Last updated: 23 July 2026. View change log.
This Schedule sets out the minimum security and technical standards that apply to services delivered under the Partner Agreement. It applies to all partners and all services unless a Partner Order expressly states otherwise.
1. Shared Responsibility and Scope
- Security is a shared responsibility between us, you and, where applicable, the End Customer.
- We are responsible for operating and maintaining the security of the infrastructure, platforms and services we are expressly contracted to manage, in accordance with the applicable service descriptions and schedules.
- Where security, backup or monitoring services are not included in the applicable Partner Order, we do not take responsibility for securing the End Customer’s wider environment, but we may provide advice, recommendations and warnings as part of support activities.
- We are responsible for assessing the security posture of systems and services we manage, and for advising on reasonable remediation steps where risks, unsupported systems or end-of-life components are identified.
- We may communicate these recommendations directly to the End Customer and/or to you for onward communication, as agreed operationally.
- You are responsible for facilitating communication between us and the End Customer where required, but you do not warrant or guarantee that End Customers will implement recommended actions.
- Where recommended actions are not implemented, we may continue to provide support on a best-efforts basis, apply risk-based limitations, or formally record acceptance of risk.
2. Supported and Unsupported Environments
- We support only systems, software and platforms that are within vendor support lifecycles.
- Unsupported or end-of-life systems may be:
- supported on a best-efforts basis only;
- subject to risk-based limitations;
- excluded from certain services; or
- subject to additional charges.
- We may require remediation or upgrades as a condition of onboarding or continued service delivery.
3. Identity and Access Management
- User access should follow least-privilege principles.
- Multi-factor authentication should be enabled where supported by the platform or service.
- Shared accounts should be avoided wherever reasonably practicable.
- You or the End Customer are responsible for timely onboarding, modification and removal of user access.
4. Endpoint and Device Security
- Endpoints accessing managed services should:
- run supported operating systems;
- receive security updates and patches;
- use appropriate endpoint protection where included in scope; and
- be configured in line with reasonable security baselines.
- Personally owned devices may be restricted or excluded where they present elevated risk.
5. Patch Management and Updates
- We apply patches and updates to systems we manage in accordance with applicable schedules.
- You or the End Customer are responsible for patching systems we do not manage.
- Critical updates may be applied outside normal maintenance windows where required to address active threats.
6. Backup, Recovery and Resilience
- We provide backup and recovery services only where they are expressly included in a service description or Partner Order.
- We do not guarantee recovery of data where backups are not in place, are misconfigured, or fall outside agreed scope.
- You and the End Customer remain responsible for deciding on appropriate data protection and retention strategies.
7. Monitoring, Logging and Alerting
- We may monitor systems and services we manage for availability, performance and security where this is included in scope.
- Monitoring scope and alerting thresholds depend on the services and schedules in place.
- Monitoring does not guarantee detection of all incidents or threats.
8. Vulnerabilities and Risk Management
- We may identify vulnerabilities or security risks during service delivery.
- Where we identify a material risk, we may recommend remediation steps.
- If recommended actions are not taken, we may limit support, adjust service scope, or require formal risk acceptance.
9. Acceptable Use
- Services must not be used for unlawful, abusive or malicious purposes.
- We may suspend services where misuse or unacceptable risk is identified.
- Additional acceptable use requirements may be set out in applicable policies or annexes.
10. Incident Response
- We handle security incidents in accordance with applicable support and incident response schedules.
- You or the End Customer must notify us promptly of any suspected security incidents affecting managed services.
- Incident response does not guarantee prevention of loss or damage.
11. Suspension for Security Reasons
- We may suspend or restrict services where necessary to:
- protect systems, data or other customers;
- comply with legal or regulatory obligations; or
- address imminent security threats.
- Where practical, we will tell you and work towards restoration.
12. Order of Priority
- If there is a conflict between this Schedule and the Partner Agreement, this Schedule prevails for security and technical standards.
- If there is a conflict between this Schedule and a Partner Order, the Partner Order prevails.