Service Level Agreements

The following are the Service Level Agreements for Netrix Global managed services. Select a service category to view its SLA details, priority definitions, and credit terms.

Managed Detection & Response — Powered by Microsoft

Priority Definitions

Priorities are defined by the following definitions and matrix.

Urgency

This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions are as follows:

  • CRITICAL — Security incident with the potential to cause critical business functions to be stopped, or there is potential for significant loss, corruption, or unauthorized access of sensitive data.
  • HIGH — Security incident with the potential to cause major business degradation, or the potential for loss, corruption, or unauthorized access of sensitive data.
  • MEDIUM — Security Incident with the potential for non-critical business functions to be stopped or degraded. There is potential for minor loss, corruption, or unauthorized access of sensitive data.
  • LOW — Non-critical business function is degraded. There is no material impact.
Impact

This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions are as follows:

  • WIDESPREAD — The incident affects a large portion of the Client’s organization, critical business functions, or a significant number of systems or users.
  • SIGNIFICANT — The incident affects a specific department, major business function, or a substantial number of systems or users.
  • MODERATE — The incident affects a limited number of systems or users, or a non-critical business function.
  • LOCALIZED — The incident affects a single system or a very small number of users and has minimal impact on business operations.
Priority Matrix

The following matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.

Urgency1 – Widespread2 – Significant3 – Moderate4 – Localized
CRITICALP1P1P2P2
HIGHP1P2P2P3
MEDIUMP2P3P3P3
LOWP4P4P4P4

Service Level Agreements

The following table provides target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.

Severity / PriorityTime to AcknowledgeTime to Respond
Critical / P130 Minutes30 Minutes
High / P21 Hour1 Hour
Medium / P34 Hours4 Hours
Low / P412 Hours12 Hours

SLA Credits for Managed Services

If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.

1. Credit Eligibility
  • Credits will only be applied to the monthly recurring charge (MRC) for the Netrix Managed and Detection service.
  • Credits will not be applied to any other fees, including but not limited to, onboarding fees, incident response fees (for escalated services), or other professional services fees.
  • To be eligible for credits, the Client must notify Netrix in writing within 30 days of the SLA failure.
  • Netrix will review the Client’s claim and determine credit eligibility based on its service logs and records.
2. Credit Calculation
  • The amount of the credit will be calculated as a percentage of the MRC for the affected service, based on the priority level of the incident and the extent of the SLA failure.
  • If multiple SLA failures occur within a single security incident, only the credit for the most significant failure will apply.
3. Credit Schedule
Severity / PriorityAcknowledge Credit per ViolationRespond Credit per ViolationSLA Target
Critical / P13%5%90%
High / P22%3%90%
Medium / P31%1%90%
Low / P40.5%0.5%90%
4. Exclusions

No credits will be issued for any SLA failure resulting from:

  • Events outside of Netrix’s reasonable control, including but not limited to:
    • Force majeure events (e.g., natural disasters, war, terrorism).
    • Client-caused delays or failures.
    • Internet service provider outages.
    • Failures of the Client’s infrastructure or systems.
    • Scheduled maintenance.
    • False positive alerts.
    • Client’s failure to provide accurate or timely information or assistance.
5. Credit Application

Approved credits will be applied to the Client’s subsequent monthly invoice.

6. Maximum Monthly SLA Credit / Exclusive Remedy
  • The maximum SLA credit is limited to 20% of the MRC notwithstanding the calculations defined above. If a credit is owed based on the previous month’s performance, the credits will be issued on the following month’s invoice.
  • Notwithstanding anything to the contrary in this SOW or the Agreement, the SLA credit set forth herein shall be Client’s exclusive and sole remedy for any failure by Netrix to meet an SLA set forth in this SOW.

Managed Detection & Response — Powered by Elastic

Priority Definitions

Priorities are defined by the following definitions and matrix.

Urgency

This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions are as follows:

  • CRITICAL — Security incident with the potential to cause critical business functions to be stopped, or there is potential for significant loss, corruption, or unauthorized access of sensitive data.
  • HIGH — Security incident with the potential to cause major business degradation, or the potential for loss, corruption, or unauthorized access of sensitive data.
  • MEDIUM — Security Incident with the potential for non-critical business functions to be stopped or degraded. There is potential for minor loss, corruption, or unauthorized access of sensitive data.
  • LOW — Non-critical business function is degraded. There is no material impact.
Impact

This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions are as follows:

  • WIDESPREAD — The incident affects a large portion of the Client’s organization, critical business functions, or a significant number of systems or users.
  • SIGNIFICANT — The incident affects a specific department, major business function, or a substantial number of systems or users.
  • MODERATE — The incident affects a limited number of systems or users, or a non-critical business function.
  • LOCALIZED — The incident affects a single system or a very small number of users and has minimal impact on business operations.
Priority Matrix

The following matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.

Urgency1 – Widespread2 – Significant3 – Moderate4 – Localized
CRITICALP1P1P2P2
HIGHP1P2P2P3
MEDIUMP2P3P3P3
LOWP4P4P4P4

Service Level Agreements

The following table provides target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.

