Cybersecurity and IT Services for Alternative Asset Managers 

This Services Guide contains provisions that define, clarify, and govern the services described in the Proposal or Scope of Work that has been provided to you (the “Proposal”).  If you do not agree with the terms of this Services Guide, you should not sign the Proposal and you must contact us for more information.

This Services Guide is our “owner’s manual” that generally describes all managed services provided or facilitated by Triada Networks (“Triada,” “we,” “us,” or “our”); however, only those services specifically described in the Proposal will be facilitated and/or provided to you (collectively, the “Services”).  

Activities or items that are not specifically described in the Proposal will be out of scope and will not be included unless otherwise agreed to by us in writing. Items listed below is a reference of how services are delivered, but may not be part of your Proposal. Items not referenced in the Proposal are not part of the agreement.

We begin our Initial Audit by conducting a consultation with your organization to align our services with your business objectives. This comprehensive assessment involves remote diagnostics using advanced tools like network analyzers and vulnerability scanners, as well as on-site evaluations if required. 

Our team examines your IT landscape, analyzing hardware, software, security postures, data flows, user permissions, and compliance gaps to identify inefficiencies and potential risks. Within a predetermined timeframe, we provide a detailed report featuring: 

  1. Actionable insights 
  2. Prioritized recommendations for improvement 
  3. Performance benchmarks 

To ensure clarity on our findings and next steps, clients participate in a virtual walkthrough with our experts. 

Post-audit guidance is provided to support the implementation of recommended improvements, ultimately reducing downtime and enhancing system reliability. 

Onboarding starts with a kickoff meeting to define project scope and timelines, ensuring alignment with your goals. Triada assigns a dedicated project manager to coordinate the integration of our services, beginning with system access setup and user account configuration. We deploy necessary software and hardware remotely, using secure protocols to minimize disruption. Staff training sessions are conducted virtually or in-person to familiarize teams with new tools. Regular checkpoints ensure smooth progress, and a final review confirms all systems are operational. Post-onboarding, we provide 30 days of enhanced support to address any issues.

Managed Services will be applied to the devices on which we install software monitoring agents (“Covered Hardware”). You will be provided with an updated list of Covered Hardware once all software agents have been installed. The list of Covered Hardware may be modified by mutual consent (email is sufficient for this purpose); however, we reserve the right to modify the list of Covered Hardware at any time if we discover devices that were not previously included in the list of Covered Hardware and which are receiving Services. We will provide technical support for Covered Devices; however, all Covered Devices must be covered, at all times and at your cost, under a then-current manufacturer’s service plan.

We will provide support for any software applications that are licensed through us. Such software (“Supported Software”) will be supported on a “best effort” basis only, and any support required beyond Level 2-type support will be facilitated with the applicable software vendor/producer. Coverage for non-Supported Software is outside of the scope of the Proposal and, if provided to you, will be provided to you on a “best effort” basis only with no guarantee of remediation.

If we are unable to remediate an issue with non-Supported Software, then you will be required to contact the manufacturer/distributor of the software for further support. Please note: Manufacturers/distributors of such software may charge fees, some of which may be significant, for technical support; therefore, we strongly recommend that you maintain service or support contracts for all non-Supported Software (“Service Contract”). If you request that we facilitate technical support for non-Supported Software, then if you have a Service Contract in place, our facilitation services will be provided at no additional cost to you.

Should our technicians provide you with general advice concerning non-Supported Software, the provision of that advice should be viewed as an accommodation to you, and not as a continuing obligation or guarantee by Triada to continue to provide such support or advice to you.

In this Services Guide, Covered Hardware and Supported Software will be referred to as the “Environment” or “Covered Equipment.”

Services will be provided remotely unless, in our discretion, we determine that an onsite visit is required. Triada visits will be scheduled in accordance with the priority assigned to the issue (below) and are subject to technician availability. Unless we agree otherwise, all onsite Services will be provided at Client’s primary business location. Additional fees may apply for onsite visits: Please review the Service Level section below for more details.

The scheduling, fees and provision of the Services are based upon the following assumptions and minimum requirements:

  • Server hardware must be under current warranty coverage.
  • All equipment with Microsoft Windows® operating systems must be running then-currently supported versions of such software and have all of the latest Microsoft service packs and critical updates installed.
  • All software must be genuine, licensed, and vendor-supported.
  • Server file systems and email systems (if applicable) must be protected by licensed and up-to-date virus protection software.
  • The managed environment must have a currently licensed, vendor-supported server-based backup solution that can be monitored.
  • All wireless data traffic in the managed environment must be securely encrypted.
  • All servers must be connected to working UPS devices.
  • Recovery coverage assumes data integrity of the backups or the data stored on the backup devices.  We do not guarantee the integrity of the backups or the data stored on the backup devices.  Server restoration will be to the point of the last successful backup.
  • Client must provide all software installation media and key codes in the event of a failure.
  • Any costs required to bring the Environment up to these minimum standards are not included in this Services Guide.

Exclusions– Services that are not expressly described in the Proposal will be out of scope and will not be provided to Client unless otherwise agreed, in writing, by Triada. Without limiting the foregoing, the following services are expressly excluded, and if required to be performed, must be agreed upon by Triada in writing

At Triada, we prioritize swift and effective support to keep your operations running smoothly. Whether your issue is routine or urgent, we offer multiple channels to ensure you get the help you need, when you need it.

For less urgent support requests, such as general inquiries, new hire setups, terminations, or special requests, you can submit a ticket through our dedicated support portal at https://triadanet.com/support. This form-based system ensures your request is tracked and addressed efficiently. Alternatively, you can email us directly at help@triadanet.com, and our team will respond during business hours.

If your issue is urgent and you need immediate assistance, please call us at 201-644-1444. Our support team is ready to assist you promptly. For after-hours emergencies, leave a message, and our on-call technician will be notified immediately to address your critical needs.

We’re committed to minimizing downtime and ensuring your technology supports your business goals. For more details on response times and service levels, please refer to our Service Levels section.

Managed IT Services

Triada’s Managed IT Services deliver a proactive, subscription-based solution customized to your business needs, ensuring operational continuity and security. We begin with a thorough onboarding audit to map your IT environment, deploying advanced monitoring tools for 24/7 oversight of critical systems. Our team manages hardware, software, and networks remotely, leveraging automated alerts to resolve issues before they impact your operations. Detailed performance reports and periodic strategy sessions keep you informed, aligning IT with your goals. From security patches to compliance checks, we streamline your infrastructure for efficiency. Access our helpdesk for immediate support during business hours, as detailed in our Service Levels.

Description: Antivirus and Anti-malware is a security service that protects devices such as laptops, desktops, servers, and mobile devices from malicious software, including viruses, worms, trojans, ransomware, and spyware. It uses signature-based detection to identify and block known threats by comparing files and programs against a database of malware signatures. The service continuously scans files, emails, web downloads, and attachments, quarantining or removing threats before they can cause harm. It also includes features like scheduled scans, email protection, and warnings for suspicious websites, with automatic updates to stay current against new threats. For advanced threats, this service can be complemented by Endpoint Detection and Response (EDR), which offers behavioral analysis and real-time threat hunting (see EDR section for details).

Purpose: The purpose of Antivirus and Anti-malware is to provide a foundational layer of defense against common cyber threats, ensuring devices remain secure and operational. It prevents malware from compromising sensitive data, disrupting systems, or spreading across networks. By blocking known threats and scanning incoming data, it reduces the attack surface, supports compliance with security standards, and maintains productivity by minimizing disruptions caused by infections.

Risks of Not Implementing: Without Antivirus and Anti-malware, devices are highly vulnerable to malware infections, which can lead to data theft, system crashes, or ransomware attacks that lock critical files. Unprotected endpoints may allow threats to spread across the network, causing widespread operational downtime and financial losses. Lack of basic protection increases the risk of compliance violations, as many regulations require malware defenses. Relying solely on manual checks or outdated solutions leaves systems exposed to rapidly evolving threats, which could be mitigated with EDR’s advanced capabilities for unknown or sophisticated attacks

Disclaimer: Review Antivirus; Anti-Malware and Removal of Agents policy

Description: Block Hours are purchased in advance and tracked via our client portal, offering flexible access to Triada’s expertise. Upon request, our team schedules remote support sessions for tasks like troubleshooting, system upgrades, or consultations, prioritized based on urgency. A dedicated account manager ensures hours are used efficiently, with detailed usage reports provided monthly. Clients submit requests through our helpdesk, and we assign technicians with relevant skills. Work is performed remotely unless on-site is required and covered by your plan. Unused hours roll over within the contract term, ensuring maximum value.

Description: Business Continuity Appliance with Cloud Backup also known as Backup and Disaster Recovery (BDR) Services provide a unified solution to protect and restore critical business data and systems. The service creates regular, image-based backups of physical, virtual, and cloud environments, storing them both locally on a dedicated appliance and in a secure, offsite cloud. It includes features like automated backup verification, ransomware detection, and rapid recovery options, such as instant virtualization or file-level restores. BDR allows businesses to resume operations quickly by restoring entire systems or individual files from local or cloud backups, with minimal configuration required.

Purpose: The purpose of BDR Services is to ensure business continuity by safeguarding data against loss from hardware failures, human errors, ransomware, or natural disasters. It combines backup and disaster recovery into a single platform to minimize downtime and simplify recovery processes. By maintaining secure, accessible copies of data and systems, BDR helps businesses meet compliance requirements and maintain operational resilience, especially in complex IT environments.

Risks of Not Implementing: Without BDR Services, businesses risk significant data loss and extended downtime from cyberattacks, hardware failures, or disasters. Without regular, verified backups, recovering critical systems or files may be impossible, leading to financial losses and operational disruptions. Lack of ransomware protection increases vulnerability to malicious attacks that can lock or destroy data. Additionally, managing multiple backup solutions can lead to errors or gaps in coverage, while failing to meet compliance standards may result in penalties or reputational damage

 

Description: Cloud Hosting and Management is a service that provides scalable, secure hosting of applications, data, and IT infrastructure on cloud platforms, such as virtual servers, storage, or databases. It includes setup, configuration, and ongoing maintenance of cloud environments, ensuring optimal performance and security. The service encompasses monitoring resource usage, applying security patches, managing access controls, and implementing backups for data protection. It also offers scalability to adjust resources based on demand and supports hybrid or multi-cloud setups to align with business needs, all managed through a centralized interface for streamlined oversight.
 
Purpose: The purpose of Cloud Hosting and Management is to enable businesses to leverage cloud technology for flexible, cost-effective IT operations without the burden of managing complex infrastructure. It ensures high availability, secure data storage, and rapid scalability to support growth or seasonal demands. By maintaining security and performance, the service minimizes disruptions, supports compliance with data protection regulations, and allows businesses to focus on core activities rather than IT management.
 
Risks of Not Implementing: Without Cloud Hosting and Management, businesses may face unreliable or insecure cloud setups, leading to data breaches, system downtime, or performance issues that disrupt operations. Unmanaged environments risk misconfigurations, which are a leading cause of cloud-based vulnerabilities, exposing sensitive data to unauthorized access. Lack of proper monitoring and patching can result in unaddressed security gaps, while inadequate backups may prevent recovery from data loss. Failing to scale resources efficiently can lead to overpaying for unused capacity or performance bottlenecks, and non-compliance with regulations may incur penalties or reputational harm.

Description: Compliance Consulting for FINRA, SEC, and NYDFS is a specialized service that helps organizations align their IT and business practices with the regulatory requirements of the Financial Industry Regulatory Authority (FINRA), the Securities and Exchange Commission (SEC), and the New York Department of Financial Services (NYDFS). The service includes assessing current processes, identifying gaps in compliance, and implementing controls to meet standards, such as data protection, recordkeeping, and cybersecurity mandates. It provides guidance on policies, employee training, and audit preparation, along with ongoing support to maintain compliance through regular reviews and updates to address evolving regulations.

Purpose: The purpose of Compliance Consulting is to ensure organizations meet the stringent cybersecurity and operational requirements of FINRA, SEC, and NYDFS, which govern financial institutions to protect sensitive data and maintain market integrity. It reduces the risk of regulatory penalties and reputational damage by establishing robust security practices and documentation. The service also helps organizations build trust with clients and regulators by demonstrating adherence to industry standards, while streamlining compliance efforts to minimize operational disruptions.

Risks of Not Implementing: Without Compliance Consulting, organizations may fail to meet FINRA, SEC, or NYDFS requirements, leading to significant fines, legal actions, or loss of operating licenses. Non-compliance, such as inadequate cybersecurity measures or incomplete recordkeeping, increases the risk of data breaches or fraud, which can erode client trust and damage reputation. Lack of expert guidance may result in overlooked regulatory gaps, making it difficult to pass audits or respond to regulatory inquiries. Evolving regulations can overwhelm unprepared organizations, leading to costly remediation efforts and operational inefficiencies.

Description: Dark Web Monitoring is a cybersecurity service that continuously scans dark web marketplaces, forums, and other hidden online platforms to detect if an organization’s sensitive information, such as stolen credentials, financial data, or proprietary documents, is being traded or exposed. The service uses automated tools to search for compromised data, including email addresses, passwords, and client information, and provides alerts with detailed reports on findings. It also offers recommendations for mitigating risks, such as resetting passwords or enhancing security controls, to prevent misuse of exposed data.
 
Purpose: The purpose of Dark Web Monitoring is to proactively identify and address data breaches or leaks before they lead to further harm, such as identity theft, financial fraud, or ransomware attacks. By detecting compromised information early, it enables organizations to take swift action to secure accounts and protect sensitive assets. The service supports compliance with data protection regulations and helps maintain client trust by demonstrating vigilance against cyber threats.
 
