Cultrix logo
Menu
    • Call us: 0330 333 5790
      • General: 0330 333 5790
      • Accounts: 0330 333 5791
      • Sales: 0330 333 5793
      • Service desk: 0330 333 5794
      • Web team: 0330 333 5792
  • Login
  • Home
  • About us+
    • Our story
    • Brand values
    • Meet the team+
      • Recruitment
    • Case studies
    • Giving back
    • News
  • IT support
  • IT services+
    • Consultancy+
      • System audit
      • Strategy
      • Troubleshooting
      • Business continuity
    • Disaster recovery+
      • Emergency server support
      • Viruses, spyware and malware
      • Computer repair
      • Data recovery
    • Supply and install+
      • Hardware, software and licensing
      • Networking and servers
      • Broadband
      • VOIP
      • CCTV
      • Power
      • Audio visual
    • Migrations
    • Relocations
    • Cybersecurity+
      • Cyber Essentials
      • Antivirus
      • Spam filtering
      • Backup
      • Content filtering and user monitoring
      • Bring Your Own Device
      • Mobile device management
      • Vulnerability audit
      • Penetration testing
      • Compliance
    • Training+
      • Floor walking
      • Cultrix appearances
      • Security awareness training
  • Cloud+
    • Virtual desktops and servers
    • Microsoft Office 365
    • Google Workspace
    • Microsoft Azure
    • Amazon Web Services
    • Backup for cloud
    • Hosting
  • Web services+
    • Startup holding page
    • Build-A-Website workshop™
    • Custom website builds+
      • Consultancy
      • Template design and build
      • Landing pages and micro sites
      • Development workshops
      • Integrations
      • Smartphone apps
    • Content creation+
      • Copywriting
      • Photography and illustration
      • Video and animation
    • Website marketing services+
      • Search Engine Optimisation
      • Social channel creation
      • Social media management
      • Chatbots
      • PPC and remarketing
      • Email marketing
    • Website support services+
      • Maintenance and support
      • Vulnerability scanning
      • Security
      • Troubleshooting
      • Sanitisation
      • Optimisation
      • Quality scanning
      • Transfers
    • Hosting+
      • Shared
      • Dedicated servers
      • SSL Certificates
  • Partners+
    • Resellers
    • White label partners+
      • Outsourced service desk
      • IT Services
      • Web services
      • Cloud
      • Hosting
      • White label admin extras+
        • White label sales admin
        • White label accounts
        • White label complaints handling
    • Field technicians
    • Strategic partnerships
    • Business handovers
  • Contact us+
    • General: 0330 333 5790
    • Accounts: 0330 333 5791
    • Sales: 0330 333 5793
    • Service desk: 0330 333 5794
    • Web team: 0330 333 5792
  • Login

Annex C - Shared Responsibility Model

  • Master Services Agreement – IT Services
  • Schedule 1 – IT Support Services
  • Schedule 2 – Patch Management Services
  • Schedule 3 - Monitoring and Alerting
  • Schedule 4 - Cloud Productivity Platform Administration and Licensing
  • Schedule 5 - Backup and Recovery Services
  • Schedule 6 - Endpoint Protection and Security Services
  • Annex A - Service Level Agreement (SLA)
  • Annex B - Acceptable Use Policy (AUP)
  • Annex C - Shared Responsibility Model
  • Annex D - Fair Use Policy (FUP)
  • Legal >
  • Terms >
  • Master Services Agreement – IT Services >
  • Annex C - Shared Responsibility Model

Last updated: 23 July 2026. View change log.

This Annex forms part of the IT Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”), and sets out the scope, responsibilities and limits that apply to the Shared Responsibility Model.

The aim of this Annex is to make clear who does what, so there are no gaps or assumptions, particularly around security, backup and business continuity. Not every responsibility listed here will apply to you; what applies in practice depends on the Services included in your Order.

