The following are the Service Level Agreements for Netrix Global managed services. Select a service category to view its SLA details, priority definitions, and credit terms.
Priorities are defined by the following definitions and matrix.
This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions are as follows:
This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions are as follows:
The following matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.
| Urgency | 1 – Widespread | 2 – Significant | 3 – Moderate | 4 – Localized |
|---|---|---|---|---|
| CRITICAL | P1 | P1 | P2 | P2 |
| HIGH | P1 | P2 | P2 | P3 |
| MEDIUM | P2 | P3 | P3 | P3 |
| LOW | P4 | P4 | P4 | P4 |
The following table provides target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.
| Severity / Priority | Time to Acknowledge | Time to Respond |
|---|---|---|
| Critical / P1 | 30 Minutes | 30 Minutes |
| High / P2 | 1 Hour | 1 Hour |
| Medium / P3 | 4 Hours | 4 Hours |
| Low / P4 | 12 Hours | 12 Hours |
If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.
| Severity / Priority | Acknowledge Credit per Violation | Respond Credit per Violation | SLA Target |
|---|---|---|---|
| Critical / P1 | 3% | 5% | 90% |
| High / P2 | 2% | 3% | 90% |
| Medium / P3 | 1% | 1% | 90% |
| Low / P4 | 0.5% | 0.5% | 90% |
No credits will be issued for any SLA failure resulting from:
Approved credits will be applied to the Client’s subsequent monthly invoice.
Priorities are defined by the following definitions and matrix.
This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions are as follows:
This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions are as follows:
The following matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.
| Urgency | 1 – Widespread | 2 – Significant | 3 – Moderate | 4 – Localized |
|---|---|---|---|---|
| CRITICAL | P1 | P1 | P2 | P2 |
| HIGH | P1 | P2 | P2 | P3 |
| MEDIUM | P2 | P3 | P3 | P3 |
| LOW | P4 | P4 | P4 | P4 |
The following table provides target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.
| Severity / Priority | Time to Acknowledge | Time to Respond |
|---|---|---|
| Critical / P1 | 30 Minutes | 30 Minutes |
| High / P2 | 1 Hour | 1 Hour |
| Medium / P3 | 4 Hours | 4 Hours |
| Low / P4 | 12 Hours | 12 Hours |
If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.
| Severity / Priority | Acknowledge Credit per Violation | Respond Credit per Violation | SLA Target |
|---|---|---|---|
| Critical / P1 | 3% | 5% | 90% |
| High / P2 | 2% | 3% | 90% |
| Medium / P3 | 1% | 1% | 90% |
| Low / P4 | 0.5% | 0.5% | 90% |
No credits will be issued for any SLA failure resulting from:
Approved credits will be applied to the Client’s subsequent monthly invoice.
Netrix SOC analysts will initially assess the validity of a security alert based on the information provided by the Netrix MDR platform. This includes:
Priorities are defined by the following definitions and matrix.
This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions as follows:
This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions as follows:
The follow matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.
| Urgency | 1 – Widespread | 2 – Significant | 3 – Moderate | 4 – Localized |
|---|---|---|---|---|
| CRITICAL | P1 | P1 | P2 | P2 |
| HIGH | P1 | P2 | P2 | P3 |
| MEDIUM | P2 | P3 | P3 | P3 |
| LOW | P4 | P4 | P4 | P4 |
Effective escalation procedures are critical to promote timely and appropriate responses to security incidents and service-related issues.
Escalations will be communicated through the channels defined during onboarding. This may include:
The systems of record for incident tracking and communication will be established during onboarding to optimize clear documentation and accountability.
The following definitions apply with respect to the scope of incident response activities included within the base Netrix MDR service versus incident response services that are applicable to a Netrix FIRE retainer or response engagement:
Initial incident response encompasses activities that the Netrix SOC will conduct as part of standard incident triage including manual investigation and actions that Netrix can execute through automated response capabilities within the SIEM platform (e.g., SOAR playbook actions such as account disablement or device isolation). Initial incident response also includes client escalations where a more detailed incident review is warranted, limited to four (4) hours per request, unless otherwise communicated to the Client during an escalation. These activities are performed as part of the standard MDR service at no additional charge to the Client. Examples include: Initial Evidence gathering from SIEM and integrated log sources, automated actions triggered by SOAR playbooks, alert triage and validation by Netrix SOC analysts and escalated investigations by Netrix Security engineers.
When an escalated incident requires sustained investigation, exceeding four (4) cumulative hours of analyst/engineer effort beyond initial triage, the engagement can be transitioned to a Client contracted FIRE retainer if previously contracted in a Netrix statement of work, or a Netrix FIRE response engagement in a new statement of work. Should the client already have a FIRE engagement contracted, the Client will be notified prior to FIRE hours being consumed.
The following tables provide target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.
| Netrix MDR Alert Priority | Initial Time to Acknowledge SLA |
|---|---|
| Critical | 30 Minutes |
| High | 1 Hour |
| Medium | 4 Hours |
| Low | 8 Hours |
| Priority Level | Time to Respond SLA |
|---|---|
| P1 (Priority 1) | 30 minutes |
| P2 (Priority 2) | 1 hour |
| P3 (Priority 3) | 4 hours |
| P4 (Priority 4) | 12 hours |
If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.
| Netrix MDR Alert Priority | Percentage Credit per Violation | SLA Target |
|---|---|---|
| High | 5% | 90% |
| Medium | 3% | 90% |
| Low | 2% | 90% |
| Priority Level | Percentage Credit per Violation | SLA Target |
|---|---|---|
| P1 (Priority 1) | 5% | 90% resolution |
| P2 (Priority 2) | 3% | 90% resolution |
| P3 (Priority 3) | 1% | 90% resolution |
| P4 (Priority 4) | 24 hours | 90% resolution |
No credits will be issued for any SLA failure resulting from:
Approved credits will be applied to the Client’s subsequent monthly invoice.
Time to review and notify Client, or closure of an alert upon finding of a false positive:
| Priority | Review & Notify |
|---|---|
| P1 (Critical) | 4 hours |
| P2 (High) | 8 hours |
| P3 (Medium) | 24 hours |
| P4 (Low) | 48 hours |