Risks of Not Implementing: Without Dark Web Monitoring, organizations may remain unaware of compromised data circulating on the dark web, increasing the likelihood of unauthorized account access, financial losses, or reputational damage. Stolen credentials can be used to launch targeted attacks, such as phishing or ransomware, disrupting operations and exposing clients to risk. Lack of monitoring delays response to breaches, potentially escalating the impact and recovery costs. Additionally, failure to detect and address data leaks may violate compliance requirements, leading to regulatory penalties or loss of customer confidence.
 
Disclaimer: Our dark web monitoring services utilize the resources of third party solution providers. Dark web monitoring can be a highly effective tool to reduce the risk of certain types of cybercrime; however, we do not guarantee that the dark web monitoring service will detect all actual or potential uses of your designated credentials or information.
Description: Desktop File Backup is a service that automatically creates secure copies of files and folders stored on desktop and laptop computers, ensuring critical data is protected and recoverable. It backs up documents, spreadsheets, presentations, and other user-generated files to a secure local device or cloud storage, with options for scheduled or continuous backups. The service allows easy file restoration in case of accidental deletion, hardware failure, or malware attacks, and includes encryption to safeguard data during storage and transfer. Users can access backed-up files from any authorized device, supporting remote work and mobility.
 
Purpose: The purpose of Desktop File Backup is to protect essential business data on individual devices from loss due to hardware issues, user errors, or cyberattacks like ransomware. It ensures business continuity by enabling quick recovery of critical files, minimizing downtime and productivity losses. The service also supports compliance with data protection regulations by maintaining secure, accessible copies of important information, reducing the risk of permanent data loss.
 
Risks of Not Implementing: Without Desktop File Backup, files on desktops and laptops are vulnerable to permanent loss from hardware failures, accidental deletions, or malware infections, leading to operational disruptions and potential financial losses. Lack of backups can delay recovery, forcing employees to recreate lost work, which impacts productivity. Unprotected data may also be irretrievable after ransomware attacks, increasing recovery costs or forcing payment of ransoms. Additionally, failure to secure sensitive files can result in non-compliance with data protection regulations, risking penalties and reputational harm.
 
Disclaimer: Review Backup and Disaster Recovery Services policy
Description: Desktop Image Backup is a service that creates comprehensive, full-system snapshots of desktop and laptop computers, capturing the operating system, applications, settings, and all files in a single image. These backups are stored securely on a local device or in the cloud, with options for scheduled or incremental backups to minimize resource usage. The service enables rapid restoration of an entire system to its previous state or to new hardware in case of device failure, malware attacks, or data corruption. It includes encryption for data security and supports flexible recovery options, such as restoring specific files or the entire system.
 
Purpose: The purpose of Desktop Image Backup is to ensure complete recovery of desktop and laptop systems, preserving both data and configurations to maintain business continuity. It protects against data loss from hardware failures, ransomware, or user errors by providing a reliable way to restore devices to full functionality quickly. The service minimizes downtime, supports compliance with data protection regulations, and ensures consistent system performance across the organization.
 
Risks of Not Implementing: Without Desktop Image Backup, a device failure, malware infection, or corruption can result in the loss of critical system configurations, applications, and data, leading to extended downtime and significant productivity losses. Recreating a system from scratch is time-consuming and may disrupt operations, especially for specialized setups. Lack of full-system backups increases vulnerability to ransomware, as restoring devices without clean images may be impossible or costly. Failure to protect sensitive data and systems may also lead to non-compliance with regulations, risking penalties and reputational damage.
 
Disclaimer: Review Backup and Disaster Recovery Services policy
Description: Device Hardening is a service that secures desktops, laptops, servers, and other devices by reducing vulnerabilities and strengthening their defenses against cyber threats. It involves configuring devices to follow industry best practices, such as disabling unnecessary services, removing unused software, and applying strict access controls. The service includes regular updates to operating systems and applications, enabling firewalls, and enforcing strong password policies. Triada conducts initial assessments to identify weaknesses, implements tailored configurations, and provides ongoing monitoring to maintain security. Clients receive quarterly reports on device compliance and security status, with helpdesk support for issues during business hours.
 
Purpose: The purpose of Device Hardening is to minimize the risk of cyberattacks, such as malware, ransomware, or unauthorized access, by reducing the attack surface of devices. It ensures devices operate securely and reliably, protecting sensitive data and supporting business continuity. The service aligns with compliance requirements, such as GDPR, HIPAA, or PCI-DSS, by maintaining secure configurations, helping organizations avoid breaches and build trust with clients and stakeholders.
 
Risks of Not Implementing: Without Device Hardening, devices are vulnerable to exploitation due to outdated software, weak configurations, or unnecessary services, increasing the likelihood of data breaches, system compromise, or ransomware attacks. Unsecured devices can serve as entry points for broader network attacks, leading to financial losses, downtime, and reputational damage. Lack of standardized security measures risks non-compliance with regulations, potentially resulting in penalties. Unhardened devices may also experience performance issues, disrupting employee productivity and operational efficiency.
 
Disclaimer: While Device Hardening significantly enhances device security, no solution can eliminate all risks due to evolving cyber threats or user errors. Regular updates, adherence to recommended configurations, and complementary security practices, such as employee training, are advised to maximize protection. Prompt reporting of issues is essential to maintain effectiveness.
Description: DNS Filtering is a security service that controls access to websites by analyzing Domain Name System (DNS) queries, which translate domain names (like example.com) into IP addresses. It blocks access to malicious, inappropriate, or unauthorized websites by checking queries against predefined policies, blocklists, or allowlists. The service can filter content by categories, such as social media, gambling, or adult content, and supports remote workers through roaming clients, ensuring protection across devices and locations. DNS Filtering operates at the network level, requiring no software installation on individual devices, and provides customizable block pages to inform users of restricted access.
 
Purpose: The purpose of DNS Filtering is to enhance cybersecurity and enforce acceptable use policies by preventing access to harmful or unproductive websites. It protects against threats like phishing, malware, and ransomware by blocking malicious domains before they load. Additionally, it helps organizations maintain productivity and comply with regulations by restricting access to non-work-related or inappropriate content, making it a critical layer of defense for both on-site and remote work environments.
 
Risks of Not Implementing: Without DNS Filtering, users may access malicious websites, increasing the risk of phishing attacks, malware infections, or data breaches, which can lead to financial loss or system downtime. Unrestricted access to inappropriate or non-work-related sites can reduce employee productivity and expose organizations to legal or compliance issues. Without centralized control over web access, it’s challenging to monitor or mitigate risks, especially for remote workers on unsecured networks, leaving sensitive data and systems vulnerable.
Description: Email Threat Protection is a security service that safeguards email systems from threats like phishing, malware, spam, and business email compromise (BEC). It uses advanced filtering to scan incoming and outgoing emails for malicious links, attachments, or suspicious content, blocking threats before they reach users. The service includes features like real-time threat detection, domain spoofing prevention, and encryption for sensitive email communications. It also provides user-friendly tools for reporting suspicious emails and customizable policies to align with organizational needs, ensuring secure and reliable email access.
 
Purpose: The purpose of Email Threat Protection is to secure email, a primary entry point for cyberattacks, by preventing unauthorized access, data breaches, or malware infections. It protects sensitive information shared via email, maintains employee productivity by reducing spam, and supports compliance with data protection regulations. By blocking phishing and BEC attempts, the service helps safeguard financial and personal data, fostering trust with clients and partners.
 
Risks of Not Implementing: Without Email Threat Protection, organizations are vulnerable to phishing attacks that can trick users into revealing credentials or downloading malware, leading to data breaches or system compromises. Unfiltered spam can overwhelm inboxes, reducing productivity and increasing the chance of accidental interaction with malicious content. BEC attacks may result in financial losses or unauthorized transactions. Lack of email security also risks non-compliance with regulations requiring data protection, potentially leading to penalties, reputational damage, or loss of client confidence.
 
Disclaimer: While Email Threat Protection significantly reduces the risk of email-based threats, no solution is infallible. Advanced or highly targeted attacks may occasionally bypass filters, and malicious emails could still be delivered. Regular user training, prompt reporting of suspicious emails, and complementary security measures are recommended to maximize protection.
Description: Endpoint Detection and Response (EDR) is a cybersecurity service that continuously monitors and protects endpoints, such as desktops, laptops, servers, and mobile devices, from advanced threats. It uses behavioral analysis, machine learning, and real-time threat intelligence to detect suspicious activities, such as malware, ransomware, or unauthorized access, that may evade traditional antivirus solutions. EDR provides detailed incident analysis, automated response actions like isolating compromised devices, and forensic tools to investigate and remediate threats. It also includes centralized reporting and dashboards for visibility across all endpoints, ensuring rapid response to incidents.
 
Purpose: The purpose of EDR is to enhance endpoint security by identifying and responding to sophisticated cyber threats that bypass standard defenses. It minimizes the impact of attacks by quickly detecting and containing incidents, protecting sensitive data and maintaining business operations. EDR supports compliance with security regulations by providing detailed audit trails and proactive threat hunting, reducing the risk of data breaches and ensuring a robust security posture.
 
Risks of Not Implementing: Without EDR, endpoints are vulnerable to advanced threats like zero-day attacks or fileless malware, which can go undetected by traditional antivirus, leading to data breaches, system compromise, or ransomware incidents. Lack of real-time monitoring and response capabilities delays incident detection, increasing downtime, recovery costs, and potential data loss. Unaddressed threats can spread across networks, amplifying damage. Failure to implement EDR may also result in non-compliance with regulations requiring advanced security measures, risking penalties and reputational harm.
 
Disclaimer: Review Security Tools and Removal of Software Agents
Description: Extended Detection and Response (XDR) is a comprehensive cybersecurity service that integrates and analyzes data across endpoints, networks, cloud environments, and email systems to detect and respond to advanced threats. Unlike Endpoint Detection and Response (EDR), which focuses solely on endpoints, XDR provides a unified view by correlating telemetry from multiple sources, using advanced analytics and threat intelligence to identify complex attacks, such as multi-stage phishing or lateral movement. It offers automated response actions, like blocking malicious traffic or quarantining systems, and provides centralized dashboards for streamlined incident management and investigation.
 
Purpose: The purpose of XDR is to deliver holistic threat detection and response across an organization’s entire IT environment, improving visibility and reducing blind spots. By connecting data from endpoints, networks, and cloud, it uncovers sophisticated threats that might be missed by siloed solutions. XDR accelerates incident response, minimizes damage from breaches, and supports compliance with regulations through detailed reporting, ensuring a proactive and cohesive security strategy.
 
Risks of Not Implementing: Without XDR, organizations lack unified visibility across their IT environment, making it harder to detect coordinated or multi-vector attacks, such as those combining email phishing with network exploitation. This can lead to prolonged breaches, data theft, or system disruptions. Siloed security tools may miss critical connections between threats, delaying response and increasing recovery costs. Lack of comprehensive monitoring risks non-compliance with regulations requiring robust security, potentially resulting in penalties or reputational damage.
 
Disclaimer: Review Security Tools and Removal of Software Agents
Description: The Firewall Solution is a managed security service that leverages a client-provided or client-purchased firewall appliance to protect network infrastructure. The service begins with an assessment of the existing firewall to confirm compatibility with the client’s network environment. Triada configures the firewall remotely, implementing custom rules to block unauthorized access, filter malicious traffic, and monitor network activity. Ongoing management includes regular firmware updates, policy adjustments based on current threat intelligence, and secure remote access for maintenance. Clients receive monthly reports detailing blocked attempts and performance metrics, with helpdesk support for troubleshooting and policy changes during business hours. On-site visits are scheduled if remote configuration fails, as outlined in the client’s plan.
 
Purpose: The purpose of the Firewall Solution is to safeguard the organization’s network by controlling incoming and outgoing traffic, preventing unauthorized access, and mitigating cyber threats like malware or hacking attempts. It provides a critical layer of defense, ensuring secure communication and data protection while maintaining network performance. The service supports compliance with security regulations by enforcing robust access controls and providing detailed activity reports, allowing businesses to focus on operations with confidence in their network security.
 
Risks of Not Implementing: Without a properly configured and managed Firewall Solution, networks are vulnerable to unauthorized access, data breaches, and malware infections, which can lead to significant financial losses and operational disruptions. Unmonitored or outdated firewalls may fail to block emerging threats, allowing attackers to exploit vulnerabilities. Lack of regular policy updates and reporting increases the risk of non-compliance with industry regulations, potentially resulting in penalties or reputational damage. Without professional management, misconfigurations or unresolved issues may weaken defenses, exposing critical systems to attack.

Disclaimer: While the Firewall Solution significantly strengthens network security, no firewall is entirely impervious to advanced or targeted attacks. Some threats may bypass defenses if not addressed promptly. Regular updates, adherence to recommended policies, and complementary security measures are advised to maximize protection.
Description: The Fractional Chief Technology Officer (CTO) service provides strategic IT leadership on a part-time or project basis, tailored to the organization’s needs. A seasoned technology expert collaborates with leadership to align IT initiatives with business goals, offering guidance on technology adoption, cybersecurity strategies, and infrastructure planning. The service includes assessing current IT systems, recommending solutions to optimize performance and scalability, and overseeing major IT projects or vendor relationships. Regular consultations, detailed reports, and actionable roadmaps ensure informed decision-making, with flexible engagement models to suit budgets and objectives.
 
