Last updated: 23 July 2026. View change log.
This Annex forms part of the IT Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”), and sets out the scope, responsibilities and limits that apply to the Shared Responsibility Model.
The aim of this Annex is to make clear who does what, so there are no gaps or assumptions, particularly around security, backup and business continuity. Not every responsibility listed here will apply to you; what applies in practice depends on the Services included in your Order.
1. Principles
The Shared Responsibility Model is based on these principles:
- we are responsible for the design, delivery and management of the Services you have ordered from us;
- you remain responsible for your business processes, how you classify data, and how your users use technology;
- some responsibilities are shared – for example, keeping devices secure needs both technical controls and good user behaviour;
- if a Service is not in your Order, you remain fully responsible for that area unless we agree otherwise in writing.
2. High-level responsibility overview
At a high level:
- We are generally responsible for:
- managing in-scope devices, systems, platforms and security tools under your Order;
- deploying and maintaining agreed configurations, updates and security policies;
- monitoring and responding to alerts where monitoring or SOC services are in place;
- giving advice and guidance on good practice.
- You are generally responsible for:
- deciding which Services to buy and making sure they stay appropriate to your risk profile;
- how your staff, contractors and partners use systems and data;
- internal HR, disciplinary and compliance processes;
- meeting regulatory obligations that go beyond the scope of the Services.
- Shared responsibilities include:
- keeping information up to date (for example joiners/leavers, or changes to locations or systems);
- putting recommended controls in place where reasonable;
- responding promptly to incidents and following agreed procedures.
Administrative access and customer responsibility
Where you or your staff are granted administrative or elevated permissions, you accept responsibility for any changes made using them. We are not responsible for service interruptions, misconfiguration or data loss that result from administrative actions you initiate. Any remediation needed is handled as chargeable consultancy.
We may recommend limiting or removing administrative privileges where repeated incidents arise from misuse.
3. Devices and endpoints
Where we provide endpoint management, patching or security services under your Order:
- Our responsibilities typically include:
- installing and managing agreed agents (for example RMM, antivirus or EDR);
- configuring and maintaining patch policies for supported operating systems and software;
- deploying security policies and controls where packages such as Support + Shield or Guardian are in place;
- monitoring device health and security where Monitoring or Endpoint Protection is included.
- Your responsibilities typically include:
- making sure users do not tamper with, disable or remove agents and security controls;
- keeping devices physically secure and reporting lost or stolen devices promptly;
- not assuming that unsupported or unmanaged devices are covered by us;
- deciding which devices are in scope for management under your Order.
4. Cloud services (Microsoft 365, Google Workspace and others)
Where we provide administration or security services for cloud platforms under your Order:
- Our responsibilities typically include:
- configuring and maintaining agreed tenant-level settings and security policies;
- setting up and managing users, groups and licences as your authorised contacts request;
- linking supported tenants into monitoring, backup and security platforms;
- giving guidance on secure configuration and best practice.
- Your responsibilities typically include:
- making sure only authorised users have accounts, and reporting leavers promptly;
- deciding which data is stored in which cloud services and how it is structured;
- making sure users follow acceptable use, data protection and information handling policies;
- buying and maintaining the necessary licences through your chosen licensing provider.
5. Backup and recovery
Where Backup and Recovery Services are included in your Order:
- Our responsibilities typically include:
- configuring and monitoring agreed backup jobs for in-scope systems and data;
- working with you to restore data or systems when you request it via the Service Desk;
- maintaining documented backup schedules and retention settings in line with the Service description;
- escalating backup failures and issues to you where they need your action.
- Your responsibilities typically include:
- defining which systems, folders and data should be in backup scope;
- making sure critical data is stored in locations covered by backup services;
- reviewing backup summaries or reports where we provide them, and raising concerns promptly;
- requesting restore tests or DR tests where your risk appetite requires them.
Where you choose not to buy a particular backup or continuity service, you remain responsible for any data or systems not covered by another backup solution.
6. Security and incident response
Where Endpoint Protection, User Protection or other security services are included in your Order:
- Our responsibilities typically include:
- deploying and managing agreed security tools (for example antivirus, EDR, email security or Dark Web monitoring);
- monitoring alerts and, where SOC services are in place, escalating threats in line with the Incident Response Policy;
- giving guidance on remediation steps and helping to contain incidents;
- keeping security tools up to date within the capabilities of vendors and platforms.
- Your responsibilities typically include:
- making sure users follow the Acceptable Use Policy and complete awareness training where provided;
- reporting suspected incidents, phishing attempts or unusual activity promptly;
- putting recommended process or policy changes in place to reduce risk;
- making risk-based decisions where you choose not to follow certain recommendations.
7. Compliance and regulatory obligations
Our Services can help with aspects of regulatory compliance (for example by providing logs, security controls and documentation). However:
- we are not your legal or compliance adviser, and we do not guarantee regulatory compliance;
- you are responsible for understanding and meeting your own legal, regulatory and contractual obligations;
- where you have specific compliance frameworks (for example Cyber Essentials, ISO 27001, PCI DSS or DORA), you are responsible for identifying the requirements and requesting the appropriate Services or advice.
8. Customer choices and risk acceptance
You may decide not to buy certain Services, to limit the scope of coverage, or to delay recommended changes. Where this happens:
- we will explain, where reasonably possible, the associated risks and potential impact;
- you are responsible for accepting those risks and documenting them internally if you need to;
- we will not be responsible for outcomes that arise from Services or controls you have chosen not to adopt.
9. Changes to this Annex
We may update this Shared Responsibility Model to reflect changes in the Services, best practice or roles and responsibilities. We will publish updated versions on our website and, for material changes, give reasonable notice.