Last updated: 23 July 2026. View change log.
This Schedule forms part of the IT Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”), and sets out the scope, responsibilities and limits that apply to Monitoring and Alerting.
Monitoring gives us continuous, or near-continuous, visibility of the health, performance and security of in-scope systems, using a mix of endpoint agents, cloud integrations and security tooling. It underpins day-to-day IT Support, but is separate from it.
Monitoring is an optional service. For you, its scope is limited to the systems and tenants included in your Order and onboarded into our tooling.
1. Service overview
Monitoring focuses on spotting issues early, so we can respond before they turn into incidents or outages. It covers:
- endpoint and server health monitoring;
- availability and performance checks on key services and infrastructure;
- security event, threat and anomaly detection across endpoints and SaaS platforms;
- alerting, triage and escalation to our support and security teams.
We usually deliver remediation of the issues Monitoring detects under other Schedules, such as IT Support, Patch Management, Backup and Recovery or Security Services, depending on the nature of the issue.
2. Service components and tooling
Monitoring typically uses the following tools and integrations (which may evolve over time as the service improves):
- Remote monitoring and management (RMM) – agent-based health and performance monitoring for supported endpoints and servers.
- Endpoint Detection and Response (EDR) – endpoint threat detection, security telemetry and response capabilities for supported devices.
- Hosting security controls – malware scanning and web application firewalling for supported hosting environments (including Cultrix Cloud where applicable).
- Vulnerability scanning – vulnerability scanning and reporting across supported Windows and Linux systems.
- SaaS monitoring – monitoring of supported SaaS platforms (such as Microsoft 365 or Google Workspace) for suspicious activity, misconfigurations and risky behaviour.
- Security information and event management (SIEM) – centralised ingestion, correlation and analysis of security logs and events.
- Security operations centre (SOC) – 24/7 monitoring of security alerts, with triage and escalation where included.
- Security validation testing – periodic testing to check how well the security controls in place are working, where included.
We may refine or extend this tooling stack over time as vendors, best practice and services evolve. Those changes will not usually need an update to this Schedule.
3. Scope of monitoring
The scope of Monitoring is set by what we bring under management in the monitoring tooling and by your Order. It typically includes some or all of:
- Endpoints and servers where monitoring and/or security agents are deployed and reporting correctly;
- Supported hosting infrastructure protected by hosting security controls and onboarded into monitoring;
- Remote desktop or hosted environments covered under your service package and onboarded into monitoring;
- Cloud productivity tenants (such as Microsoft 365 or Google Workspace) linked into SaaS monitoring and security integrations;
- Other supported SaaS platforms that are onboarded to the Monitoring service;
- Security logs and events ingested into the security monitoring platform for correlation and review.
Systems, tenants or environments that are not onboarded into the Monitoring tooling, or where agents are missing or offline, are out of scope until we bring them under management.
4. Monitoring activities
Depending on your package and onboarding, Monitoring may include:
- agent heartbeat and service availability checks on managed devices;
- disk, CPU, memory and key service monitoring on servers and critical endpoints;
- alerting on backup job failures (where we provide backup services);
- scheduling vulnerability scans and reviewing the results;
- security event correlation and threat detection across endpoints and SaaS platforms;
- automated or semi-automated responses where the tooling supports them (for example isolating an endpoint);
- regular review of high-risk alerts and trends with the RocketCyber SOC.
5. Alert handling, triage and escalation
Monitoring generates alerts that we triage and, where appropriate, escalate for further action. In general:
- our support team reviews routine health alerts, which may lead to a support ticket where appropriate;
- security alerts are ingested into the security monitoring platform for prioritisation and correlation with other events;
- we escalate high-severity security events to Support and/or your nominated contacts in line with our Incident Response Procedure.
Where a managed security operations service is included, we may review security alerts on a 24/7 basis for rapid triage and escalation.
How we classify alerts, and the actions we take in response, follow our internal incident response procedures. Response times for tickets raised from Monitoring are governed by our support prioritisation and target times, not by the timestamp of the originating monitoring alert.
6. Service boundaries and exclusions
Monitoring focuses on detection and alerting, not on full-service remediation of every issue. In particular, Monitoring does not include, unless we agree it in another Schedule or Order:
- guaranteed detection of every possible security threat, misconfiguration or performance issue;
- guaranteed prevention of malware, ransomware or other attacks;
- complete coverage of systems where agents cannot be installed or are repeatedly removed or disabled;
- management of third-party monitoring tools or dashboards outside the agreed stack;
- remediation work that falls under IT Support, Patch Management, Backup and Recovery, projects or consultancy.
Some alerts are low-risk, informational or transient, and will not always lead to a ticket or a specific message to you.
7. Customer responsibilities
To keep Monitoring effective, you must:
- allow us to install and run the necessary monitoring and security agents on in-scope devices and systems;
- keep devices powered on and able to communicate with our tooling during agreed monitoring windows;
- tell us in advance about planned changes that may affect monitoring (for example outages, migrations or major reconfigurations);
- tell us promptly if you think a system, tenant or environment has not been onboarded correctly.
8. Dependencies on third parties
Monitoring relies on:
- the availability and performance of the monitored systems and networks;
- the availability of third-party monitoring, security and management platforms;
- the quality and timeliness of the logs and telemetry the monitored systems and services produce.
Failures or limitations in third-party platforms may temporarily affect monitoring coverage. We will act reasonably to work with the relevant suppliers and restore functionality where we can.
9. Changes to this Schedule
We may update this Schedule to reflect changes in monitoring tools, best practice or the services we offer. We will publish updated versions on our website and, for material changes, give reasonable notice.
Note: Monitoring and Alerting focuses on detection, alerting and escalation. We deliver remediation and threat-response work under the applicable Support, Patch Management, Endpoint Protection or other relevant Schedule.