Purpose: The purpose of the Fractional CTO service is to deliver high-level IT expertise without the cost of a full-time executive, enabling organizations to navigate complex technology landscapes effectively. It ensures IT strategies support business growth, enhance operational efficiency, and strengthen security. By providing objective insights and proactive planning, the service helps mitigate risks, improve system reliability, and maintain compliance with industry standards, fostering long-term success.
 
Risks of Not Implementing: Without a Fractional CTO, organizations may lack strategic IT direction, leading to misaligned technology investments, inefficient systems, or missed opportunities for innovation. Unaddressed cybersecurity gaps or outdated infrastructure can increase vulnerability to breaches, downtime, or data loss, impacting operations and finances. Poor vendor or project oversight may result in cost overruns or failed implementations. Additionally, navigating regulatory requirements without expert guidance risks non-compliance, potentially causing penalties or reputational harm.
Description: The Fractional Chief Technology Officer (CTO) service provides strategic IT leadership on a part-time or project basis, tailored to the organization’s needs. A seasoned technology expert collaborates with leadership to align IT initiatives with business goals, offering guidance on technology adoption, cybersecurity strategies, and infrastructure planning. The service includes assessing current IT systems, recommending solutions to optimize performance and scalability, and overseeing major IT projects or vendor relationships. Regular consultations, detailed reports, and actionable roadmaps ensure informed decision-making, with flexible engagement models to suit budgets and objectives.
 
Purpose: The purpose of the Fractional CTO service is to deliver high-level IT expertise without the cost of a full-time executive, enabling organizations to navigate complex technology landscapes effectively. It ensures IT strategies support business growth, enhance operational efficiency, and strengthen security. By providing objective insights and proactive planning, the service helps mitigate risks, improve system reliability, and maintain compliance with industry standards, fostering long-term success.
 
Risks of Not Implementing: Without a Fractional CTO, organizations may lack strategic IT direction, leading to misaligned technology investments, inefficient systems, or missed opportunities for innovation. Unaddressed cybersecurity gaps or outdated infrastructure can increase vulnerability to breaches, downtime, or data loss, impacting operations and finances. Poor vendor or project oversight may result in cost overruns or failed implementations. Additionally, navigating regulatory requirements without expert guidance risks non-compliance, potentially causing penalties or reputational harm.
 
 
Description: Google Workspace Management is a service that oversees the administration, security, and optimization of Google Workspace (formerly G Suite), including tools like Gmail, Google Drive, Docs, and Calendar. It includes configuring user accounts, setting up security policies such as multi-factor authentication and data loss prevention, and managing access permissions to ensure secure collaboration. The service provides ongoing maintenance, such as monitoring usage, applying updates, and resolving user issues, along with training to maximize tool adoption. Clients receive regular reports on account activity and security status, with helpdesk support for troubleshooting during business hours.
 
Purpose: The purpose of Google Workspace Management is to ensure the secure, efficient, and reliable use of Google Workspace tools, enabling seamless collaboration and productivity. It protects sensitive data shared through email and cloud storage, supports compliance with data protection regulations, and reduces administrative burdens on internal teams. By optimizing configurations and providing user support, the service enhances operational efficiency and ensures employees can leverage the full potential of the platform.
 
Risks of Not Implementing: Without Google Workspace Management, misconfigured settings or lax security policies can expose sensitive data to unauthorized access, phishing, or data leaks, leading to breaches or compliance violations. Unmanaged user accounts may result in unauthorized sharing of files, increasing the risk of data loss. Lack of monitoring and updates can lead to system vulnerabilities or performance issues, disrupting workflows. Without proper support, employees may underutilize tools, reducing productivity, while compliance failures could result in penalties or reputational damage.
 
Disclaimer: While Google Workspace Management significantly enhances the security and efficiency of the platform, no solution can fully eliminate risks due to evolving cyber threats or user errors. Effective protection requires adherence to recommended security practices and ongoing user training. Regular collaboration and prompt reporting of issues are advised to maximize benefits.
Description: Hardware as a Service (HaaS) for Workstations is a subscription-based service that provides fully managed desktop or laptop computers tailored to an organization’s needs. The service includes procurement, setup, and configuration of workstations with required software, security tools, and updates. It covers ongoing maintenance, such as hardware repairs, replacements, and upgrades, as well as secure data wiping and disposal at the end of a device’s lifecycle. Workstations are monitored for performance and security, with helpdesk support for troubleshooting. Clients benefit from predictable costs and flexible refresh cycles to keep hardware current.
 
Purpose: The purpose of HaaS for Workstations is to simplify IT management by providing reliable, up-to-date hardware without the burden of ownership. It ensures employees have secure, high-performing devices to support productivity while reducing the need for in-house IT resources to manage hardware. The service supports compliance by maintaining secure configurations and proper data handling, allowing organizations to focus on core operations with cost-effective, scalable technology solutions.
 
Description: Infrastructure / Network Wiring is a service that designs, installs, and maintains structured cabling systems to support reliable network connectivity. Triada begins with a site survey, conducted on-site or using client-provided schematics, to create a customized cabling plan. Certified technicians install high-quality wiring, such as Ethernet or fiber optic cables, following industry standards for optimal performance. Post-installation, all connections are tested with diagnostic tools to verify reliability and speed. The service includes remote monitoring of network performance, with adjustments as needed, and provides clients with a detailed cabling layout and maintenance guide. Ongoing support for wiring issues is available remotely or on-site, based on the client’s service plan.
 
Purpose: The purpose of Infrastructure / Network Wiring is to establish a robust, scalable foundation for network connectivity, ensuring fast and reliable communication across an organization’s IT systems. It supports critical operations by minimizing connectivity issues and enabling seamless data transfer for applications, VoIP, and cloud services. The service enhances long-term efficiency, reduces maintenance burdens, and supports compliance with standards requiring secure and reliable network infrastructure.
Description: General IT Consulting is a service that provides expert guidance to optimize an organization’s IT environment and align technology with business objectives. It begins with a comprehensive assessment of existing systems, processes, and goals, conducted through interviews, system reviews, or client-provided documentation. Triada’s consultants develop tailored strategies for areas like infrastructure upgrades, software selection, cybersecurity enhancements, or cloud adoption. The service includes detailed recommendations, implementation roadmaps, and project oversight, with regular progress reports. Ongoing support is provided via consultations or helpdesk access, based on the client’s service plan, to address evolving IT needs.
 
Purpose: The purpose of General IT Consulting is to improve operational efficiency, security, and scalability by leveraging technology strategically. It helps organizations make informed decisions about IT investments, avoid costly missteps, and enhance system performance. The service supports compliance with industry standards, mitigates risks, and ensures IT initiatives drive business growth, allowing leadership to focus on core operations while maintaining a reliable technology foundation.
Description: Managed E-Mail Signatures is a service that designs, deploys, and maintains professional, consistent email signatures across an organization’s email platforms, such as Microsoft 365 or Google Workspace. The service includes creating customized signature templates with branding, contact details, and optional promotional banners, tailored to different departments or roles. Signatures are applied automatically to all emails, including mobile devices, with centralized management to ensure uniformity and compliance with company standards. Triada handles updates for staff changes, campaigns, or branding refreshes, with minimal user effort. Clients receive reports on signature deployment and helpdesk support for issues during business hours.
 
Purpose: The purpose of Managed Signatures is to enhance brand consistency and professionalism in email communications while simplifying signature management. It ensures every email reflects the organization’s identity, strengthens marketing efforts through targeted banners, and saves time by automating updates. The service supports compliance with regulations like GDPR by including required disclaimers or legal notices, reinforcing trust and credibility with clients and partners.
 
Risks of Not Implementing: Without Managed Signatures, inconsistent or outdated email signatures can weaken brand identity, confuse recipients, or miss marketing opportunities, diminishing professional credibility. Manual signature management increases administrative burdens and risks errors, such as incorrect contact details or missing legal disclaimers, potentially leading to compliance violations or reputational harm. Lack of centralized control may result in non-compliant signatures, exposing the organization to regulatory penalties or reduced customer trust.
 
Description: Managed Endpoint Detection and Response (MDR) is a fully managed cybersecurity service that builds on Endpoint Detection and Response (EDR) capabilities to protect desktops, laptops, servers, and mobile devices. It combines advanced EDR tools—using behavioral analysis, machine learning, and threat intelligence to detect threats like malware or ransomware—with 24/7 monitoring and response by a dedicated security team. The service includes proactive threat hunting, automated incident containment (e.g., isolating compromised devices), and detailed forensic analysis. Clients receive real-time alerts, regular security reports, and access to expert support for incident resolution, all managed remotely to minimize operational impact.
 
Purpose: The purpose of MDR is to provide comprehensive, hands-on protection against sophisticated cyber threats, extending beyond EDR’s capabilities with expert oversight and rapid response. It ensures endpoints remain secure, minimizing the risk of data breaches or system disruptions while reducing the burden on internal IT teams. MDR supports compliance with security regulations through continuous monitoring and detailed reporting, offering peace of mind and enabling businesses to focus on core operations.
 
Risks of Not Implementing: Without MDR, organizations may struggle to detect or respond to advanced threats like zero-day exploits or fileless malware, increasing the likelihood of data breaches, ransomware, or network-wide attacks. Relying solely on EDR without expert management can overwhelm internal teams, delaying incident response and escalating damage or downtime. Lack of proactive threat hunting and continuous monitoring leaves vulnerabilities unaddressed, risking financial losses and reputational harm. Non-compliance with regulations requiring robust security measures may also result in penalties.
 
Disclaimer: While MDR significantly enhances endpoint security with expert management, no solution can fully eliminate risks due to evolving cyber threats. Advanced attacks may occasionally bypass defenses, requiring ongoing updates and vigilance. Combining MDR with employee training and complementary security practices is recommended to maximize protection.
Description: Managed Firewall is a comprehensive security service that provides and fully manages a high-performance firewall appliance to protect an organization’s network. The service begins with selecting and deploying a firewall tailored to the client’s network requirements, followed by remote configuration of custom rules to block unauthorized access and filter malicious traffic. Ongoing management includes monitoring, firmware updates, and policy adjustments based on current threat intelligence. Clients receive monthly reports on blocked threats and network performance, with helpdesk support for troubleshooting and policy changes during business hours. On-site support is available if remote resolution is not feasible, per the service plan.
 
Purpose: The purpose of Managed Firewall is to deliver robust network security by preventing cyber threats like hacking, malware, or data breaches, while ensuring seamless connectivity. It provides a critical defense layer, protecting sensitive data and maintaining operational reliability without requiring clients to manage complex hardware or configurations. The service supports compliance with security regulations through consistent monitoring and reporting, allowing businesses to operate confidently with a secure network foundation.
 
Risks of Not Implementing: Without a Managed Firewall, networks are exposed to unauthorized access, malware infections, or data breaches, which can lead to significant financial losses, downtime, or reputational damage. Unmanaged or absent firewalls may fail to block evolving threats, allowing attackers to exploit vulnerabilities. Lack of expert monitoring and updates increases the risk of misconfigurations or outdated defenses, weakening security. Non-compliance with regulations requiring network protection may result in penalties, while network disruptions could hinder business operations.
 
Disclaimer: While Managed Firewall significantly strengthens network security, no solution is entirely impervious to advanced or targeted attacks. Some threats may bypass defenses if not addressed promptly. Regular policy reviews, adherence to recommended security practices, and complementary measures are advised to maximize protection.
Description: Microsoft 365 Management is a service that administers, secures, and optimizes Microsoft 365 environments, including tools like Outlook, Teams, OneDrive, and SharePoint. It encompasses user account setup, configuration of security features such as multi-factor authentication and data loss prevention, and management of access permissions to ensure secure collaboration. The service provides ongoing maintenance, including monitoring for suspicious activity, applying updates, and resolving user issues. It also includes employee training to enhance platform adoption and productivity. Clients receive regular reports on usage, security status, and compliance, with helpdesk support for troubleshooting during business hours.
 
Purpose: The purpose of Microsoft 365 Management is to ensure the secure, efficient, and reliable operation of Microsoft 365, enabling seamless communication, collaboration, and data management. It protects sensitive information stored or shared in the cloud, supports compliance with data protection regulations like GDPR or HIPAA, and reduces administrative overhead for internal teams. By optimizing configurations and providing support, the service maximizes the platform’s value and enhances employee productivity.
 
Risks of Not Implementing: Without Microsoft 365 Management, misconfigured security settings or unmanaged accounts can lead to data breaches, phishing attacks, or unauthorized access, compromising sensitive information and disrupting operations. Lack of monitoring may allow vulnerabilities to go unnoticed, increasing the risk of malware or compliance violations. Employees may struggle with underutilized tools, reducing efficiency and collaboration. Failure to maintain proper configurations and updates risks non-compliance with regulations, potentially resulting in penalties, reputational damage, or loss of client trust.
 
Disclaimer: While Microsoft 365 Management significantly enhances the security and efficiency of the platform, no solution can completely eliminate risks due to evolving cyber threats or user errors. Effective protection requires adherence to recommended security practices and ongoing user training. Regular collaboration and prompt reporting of issues are advised to maximize benefits.
Description: Multi-Factor Authentication (MFA) is a security service that requires users to provide two or more verification methods to access systems, applications, or data, such as a password combined with a mobile app code, biometric scan, or security token. The service includes setup and configuration of MFA across platforms like email, cloud services, and VPNs, with user-friendly options to minimize login friction. It provides centralized management to enforce MFA policies, monitor compliance, and troubleshoot issues. Clients receive regular reports on MFA usage and security incidents, with helpdesk support for user assistance during business hours.
 
