CYBERSECURITY ADDENDUM


Effective as of April 11, 2024 (Version Number: 45393)




All terms not defined herein shall have the meaning ascribed to them in the DAS Standard Incorporated Terms and Conditions.

Cybersecurity Bundled Packages: All services within the applicable Cybersecurity Bundled Package will be offered to Client upon purchasing, Client retains the right to decline or delay implementation of any specific service due to business needs, however, payment will not be adjusted or prorated to accommodate any of those delays or declination to implement a particular included service, and Client accepts all risk for any such delay or declination. Cybersecurity is NOT included with any other service unless one of the following services is specifically purchased on a COF, in which case DAS will use reasonable commercial efforts to provide the purchased service.

  1. Managed Security Essentials incudes:
    1. Enterprise Grade Endpoint Detection and Response (EDR)
    2. Extended Detection and Response (XDR)
    3. Anti-Ransomware, Deep Learning Technology, Exploit Prevention, Managed Threat Response, and Active Adversary Mitigations
    4. Discounted Standard Cybersecurity Hourly Support such as: assistance with completing Cybersecurity Insurance, NIST or PCI Compliance Questionnaires
  2. Managed Security Advanced incudes:
    1. Managed Security Essentials plus
    2. Annual Advanced Technical Security Audit
    3. HIPAA Security Risk Analysis (Healthcare Clients Only)
    4. Security Awareness Training (Annual and Micro)
    5. Email Phishing Campaigns
    6. Dark Web Scanning
    7. Standard Cybersecurity Support which includes assistance with completing Cybersecurity Insurance, NIST or PCI Compliance Questionnaires (up to 2 hours per month, per practice) Advanced notice must be provided and work to be completed within 2 weeks of the original request.
  3. Managed Security Complete includes:
    1. Managed Security Advanced plus
    2. Virtual CISO Services which includes priority assistance with Board Meetings, Tabletop Exercises, Policy and Procedure Review (up to 1 hour per month, per practice). Advanced notice must be provided and work to be completed within 2 weeks of the original request.
    3. MFA App (Tokens must be purchased separately)
    4. On-going Vulnerability and Compliance Management with Annual Penetration Test
    5. Protective DNS
    6. SOC Services
      1. Pricing for Cybersecurity “Managed Security Essentials” purchased prior to April 10th, 2024, is charged on a per Device basis and will be retroactively increased based on actual managed Devices included for any portion of a calendar month. Retroactive adjustments will not exceed three (3) months.
      2. Pricing for Cybersecurity “Managed Security Advance”, “Managed Security Complete”, and pricing for “Managed Security Essentials” purchased on or after April 10th, 2024, is charged on a per User basis and will be retroactively increased based on actual managed Users included for any portion of a calendar month. Retroactive adjustments will not exceed three (3) months.

Unless otherwise specifically contracted, the Cybersecurity Bundled Package does not cover the Client website.