Terms and conditions for a cybersecurity consultancy

Business-to-business terms for cybersecurity consultancies offering assessments, audits, advisory and incident support, drafted for a fixed fee of £995 in five working days.

Share

Terms and conditions for a cybersecurity consultancy

Business-to-business supplier terms for security consultancies and auditors, covering scope and point-in-time assessments, authority and access, findings and confidentiality, remediation and the client's decisions, and fees, liability and data. £995, delivered in five working days.

Buy now, £995

A security consultant is asked to make a business safe and can only make it safer, and the terms have to say that in a way a client accepts before a breach rather than after it. They also have to scope each assessment tightly, secure written authority for anything that touches the client's systems, protect the findings, and cap the liability of a business whose advice is followed selectively. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Cybersecurity consultancies, virtual CISO services, security auditors and incident response advisers in England and Wales working for business clients on assessments, compliance projects, advisory retainers and incident support. These are business-to-business terms.

What matters in cybersecurity consultancy terms

Scope and the point-in-time nature of an assessment

The terms should provide that each engagement is defined by a written scope (systems, sites, standards, dates), that an assessment reports on what was found in the scope at the time, and that new vulnerabilities, changes to the client's systems and threats that emerge afterwards are outside it. Advice is given with reasonable skill and care; the terms should say plainly that no assessment can find every weakness and that no advice makes a system secure.

Authority, access and the law

Any testing or access to systems needs the written authority of whoever controls them, because under the Computer Misuse Act 1990 unauthorised access is an offence regardless of intent. The terms should require the client to confirm that it owns or is authorised to have every system in scope tested, including systems hosted by third parties, and to obtain the hosting provider's consent where their rules require it, and should make the client responsible if that confirmation is wrong.

Findings, confidentiality and disclosure

Findings are dangerous in the wrong hands. The terms should impose confidentiality on both sides, say that reports are for the client's internal use and its regulators and auditors, that the consultancy may not be named in the client's marketing without agreement, and how the consultancy retains and destroys evidence and data gathered during an engagement. Where the client asks the consultancy to speak to its customers or a regulator, that is a separate service.

Remediation, retesting and the client's decisions

The consultancy advises; the client decides. The terms should say that remediation is the client's responsibility unless engaged separately, that retesting is a further engagement, that advice not followed is the client's risk, and that the client must give the consultancy accurate information about its systems and incidents. Incident response should be described as a separate service with its own rates and response commitments.

Fees, liability, data and insurance

Fees are fixed per engagement or on a retainer, invoiced in advance or at milestones, with interest and fixed compensation on late payment under the Late Payment of Commercial Debts (Interest) Act 1998. Liability should be capped at a figure matching your professional indemnity insurance, with consequential loss, loss of data and regulatory fines excluded, tested for reasonableness under the Unfair Contract Terms Act 1977; the cap should not apply to what cannot be excluded. Personal data seen during an engagement is processed under the UK GDPR and the Data Protection Act 2018 as the terms describe, and the consultancy's insurance should be stated.

What it costs

Customer or supplier terms and conditions, £995. One set of terms, customer-facing or supplier-facing, drafted for your business. Five working days.

Review of your existing terms, £495. You already have terms and want them checked and brought up to date. Returned marked up with my amendments and an explanation of the changes. Three working days.

Buying online forms the engagement on payment. The scope is what the terms and conditions drafting page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A full set of bespoke terms drafted for your business, reflecting the legal requirements that apply to your business and sector
  • A note in plain English explaining the terms I have drafted for you
  • Liability, payment, termination and IP provisions that protect your position and are drafted to withstand scrutiny from the other side
  • Guidance on how to incorporate the terms properly
  • Your questions and comments answered by email or phone
  • One round of amendments to finalise the terms ready for use

What is not included

  • Negotiating your terms with individual customers (I am happy to quote for this as an additional service if required)
  • Sector-specific regulatory compliance beyond the contract terms themselves
  • Website privacy notice and cookie compliance, which I quote separately
  • Terms governed by the law of another country
  • Tax advice

Questions I am often asked

The client was breached six months after our audit and blames us. Where do we stand?

If the terms say the assessment reports on the scope at the time, that no assessment finds everything and that remediation and later changes are the client's, and the audit was done with reasonable skill and care, the breach is not a failure of the audit. The cap applies to whatever remains.

Can we test a system the client says belongs to them but is hosted by a third party?

Only with the client's written confirmation of its authority and, where the host's rules require it, the host's consent. The terms should make that confirmation a condition of starting and place the consequences of a wrong confirmation on the client.

The client wants us to sign a statement that they are secure. Should we?

No consultancy can say that accurately. The terms should say that reports describe findings and recommendations at a point in time and that the consultancy gives no assurance of security, and the report should say the same.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.