Purpose: The purpose of Multi-Factor Authentication is to strengthen access security by adding layers of verification, significantly reducing the risk of unauthorized access due to stolen or weak passwords. It protects sensitive data, systems, and accounts from cyber threats like phishing or credential theft, while supporting compliance with regulations requiring robust access controls, such as GDPR, HIPAA, or PCI-DSS. MFA enhances trust and ensures secure access for employees, whether on-site or remote.
Risks of Not Implementing: Without MFA, reliance on passwords alone leaves systems vulnerable to unauthorized access, as stolen or guessed credentials can lead to data breaches, financial losses, or ransomware attacks. Weak access controls increase the likelihood of insider threats or external attacks, compromising sensitive information. Lack of MFA may result in non-compliance with industry regulations, risking penalties or reputational damage. Without secure access measures, remote work environments are particularly exposed, potentially disrupting operations and eroding client confidence.
 
Disclaimer: While Multi-Factor Authentication significantly enhances access security, no solution is entirely foolproof. Sophisticated attacks, such as social engineering, may occasionally bypass MFA if users are not vigilant. Regular user training, adherence to security policies, and complementary measures are recommended to maximize protection.

Triada’s Network Design and Implementation service begins with a comprehensive assessment of your connectivity needs, conducted remotely or on-site to design a high-performance network architecture. We plan and deploy LAN/WAN solutions, including switches, routers, and wireless access points, using industry standards like Cisco or Ubiquiti. Our team configures VLANs, QoS, and security protocols remotely, with on-site installation for physical components. Post-deployment, we monitor network performance, optimizing remotely to ensure reliability. Clients receive detailed documentation and performance reports, with ongoing support for upgrades. On-site maintenance is provided if needed, per your plan.

Description: On-site Support is a service that provides expert technical assistance at a client’s location for issues that cannot be resolved remotely, such as hardware failures, complex network installations, or critical system restorations. Triada begins with a remote triage through our helpdesk to evaluate the issue, dispatching certified technicians only when necessary, as outlined in the client’s service plan. On-site visits are scheduled promptly, with updates provided via a client portal to minimize disruption. Technicians arrive equipped with diagnostic tools and replacement parts to resolve issues efficiently. After each visit, clients receive a detailed report of actions taken and preventive recommendations, with follow-up remote monitoring to ensure system stability.
 
Purpose: The purpose of On-site Support is to address critical IT issues requiring physical intervention, ensuring rapid resolution to maintain business operations. It minimizes downtime by providing hands-on expertise for complex problems, complements remote support services, and enhances system reliability. The service supports compliance by ensuring proper hardware and network configurations, helping organizations avoid prolonged disruptions and maintain productivity.
 
Risks of Not Implementing: Without On-site Support, unresolved hardware or network issues can lead to extended downtime, disrupting business operations and reducing employee productivity. Delays in addressing critical failures may escalate problems, increasing repair costs or risking data loss. Lack of professional onsite intervention can result in improper setups or repairs, compromising system security and performance. Failure to maintain compliant configurations may also lead to regulatory penalties or reputational damage, particularly for organizations reliant on stable IT infrastructure. Not including On-site Support will lead to billable service if on-site support is required.
 
Disclaimer: While On-site Support significantly reduces downtime and resolves complex IT issues, no service can guarantee immediate resolution for all scenarios due to factors like part availability or unforeseen complexities. Timely reporting of issues and adherence to recommended maintenance practices are advised to maximize benefits. Remote support and proactive monitoring are recommended to minimize the need for on-site interventions.
Description: Password Manager is a service that provides a secure, centralized platform for generating, storing, and managing complex passwords for users across an organization’s applications and systems. It enables employees to create strong, unique passwords without needing to memorize them, using encrypted vaults accessible via a single master password or multi-factor authentication. The service includes features like secure password sharing, automated password rotation, and integration with single sign-on systems. Administrators can enforce password policies, monitor usage, and generate compliance reports. Clients receive setup assistance, user training, and helpdesk support for troubleshooting based on their support agreement.
 
Purpose: The purpose of Password Manager is to enhance cybersecurity by ensuring strong, unique passwords are used consistently, reducing the risk of credential theft or unauthorized access. It simplifies password management for employees, boosting productivity while protecting sensitive data and systems from breaches. The service supports compliance with regulations by enforcing secure password practices and providing audit trails, fostering a secure and efficient IT environment.
 
Risks of Not Implementing: Without a Password Manager, employees may use weak, reused, or easily guessed passwords, significantly increasing the risk of data breaches, phishing attacks, or account takeovers. Manual password management can lead to forgotten credentials, reducing productivity and burdening IT teams with reset requests. Lack of centralized oversight makes it difficult to enforce secure password practices, risking non-compliance with regulatory requirements. Unmanaged credentials also heighten the potential for insider threats or unauthorized access, leading to financial losses or reputational damage.
 
Disclaimer: While Password Manager greatly strengthens credential security, no solution can fully eliminate risks, particularly from social engineering or user errors like sharing master passwords. Regular employee training, adherence to security policies, and complementary measures like multi-factor authentication are recommended to maximize protection.
Description: Patch Management is a service that systematically manages the deployment of software updates and security patches for operating systems, applications, and devices across an organization’s IT environment. It includes identifying, testing, and applying patches to address vulnerabilities, enhance performance, and ensure compatibility. The service uses automated tools to schedule updates during low-impact periods, minimizing disruption, and provides centralized monitoring to verify successful deployment. Clients receive regular reports on patch status and compliance, with helpdesk support for troubleshooting issues during business hours. Critical patches are prioritized to address high-risk vulnerabilities promptly. Triada updates occur a minimum of 7 days after the patch is released, to minimize patch related problems. If there is an emergency and a vulnerability is actively being exploited, the patch timing will be moved up acccordingly.
 
Purpose: The purpose of Patch Management is to maintain the security, stability, and performance of IT systems by closing vulnerabilities that could be exploited by cyber threats like malware or ransomware. It reduces the risk of breaches, ensures software operates efficiently, and supports compliance with regulations requiring up-to-date systems, such as GDPR, HIPAA, or PCI-DSS. By automating and streamlining updates, the service minimizes administrative burdens and prevents disruptions from unpatched systems.
 
Risks of Not Implementing: Without Patch Management, unpatched vulnerabilities can be exploited by attackers, leading to data breaches, ransomware attacks, or system compromises that cause financial losses and downtime. Outdated software may degrade performance or cause compatibility issues, reducing productivity. Lack of centralized patch oversight increases the likelihood of missed updates, leaving systems exposed to known exploits. Failure to maintain patched systems risks non-compliance with regulatory standards, potentially resulting in penalties or reputational damage.
 
Disclaimer: While Patch Management significantly enhances system security and performance, no solution can eliminate all risks, as new vulnerabilities may emerge before patches are available. Timely application of patches, adherence to recommended schedules, and complementary security practices are advised to maximize protection. Regular monitoring and prompt reporting of issues are recommended to ensure effectiveness. Most patches and updates will require computer reboots for them to take affect, weekly reboots are recommended.
Description: Internal Penetration Testing is a cybersecurity service that simulates real-world cyberattacks within an organization’s internal network to identify vulnerabilities and weaknesses. Conducted by certified security professionals, it assesses systems, applications, and devices accessible from inside the network, such as employee workstations, servers, or databases. The service uses controlled techniques like privilege escalation, lateral movement, or configuration exploits to uncover risks. Clients receive a detailed report with findings, risk levels, and actionable remediation recommendations, along with follow-up support to verify fixes. Testing is scheduled to minimize disruption, with results aligned to frameworks like NIST or CIS.
 
Purpose: The purpose of Internal Penetration Testing is to proactively identify and address security gaps that could be exploited by insiders or attackers who gain internal access, such as through phishing or compromised credentials. It strengthens defenses, protects sensitive data, and supports compliance with regulations like GDPR, HIPAA, or PCI-DSS by demonstrating due diligence. The service enhances overall security posture, reducing the risk of data breaches or operational disruptions from internal threats.
 
Risks of Not Implementing: Without Internal Penetration Testing, undetected vulnerabilities within the network may allow attackers or malicious insiders to access sensitive systems, leading to data breaches, financial losses, or ransomware attacks. Weak configurations or unpatched systems can be exploited, escalating damage across the organization. Lack of testing increases the risk of non-compliance with regulations requiring proactive security measures, potentially resulting in penalties or reputational harm. Unaddressed internal risks may also erode client trust and disrupt business operations if exploited.
 
Disclaimer: While Internal Penetration Testing significantly improves security by identifying internal vulnerabilities, no solution can guarantee complete protection against all threats, as new vulnerabilities may emerge. Implementing recommended fixes, maintaining complementary security practices, and conducting regular testing are advised to maximize benefits. Prompt action on findings is essential to ensure effectiveness.
Description: External Penetration Testing is a cybersecurity service that simulates real-world cyberattacks from outside an organization’s network to identify vulnerabilities in internet-facing systems, such as websites, servers, firewalls, or cloud applications. Conducted by certified security professionals, it uses controlled techniques like scanning, exploitation, or social engineering to uncover weaknesses in external defenses. The service provides a detailed report with findings, risk assessments, and prioritized remediation recommendations, along with follow-up support to verify fixes. Testing is scheduled to avoid disruptions, with methodologies aligned to frameworks like NIST or CIS for consistency and compliance.
 
Purpose: The purpose of External Penetration Testing is to proactively detect and address security flaws in systems exposed to the internet, reducing the risk of exploitation by external attackers. It strengthens defenses against threats like data breaches, malware, or unauthorized access, protecting sensitive data and maintaining operational reliability. The service supports compliance with regulations like GDPR, HIPAA, or PCI-DSS by demonstrating proactive security efforts, enhancing trust with clients and stakeholders.
 
Risks of Not Implementing: Without External Penetration Testing, vulnerabilities in internet-facing systems may go undetected, allowing attackers to exploit weaknesses, leading to data breaches, ransomware, or service disruptions. Unsecured external assets can serve as entry points for broader network attacks, causing financial losses and reputational damage. Lack of testing increases the risk of non-compliance with regulations requiring robust security measures, potentially resulting in penalties. Unaddressed external risks may also undermine client confidence and disrupt business operations if exploited.
 
Disclaimer: While External Penetration Testing significantly enhances security by identifying external vulnerabilities, no solution can guarantee absolute protection against all threats, as new vulnerabilities may emerge. Implementing recommended fixes, maintaining complementary security practices, and conducting regular testing are advised to maximize benefits. Prompt action on findings is essential to ensure effectiveness.
Description: Web Application/API Penetration Testing is a cybersecurity service that evaluates the security of web applications by simulating real-world cyberattacks. Conducted by certified security professionals, it targets vulnerabilities in web-based systems, such as online portals, e-commerce platforms, or internal applications, using techniques like SQL injection, cross-site scripting (XSS), or authentication bypass. The service includes a thorough assessment of application code, configurations, and APIs, aligned with frameworks like OWASP or NIST. Clients receive a detailed report with findings, risk levels, and prioritized remediation recommendations, along with follow-up support to verify fixes. Testing is scheduled to minimize disruptions to application availability.
 
Purpose: The purpose of Web Application Penetration Testing is to identify and mitigate vulnerabilities in web applications that could be exploited by attackers, preventing data breaches, unauthorized access, or service disruptions. It ensures the security of sensitive user data, such as personal or financial information, and maintains application reliability. The service supports compliance with regulations like GDPR, PCI-DSS, or HIPAA by demonstrating proactive security measures, enhancing trust with users and stakeholders.
 
Risks of Not Implementing: Without Web Application Penetration Testing, vulnerabilities in web applications may remain undetected, allowing attackers to exploit weaknesses, leading to data theft, financial losses, or compromised user accounts. Unsecured applications can disrupt services, erode customer trust, and cause reputational damage. Lack of testing increases the risk of non-compliance with regulations requiring secure handling of sensitive data, potentially resulting in penalties. Unaddressed flaws may also enable attackers to gain broader network access, escalating the impact on business operations.
 
Disclaimer: While Web Application Penetration Testing significantly strengthens application security, no solution can eliminate all risks, as new vulnerabilities may emerge over time. Implementing recommended fixes, maintaining secure development practices, and conducting regular testing are advised to maximize protection. Prompt action on findings is essential to ensure effectiveness.
Description: Social Engineering Penetration Testing is a cybersecurity service that simulates real-world social engineering attacks, such as phishing, pretexting, or impersonation, to evaluate an organization’s susceptibility to human-targeted threats. Conducted by certified security professionals, it assesses employee awareness and response to manipulative tactics aimed at gaining unauthorized access to systems, data, or facilities. Techniques include simulated phishing emails, phone-based scams, or physical tailgating attempts, tailored to the organization’s environment. Clients receive a detailed report with findings, risk levels, and recommendations for training and policy improvements, along with follow-up support to implement fixes. Testing is conducted discreetly to minimize disruption and aligned with frameworks like NIST or CIS.
 
Purpose: The purpose of Social Engineering Penetration Testing is to identify weaknesses in employee behavior and organizational processes that could be exploited by attackers, reducing the risk of data breaches, credential theft, or unauthorized access. It strengthens defenses by highlighting the need for enhanced training and policies, ensuring employees are better equipped to recognize and resist social engineering tactics. The service supports compliance with regulations like GDPR or HIPAA by demonstrating proactive security awareness efforts, fostering a security-conscious culture.
 