1. Principles

The Shared Responsibility Model is based on these principles:

  • we are responsible for the design, delivery and management of the Services you have ordered from us;
  • you remain responsible for your business processes, how you classify data, and how your users use technology;
  • some responsibilities are shared – for example, keeping devices secure needs both technical controls and good user behaviour;
  • if a Service is not in your Order, you remain fully responsible for that area unless we agree otherwise in writing.

2. High-level responsibility overview

At a high level:

  • We are generally responsible for:
    • managing in-scope devices, systems, platforms and security tools under your Order;
    • deploying and maintaining agreed configurations, updates and security policies;
    • monitoring and responding to alerts where monitoring or SOC services are in place;
    • giving advice and guidance on good practice.
  • You are generally responsible for:
    • deciding which Services to buy and making sure they stay appropriate to your risk profile;
    • how your staff, contractors and partners use systems and data;
    • internal HR, disciplinary and compliance processes;
    • meeting regulatory obligations that go beyond the scope of the Services.
  • Shared responsibilities include:
    • keeping information up to date (for example joiners/leavers, or changes to locations or systems);
    • putting recommended controls in place where reasonable;
    • responding promptly to incidents and following agreed procedures.

Administrative access and customer responsibility

Where you or your staff are granted administrative or elevated permissions, you accept responsibility for any changes made using them. We are not responsible for service interruptions, misconfiguration or data loss that result from administrative actions you initiate. Any remediation needed is handled as chargeable consultancy.

We may recommend limiting or removing administrative privileges where repeated incidents arise from misuse.

3. Devices and endpoints

Where we provide endpoint management, patching or security services under your Order:

  • Our responsibilities typically include:
    • installing and managing agreed agents (for example RMM, antivirus or EDR);
    • configuring and maintaining patch policies for supported operating systems and software;
    • deploying security policies and controls where packages such as Support + Shield or Guardian are in place;
    • monitoring device health and security where Monitoring or Endpoint Protection is included.
  • Your responsibilities typically include:
    • making sure users do not tamper with, disable or remove agents and security controls;
    • keeping devices physically secure and reporting lost or stolen devices promptly;
    • not assuming that unsupported or unmanaged devices are covered by us;
    • deciding which devices are in scope for management under your Order.

4. Cloud services (Microsoft 365, Google Workspace and others)

Where we provide administration or security services for cloud platforms under your Order:

  • Our responsibilities typically include:
    • configuring and maintaining agreed tenant-level settings and security policies;
    • setting up and managing users, groups and licences as your authorised contacts request;
    • linking supported tenants into monitoring, backup and security platforms;
    • giving guidance on secure configuration and best practice.
  • Your responsibilities typically include:
    • making sure only authorised users have accounts, and reporting leavers promptly;
    • deciding which data is stored in which cloud services and how it is structured;
    • making sure users follow acceptable use, data protection and information handling policies;
    • buying and maintaining the necessary licences through your chosen licensing provider.

5. Backup and recovery

Where Backup and Recovery Services are included in your Order:

  • Our responsibilities typically include:
    • configuring and monitoring agreed backup jobs for in-scope systems and data;
    • working with you to restore data or systems when you request it via the Service Desk;
    • maintaining documented backup schedules and retention settings in line with the Service description;
    • escalating backup failures and issues to you where they need your action.
  • Your responsibilities typically include:
    • defining which systems, folders and data should be in backup scope;
    • making sure critical data is stored in locations covered by backup services;
    • reviewing backup summaries or reports where we provide them, and raising concerns promptly;
    • requesting restore tests or DR tests where your risk appetite requires them.

Where you choose not to buy a particular backup or continuity service, you remain responsible for any data or systems not covered by another backup solution.