Severity / PriorityTime to AcknowledgeTime to Respond
Critical / P130 Minutes30 Minutes
High / P21 Hour1 Hour
Medium / P34 Hours4 Hours
Low / P412 Hours12 Hours

SLA Credits for Managed Services

If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.

1. Credit Eligibility
  • Credits will only be applied to the monthly recurring charge (MRC) for the Netrix Managed and Detection service.
  • Credits will not be applied to any other fees, including but not limited to, onboarding fees, incident response fees (for escalated services), or other professional services fees.
  • To be eligible for credits, the Client must notify Netrix in writing within 30 days of the SLA failure.
  • Netrix will review the Client’s claim and determine credit eligibility based on its service logs and records.
2. Credit Calculation
  • The amount of the credit will be calculated as a percentage of the MRC for the affected service, based on the priority level of the incident and the extent of the SLA failure.
  • If multiple SLA failures occur within a single security incident, only the credit for the most significant failure will apply.
3. Credit Schedule
Severity / PriorityAcknowledge Credit per ViolationRespond Credit per ViolationSLA Target
Critical / P13%5%90%
High / P22%3%90%
Medium / P31%1%90%
Low / P40.5%0.5%90%
4. Exclusions

No credits will be issued for any SLA failure resulting from:

  • Events outside of Netrix’s reasonable control, including but not limited to:
    • Force majeure events (e.g., natural disasters, war, terrorism).
    • Client-caused delays or failures.
    • Internet service provider outages.
    • Failures of the Client’s infrastructure or systems.
    • Scheduled maintenance.
    • False positive alerts.
    • Client’s failure to provide accurate or timely information or assistance.
5. Credit Application

Approved credits will be applied to the Client’s subsequent monthly invoice.

6. Maximum Monthly SLA Credit / Exclusive Remedy
  • The maximum SLA credit is limited to 20% of the MRC notwithstanding the calculations defined above. If a credit is owed based on the previous month’s performance, the credits will be issued on the following month’s invoice.
  • Notwithstanding anything to the contrary in this SOW or the Agreement, the SLA credit set forth herein shall be Client’s exclusive and sole remedy for any failure by Netrix to meet an SLA set forth in this SOW.

Managed Detection & Response — Powered by Elastic

Priority Determination Process

Initial Analyst Assessment from the Netrix MDR platform

Netrix SOC analysts will initially assess the validity of a security alert based on the information provided by the Netrix MDR platform. This includes:

  • The severity level assigned by the Netrix MDR platform.
  • The type of attack or suspicious activity.
  • Correlating details from other security tools.
  • The affected systems and data.
  • Any automated risk scoring or threat intelligence information available.
  • Any direct instructions provided by the Client as to manual incident priority assignment related to a specific alert.
Client Input and Adjustment
  • The Client has the ability to provide additional context and adjust the priority of an alert based on their specific business needs and understanding of the environment.
  • Any such adjustment shall be communicated to Netrix as soon as possible.
  • During the onboarding process outlined in Phase 5, the Parties will collaborate to establish clear communication channels and procedures for priority adjustment, as documented in the Client runbook.

Priority Definitions

Priorities are defined by the following definitions and matrix.

Urgency

This refers to the timeframe within which the incident needs to be addressed to avoid or minimize the potential impact. Definitions as follows:

  • CRITICAL — Security incident with the potential to cause critical business functions to be stopped, or there is potential for significant loss, corruption, or unauthorized access of sensitive data.
  • HIGH — Security incident with the potential to cause major business degradation, or the potential for loss, corruption, or unauthorized access of sensitive data.
  • MEDIUM — Security Incident with the potential for Non-critical business functions to be stopped or degraded. There is potential for minor loss, corruption, or unauthorized access of sensitive data.
  • LOW — Non-critical business function is degraded. There is no material impact.
Impact

This refers to the potential damage to the Client’s business operations, data, or reputation if the incident is not addressed. Definitions as follows:

  • WIDESPREAD — The incident affects a large portion of the Clients organization, critical business functions, or a significant number of systems or users.
  • SIGNIFICANT — The incident affects a specific department, major business function, or a substantial number of systems or users.
  • MODERATE — The incident affects a limited number of systems or users, or a non-critical business function.
  • LOCALIZED — The incident affects a single system or a very small number of users, and has minimal impact on business operations.
Priority Matrix

The follow matrix will be used by Netrix to determine the Priority assigned to an alert after the investigation is completed.

Urgency1 – Widespread2 – Significant3 – Moderate4 – Localized
CRITICALP1P1P2P2
HIGHP1P2P2P3
MEDIUMP2P3P3P3
LOWP4P4P4P4

Incident Escalation

Effective escalation procedures are critical to promote timely and appropriate responses to security incidents and service-related issues.