Risks of Not Implementing: Without Social Engineering Penetration Testing, employees may fall victim to phishing or other social engineering attacks, leading to compromised credentials, data breaches, or malware infections that disrupt operations and cause financial losses. Untrained staff or weak policies can serve as easy entry points for attackers, escalating risks across systems. Lack of testing increases the likelihood of non-compliance with regulations requiring employee security awareness, potentially resulting in penalties or reputational damage. Unaddressed vulnerabilities in human defenses may undermine overall security efforts, eroding client trust.
 
Disclaimer: While Social Engineering Penetration Testing significantly improves employee awareness and organizational resilience, no solution can fully eliminate the risk of human error or sophisticated attacks. Ongoing employee training, adherence to security policies, and regular testing are recommended to maximize protection. Prompt implementation of recommendations is essential to ensure effectiveness.
Description: Phishing Simulationsis a service that conducts controlled, mock phishing campaigns to test and improve employees’ ability to recognize and respond to phishing emails. Customized, realistic email scenarios are sent to employees, mimicking common tactics like fraudulent links or urgent requests. The service tracks user responses, such as clicks or data submissions, and provides immediate feedback or brief training to those who fall for the simulation. Clients receive detailed reports on campaign results, employee performance, and trends, with recommendations for further training. Ongoing simulations are scheduled to maintain awareness, supported by helpdesk assistance during business hours.
 
Purpose: The purpose of Phishing Simulations, when paired with Security Awareness Training, is to strengthen employee defenses against phishing attacks, a leading cause of data breaches, by training them to identify and avoid malicious emails. It reduces the likelihood of employees clicking harmful links or sharing sensitive information, protecting business data and systems. The service supports compliance with regulations by demonstrating proactive security awareness efforts, fostering a vigilant workforce.
 
Risks of Not Implementing: Without Phishing Simulations, employees may be unprepared to recognize phishing emails, increasing the risk of data breaches, malware infections, or credential theft, which can lead to financial losses and operational disruptions. Untrained staff are more vulnerable to sophisticated phishing tactics, weakening overall security. Lack of testing and feedback may result in non-compliance with regulations requiring employee security training, risking penalties or reputational damage. Unaddressed vulnerabilities in employee awareness can undermine broader cybersecurity efforts.
 
Disclaimer: While Phishing Simulations significantly improve employee awareness and reduce phishing risks, no solution can guarantee all employees will always avoid malicious emails, especially with evolving attack methods. Regular simulations, combined with ongoing training and complementary security measures, are advised to maximize protection. Encouraging prompt reporting of suspicious emails is essential for effectiveness.
Description: Privileged Access Management (PAM) is a cybersecurity service that controls and monitors access to critical systems, applications, and data by users with elevated permissions, such as IT administrators or technicians. It ensures only authorized individuals can access sensitive resources through secure methods like multi-factor authentication, role-based permissions, and temporary, just-in-time access. PAM eliminates shared admin credentials by allowing technicians to log in as themselves with limited, specific privileges. It includes automated password rotation, detailed permission controls, and audit logs to track access activities. The service is managed via a centralized dashboard, simplifying oversight across multiple clients or environments.
 
Purpose: PAM secures privileged accounts, which have access to sensitive systems and data, making them high-risk targets for cyberattacks. By enforcing minimal access rights and automating credential management, PAM reduces the chance of unauthorized access or misuse. It also streamlines administrative tasks, improves accountability with clear access records, and supports compliance with regulations requiring strict access controls.
 
Risks of Not Implementing: Without PAM, privileged accounts may rely on shared or unmanaged credentials, increasing the risk of unauthorized access, data breaches, or insider threats. Weak access controls can allow attackers to exploit sensitive systems, leading to data loss, system downtime, or ransomware incidents. Lack of audit logs makes it hard to trace access events, complicating incident response. Failure to secure privileged accounts may also result in non-compliance with industry regulations, leading to penalties and reputational harm.
Description: Procurement Services is a where Triada handles the sourcing, purchasing, and deployment of IT hardware, software, and services to meet an organization’s technology needs. The service begins with a needs assessment to identify requirements, followed by vendor selection, price negotiation, and acquisition of products like workstations, servers, or licenses. Triada ensures compatibility with existing systems, coordinates delivery, and oversees installation or configuration as needed. The service includes ongoing vendor management, warranty tracking, and lifecycle planning for replacements or upgrades. 
 
Purpose: The purpose of Procurement Services is to streamline the acquisition of IT resources, ensuring cost-effective, reliable, and compatible solutions that align with business goals. It saves time and reduces the complexity of managing multiple vendors, allowing organizations to focus on core operations. The service supports compliance by ensuring purchases meet regulatory or security standards, while optimizing budgets and maintaining a modern, efficient IT environment.
 
Risks of Not Implementing: Without Procurement Services, organizations may face inefficient purchasing processes, leading to overpaying for IT resources, acquiring incompatible systems, or delays in deployment that disrupt operations. Poor vendor selection or lack of lifecycle planning can result in outdated hardware or software, increasing maintenance costs and security vulnerabilities. Unmanaged procurement may overlook compliance requirements, risking penalties or operational inefficiencies. Without expert oversight, organizations may struggle with warranty issues or miss cost-saving opportunities, impacting financial performance.
 
Disclaimer: While Procurement Services significantly improves efficiency and cost-effectiveness in IT acquisitions, no solution can guarantee perfect outcomes due to market fluctuations or unforeseen compatibility issues. Adherence to recommended specifications and timely communication of needs are advised to maximize benefits. Complementary IT planning and maintenance practices are recommended to ensure long-term success.
Description: Remote Help Desk Support is a service that provides prompt, expert technical assistance to employees for IT-related issues via phone, email, or secure remote access tools. It covers troubleshooting for hardware, software, network connectivity, and application errors, as well as user account management and basic training on tools like Microsoft 365 or Google Workspace. The service operates during business hours, with ticketing systems to track issues and ensure timely resolution. Clients receive regular reports on support activity and resolution metrics, with escalation paths for complex issues requiring onsite or specialized support.
 
Purpose: The purpose of Remote Help Desk Support is to maintain employee productivity and system reliability by quickly resolving IT issues without the need for onsite intervention. It reduces downtime, alleviates the burden on internal IT teams, and ensures consistent user experiences across the organization. The service supports compliance by enforcing secure access protocols and documenting support activities, helping businesses maintain operational efficiency and user satisfaction.
Risks of Not Implementing: Without Remote Help Desk Support, unresolved IT issues can lead to prolonged downtime, reduced employee productivity, and frustration, impacting business operations. Lack of centralized support may overwhelm internal resources or result in inconsistent resolutions, increasing costs and security risks. Unaddressed user errors or system issues can escalate into larger problems, such as data loss or vulnerabilities. Failure to provide documented support processes may also hinder compliance with regulations requiring secure IT management, risking penalties or reputational damage.
 
Disclaimer: While Remote Help Desk Support significantly improves IT issue resolution and user productivity, no service can address all issues remotely or guarantee instant fixes due to complex problems or external dependencies. Timely reporting of issues and adherence to provided guidance are advised to maximize benefits. Complementary onsite support or specialized services may be required for certain scenarios.
Description: Remote Server Management and Monitoring is a service that oversees the performance, security, and maintenance of an organization’s servers, whether physical, virtual, or cloud-based. It includes monitoring of server health metrics, such as CPU, memory, disk usage, and network activity, using automated tools to detect issues like performance bottlenecks or potential failures. The service encompasses proactive maintenance tasks, including patch management, security updates, and backup verification, all performed remotely. Clients receive regular reports on server status, security events, and maintenance activities, with helpdesk support for troubleshooting and escalations during business hours.
 
Purpose: The purpose of Remote Server Management and Monitoring is to ensure servers operate reliably, securely, and efficiently, minimizing downtime and supporting critical business applications. It proactively addresses vulnerabilities and performance issues to prevent disruptions, while optimizing resource usage to meet demand. The service supports compliance with regulations by maintaining secure configurations and audit trails, allowing organizations to focus on operations with confidence in their server infrastructure.
 
Risks of Not Implementing: Without Remote Server Management and Monitoring, unaddressed server issues can lead to outages, data loss, or performance degradation, disrupting business operations and impacting productivity. Unpatched vulnerabilities or lack of monitoring may expose servers to cyberattacks, such as ransomware or data breaches, causing financial and reputational damage. Inefficient resource management can result in overprovisioning or underperformance, increasing costs. Failure to maintain compliant server configurations risks regulatory penalties, while undetected failures may escalate into costly recovery efforts.
 
Disclaimer: While Remote Server Management and Monitoring significantly enhances server reliability and security, no solution can eliminate all risks due to evolving threats or hardware limitations. Timely reporting of issues, adherence to maintenance schedules, and complementary security practices are advised to maximize benefits. Certain issues may require onsite support or specialized intervention, depending on the service plan.
Description: Remote Server Support is a service that provides expert technical assistance for server-related issues, ensuring the smooth operation of physical, virtual, or cloud-based servers. It includes troubleshooting for hardware failures, software errors, connectivity issues, or performance problems, performed via secure remote access tools. The service covers user access management, configuration adjustments, and assistance with server applications, with support available during business hours through a ticketing system. Clients receive detailed resolution reports and recommendations for preventive measures, with escalation options for complex issues requiring specialized or onsite intervention.
 
Purpose: The purpose of Remote Server Support is to quickly resolve server issues to minimize downtime and maintain business continuity. It ensures servers remain operational and accessible, supporting critical applications and data storage without burdening internal IT teams. The service enhances system reliability, improves user productivity, and supports compliance with regulations like GDPR or HIPAA by documenting support activities and maintaining secure server environments.
 
Risks of Not Implementing: Without Remote Server Support, unresolved server issues can lead to prolonged outages, disrupting critical business operations and causing financial losses. Lack of timely support may exacerbate problems, such as data access failures or application downtime, reducing productivity and user satisfaction. Unaddressed configuration errors or vulnerabilities can increase the risk of cyberattacks, compromising sensitive data. Failure to provide documented support processes may also hinder compliance with regulatory requirements, risking penalties or reputational damage.
 
Disclaimer: While Remote Server Support significantly improves server reliability and issue resolution, no service can guarantee instant fixes for all issues due to complex dependencies or hardware limitations. Timely reporting of problems and adherence to provided guidance are advised to maximize benefits. Complementary services, such as onsite support or specialized management, may be required for certain scenarios.
Description: Risk Assessment is a systematic service that identifies, evaluates, and prioritizes potential cybersecurity risks to an organization’s IT systems, data, and operations. It involves analyzing assets, vulnerabilities, and threats through interviews, system scans, and policy reviews. The assessment aligns with industry-standard frameworks like the Center for Internet Security (CIS) Controls, which focus on prioritized security practices, and the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which emphasizes risk management through identify, protect, detect, respond, and recover functions. The service delivers a detailed report with findings, risk ratings, and actionable recommendations to mitigate identified risks.
 
Purpose: The purpose of Risk Assessment is to provide a clear understanding of an organization’s security posture, enabling informed decisions to protect critical assets. By identifying vulnerabilities and potential threats, it helps prioritize security investments and implement controls to reduce risk. Aligning with frameworks like CIS and NIST ensures a structured approach, supports compliance with regulations, and strengthens defenses against cyberattacks, data breaches, and operational disruptions.
 
Risks of Not Implementing: Without a Risk Assessment, organizations lack visibility into vulnerabilities, leaving systems exposed to undetected threats like malware, phishing, or insider attacks. Unaddressed risks can lead to data breaches, financial losses, or reputational damage. Without a structured framework like CIS or NIST, security efforts may be inconsistent or inadequate, increasing the likelihood of non-compliance with industry regulations, which can result in penalties. Failing to prioritize risks may also lead to inefficient resource allocation, leaving critical assets unprotected and hindering recovery from incidents.
Description: Secure Access Service Edge (SASE) is a cloud-based service that makes it safe and easy for employees to access company applications and data from anywhere. It combines tools to protect against online threats, secure internet connections, and ensure fast, reliable access to resources. The service is managed remotely, with automatic updates and consistent security rules applied across all users. Clients receive regular reports on system performance and security, plus helpdesk support for setup or issues as per agreement.
Purpose: The purpose of SASE is to deliver secure, scalable, and efficient access to cloud and on-premises resources, supporting remote work and distributed teams. It protects against cyber threats like malware, phishing, or unauthorized access by enforcing consistent security policies across all connections. SASE simplifies network management, reduces reliance on traditional VPNs, and supports compliance with regulations by providing robust security and audit capabilities, ensuring seamless and safe user experiences.
 
Risks of Not Implementing: Without SASE, organizations may struggle to secure remote access, leaving data and applications vulnerable to breaches, malware, or unauthorized access, especially in distributed work environments. Traditional VPNs or disjointed security tools can lead to performance bottlenecks, increasing latency and reducing productivity. Lack of unified security and network management heightens the risk of misconfigurations or unaddressed vulnerabilities, potentially causing financial losses or reputational damage. Non-compliance with regulations requiring secure access controls may result in penalties or loss of client trust.
 
Disclaimer: While SASE significantly enhances network security and performance, no solution can fully eliminate risks due to evolving cyber threats or user errors. Adherence to recommended policies, regular monitoring, and complementary security practices are advised to maximize protection. Prompt reporting of issues and ongoing user training are recommended to ensure effectiveness.
Description: Secure Browsing is a service that enhances web browser security through a lightweight browser extension, creating a managed, protected workspace. It provides detailed reporting on browser activity, analyzes employee credentials to identify weak, reused, or compromised passwords, and prevents unauthorized data uploads to personal email or non-corporate apps. The service blocks malicious phishing links and inappropriate websites, such as those related to gambling or adult content, and includes features like on-screen data masking and webpage watermarking for added protection.
 