6. Security and incident response

Where Endpoint Protection, User Protection or other security services are included in your Order:

  • Our responsibilities typically include:
    • deploying and managing agreed security tools (for example antivirus, EDR, email security or Dark Web monitoring);
    • monitoring alerts and, where SOC services are in place, escalating threats in line with the Incident Response Policy;
    • giving guidance on remediation steps and helping to contain incidents;
    • keeping security tools up to date within the capabilities of vendors and platforms.
  • Your responsibilities typically include:
    • making sure users follow the Acceptable Use Policy and complete awareness training where provided;
    • reporting suspected incidents, phishing attempts or unusual activity promptly;
    • putting recommended process or policy changes in place to reduce risk;
    • making risk-based decisions where you choose not to follow certain recommendations.

7. Compliance and regulatory obligations

Our Services can help with aspects of regulatory compliance (for example by providing logs, security controls and documentation). However:

  • we are not your legal or compliance adviser, and we do not guarantee regulatory compliance;
  • you are responsible for understanding and meeting your own legal, regulatory and contractual obligations;
  • where you have specific compliance frameworks (for example Cyber Essentials, ISO 27001, PCI DSS or DORA), you are responsible for identifying the requirements and requesting the appropriate Services or advice.

8. Customer choices and risk acceptance

You may decide not to buy certain Services, to limit the scope of coverage, or to delay recommended changes. Where this happens:

  • we will explain, where reasonably possible, the associated risks and potential impact;
  • you are responsible for accepting those risks and documenting them internally if you need to;
  • we will not be responsible for outcomes that arise from Services or controls you have chosen not to adopt.

9. Changes to this Annex

We may update this Shared Responsibility Model to reflect changes in the Services, best practice or roles and responsibilities. We will publish updated versions on our website and, for material changes, give reasonable notice.

Contact us

  • Get a call back
  • New Supplier
  • Setup a Direct Debit
  • Tel: 0330 333 5790
  • Email: ITexperts@cultrix.co.uk
  • Location pin
  • Facebook logo
  • Instagram logo
  • LinkedIn logo
  • Medium logo
  • Pinterest logo
  • Twitter logo
  • YouTube logo

What we do

  • Backup
  • Business continuity
  • Cloud
  • Consultancy
  • Disaster recovery
  • G Suite
  • Hosting
  • IT support
  • Microsoft Office 365
  • Security
  • Supply and install
  • System audit
  • White label IT services
  • White label product support
  • White label Service desk
  • White label support on-demand

IT support

  • Announcements
  • Service status
  • Login
  • IT Academy
  • Web Academy
  • Legal
  • Privacy and cookies
  • GDPR
  • DPA
  • Infrastructure

© Cultrix Limited 2026. All rights reserved.

All calls to and from Cultrix HQ are recorded to help us with staff training, as well as for our own monitoring and customer quality assurance purposes.

Cultrix Limited is a company registered in England and Wales with company number 4556716 and VAT number 804568131.

Cultrix and Cultrix Digital are trading names of Cultrix Limited.

  • IT support locations+
    • IT support East Midlands+
      • IT support Chesterfield
      • IT support Derbyshire
      • IT support Mansfield
      • IT support Northampton
      • IT support Nottingham
    • IT support London
    • IT support North West+
      • IT support Manchester
    • IT support Yorkshire+
      • IT support East Yorkshire
      • IT support North Yorkshire+
        • IT support York
      • IT support South Yorkshire+
        • IT support Barnsley
        • IT support Doncaster
        • IT support Rotherham
        • IT support Sheffield
      • IT support West Yorkshire+
        • IT support Castleford
        • IT support Featherstone
        • IT support Huddersfield
        • IT support Leeds
        • IT support Normanton
        • IT support Pontefract
        • IT support Wakefield
  • IT support specialisms+
    • Charity IT support
    • Multi-office IT support
    • PAYG/On-demand IT support
    • Remote IT management
    • Remote IT support
    • Tenant IT support
    • White Label IT support
  • Move to Cultrix

This website uses cookies, if you'd like to know more about these cookies here's our cookie policy.Close