Initial Escalation
  • Netrix SOC analysts will perform an initial assessment of security alerts generated by the Netrix MDR platform. If an alert is determined to be a security incident, it will be prioritized according to the aforementioned “Priority Definitions” and “Priority Matrix” sections.
  • Netrix SOC analyst will escalate the incident to the appropriate Client contact(s) as defined in the communication plan established during onboarding. This escalation will include the priority of the incident, relevant details about the incident, its potential impact, and the recommended response actions.
Escalation Channels and Systems of Record

Escalations will be communicated through the channels defined during onboarding. This may include:

  • Phone calls.
  • Email.
  • Tickets within the Client or Netrix service management system.
  • Other communication platforms as agreed upon.

The systems of record for incident tracking and communication will be established during onboarding to optimize clear documentation and accountability.

MDR Incident Response and Escalations vs. Advanced Incident Response

The following definitions apply with respect to the scope of incident response activities included within the base Netrix MDR service versus incident response services that are applicable to a Netrix FIRE retainer or response engagement:

Initial Incident Response (Included in the Netrix MDR Service)

Initial incident response encompasses activities that the Netrix SOC will conduct as part of standard incident triage including manual investigation and actions that Netrix can execute through automated response capabilities within the SIEM platform (e.g., SOAR playbook actions such as account disablement or device isolation). Initial incident response also includes client escalations where a more detailed incident review is warranted, limited to four (4) hours per request, unless otherwise communicated to the Client during an escalation. These activities are performed as part of the standard MDR service at no additional charge to the Client. Examples include: Initial Evidence gathering from SIEM and integrated log sources, automated actions triggered by SOAR playbooks, alert triage and validation by Netrix SOC analysts and escalated investigations by Netrix Security engineers.

Advanced Incident Response (Not included in the Netrix MDR service, contracted separately under a separate Statement of Work)

When an escalated incident requires sustained investigation, exceeding four (4) cumulative hours of analyst/engineer effort beyond initial triage, the engagement can be transitioned to a Client contracted FIRE retainer if previously contracted in a Netrix statement of work, or a Netrix FIRE response engagement in a new statement of work. Should the client already have a FIRE engagement contracted, the Client will be notified prior to FIRE hours being consumed.

Service Level Agreements

The following tables provide target time frames for alert acknowledgement and response as defined in the security incident management section in this SOW.

Time to Acknowledge
Netrix MDR Alert PriorityInitial Time to Acknowledge SLA
Critical30 Minutes
High1 Hour
Medium4 Hours
Low8 Hours
Time to Respond
Priority LevelTime to Respond SLA
P1 (Priority 1)30 minutes
P2 (Priority 2)1 hour
P3 (Priority 3)4 hours
P4 (Priority 4)12 hours

SLA Credits & Remedies for Managed Services

If Netrix fails to meet the Initial Response Time or Time to Respond SLAs as defined in the “Service Level Agreement (SLA)” section, the Client may be eligible for service credits as outlined below.

1. Credit Eligibility
  • Credits will only be applied to the monthly recurring charge (MRC) for the Netrix Managed and Detection service.
  • Credits will not be applied to any other fees, including but not limited to, onboarding fees, incident response fees (for escalated services), or other professional services fees.
  • To be eligible for credits, the Client must notify Netrix in writing within 30 days of the SLA failure.
  • Netrix will review the Client’s claim and determine credit eligibility based on its service logs and records.
2. Credit Calculation
  • The amount of the credit will be calculated as a percentage of the MRC for the affected service, based on the priority level of the incident and the extent of the SLA failure.
  • If multiple SLA failures occur within a single security incident, only the credit for the most significant failure will apply.
3. Credit Schedule
Time to Acknowledge
Netrix MDR Alert PriorityPercentage Credit per ViolationSLA Target
High5%90%
Medium3%90%
Low2%90%
Time to Respond
Priority LevelPercentage Credit per ViolationSLA Target
P1 (Priority 1)5%90% resolution
P2 (Priority 2)3%90% resolution
P3 (Priority 3)1%90% resolution
P4 (Priority 4)24 hours90% resolution
4. Exclusions

No credits will be issued for any SLA failure resulting from:

  • Events outside of Netrix’s reasonable control, including but not limited to:
    • Force majeure events (e.g., natural disasters, war, terrorism).
    • Client-caused delays or failures.
    • Internet service provider outages.
    • Failures of the Client’s infrastructure or systems.
    • Scheduled maintenance.
    • False positive alerts.
    • Client’s failure to provide accurate or timely information or assistance.
5. Credit Application

Approved credits will be applied to the Client’s subsequent monthly invoice.

6. Maximum Monthly SLA Credit / Exclusive Remedy
  • The maximum SLA credit is limited to 10% of the MRC notwithstanding the calculations defined above. If a credit is owed based on the previous month’s performance, the credits will be issued on the following month’s invoice.
  • Notwithstanding anything to the contrary in this SOW or the Agreement, the SLA credit set forth herein shall be Client’s exclusive and sole remedy for any failure by Netrix to meet an SLA set forth in this SOW.

Managed Threat Intelligence

Time to Review and Notify Client

Time to review and notify Client, or closure of an alert upon finding of a false positive:

PriorityReview & Notify
P1 (Critical)4 hours
P2 (High)8 hours
P3 (Medium)24 hours
P4 (Low)48 hours