Purpose: The purpose of Secure Browsing is to safeguard the web browser, a critical workspace for employees using Software as a Service (SaaS) and web applications, by offering visibility into user behavior and data flow. It strengthens security by mitigating risks like data leakage, malware, and phishing attacks while supporting remote work without heavy reliance on Virtual Private Networks (VPNs). The service ensures compliance and protects sensitive data without disrupting user workflows.
 
Risks of Not Implementing: Without Secure Browsing, browsers remain vulnerable to phishing, malware, and data breaches due to limited visibility into web activity. Weak or compromised credentials may go undetected, increasing the risk of unauthorized access. Employees could inadvertently upload sensitive data to unsecured apps, leading to data loss or compliance violations. Unblocked malicious websites heighten exposure to cyber threats, potentially causing operational disruptions or reputational damage.
Description: Security Awareness Training is a service that educates employees on recognizing and responding to cyber threats, such as phishing emails, social engineering, or unsafe online practices. Delivered through engaging online modules, live workshops, or simulated attacks (like mock phishing campaigns), the training covers topics like password hygiene, safe internet use, and data protection. The service includes regular assessments to measure progress, customizable content to fit organizational needs, and reports on employee performance. Ongoing support provides updated training materials and helpdesk assistance for questions during business hours.
 
Purpose: The purpose of Security Awareness Training is to empower employees to act as the first line of defense against cyberattacks by making informed security decisions. It reduces the risk of breaches caused by human error, such as clicking malicious links or sharing sensitive information. The service fosters a security-conscious culture, supports compliance with regulations like GDPR, HIPAA, or PCI-DSS, and protects business operations by minimizing vulnerabilities tied to employee behavior.
 
Risks of Not Implementing: Without Security Awareness Training, employees may unknowingly fall victim to phishing, social engineering, or other attacks, leading to data breaches, ransomware, or financial losses. Untrained staff are more likely to mishandle sensitive data, increasing the risk of compliance violations and regulatory penalties. Lack of awareness can weaken overall security efforts, allowing threats to exploit human vulnerabilities, disrupting operations, and damaging reputation or client trust.
 
Disclaimer: While Security Awareness Training significantly reduces risks tied to human error, no program can eliminate all threats, as sophisticated attacks or lapses in judgment may still occur. Regular training updates, employee engagement, and complementary security measures are advised to maximize effectiveness. Prompt reporting of suspicious activities is essential to ensure protection.
Description: The Security Operations Center (SOC) is a managed service that provides 24/7 monitoring, detection, and response to cyber threats across an organization’s IT environment, including networks, endpoints, and cloud systems. Operated by a team of security analysts, the SOC uses advanced tools to analyze logs, detect suspicious activities, and investigate potential incidents like malware, phishing, or unauthorized access. The service includes real-time alerts, incident containment, and remediation guidance, with detailed reports on threats and response actions. Clients have access to a secure portal for updates and helpdesk support for inquiries during business hours.
 
Purpose: The purpose of the SOC is to proactively protect an organization’s data and systems by identifying and neutralizing threats before they cause significant harm. It ensures rapid response to incidents, minimizing damage and downtime, while providing comprehensive visibility into security events. The service supports compliance with regulations through continuous monitoring and documented incident handling, enhancing trust and operational resilience.
 
Risks of Not Implementing: Without a SOC, organizations may fail to detect or respond to cyber threats in time, leading to data breaches, ransomware, or system disruptions that cause financial losses and reputational damage. Lack of 24/7 monitoring leaves vulnerabilities unaddressed, allowing attacks to escalate. Delayed or inadequate incident response can prolong recovery, increasing costs. Failure to maintain continuous security oversight risks non-compliance with regulations, potentially resulting in penalties or loss of client confidence.
 
Disclaimer: While the SOC significantly strengthens threat detection and response, no solution can eliminate all risks due to evolving cyber threats or complex IT environments. Regular system updates, employee training, and adherence to recommended security practices are advised to maximize protection. Prompt collaboration and reporting of issues are essential for optimal effectiveness.
Description: Security Incident & Event Monitoring (SIEM) is a service that continuously collects and analyzes log data from IT systems, networks, and applications to detect and respond to potential security incidents. It uses advanced analytics to identify unusual activity, such as unauthorized access or malware, and correlates events across environments for comprehensive threat detection. The service provides real-time alerts, automated incident prioritization, and detailed reports on security events. Managed remotely, it includes 24/7 monitoring by security experts, with helpdesk support for incident response guidance during business hours.
 
Purpose: The purpose of SIEM is to proactively identify and mitigate security threats before they escalate into breaches, ensuring the protection of sensitive data and systems. It enhances visibility into IT environments, enabling rapid response to incidents and minimizing damage or downtime. The service supports compliance with regulations like GDPR, HIPAA, or PCI-DSS by providing audit-ready logs and demonstrating proactive security monitoring, maintaining operational integrity and stakeholder trust.
 
Risks of Not Implementing: Without SIEM, organizations may fail to detect threats like data breaches, ransomware, or insider attacks in time, leading to significant financial losses, data exposure, or reputational damage. Lack of centralized monitoring leaves blind spots, delaying incident response and increasing recovery costs. Unmonitored systems are more vulnerable to exploitation, and without detailed logs, proving compliance with regulatory requirements becomes challenging, risking penalties. Delayed or missed threat detection can disrupt operations and erode client confidence.
 
Disclaimer: While SIEM significantly enhances threat detection and response, no solution can eliminate all risks due to evolving cyber threats or system complexities. Regular system updates, adherence to security policies, and complementary measures like employee training are advised to maximize protection. Prompt action on alerts and ongoing collaboration with security teams are essential for effectiveness.
Description: Server File Backup, Direct to Cloud is a service that securely backs up critical files from physical or virtual servers to an encrypted cloud platform. Triada installs and configures backup agents remotely, selecting essential files for protection based on client needs. Incremental backups are scheduled to minimize server impact, with daily checks to verify success and immediate alerts for any failures, resolved promptly. Clients can initiate file restores through a secure online portal, supported by our helpdesk remotely. Quarterly reports detail data availability and integrity. This service is integrated with our broader Backup and Disaster Recovery (BDR) Services policy.
 
Purpose: The purpose of Server File Backup, Direct to Cloud is to protect critical server data from loss due to hardware failures, cyberattacks, or human errors, ensuring quick recovery with minimal downtime. It provides a secure, offsite storage solution for business continuity, supporting remote access to restored files. The service simplifies backup management and supports compliance with data protection regulations like GDPR or HIPAA by maintaining secure, verifiable data copies.
 
Risks of Not Implementing: Without Server File Backup, Direct to Cloud, server data is at risk of permanent loss from ransomware, hardware crashes, or accidental deletions, leading to operational disruptions and financial losses. Lack of offsite backups delays recovery, as local data may be inaccessible or corrupted. Unverified backups increase the chance of restore failures, prolonging downtime. Failure to maintain secure data copies risks non-compliance with regulations, potentially resulting in penalties or reputational damage.
 
Disclaimer: Review Backup and Disaster Recovery Services Policies
Description: Server Image Backup, Direct to Cloud is a service that creates full-system snapshots of physical or virtual servers, including operating systems, applications, settings, and data, and stores them securely in an encrypted cloud platform. Triada remotely installs and configures backup agents to capture complete server images, with incremental backups scheduled to minimize server impact. Daily verification checks ensure backup integrity, with immediate alerts for issues resolved promptly. Clients can initiate full or partial restores via a secure portal, guided by our help Carlyle during business hours. Quarterly reports confirm data availability and integrity. This service is part of our Backup and Disaster Recovery (BDR) Services policy.
 
Purpose: The purpose of Server Image Backup, Direct to Cloud is to protect entire server environments from loss due to hardware failures, ransomware, or disasters, enabling rapid recovery of systems and data with minimal downtime. It ensures business continuity by providing secure, offsite backups accessible for full system restoration or file-level recovery. The service supports compliance with data protection regulations like GDPR or HIPAA by maintaining secure, verifiable server images, simplifying disaster recovery.
 
Risks of Not Implementing: Without Server Image Backup, Direct to Cloud, server failures or cyberattacks can result in significant data and system loss, leading to extended downtime and operational disruptions. Lack of offsite image backups complicates recovery, as rebuilding servers from scratch is time-consuming and costly. Unverified backups risk restore failures, delaying critical operations. Failure to maintain secure system images may lead to non-compliance with regulations, risking penalties or reputational damage.
 
Disclaimer: Review Backup and Disaster Recovery Services Policies
Description: Technology Alignment is a service that optimizes an organization’s IT environment to support business goals, enhance efficiency, and minimize disruptions. A dedicated Technology Alignment Manager (TAM) conducts an onsite assessment, evaluating hardware, software, and cloud services against industry frameworks, compliance standards, and support ticket trends. Using diagnostic tools and configuration audits, we identify risks and inefficiencies, providing tailored recommendations to prevent issues. Assessments are performed with minimal disruption, including brief check-ins and end-of-day summaries shared via a secure client portal. Detailed records of the IT environment are maintained for consistent future implementations. Clients receive quarterly reports on reduced support tickets, improved productivity, and progress toward key performance indicators, with ongoing support to ensure sustained alignment.
 
Purpose: The purpose of Technology Alignment is to transform IT into a strategic asset that drives business success by ensuring systems are reliable, secure, and aligned with organizational objectives. It proactively addresses technical risks, reduces outages, and optimizes performance, enabling employees to work efficiently. The service supports compliance with regulations by maintaining standardized, auditable IT configurations, fostering a competitive edge through a proactive IT partnership.
 
Risks of Not Implementing: Without Technology Alignment, misaligned or outdated IT systems can lead to frequent outages, reduced productivity, and increased support costs, hindering business operations. Unidentified risks or inefficiencies may result in security vulnerabilities, data breaches, or system failures, causing financial losses and reputational damage. Lack of standardized assessments risks non-compliance with regulatory requirements, potentially leading to penalties. Without proactive alignment, organizations may miss opportunities to leverage technology for growth, falling behind competitors.
 
Disclaimer: While Technology Alignment significantly enhances IT reliability and business outcomes, no solution can eliminate all risks due to evolving technology or unforeseen challenges. Adherence to recommendations, regular assessments, and complementary IT practices are advised to maximize benefits. Prompt communication of changes or issues is essential to ensure ongoing alignment and effectiveness.
 
 
Description: Technology Documentation is a service that creates and maintains comprehensive, organized records of an organization’s IT environment, including hardware, software, network configurations, and security policies. The process begins with an assessment to catalog systems and settings, followed by the development of clear, standardized documentation tailored to the client’s needs. Documents may include network diagrams, system inventories, user guides, and disaster recovery plans. Triada updates records regularly to reflect changes, ensures secure storage, and provides access via a client portal. Clients receive quarterly documentation reviews and helpdesk support for inquiries during business hours.
 
Purpose: The purpose of Technology Documentation is to provide a clear, up-to-date reference of the IT environment, enabling efficient troubleshooting, onboarding, and disaster recovery. It enhances operational continuity by ensuring critical information is accessible during system failures or staff transitions. The service supports compliance with regulations like GDPR, HIPAA, or PCI-DSS by maintaining auditable records of configurations and security measures, reducing risks and streamlining IT management.
 
Risks of Not Implementing: Without Technology Documentation, organizations may face delays or errors in troubleshooting, system recovery, or onboarding due to missing or outdated IT records, leading to downtime and increased costs. Lack of clear documentation complicates compliance audits, risking penalties or reputational damage for failing to meet regulatory standards. Inconsistent or incomplete records can hinder disaster recovery efforts, prolonging disruptions. Un-documented systems also increase reliance on individual staff knowledge, creating vulnerabilities during turnover or emergencies.
 
Disclaimer: While Technology Documentation significantly improves IT management and compliance, no solution can account for all unforeseen changes or eliminate risks from external factors. Regular updates, adherence to documentation protocols, and complementary IT practices are advised to maximize benefits. Prompt reporting of system changes is essential to ensure accuracy and effectiveness.
Description: Threat Intelligence is a service that collects, analyzes, and shares information about current and emerging cyber threats, such as malware, phishing campaigns, or vulnerabilities, to enhance an organization’s security posture. It aggregates data from global sources, including dark web monitoring, industry reports, and real-time attack trends, to provide actionable insights. The service delivers tailored alerts, risk assessments, and recommendations for mitigating threats, integrated into existing security tools like firewalls or SIEM systems. Clients receive regular reports on threat trends and mitigation outcomes, with helpdesk support for inquiries during business hours.
 
Purpose: The purpose of Threat Intelligence is to proactively inform and prepare organizations to defend against cyber threats by understanding attacker tactics, vulnerabilities, and trends. It enables faster, more informed decision-making to prevent attacks, strengthen defenses, and reduce risk. The service supports compliance with regulations like GDPR, HIPAA, or PCI-DSS by demonstrating proactive risk management, helping protect sensitive data and maintain operational continuity.
 
Risks of Not Implementing: Without Threat Intelligence, organizations may be unaware of emerging threats, leaving systems vulnerable to undetected attacks like zero-day exploits, ransomware, or targeted phishing, leading to data breaches or financial losses. Lack of proactive insights delays response to new vulnerabilities, increasing damage and recovery costs. Uninformed security measures may fail to address evolving risks, risking non-compliance with regulations and resulting in penalties or reputational harm. Blind spots in threat awareness can also weaken overall security, eroding client trust.
 
