms only if expressly incorporated into an accepted written agreement. Browsing this page or sending an enquiry does not create a contract. The engagement identifies the legal entities, authorised contacts and any order of precedence between the proposal, statement of work and other documents.
Scope and deliverables
The statement of work records systems, exclusions, objectives, methods, milestones, deliverables and acceptance criteria. Testing requires separate rules of engagement where appropriate. Neither party should assume that monitoring, remediation, retesting or ongoing support is included unless documented.
Access and client dependencies
The client arranges lawful access, third-party permissions, accurate system information and a decision-maker for approvals. Both parties agree secure channels and minimum access. Credentials should be shared through an approved mechanism and revoked when no longer needed. Material access restrictions or delays should be discussed promptly, with schedule effects documented.
Fees and changes
The proposal records fees, GST treatment, payment dates, authorised expenses and billing milestones. No fee schedule or cancellation charge is imposed by this page. Scope, pricing and timing changes require recorded agreement before additional work proceeds, except actions already authorised under an incident response arrangement.
Confidentiality and information handling
The engagement defines confidentiality duties for both parties, permitted recipients, subcontractor involvement and lawful disclosure exceptions. It also records evidence collection, location, encryption, retention, return or deletion and breach escalation. Public use of a client name, logo or report requires permission.
Ownership and permitted reliance
Agree intellectual-property ownership and licences before work, including client inputs, reusable tools and third-party materials. Reports identify their intended audience and purpose. Sharing with advisers, insurers or regulators should be addressed expressly without limiting mandatory legal disclosure rights.
Delivery, suspension and termination
Agree how deliverables are reviewed and concerns resolved, with reasonable opportunities to clarify or correct deficiencies. Suspension and termination conditions should address serious breach, unsafe or unauthorised testing, payment disputes and orderly handover. Notice, remedy periods and any charges must be fair and documented, not assumed from this page.
Liability, disputes and governing law
Any liability allocation, insurance requirement or limitation must be expressly agreed, proportionate and consistent with mandatory law. Nothing excludes non-excludable consumer guarantees or other rights. Identify a practical dispute escalation process, governing law and jurisdiction in the signed engagement; no arbitrary liability cap or state jurisdiction is imposed here.
Starting an engagement
Contact [email protected] to discuss objectives and obtain a written proposal. Confirm the entity details, scope, privacy arrangements and commercial terms before authorising work. The general Disclaimer, Consulting Disclaimer and Privacy Policy provide context but do not replace the negotiated agreement.
Australian context: ACCC consumer guarantees and ACCC contract guidance. Sources checked 11 October 2026. Applicability depends on the transaction and organisation.