Disclaimer: While Threat Intelligence significantly enhances proactive defense against cyber threats, no solution can predict or prevent all attacks due to the dynamic nature of cybercrime. Regular integration of intelligence, adherence to recommendations, and complementary security practices are advised to maximize protection. Prompt action on alerts and ongoing collaboration are essential for effectiveness.
Description: Voice over IP (VoIP) Services provide a cloud-based phone system that enables voice calls, video conferencing, and messaging over the internet, replacing traditional phone lines. The service includes setup and configuration of VoIP phones, mobile apps, and desktop clients, tailored to the organization’s needs. Triada manages call routing, voicemail, and features like auto-attendants or call analytics, with ongoing maintenance to ensure quality and reliability. Clients receive regular reports on call performance and system status, with helpdesk support for troubleshooting during business hours. The service integrates with tools like Microsoft 365 for streamlined communication.
 
Purpose: The purpose of VoIP Services is to deliver a flexible, cost-effective communication solution that supports remote and on-site teams, enhancing collaboration and customer interactions. It ensures clear, reliable calls and messaging while reducing costs compared to traditional phone systems. The service supports compliance with data protection regulations by securing voice and message data, helping businesses maintain efficient and professional communication.
 
Risks of Not Implementing: Without VoIP Services, organizations may rely on outdated or costly phone systems, limiting flexibility for remote work and increasing communication expenses. Poor call quality or unreliable systems can disrupt customer service and internal collaboration, harming productivity and reputation. Lack of modern features like call analytics or integration with business tools may hinder efficiency. Unsecured communication channels risk data exposure, potentially leading to non-compliance with regulations, penalties, or loss of client trust.
 
Disclaimer: While VoIP Services significantly improve communication reliability and efficiency, no solution can guarantee uninterrupted service due to internet connectivity issues or external disruptions. Adherence to recommended network configurations and prompt reporting of issues are advised to maximize benefits. Complementary IT practices, such as network monitoring, are recommended to ensure optimal performance.
Description: Website Design is a service that creates professional, user-friendly websites tailored to an organization’s brand and business goals. The process begins with a consultation to understand requirements, followed by the design of a custom or template-based website with features like responsive layouts, contact forms, or e-commerce functionality. Triada handles content integration, search engine optimization (SEO) basics, and accessibility compliance to ensure broad usability. 
 
Purpose: The purpose of Website Design is to establish a strong online presence that engages customers, promotes services, and supports business growth. A well-designed website enhances credibility, improves user experience, and drives traffic through search visibility. The service supports compliance with accessibility standards like WCAG, ensuring inclusivity and reducing legal risks, while providing a platform to showcase the organization’s value and connect with its audience.
 
Disclaimer: While Website Design significantly enhances online presence and user engagement, no solution can guarantee top search rankings or universal user satisfaction due to evolving algorithms and user preferences. Regular content updates, adherence to recommended maintenance, and complementary marketing efforts are advised to maximize benefits. Prompt reporting of issues is essential to ensure ongoing performance and security.
Description: Website Hosting and Management is a service that provides reliable, secure hosting for websites on cloud-based servers, coupled with ongoing management to ensure optimal performance. The service includes setup of hosting environments, domain configuration, and security features like SSL certificates and firewalls. Triada manages regular backups, software updates, and performance monitoring to prevent downtime or vulnerabilities.
 
Purpose: The purpose of Website Hosting and Management is to keep websites running smoothly, securely, and accessible to users, supporting an organization’s online presence and business objectives. It protects against cyber threats, ensures fast load times, and maintains user trust through consistent availability. The service supports compliance with data protection and accessibility regulations, such as GDPR or WCAG, by securing user data and maintaining reliable hosting environments, allowing businesses to focus on engaging their audience.
 
Risks of Not Implementing: Without Website Hosting and Management, websites may suffer from downtime, slow performance, or security breaches, driving away visitors and damaging brand reputation. Unmanaged hosting environments are vulnerable to hacking or data loss, risking customer trust and potential financial losses. Lack of regular updates and backups can lead to prolonged outages or data recovery issues. Failure to meet regulatory standards for data security or accessibility may result in penalties or legal risks, while poor website performance can reduce customer engagement and sales.
 
Disclaimer: While Website Hosting and Management significantly enhances website reliability and security, no solution can guarantee uninterrupted uptime or complete protection against advanced cyber threats. Adherence to recommended security practices, timely content updates, and complementary IT measures are advised to maximize benefits. Prompt reporting of issues is essential to ensure ongoing performance and protection.
Description: Workstation Monitoring and Maintenance is a service that continuously oversees the performance, security, and health of desktop and laptop computers. It involves real-time monitoring of system resources, such as CPU, memory, and disk usage, as well as tracking software updates, security patches, and potential hardware issues. The service includes proactive maintenance tasks like installing updates, optimizing performance, and resolving errors before they escalate. It also provides alerts for suspicious activities or vulnerabilities and generates reports to ensure workstations remain secure and operational, with minimal user disruption.
 
Purpose: The purpose of Workstation Monitoring and Maintenance is to keep workstations running efficiently and securely, reducing the risk of downtime, performance issues, or security breaches. By proactively addressing software vulnerabilities, hardware failures, and system inefficiencies, it enhances productivity and extends device lifespan. The service supports compliance with security standards by ensuring systems are up-to-date and protected, while minimizing the need for reactive IT interventions.
 
Risks of Not Implementing: Without Workstation Monitoring and Maintenance, unaddressed software vulnerabilities or outdated systems can expose workstations to malware, phishing, or other cyberattacks, potentially compromising sensitive data and disrupting operations. Hardware or performance issues may go unnoticed, leading to system slowdowns, crashes, or costly repairs that impact employee productivity. Lack of proactive maintenance increases the likelihood of non-compliance with security regulations, risking penalties or reputational harm. Unmonitored workstations may also accumulate inefficiencies, reducing performance and requiring more extensive, reactive fixes over time.
Description: Workstation Setup is a service that provides professional installation and configuration of desktop and laptop computers to ensure they are ready for immediate use. Triada’s technicians handle the physical setup, including connecting hardware, installing operating systems, and configuring software, security settings, and network access. The service includes user account setup, application installation, and basic training on system use, tailored to client specifications. Performed onsite or remotely when feasible, the process minimizes disruption, with a post-setup checklist provided to confirm functionality. Clients receive helpdesk support for post-setup issues during business hours, with documentation of configurations for future reference.
 
Purpose: The purpose of Workstation Setup is to deliver fully operational workstations that support employee productivity and align with organizational IT standards. It ensures devices are secure, properly configured, and optimized for performance, reducing setup errors and delays. The service supports compliance with security and data protection regulations by implementing standardized configurations, enabling employees to focus on their roles without technical hindrances.
 
Risks of Not Implementing: Without professional Workstation Setup, improper configurations or missed security settings can expose devices to vulnerabilities, increasing the risk of malware, data breaches, or unauthorized access. Inconsistent setups may lead to performance issues or software incompatibilities, reducing employee efficiency and causing downtime. Lack of standardized configurations risks non-compliance with regulatory requirements, potentially resulting in penalties or reputational damage. Ad-hoc setups by untrained staff can also increase support costs and delay onboarding or system readiness.
 
Disclaimer: While Workstation Setup significantly enhances device readiness and security, no solution can eliminate all risks, such as user errors or evolving cyber threats. Adherence to provided configurations, timely reporting of issues, and complementary security practices are advised to maximize benefits. Certain complex setups may require additional specialized support, depending on the service plan.

Policies

All data transmitted over the Internet may be subject to malware and computer contaminants such as viruses, worms and trojan horses, as well as attempts by unauthorized users, such as hackers, to access or damage Client’s data. Neither Triada nor its designated affiliates will be responsible for the outcome or results of such activities.

BDR services require a reliable, always-connected internet solution. Data backup and recovery time will depend on the speed and reliability of your internet connection. Internet and telecommunications outages will prevent the BDR services from operating correctly. In addition, all computer hardware is prone to failure due to equipment malfunction, telecommunication-related issues, etc., for which we will be held harmless. Due to technology limitations, all computer hardware, including communications equipment, network servers and related equipment, has an error transaction rate that can be minimized, but not eliminated. Triada cannot and does not warrant that data corruption or loss will be avoided, and Client agrees that Triada shall be held harmless if such data corruption or loss occurs. Client is strongly advised to keep a local backup of all of stored data to mitigate against the unintentional loss of data.

Automated monitoring is provided on an ongoing (i.e., 24x7x365) basis. Response, repair, and/or remediation services (as applicable) will be provided only during our business hours (currently M-F, 9 AM – 5 PM Eastern Time, excluding legal holidays and Triada-observed holidays as listed below), unless otherwise specifically stated in the Proposal or as otherwise described below.

We will respond to problems, errors, or interruptions in the provision of the Services during business hours in the timeframe(s) described below. Severity levels will be determined by Triada in our discretion after consulting with the Client. All remediation services will initially be attempted remotely; Triada will provide onsite service only if remote remediation is ineffective and, under all circumstances, only if covered under the Service plan selected by Client.

Trouble / Severity Response Time
Critical / Service Not Available (e.g., all users and functions unavailable) Response within two (2) business hours after notification.
Significant Degradation (e.g., large number of users or business critical functions affected) Response within four (4) business hours after notification.
Limited Degradation (e.g., limited number of users or functions affected, business process can continue) Response within eight (8) business hours after notification.
Small Service Degradation (e.g., business process can continue, one user affected) Response within two (2) business days after notification.
Long Term Project, Preventative Maintenance Response within four (4) business days after notification.

All time frames are calculated as of the time that we are notified of the applicable issue/problem by Client through our designated support portal, help desk, or by telephone at the telephone number listed in the Proposal. Notifications received in any manner other than described herein may result in a delay in the provision of remediation efforts.

Support During Off-Hours/Non-Business Hours

Technical support provided outside of our normal business hours is offered on a case-by-case basis and is subject to technician availability. If Triada agrees to provide off-hours/non-business hours support (“Non-Business Hour Support”), then that support will be provided on a time and materials basis (which is not covered under any Service plan for non-emergency service), and will be billed to Client at the following increased hourly rates:

  • Project Professional Level 1: 1.5x normal rate
  • Project Professional Advanced: 1.5x normal rate
  • Support Technician, Level 1: 1.5x normal rate
  • Support Technician, Senior: 1.5x normal rate

All hourly services are billed in 15 minute increments, and partial increments are rounded to the next highest increment. A one (1) hour minimum applies to all Non-Business Hour Support.

Triada-Observed Holidays

Triada observes the following holidays:

  • New Year’s Day
  • Martin Luther King Jr. Day
  • President’s Day
  • Good Friday
  • Armenian Genocide Remembrance Day (April 24)
  • Memorial Day
  • Juneteenth National Independence Day
  • Independence Day
  • Labor Day
  • Thanksgiving Day
  • Christmas Eve – Half Day
  • Christmas Day
  • New Year’s Eve – Half Day

Everything in the managed environment must be genuine and licensed—including all hardware, software, etc. If we ask for proof of authenticity and/or licensing, you must provide us with such proof. All minimum hardware or software requirements as indicated in a Proposal or this Services Guide (“Minimum Requirements”) must be implemented and maintained as an ongoing requirement of us providing the Services to you.

Unless otherwise indicated in the Proposal, all monitoring and alert-type services are limited to detection and notification functionalities only. Monitoring levels will be set by Triada, and Client shall not modify these levels without our prior written consent.

Certain third party services provided to you under this Services Guide may provide you with administrative access through which you could modify the configurations, features, and/or functions (“Configurations”) of those services. However, any modifications of Configurations made by you without our knowledge or authorization could disrupt the Services and/or or cause a significant increase in the fees charged for those third party services. For that reason, we strongly advise you to refrain from changing the Configurations unless we authorize those changes. You will be responsible for paying any increased fees or costs arising from or related to changes to the Configurations.

Modification of Environment

Changes made to the Environment without our prior authorization or knowledge may have a substantial, negative impact on the provision and effectiveness of the Services and may impact the fees charged under the Proposal. You agree to refrain from moving, modifying, or otherwise altering any portion of the Environment without our prior knowledge or consent. For example, you agree to refrain from adding or removing hardware from the Environment, installing applications on the Environment, or modifying the configuration or log files of the Environment without our prior knowledge or consent.

Co-Managed Environment

In co-managed situations (e.g., where you have designated other vendors or personnel, or “Co-managed Providers,” to provide you with services that overlap or conflict with the Services provided by us), we will endeavor to implement the Services in an efficient and effective manner; however, (a) we will not be responsible for the acts or omissions of Co-Managed Providers, or the remediation of any problems, errors, or downtime associated with those acts or omissions, and (b) in the event that a Co-managed Provider’s determination on an issue differs from our position on a Service-related matter, we will yield to the Co-Managed Provider’s determination and bring that situation to your attention.

Breach/Cyber Security Incident Recovery

Unless otherwise expressly stated in the Proposal, the scope of the Services does not include the remediation and/or recovery from a Security Incident (defined below). Such services, if requested by you, will be provided on a time and materials basis under our then-current hourly labor rates. Given the varied number of possible Security Incidents, we cannot and do not warrant or guarantee (i) the amount of time required to remediate the effects of a Security Incident (or that recovery will be possible under all circumstances), or (ii) that all data or systems impacted by the incident will be recoverable or remediated. For the purposes of this paragraph, a Security Incident means any unauthorized or impermissible access to or use of the Environment, or any unauthorized or impermissible disclosure of Client’s confidential information (such as user names, passwords, etc.), that (i) compromises the security or privacy of the information or applications in, or the structure or integrity of, the managed environment, or (ii) prevents normal access to the managed environment, or impedes or disrupts the normal functions of the managed environment.

Environmental Factors

Exposure to environmental factors, such as water, heat, cold, or varying lighting conditions, may cause installed equipment to malfunction. Unless expressly stated in the Proposal, we do not warrant or guarantee that installed equipment will operate error-free or in an uninterrupted manner, or that any video or audio equipment will clearly capture and/or record the details of events occurring at or near such equipment under all circumstances.

Fair Usage Policy

Our Fair Usage Policy (“FUP”) applies to all services that are described or designated as “unlimited” or which are not expressly capped in the number of available usage hours per month. An “unlimited” service designation means that, subject to the terms of this FUP, you may use the applicable service as reasonably necessary for you to enjoy the use and benefit of the service without incurring additional time-based or usage-based costs. However, unless expressly stated otherwise in the Proposal, all unlimited services are provided during our normal business hours only and are subject to our technicians’ availabilities, which cannot always be guaranteed. In addition, we reserve the right to assign our technicians as we deem necessary to handle issues that are more urgent, critical, or pressing than the request(s) or issue(s) reported by you. Consistent with this FUP, you agree to refrain from (i) creating urgent support tickets for non-urgent or non-critical issues, (ii) requesting excessive support services that are inconsistent with normal usage patterns in the industry (e.g., requesting support in lieu of training), (iii) requesting support or services that are intended to interfere, or may likely interfere, with our ability to provide our services to our other customers.

Hosted Email

You are solely responsible for the proper use of any hosted email service provided to you (“Hosted Email”).

Hosted Email solutions are subject to acceptable use policies (“AUPs”), and your use of Hosted Email must comply with those AUPs—including ours. In all cases, you agree to refrain from uploading, posting, transmitting or distributing (or permitting any of your authorized users of the Hosted Email to upload, post, transmit or distribute) any prohibited content, which is generally content that (i) is obscene, illegal, or intended to advocate or induce the violation of any law, rule or regulation, or (ii) violates the intellectual property rights or privacy rights of any third party, or (iii) mischaracterizes you, and/or is intended to create a false identity or to otherwise attempt to mislead any person as to the identity or origin of any communication, or (iv) interferes or disrupts the services provided by Triada or the services of any third party, or (v) contains Viruses, trojan horses or any other malicious code or programs. In addition, you must not use the Hosted Email for the purpose of sending unsolicited commercial electronic messages (“SPAM”) in violation of any federal or state law. Triada reserves the right, but not the obligation, to suspend Client’s access to the Hosted Email and/or all transactions occurring under Client’s Hosted Email account(s) if Triada believes, in its discretion, that Client’s email account(s) is/are being used in an improper or illegal manner.

Patch Management

We will keep all managed hardware and managed software current with critical patches and updates (“Patches”) as those Patches are released generally by the applicable manufacturers. Patches are developed by third party vendors and, on rare occasions, may make the Environment, or portions of the Environment, unstable or cause the managed equipment or software to fail to function properly even when the Patches are installed correctly. We will not be responsible for any downtime or losses arising from or related to the installation or use of any Patch. We reserve the right, but not the obligation, to refrain from installing a Patch if we are aware of technical problems caused by a Patch, or we believe that a Patch may render the Environment, or any portion of the Environment, unstable.

Procurement

Equipment and software procured by Triada on Client’s behalf (“Procured Equipment”) may be covered by one or more manufacturer warranties, which will be passed through to Client to the greatest extent possible. By procuring equipment or software for Client, Triada does not make any warranties or representations regarding the quality, integrity, or usefulness of the Procured Equipment. Certain equipment or software, once purchased, may not be returnable or, in certain cases, may be subject to third party return policies and/or re-stocking fees, all of which shall be Client’s responsibility in the event that a return of the Procured Equipment is requested. Triada is not a warranty service or repair center. Triada will facilitate the return or warranty repair of Procured Equipment; however, Client understands and agrees that (i) the return or warranty repair of Procured Equipment is governed by the terms of the warranties (if any) governing the applicable Procured Equipment, for which Triada will be held harmless, and (ii) Triada is not responsible for the quantity, condition, or timely delivery of the Procured Equipment once the equipment has been tendered to the designated shipping or delivery courier.

Business Review / IT Strategic Planning Meetings

We strongly suggest that you participate in business review/strategic planning meetings as may requested by us from time to time. These meetings are intended to educate you about recommended (and potentially crucial) modifications to your IT environment, as well as to discuss your company’s present and future IT-related needs. These reviews can provide you with important insights and strategies to make your managed IT environment more efficient and secure. You understand that by suggesting a particular service or solution, we are not endorsing any specific manufacturer or service provider.

Fractional-CTO or Fractional-CIO Services or Fractional-CISO

The advice and suggestions provided us in our capacity as a fractional chief technology or information officer will be for your informational and/or educational purposes only. Triada will not hold an actual director or officer position in Client’s company, and we will neither hold nor maintain any fiduciary relationship with Client. Under no circumstances shall Client list or place Triada on Client’s corporate records or accounts. Some due diligence questionnaires may require a named CTO or CISO (Chief Information Security Officer). You must request approval in writing (email is sufficient) before doing so.

Return of Equipment owned by Triada

Within ten (10) days after being directed to do so, Client will remove, package and ship, at Client’s expense and in a commercially reasonable manner, all hardware, equipment, and accessories provided to Client by Triada that were used in the provision of the Services.  If you fail to timely return all equipment to us, or if the equipment is returned to us damaged (normal wear and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged equipment.

Removal of Software Agents

Unless we expressly direct you to do so, you will not remove or disable, or attempt to remove or disable, any software agents that we installed in the managed environment or any of the devices on which we installed software agents. Doing so without our guidance may make it difficult or impracticable to remove the software agents, which could result in network vulnerabilities and/or the continuation of license fees for the software agents for which you will be responsible, and/or the requirement that we remediate the situation at our then-current hourly rates, for which you will also be responsible. Depending on the particular software agent and the costs of removal, we may elect to keep the software agent in the managed environment but in a dormant and/or unused state.

Sample Policies, Procedures

From time to time, we may provide you with sample (i.e., template) policies and procedures for use in connection with Client’s business (“Sample Policies”). The Sample Policies are for your informational use only, and do not constitute or comprise legal or professional advice, and the policies are not intended to be a substitute for the advice of competent counsel. You should seek the advice of competent legal counsel prior to using or distributing the Sample Policies, in part or in whole, in any transaction. We do not warrant or guarantee that the Sample Policies are complete, accurate, or suitable for your (or your customers’) specific needs, or that you will reduce or avoid liability by utilizing the Sample Policies in your (or your customers’) business operations.

Penetration Testing; Vulnerability Assessment

You understand and agree that security devices, alarms, or other security measures, both physical and virtual, may be tripped or activated during the penetration testing process, despite our efforts to avoid such occurrences. You will be solely responsible for notifying any monitoring company and all law enforcement authorities of the potential for “false alarms” due to the provision of the penetration testing services, and you agree to take all steps necessary to ensure that false alarms are not reported or treated as “real alarms” or credible threats against any person, place or property. Some alarms and advanced security measures, when activated, may cause the partial or complete shutdown of the Environment, causing substantial downtime and/or delay to your business activities. We will not be responsible for any claims, costs, fees or expenses arising or resulting from (i) any response to the penetration testing services by any monitoring company or law enforcement authorities, or (ii) the partial or complete shutdown of the Environment by any alarm or security monitoring device.

Security Tools

Our security tools will generally protect the Environment from becoming infected with new viruses and malware (“Viruses”); however, Viruses that exist in the Environment at the time that the security solution is implemented may not be capable of being removed without additional services, for which a charge may be incurred. We do not warrant or guarantee that all Viruses and malware will be capable of being detected, avoided, or removed, or that any data erased, corrupted, or encrypted by malware will be recoverable. To improve security awareness, you agree that Triada or its designated third party affiliate may transfer information about the results of processed files, information used for URL reputation determination, security risk tracking, and statistics for protection against spam and malware. Any information obtained in this manner does not and will not contain any personal or confidential information.

No Third Party Scanning

Unless we authorize such activity in writing, you will not conduct any test, nor request or allow any third party to conduct any test (diagnostic or otherwise), of the security system, protocols, processes, or solutions that we implement in the managed environment (“Testing Activity”). Any services required to diagnose or remediate errors, issues, or problems arising from unauthorized Testing Activity are not covered under the Proposal, and if you request us (and we elect) to perform those services, those services will be billed to you at our then-current hourly rates.

Obsolescence

If at any time any portion of the managed environment becomes outdated, obsolete, reaches the end of its useful life, or acquires “end of support” status from the applicable device’s or software’s manufacturer (“Obsolete Element”), then we may designate the device or software as “unsupported” or “non-standard” and require you to update the Obsolete Element within a reasonable time period. If you do not replace the Obsolete Element reasonably promptly, then in our discretion we may (i) continue to provide the Services to the Obsolete Element using our “best efforts” only with no warranty or requirement of remediation whatsoever regarding the operability or functionality of the Obsolete Element, or (ii) eliminate the Obsolete Element from the scope of the Services by providing written notice to you (email is sufficient for this purpose). In any event, we make no representation or warranty whatsoever regarding any Obsolete Element or the deployment, service level guarantees, or remediation activities for any Obsolete Element.

Licenses

If we are required to re-install or replicate any software provided by you as part of the Services, then it is your responsibility to verify that all such software is properly licensed. We reserve the right, but not the obligation, to require proof of licensing before installing, re-installing, or replicating software into the managed environment. The cost of acquiring licenses is not included in the scope of the Proposal unless otherwise expressly stated therein.

Regardless of the reason for the termination of the Services, you will be required to pay for all per seat licenses (such as, if applicable, Microsoft NCE licenses) that we acquire on your behalf.

VOIP – Dialing 911 (Emergency) Services

The following terms and conditions apply to your use of any VoIP service that we facilitate for you or that is provided to you by a third party provider of such service. Please note, by using VoIP services you agree to the provisions of the waiver at the end of this section. If you do not understand or do not agree with any of the terms below, you must not subscribe to, use, or rely upon any VoIP service and, instead, you must contact us immediately.

There is an important difference in how 9-1-1 (i.e., emergency) services can be dialed using a VoIP service as compared to a traditional telephone line. Calling emergency services using a VoIP service is referred to as “E911.”

Registration: You are responsible for activating the E911 dialing feature by registering the address where you will use the VoIP service. This will not be done for you, and you must take this step on your own initiative. To do this, you must log into your VoIP control panel and provide a valid physical address. If you do not take this step, then E911 services may not work correctly, or at all, using the VoIP service. Emergency service dispatchers will only send emergency personnel to a properly registered E911 service address.

Location: The address you provide in the control panel is the location to which emergency services (such as the fire department, the police department, etc.) will respond. For this reason, it is important that you correctly enter the location at which you are using the VoIP services. PO boxes are not proper addresses for registration and must not be used as your registered address. Please note, even if your account is properly registered with a correct physical address, (i) there may be a problem automatically transmitting a caller’s physical location to the emergency responders, even if the caller can reach the 911 call center, and (ii) a VoIP 911 call may go to an unstaffed call center administrative line or be routed to a call center in the wrong location. These issues are inherent to all VoIP systems and services. We will not be responsible for, and you agree to hold us harmless from, any issues, problems, incidents, damages (both bodily- and property-related), costs, expenses, and fees arising from or related to your failure to register timely and correctly your physical location information into the control panel.

Address Change(s): If you change the address used for E911 calling, the E911 services may not be available and/or may operate differently than expected. Moreover, if you do not properly and promptly register a change of address, then emergency services may be directed to the location where your services are registered and not where the emergency may be occurring. For that reason, you must register a change of address with us through the VoIP control panel no less than three (3) business days prior to your anticipated move/address change. Address changes that are provided to us with less than three (3) business days notice may cause incorrect/outdated information to be conveyed to emergency service personnel. If you are unable to provide us with at least three (3) business days notice of an address change, then you should not rely on the E911 service to provide correct physical location information to emergency service personnel. Under those circumstances, you must provide your correct physical location to emergency service dispatchers if you call them using the VoIP services.

If you do not register the VoIP service at your location and you dial 9-1-1, that call will be categorized as a “rogue 911 call.” If you are responsible for dialing a rogue 911 call, you will be charged a non-refundable and non-disputable fee of $250/call.

Power Loss: If you lose power or there is a disruption to power at the location where the VoIP services are used, then the E911 calling service will not function until power is restored. You should also be aware that after a power failure or disruption, you may need to reset or reconfigure the device prior to utilizing the service, including E911 dialing.

Internet Disruption: If your internet connection or broadband service is lost, suspended, terminated or disrupted, E911 calling will not function until the internet connection and/or broadband service is restored.

Account Suspension: If your account is suspended or terminated, then all E911 dialing services will not function.

Network Congestion: There may be a greater possibility of network congestion and/or reduced speed in the routing of E911 calls as compared to 911 dialing over traditional public telephone networks.

WAIVER: You hereby agree to release, indemnify, defend, and hold us and our officers, directors, representatives, agents, and any third party service provider that furnishes VoIP-related services to you, harmless from any and all claims, damages, losses, suits or actions, fines, penalties, costs and expenses (including, but not limited to, attorneys’ fees), whether suffered, made, instituted or asserted by you or by any other party or person (collectively, “Claims”) arising from or related to the VoIP services, including but not limited to any failure or outage of the VoIP services, incorrect routing or use of, or any inability to use, E911 dialing features. The foregoing waiver and release shall not apply to Claims arising from our gross negligence, recklessness, or willful misconduct.